Re: [PATCH] drm/xe/oa: Fix sync entry leak on OA config emit failure

From: Dixit, Ashutosh

Date: Thu Jul 30 2026 - 18:20:41 EST


On Tue, 14 Jul 2026 19:33:32 -0700, Linmao Li wrote:
>

Hi Linmao,

Sorry for the delay in responding to this patch.

> xe_oa_emit_oa_config() releases the sync entries and the syncs array
> only on its success path. When it fails before the point of no return
> (fence allocation, config buffer allocation or batch submission), it
> returns without touching stream->syncs.
>
> The stream open path handles such failures in the caller, but
> xe_oa_config_locked() propagates the error without any cleanup, so the
> syncs array and the fence references held by the parsed entries are
> leaked. The next config ioctl overwrites stream->syncs, making the
> memory unreachable for good.
>
> Clean up the parsed syncs when xe_oa_emit_oa_config() fails, matching
> the cleanup done by the stream open error path, and reset the stream
> sync state so it does not point at freed entries.
>
> Fixes: 9920c8b88c5c ("drm/xe/oa: Add syncs support to OA config ioctl")
> Signed-off-by: Linmao Li <lilinmao@xxxxxxxxxx>
> ---
> drivers/gpu/drm/xe/xe_oa.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/drivers/gpu/drm/xe/xe_oa.c b/drivers/gpu/drm/xe/xe_oa.c
> index 2dce6a47202c..b1ce312ea97a 100644
> --- a/drivers/gpu/drm/xe/xe_oa.c
> +++ b/drivers/gpu/drm/xe/xe_oa.c
> @@ -1594,6 +1594,12 @@ static long xe_oa_config_locked(struct xe_oa_stream *stream, u64 arg)
> config = xchg(&stream->oa_config, config);
> drm_dbg(&stream->oa->xe->drm, "changed to oa config uuid=%s\n",
> stream->oa_config->uuid);
> + } else {
> + while (param.num_syncs--)
> + xe_sync_entry_cleanup(&param.syncs[param.num_syncs]);
> + kfree(param.syncs);
> + stream->num_syncs = 0;
> + stream->syncs = NULL;

Yes this looks correct to me. Except that we don't need the two lines
above. Can you please resend a v2 deleting the above two lines.

Thanks for the patch,
Ashutosh

> }
>
> err_config_put:
> --
> 2.25.1
>