On Tuesday, July 14, 2026 10:19 PM Guangshuo Li wrote:
> tegra_bo_alloc_object() allocates bo and passes its embedded GEM object
> to drm_gem_object_init().
>
> drm_gem_object_init() initializes the GEM private state before creating
> the shmem backing file. If the file creation fails, it returns an error
> with the reservation object and GPUVA mutex still initialized.
>
> The current error path directly frees bo, bypassing the matching GEM
> private-object cleanup. Finalize the partially initialized GEM object
> with drm_gem_private_object_fini() before freeing bo.
>
> This issue was found by a static analysis tool I am developing.
>
> Fixes: c28d4a317fef ("drm/tegra: gem: Extract tegra_bo_alloc_object()")
> Signed-off-by: Guangshuo Li <[email protected]>
> ---
> drivers/gpu/drm/tegra/gem.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/gpu/drm/tegra/gem.c b/drivers/gpu/drm/tegra/gem.c
> index 436394e04812..eb513cb7521c 100644
> --- a/drivers/gpu/drm/tegra/gem.c
> +++ b/drivers/gpu/drm/tegra/gem.c
> @@ -314,8 +314,10 @@ static struct tegra_bo *tegra_bo_alloc_object(struct
> drm_device *drm,
> size = round_up(size, PAGE_SIZE);
>
> err = drm_gem_object_init(drm, &bo->gem, size);
> - if (err < 0)
> + if (err < 0) {
> + drm_gem_private_object_fini(&bo->gem);
> goto free;
> + }
>
> err = drm_gem_create_mmap_offset(&bo->gem);
> if (err < 0)
> --
> 2.43.0
>
>
This looks correct, but a quick analysis shows a lot of drivers have
the same issue. I think it'd be a good idea to either
1. Fix drm_gem_object_init to clean up after itself (and update
callers accordingly)
or
2. Fix the same issue at other call sites of drm_gem_object_init
as well in one go.
In any case,
Reviewed-by: Mikko Perttunen <[email protected]>
Thank you
Mikko