> virtio_gpu_deinit() calls mutex_destroy() on obj_restore_lock, but
> deinit runs from virtio_gpu_remove() at unbind or PCI remove, and GEM
> objects can outlive that. An open /dev/fb0 keeps the fbdev buffer
> alive, and the fbdev DRM client holds a drm_device reference. When the
> fd is finally closed, the buffer is freed and takes the destroyed lock:
>
> fb_release()
> drm_fbdev_shmem_fb_destroy()
> drm_client_buffer_delete()
> virtio_gpu_free_object()
> virtio_gpu_remove_from_restore_list()
> mutex_lock(&vgdev->obj_restore_lock)
>
> DEBUG_LOCKS_WARN_ON(lock->magic != lock)
> WARNING: kernel/locking/mutex.c:625 at __mutex_lock+0xf2c/0x12ec
> [ ... ]
> Fixes: 54a970048296 ("drm/virtio: Add support for saving and restoring
> virtio_gpu_objects")
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=3590d97d8a586fa955c2
> Assisted-by: LLM
> Signed-off-by: Abhin Parekadan Jose <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review ยท
https://sashiko.dev/#/patchset/[email protected]?part=1