On Wed, Sep 16, 2026 at 10:58 AM Wentao Liang <[email protected]> wrote:
>
> dsi_tx_buf_alloc_6g() takes a reference to the kms VM with
> drm_gpuvm_get() and stores it in msm_host->vm.  If
> msm_gem_kernel_new() fails, the function returns early without
> dropping that reference.  Since msm_host->tx_gem_obj is cleared on
> the error path, msm_dsi_tx_buf_free() will never see a non-NULL
> tx_gem_obj and thus never calls drm_gpuvm_put(), leaking the VM
> reference.
>
> Drop the VM reference and clear msm_host->vm on the error path.
>
> Fixes: 5e05be782645 ("drm/msm/dsi: free TX buffer in unbind")
> Cc: [email protected]
> Signed-off-by: Wentao Liang <[email protected]>

Reviewed-by: Rob Clark <[email protected]>

> ---
>  drivers/gpu/drm/msm/dsi/dsi_host.c | 2 ++
>  1 file changed, 2 insertions(+)
>
> diff --git a/drivers/gpu/drm/msm/dsi/dsi_host.c 
> b/drivers/gpu/drm/msm/dsi/dsi_host.c
> index 982abaaac00d..29e0de0e0c22 100644
> --- a/drivers/gpu/drm/msm/dsi/dsi_host.c
> +++ b/drivers/gpu/drm/msm/dsi/dsi_host.c
> @@ -1250,6 +1250,8 @@ int dsi_tx_buf_alloc_6g(struct msm_dsi_host *msm_host, 
> int size)
>
>         if (IS_ERR(data)) {
>                 msm_host->tx_gem_obj = NULL;
> +               drm_gpuvm_put(msm_host->vm);
> +               msm_host->vm = NULL;
>                 return PTR_ERR(data);
>         }
>
> --
> 2.34.1
>

Reply via email to