Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues: - [High] The timeout loop in drm_gpusvm_range_evict can return 0 (success) without doing any work, or return -EBUSY instead of -ETIME on timeout. -- --- Patch [1]: [PATCH] drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict --- commit 288b0fd8ba30a0ce9832357a667252b6d60749ce Author: Matthew Brost <[email protected]> Subject: drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict This commit fixes a reference leak in drm_gpusvm_range_evict(). It drops the MM reference on the kvmalloc_array() failure path. > diff --git a/drivers/gpu/drm/drm_gpusvm.c b/drivers/gpu/drm/drm_gpusvm.c > index 958cb605aedd5..9e02a33659d43 100644 > --- a/drivers/gpu/drm/drm_gpusvm.c > +++ b/drivers/gpu/drm/drm_gpusvm.c > @@ -1732,8 +1732,10 @@ int drm_gpusvm_range_evict(struct drm_gpusvm *gpusvm, > return -EFAULT; > > pfns = kvmalloc_array(npages, sizeof(*pfns), GFP_KERNEL); > - if (!pfns) > + if (!pfns) { > + mmput(mm); > return -ENOMEM; > + } > > hmm_range.hmm_pfns = pfns; > while (!time_after(jiffies, timeout)) { [Severity: High] This is a pre-existing issue, but can this loop return 0 (success) without doing any work if the timeout expires during the memory allocation? The timeout is computed before calling kvmalloc_array() with GFP_KERNEL. If memory pressure causes the allocation to block longer than the timeout, this loop condition will evaluate to false immediately, and the function will exit returning err = 0. Additionally, if hmm_range_fault() returns -EBUSY and the timeout is subsequently reached, the loop terminates here and incorrectly returns -EBUSY rather than -ETIME. Would it be safer to compute the timeout after the kvmalloc_array() call, or check the expiration condition after the loop to ensure the correct error code is returned? -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=1
