[PATCH] drm/qxl: use correct offset when stamping drawable mm_time
From: Aldo Ariel Panzardo
Date: Wed Sep 23 2026 - 11:25:40 EST
qxl_process_single_command() maps the page containing the current
release slot and copies the userspace command into it at the
release_offset within the page:
fb_cmd = qxl_bo_kmap_atomic_page(qdev, cmd_bo,
(release->release_offset & PAGE_MASK));
copy_from_user(fb_cmd + sizeof(union qxl_release_info) +
(release->release_offset & ~PAGE_MASK), ...);
However, the subsequent mm_time stamp casts the page-start pointer
directly:
struct qxl_drawable *draw = fb_cmd;
draw->mm_time = qdev->rom->mm_clock;
This writes mm_time into the release_info header or whatever sits
at the page start rather than into the drawable that was just
copied. Apply the same offset so mm_time lands in the right place.
Fixes: f64122c1f6ad ("drm: add new QXL driver. (v1.4)")
Cc: stable@xxxxxxxxxxxxxxx
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>
---
diff --git a/drivers/gpu/drm/qxl/qxl_ioctl.c b/drivers/gpu/drm/qxl/qxl_ioctl.c
index 591b026..e7594d1 100644
--- a/drivers/gpu/drm/qxl/qxl_ioctl.c
+++ b/drivers/gpu/drm/qxl/qxl_ioctl.c
@@ -188,7 +188,9 @@ static int qxl_process_single_command(struct qxl_device *qdev,
u64_to_user_ptr(cmd->command), cmd->command_size);
{
- struct qxl_drawable *draw = fb_cmd;
+ struct qxl_drawable *draw = fb_cmd +
+ sizeof(union qxl_release_info) +
+ (release->release_offset & ~PAGE_MASK);
draw->mm_time = qdev->rom->mm_clock;
}
--
2.43.0