Re: [PATCH v2 0/3] drm/nouveau/uvmm: fix VM_BIND submit/unwind error-path bugs

[email protected]
Newsgroups org.freedesktop.lists.nouveau,org.freedesktop.lists.dri-devel,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
This patch series is:

Reviewed-by: Lyude Paul <[email protected]>

On Tue, 2026-08-11 at 16:46 +0800, Zhenhao Wan wrote:
> Three bugs on the nouveau VM_BIND submit/unwind/cleanup error path,
> all
> introduced by the original VM_BIND uAPI (Fixes: b88baab82871) and all
> reachable by an unprivileged render-node client:
> 
>   1/3 NULL deref when the unwind loop frees a never-populated
>       OP_MAP_SPARSE op's ops list.
>   2/3 premature free of a region on a failed OP_UNMAP_SPARSE, because
>       op->reg is left set on the failure paths.
>   3/3 a sparse region left permanently marked dirty after unwind,
>       wedging later binds over that range.
> 
> Each fix is minimal and self-contained; all are Cc: stable.
> 
> Signed-off-by: Zhenhao Wan <[email protected]>
> ---
> Changes in v2:
> - Add an Assisted-by: trailer to each patch; no code changes.
> - Link to v1:
> https://patch.msgid.link/[email protected]
> 
> ---
> Zhenhao Wan (3):
>       drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op
>       drm/nouveau/uvmm: fix premature region free on failed
> OP_UNMAP_SPARSE
>       drm/nouveau/uvmm: clear the dirty flag when unwinding an
> OP_UNMAP_SPARSE
> 
>  drivers/gpu/drm/nouveau/nouveau_uvmm.c | 6 +++++-
>  1 file changed, 5 insertions(+), 1 deletion(-)
> ---
> base-commit: ba3e43a9e601636f5edb54e259a74f96ca3b8fd8
> change-id: 20260811-nouveau-uvmm-vmbind-fixes-c2dfab359df2
> 
> Best regards,
> --  
> Zhenhao Wan <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.