Re: [PATCH 1/2] drm/loongson: Fix double free on BO initialization failure
From: wuqianhai
Date: Fri Oct 09 2026 - 05:37:59 EST
Reviewed-by: Qianhai Wu <wuqianhai@xxxxxxxxxxx>
The fix looks correct and the TTM ownership analysis is accurate.
Thanks,
Qianhai Wu
在 2026/10/9 16:42, Icenowy Zheng 写道:
在 2026-10-03六的 09:34 +0000,Evanshenf写道:
If ttm_bo_init_validate() fails, it drops the buffer object's
reference
and cleans it up through the supplied destroy callback.
lsdc_bo_destroy()
releases the GEM object and frees the enclosing lsdc_bo, so freeing
it
again in lsdc_bo_create() causes a double free on a synchronous
failure
path.
Let TTM own the cleanup after initialization has started and return
the
error directly. Keep the explicit free on drm_gem_object_init()
failure,
which occurs before ownership is passed to TTM.
Tested on LS7A2000 by making drm_vma_offset_add() return -ENOSPC for
one
selected dumb-buffer creation. The error reached userspace, the
destroy
callback ran once, and no handle was published or tracked BO
retained.
Normal buffer creation, zeroing, mapping, readback and release
passed.
AI assistance was used for the ownership analysis, fix, fault-
injection
tools, build and test execution.
Fixes: f39db26c5428 ("drm: Add kms driver for loongson display
controller")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Evanshenf <archwse@xxxxxxxxx>
---
drivers/gpu/drm/loongson/lsdc_ttm.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/loongson/lsdc_ttm.c
b/drivers/gpu/drm/loongson/lsdc_ttm.c
index d7441d9..88536e2 100644
--- a/drivers/gpu/drm/loongson/lsdc_ttm.c
+++ b/drivers/gpu/drm/loongson/lsdc_ttm.c
@@ -475,10 +475,8 @@ struct lsdc_bo *lsdc_bo_create(struct drm_device
*ddev,
ret = ttm_bo_init_validate(bdev, tbo, bo_type, &lbo-placement, 0,false, sg, resv,
lsdc_bo_destroy);
- if (ret) {
- kfree(lbo);
+ if (ret)
return ERR_PTR(ret);
It looks like this fix is valid, ttm_bo_init_reserved() (called by
ttm_bo_init_validate() ) will do a ttm_bo_put() operation when failure,
which leads to calling the destroy callback.
```
Reviewed-by: Icenowy Zheng <zhengxingda@xxxxxxxxxxx>
```
Thanks,
Icenowy
- }
return lbo;
}
base-commit: bca45af5998a05f34b13a2ef11e639bac9c62643