Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:

Pre-existing issues:
- [High] The timeout loop in drm_gpusvm_range_evict can return 0 (success) 
without doing any work, or return -EBUSY instead of -ETIME on timeout.
--

--- Patch [1]: [PATCH] drm/gpusvm: Fix MM reference leak in 
drm_gpusvm_range_evict ---
commit 288b0fd8ba30a0ce9832357a667252b6d60749ce
Author: Matthew Brost <[email protected]>
Subject: drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict

This commit fixes a reference leak in drm_gpusvm_range_evict(). It drops the
MM reference on the kvmalloc_array() failure path.

> diff --git a/drivers/gpu/drm/drm_gpusvm.c b/drivers/gpu/drm/drm_gpusvm.c
> index 958cb605aedd5..9e02a33659d43 100644
> --- a/drivers/gpu/drm/drm_gpusvm.c
> +++ b/drivers/gpu/drm/drm_gpusvm.c
> @@ -1732,8 +1732,10 @@ int drm_gpusvm_range_evict(struct drm_gpusvm *gpusvm,
>               return -EFAULT;
>  
>       pfns = kvmalloc_array(npages, sizeof(*pfns), GFP_KERNEL);
> -     if (!pfns)
> +     if (!pfns) {
> +             mmput(mm);
>               return -ENOMEM;
> +     }
>  
>       hmm_range.hmm_pfns = pfns;
>       while (!time_after(jiffies, timeout)) {

[Severity: High]
This is a pre-existing issue, but can this loop return 0 (success) without
doing any work if the timeout expires during the memory allocation?

The timeout is computed before calling kvmalloc_array() with GFP_KERNEL. If
memory pressure causes the allocation to block longer than the timeout,
this loop condition will evaluate to false immediately, and the function
will exit returning err = 0.

Additionally, if hmm_range_fault() returns -EBUSY and the timeout is
subsequently reached, the loop terminates here and incorrectly returns
-EBUSY rather than -ETIME.

Would it be safer to compute the timeout after the kvmalloc_array() call,
or check the expiration condition after the loop to ensure the correct error
code is returned?

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=1

Reply via email to