drivers/gpu/drm/tegra/gem.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-)
tegra_bo_alloc_object() allocates bo and passes its embedded GEM object
to drm_gem_object_init().
drm_gem_object_init() initializes the GEM private state before creating
the shmem backing file. If the file creation fails, it returns an error
with the reservation object and GPUVA mutex still initialized.
The current error path directly frees bo, bypassing the matching GEM
private-object cleanup. Finalize the partially initialized GEM object
with drm_gem_private_object_fini() before freeing bo.
This issue was found by a static analysis tool I am developing.
Fixes: c28d4a317fef ("drm/tegra: gem: Extract tegra_bo_alloc_object()")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
---
drivers/gpu/drm/tegra/gem.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/tegra/gem.c b/drivers/gpu/drm/tegra/gem.c
index 436394e04812..eb513cb7521c 100644
--- a/drivers/gpu/drm/tegra/gem.c
+++ b/drivers/gpu/drm/tegra/gem.c
@@ -314,8 +314,10 @@ static struct tegra_bo *tegra_bo_alloc_object(struct drm_device *drm,
size = round_up(size, PAGE_SIZE);
err = drm_gem_object_init(drm, &bo->gem, size);
- if (err < 0)
+ if (err < 0) {
+ drm_gem_private_object_fini(&bo->gem);
goto free;
+ }
err = drm_gem_create_mmap_offset(&bo->gem);
if (err < 0)
--
2.43.0
On Tuesday, July 14, 2026 10:19 PM Guangshuo Li wrote:
> tegra_bo_alloc_object() allocates bo and passes its embedded GEM object
> to drm_gem_object_init().
>
> drm_gem_object_init() initializes the GEM private state before creating
> the shmem backing file. If the file creation fails, it returns an error
> with the reservation object and GPUVA mutex still initialized.
>
> The current error path directly frees bo, bypassing the matching GEM
> private-object cleanup. Finalize the partially initialized GEM object
> with drm_gem_private_object_fini() before freeing bo.
>
> This issue was found by a static analysis tool I am developing.
>
> Fixes: c28d4a317fef ("drm/tegra: gem: Extract tegra_bo_alloc_object()")
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
> drivers/gpu/drm/tegra/gem.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/gpu/drm/tegra/gem.c b/drivers/gpu/drm/tegra/gem.c
> index 436394e04812..eb513cb7521c 100644
> --- a/drivers/gpu/drm/tegra/gem.c
> +++ b/drivers/gpu/drm/tegra/gem.c
> @@ -314,8 +314,10 @@ static struct tegra_bo *tegra_bo_alloc_object(struct drm_device *drm,
> size = round_up(size, PAGE_SIZE);
>
> err = drm_gem_object_init(drm, &bo->gem, size);
> - if (err < 0)
> + if (err < 0) {
> + drm_gem_private_object_fini(&bo->gem);
> goto free;
> + }
>
> err = drm_gem_create_mmap_offset(&bo->gem);
> if (err < 0)
> --
> 2.43.0
>
>
This looks correct, but a quick analysis shows a lot of drivers have
the same issue. I think it'd be a good idea to either
1. Fix drm_gem_object_init to clean up after itself (and update
callers accordingly)
or
2. Fix the same issue at other call sites of drm_gem_object_init
as well in one go.
In any case,
Reviewed-by: Mikko Perttunen <mperttunen@nvidia.com>
Thank you
Mikko
© 2016 - 2026 Red Hat, Inc.