Re: [PATCH v2 1/3] drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op
| Newsgroups | org.freedesktop.lists.nouveau,org.freedesktop.lists.dri-devel,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
Reviewed-by: Lyude Paul <[email protected]> On Tue, 2026-08-11 at 16:46 +0800, Zhenhao Wan wrote: > Each bind_job_op is zeroed by kzalloc_obj() in > bind_job_op_from_uop(), > and the OP_MAP_SPARSE case in nouveau_uvmm_bind_job_submit() only > creates > a region, so op->ops stays NULL for a successfully processed sparse > map. > > If a later op in the same job fails, the reverse unwind loop revisits > that > op and calls drm_gpuva_ops_free(&uvmm->base, op->ops) > unconditionally. > drm_gpuva_ops_free() dereferences its argument right away > (list_for_each_entry_safe on &ops->list), so a NULL op->ops oopses. > The > path is reachable by any render-node fd holder, since NOUVEAU_VM_BIND > is > DRM_RENDER_ALLOW. > > Guard the free with IS_ERR_OR_NULL(), as > nouveau_uvmm_bind_job_cleanup() > already does for the identical free. > > Fixes: b88baab82871 ("drm/nouveau: implement new VM_BIND uAPI") > Reported-by: Yuhao Jiang <[email protected]> > Assisted-by: Claude:claude-opus-5 > Cc: [email protected] > Signed-off-by: Zhenhao Wan <[email protected]> > --- > drivers/gpu/drm/nouveau/nouveau_uvmm.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/drivers/gpu/drm/nouveau/nouveau_uvmm.c > b/drivers/gpu/drm/nouveau/nouveau_uvmm.c > index 36445915aa58..849bf42c124e 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_uvmm.c > +++ b/drivers/gpu/drm/nouveau/nouveau_uvmm.c > @@ -1489,7 +1489,8 @@ nouveau_uvmm_bind_job_submit(struct nouveau_job > *job, > break; > } > > - drm_gpuva_ops_free(&uvmm->base, op->ops); > + if (!IS_ERR_OR_NULL(op->ops)) > + drm_gpuva_ops_free(&uvmm->base, op->ops); > op->ops = NULL; > op->reg = NULL; > }