> virtio_gpu_alloc_vbufs() creates a kmem_cache with the fixed name
> "virtio-gpu-vbufs" for every device and destroys it from
> virtio_gpu_release(), which only runs once the last drm_device
> reference is dropped. If a reference outlives the PCI removal (for
> instance an open /dev/fbN), a rescan probes the device again while the
> old cache still exists:
> 
>   kmem_cache of name 'virtio-gpu-vbufs' already exists
>   WARNING: mm/slab_common.c:111 at __kmem_cache_create_args
>   Call Trace:
>    virtio_gpu_alloc_vbufs
>    virtio_gpu_init
>    virtio_gpu_probe
>    ...
>    pci_rescan_bus
>    rescan_store
> 
> kmem_cache_create() then fails and the new device does not probe.
> 
> A vbuf is 216 bytes and lands in kmalloc-256 anyway, so the dedicated
> cache buys nothing. Use kzalloc()/kfree() and drop the per-device cache.
> 
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=1b129b44597a126d2d79
> Fixes: dc5698e80cf7 ("Add virtio gpu driver.")
> Signed-off-by: Nguyen Ngoc Thang <[email protected]>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=1

Reply via email to