> virtio_gpu_queue_ctrl_sgs() drops the command when drm_dev_enter() fails
> or when vqs_released is set. It unlocks the reservation and frees the
> vbuf, but never releases the references that the caller handed over in
> vbuf->objs. Those references are normally dropped from the dequeue path,
> which never sees a command that was not queued.
> 
> If a framebuffer flush races with device removal, the GEM object backing
> the fbdev buffer keeps a stale reference, is never freed, and its node is
> still in the vma offset manager when the drm_device is released:
> 
>   Memory manager not clean during takedown.
>   WARNING: drivers/gpu/drm/drm_mm.c:965 at drm_mm_takedown
>   Call Trace:
>    drm_managed_release
>    drm_dev_put
>    virtio_dev_remove
>    virtio_pci_remove
>    pci_device_remove
>    remove_store
> 
> Drop the object references together with the vbuf on both early-exit
> paths.
> 
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=d93b9064fe5f74af3aa3
> Fixes: b7170f9457f2 ("drm/virtio: return virtio_gpu_queue errors")
> Signed-off-by: Nguyen Ngoc Thang <[email protected]>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=1

Reply via email to