Re: [PATCH] drm/virtio: reject mappable HOST3D blobs without host-visible memory

From: Dmitry Osipenko

Date: Sat Oct 10 2026 - 16:19:51 EST


On 10/10/26 11:10, Henry Martin wrote:
> virtio_gpu_resource_create_blob_ioctl() -> verify_blob() validates
> blob flags, memory type, context and alignment, but never checks
> VIRTGPU_BLOB_FLAG_USE_MAPPABLE against vgdev->has_host_visible.
>
> For blob_mem == VIRTGPU_BLOB_MEM_HOST3D the blob is created via
> virtio_gpu_vram_create(), and on a device without host-visible
> memory (plain virtio-gpu-pci,blob=on with no hostmem) the failure
> comes too late: the GEM object has been allocated, a host resource
> id taken and the create_blob command issued when
> virtio_gpu_vram_map() returns -EINVAL, and the cleanup calls
> virtio_gpu_vram_free(), which is a no-op while bo->created is still
> false (the host response has not been processed yet). Every such

virtio_gpu_cmd_resource_create_blob() is invoked before
virtio_gpu_vram_map() in virtio_gpu_vram_create(), hence bo->created is
always true, how come it's false?

--
Best regards,
Dmitry