[PATCH v3 1/5] drm/nouveau: Fix cleanup bug in nouveau_drm_device_new()
From: Lyude Paul
Date: Thu Jul 30 2026 - 16:37:53 EST
Sashiko caught this while reviewing the patches for enabling atomic by
default - if we fail to allocate the DRM device pointer, we'll attempt to
free the error pointer that it returns rather than the actual struct.
Let's fix this while we're at it.
Signed-off-by: Lyude Paul <lyude@xxxxxxxxxx>
---
V3:
* Don't use devm, that will just break during unbind (Sashiko).
drivers/gpu/drm/nouveau/nouveau_drm.c | 28 +++++++++++++++------------
1 file changed, 16 insertions(+), 12 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nouveau_drm.c b/drivers/gpu/drm/nouveau/nouveau_drm.c
index 4d1ad718e09b7..3dfe21cd4bde4 100644
--- a/drivers/gpu/drm/nouveau/nouveau_drm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
@@ -749,7 +749,7 @@ nouveau_drm_device_new(const struct drm_driver *drm_driver, struct device *paren
drm->dev = drm_dev_alloc(drm_driver, parent);
if (IS_ERR(drm->dev)) {
ret = PTR_ERR(drm->dev);
- goto done;
+ goto err_free_drm;
}
drm->dev->dev_private = drm;
@@ -762,39 +762,43 @@ nouveau_drm_device_new(const struct drm_driver *drm_driver, struct device *paren
ret = nvif_driver_init(NULL, nouveau_config, nouveau_debug, "drm",
nouveau_name(drm->dev), &drm->_client);
if (ret)
- goto done;
+ goto err_device_del;
ret = nvif_device_ctor(&drm->_client, "drmDevice", &drm->device);
if (ret) {
NV_ERROR(drm, "Device allocation failed: %d\n", ret);
- goto done;
+ goto err_device_del;
}
ret = nvif_device_map(&drm->device);
if (ret) {
NV_ERROR(drm, "Failed to map PRI: %d\n", ret);
- goto done;
+ goto err_device_del;
}
ret = nvif_mclass(&drm->device.object, mmus);
if (ret < 0) {
NV_ERROR(drm, "No supported MMU class\n");
- goto done;
+ goto err_device_del;
}
ret = nvif_mmu_ctor(&drm->device.object, "drmMmu", mmus[ret].oclass, &drm->mmu);
if (ret) {
NV_ERROR(drm, "MMU allocation failed: %d\n", ret);
- goto done;
+ goto err_device_del;
}
-done:
- if (ret) {
- nouveau_drm_device_del(drm);
- drm = NULL;
- }
+ return 0;
+
+err_free_drm:
+ kfree(drm);
+
+ return ERR_PTR(ret);
+
+err_device_del:
+ nouveau_drm_device_del(drm);
- return ret ? ERR_PTR(ret) : drm;
+ return ERR_PTR(ret);
}
/*
--
2.55.0