On Thu, 30 Jul 2026 18:19:32 -0700, Linmao Li wrote:
>
> xe_oa_emit_oa_config() releases the sync entries and the syncs array
> only on its success path. When it fails before the point of no return
> (fence allocation, config buffer allocation or batch submission), it
> returns without touching stream->syncs.
>
> The stream open path handles such failures in the caller, but
> xe_oa_config_locked() propagates the error without any cleanup, so the
> syncs array and the fence references held by the parsed entries are
> leaked. The next config ioctl overwrites stream->syncs, making the
> memory unreachable for good.
>
> Clean up the parsed syncs when xe_oa_emit_oa_config() fails, matching
> the cleanup done by the stream open error path.
>
> Fixes: 9920c8b88c5c ("drm/xe/oa: Add syncs support to OA config ioctl")
> Signed-off-by: Linmao Li <[email protected]>
> ---
> v2:
> - drop the stream->syncs/num_syncs reset; nothing dereferences them
> before they are overwritten or the stream is destroyed (Ashutosh Dixit)
>
> drivers/gpu/drm/xe/xe_oa.c | 4 ++++
> 1 file changed, 4 insertions(+)
>
> diff --git a/drivers/gpu/drm/xe/xe_oa.c b/drivers/gpu/drm/xe/xe_oa.c
> index b3acbcd678b7c..d334ce8fed1c2 100644
> --- a/drivers/gpu/drm/xe/xe_oa.c
> +++ b/drivers/gpu/drm/xe/xe_oa.c
> @@ -1594,6 +1594,10 @@ static long xe_oa_config_locked(struct xe_oa_stream
> *stream, u64 arg)
> config = xchg(&stream->oa_config, config);
> drm_dbg(&stream->oa->xe->drm, "changed to oa config uuid=%s\n",
> stream->oa_config->uuid);
> + } else {
> + while (param.num_syncs--)
> + xe_sync_entry_cleanup(¶m.syncs[param.num_syncs]);
> + kfree(param.syncs);
> }
Reviewed-by: Ashutosh Dixit <[email protected]>
Thanks for the patch Linmao, we'll get it merged.
Thanks.
--
Ashutosh
>
> err_config_put:
> --
> 2.25.1
>