Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 1ef5325b authored by Jerome Glisse's avatar Jerome Glisse Committed by Dave Airlie
Browse files

drm/radeon: fix rare segfault



In gem idle/busy ioctl the radeon object was derefenced after
drm_gem_object_unreference_unlocked which in case the object
have been destroyed lead to use of a possibly free pointer with
possibly wrong data.

Signed-off-by: default avatarJerome Glisse <jglisse@redhat.com>
Reviewed-by: default avatarAlex Deucher <alexander.deucher@amd.com>
Reviewed-by: default avatarChristian König <christian.koenig@amd.com>
Signed-off-by: default avatarDave Airlie <airlied@redhat.com>
parent c21b328e
Loading
Loading
Loading
Loading
+6 −4
Original line number Original line Diff line number Diff line
@@ -292,6 +292,7 @@ int radeon_gem_mmap_ioctl(struct drm_device *dev, void *data,
int radeon_gem_busy_ioctl(struct drm_device *dev, void *data,
int radeon_gem_busy_ioctl(struct drm_device *dev, void *data,
			  struct drm_file *filp)
			  struct drm_file *filp)
{
{
	struct radeon_device *rdev = dev->dev_private;
	struct drm_radeon_gem_busy *args = data;
	struct drm_radeon_gem_busy *args = data;
	struct drm_gem_object *gobj;
	struct drm_gem_object *gobj;
	struct radeon_bo *robj;
	struct radeon_bo *robj;
@@ -317,13 +318,14 @@ int radeon_gem_busy_ioctl(struct drm_device *dev, void *data,
		break;
		break;
	}
	}
	drm_gem_object_unreference_unlocked(gobj);
	drm_gem_object_unreference_unlocked(gobj);
	r = radeon_gem_handle_lockup(robj->rdev, r);
	r = radeon_gem_handle_lockup(rdev, r);
	return r;
	return r;
}
}


int radeon_gem_wait_idle_ioctl(struct drm_device *dev, void *data,
int radeon_gem_wait_idle_ioctl(struct drm_device *dev, void *data,
			      struct drm_file *filp)
			      struct drm_file *filp)
{
{
	struct radeon_device *rdev = dev->dev_private;
	struct drm_radeon_gem_wait_idle *args = data;
	struct drm_radeon_gem_wait_idle *args = data;
	struct drm_gem_object *gobj;
	struct drm_gem_object *gobj;
	struct radeon_bo *robj;
	struct radeon_bo *robj;
@@ -336,10 +338,10 @@ int radeon_gem_wait_idle_ioctl(struct drm_device *dev, void *data,
	robj = gem_to_radeon_bo(gobj);
	robj = gem_to_radeon_bo(gobj);
	r = radeon_bo_wait(robj, NULL, false);
	r = radeon_bo_wait(robj, NULL, false);
	/* callback hw specific functions if any */
	/* callback hw specific functions if any */
	if (robj->rdev->asic->ioctl_wait_idle)
	if (rdev->asic->ioctl_wait_idle)
		robj->rdev->asic->ioctl_wait_idle(robj->rdev, robj);
		robj->rdev->asic->ioctl_wait_idle(rdev, robj);
	drm_gem_object_unreference_unlocked(gobj);
	drm_gem_object_unreference_unlocked(gobj);
	r = radeon_gem_handle_lockup(robj->rdev, r);
	r = radeon_gem_handle_lockup(rdev, r);
	return r;
	return r;
}
}