> virtio_gpu_queue_ctrl_sgs() drops the command when drm_dev_enter() fails > or when vqs_released is set. It unlocks the reservation and frees the > vbuf, but never releases the references that the caller handed over in > vbuf->objs. Those references are normally dropped from the dequeue path, > which never sees a command that was not queued. > > If a framebuffer flush races with device removal, the GEM object backing > the fbdev buffer keeps a stale reference, is never freed, and its node is > still in the vma offset manager when the drm_device is released: > > Memory manager not clean during takedown. > WARNING: drivers/gpu/drm/drm_mm.c:965 at drm_mm_takedown > Call Trace: > drm_managed_release > drm_dev_put > virtio_dev_remove > virtio_pci_remove > pci_device_remove > remove_store > > Drop the object references together with the vbuf on both early-exit > paths. > > Reported-by: [email protected] > Closes: https://syzkaller.appspot.com/bug?extid=d93b9064fe5f74af3aa3 > Fixes: b7170f9457f2 ("drm/virtio: return virtio_gpu_queue errors") > Signed-off-by: Nguyen Ngoc Thang <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=1
