]> git.hungrycats.org Git - linux/commitdiff
drm/xe/hw_engine: Fix double-free of managed BO in error path
authorShuicheng Lin <shuicheng.lin@intel.com>
Fri, 26 Jun 2026 21:06:31 +0000 (21:06 +0000)
committerShuicheng Lin <shuicheng.lin@intel.com>
Mon, 29 Jun 2026 22:22:43 +0000 (15:22 -0700)
The error path in hw_engine_init() explicitly frees a BO allocated
with xe_managed_bo_create_pin_map() via xe_bo_unpin_map_no_vm().
Since the managed BO already has a devm cleanup action registered,
this causes a double-free when devm unwinds during probe failure.

Remove the explicit free and let devm handle it, consistent with
all other xe_managed_bo_create_pin_map() callers.

Fixes: 0e1a47fcabc8 ("drm/xe: Add a helper for DRM device-lifetime BO create")
Assisted-by: Claude:claude-opus-4.6
Reviewed-by: Zongyao Bai <zongyao.bai@intel.com>
Link: https://patch.msgid.link/20260626210631.3887291-1-shuicheng.lin@intel.com
Signed-off-by: Shuicheng Lin <shuicheng.lin@intel.com>
drivers/gpu/drm/xe/xe_hw_engine.c

index 76aee461bcbe08b327a890d32d0365f430f2d3a5..87d60c4117bd8eaf61dfa5134cfe3c4c089c12cd 100644 (file)
@@ -636,7 +636,7 @@ static int hw_engine_init(struct xe_gt *gt, struct xe_hw_engine *hwe,
                hwe->exl_port = xe_execlist_port_create(xe, hwe);
                if (IS_ERR(hwe->exl_port)) {
                        err = PTR_ERR(hwe->exl_port);
-                       goto err_hwsp;
+                       goto err_name;
                }
        } else {
                /* GSCCS has a special interrupt for reset */
@@ -656,8 +656,6 @@ static int hw_engine_init(struct xe_gt *gt, struct xe_hw_engine *hwe,
 
        return devm_add_action_or_reset(xe->drm.dev, hw_engine_fini, hwe);
 
-err_hwsp:
-       xe_bo_unpin_map_no_vm(hwe->hwsp);
 err_name:
        hwe->name = NULL;