On Tuesday, July 14, 2026 10:19 PM Guangshuo Li wrote:
> tegra_bo_alloc_object() allocates bo and passes its embedded GEM object
> to drm_gem_object_init().
> 
> drm_gem_object_init() initializes the GEM private state before creating
> the shmem backing file. If the file creation fails, it returns an error
> with the reservation object and GPUVA mutex still initialized.
> 
> The current error path directly frees bo, bypassing the matching GEM
> private-object cleanup. Finalize the partially initialized GEM object
> with drm_gem_private_object_fini() before freeing bo.
> 
> This issue was found by a static analysis tool I am developing.
> 
> Fixes: c28d4a317fef ("drm/tegra: gem: Extract tegra_bo_alloc_object()")
> Signed-off-by: Guangshuo Li <[email protected]>
> ---
>  drivers/gpu/drm/tegra/gem.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/gpu/drm/tegra/gem.c b/drivers/gpu/drm/tegra/gem.c
> index 436394e04812..eb513cb7521c 100644
> --- a/drivers/gpu/drm/tegra/gem.c
> +++ b/drivers/gpu/drm/tegra/gem.c
> @@ -314,8 +314,10 @@ static struct tegra_bo *tegra_bo_alloc_object(struct 
> drm_device *drm,
>       size = round_up(size, PAGE_SIZE);
>  
>       err = drm_gem_object_init(drm, &bo->gem, size);
> -     if (err < 0)
> +     if (err < 0) {
> +             drm_gem_private_object_fini(&bo->gem);
>               goto free;
> +     }
>  
>       err = drm_gem_create_mmap_offset(&bo->gem);
>       if (err < 0)
> -- 
> 2.43.0
> 
> 

This looks correct, but a quick analysis shows a lot of drivers have
the same issue. I think it'd be a good idea to either

1. Fix drm_gem_object_init to clean up after itself (and update
   callers accordingly)

or

2. Fix the same issue at other call sites of drm_gem_object_init
   as well in one go.

In any case,

Reviewed-by: Mikko Perttunen <[email protected]>

Thank you
Mikko


Reply via email to