[PATCH] drm/tegra: Finalize GEM object on initialization failure

Guangshuo Li posted 1 patch 1 week, 4 days ago
drivers/gpu/drm/tegra/gem.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
[PATCH] drm/tegra: Finalize GEM object on initialization failure
Posted by Guangshuo Li 1 week, 4 days ago
tegra_bo_alloc_object() allocates bo and passes its embedded GEM object
to drm_gem_object_init().

drm_gem_object_init() initializes the GEM private state before creating
the shmem backing file. If the file creation fails, it returns an error
with the reservation object and GPUVA mutex still initialized.

The current error path directly frees bo, bypassing the matching GEM
private-object cleanup. Finalize the partially initialized GEM object
with drm_gem_private_object_fini() before freeing bo.

This issue was found by a static analysis tool I am developing.

Fixes: c28d4a317fef ("drm/tegra: gem: Extract tegra_bo_alloc_object()")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
---
 drivers/gpu/drm/tegra/gem.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/tegra/gem.c b/drivers/gpu/drm/tegra/gem.c
index 436394e04812..eb513cb7521c 100644
--- a/drivers/gpu/drm/tegra/gem.c
+++ b/drivers/gpu/drm/tegra/gem.c
@@ -314,8 +314,10 @@ static struct tegra_bo *tegra_bo_alloc_object(struct drm_device *drm,
 	size = round_up(size, PAGE_SIZE);
 
 	err = drm_gem_object_init(drm, &bo->gem, size);
-	if (err < 0)
+	if (err < 0) {
+		drm_gem_private_object_fini(&bo->gem);
 		goto free;
+	}
 
 	err = drm_gem_create_mmap_offset(&bo->gem);
 	if (err < 0)
-- 
2.43.0
Re: [PATCH] drm/tegra: Finalize GEM object on initialization failure
Posted by Mikko Perttunen 1 week, 3 days ago
On Tuesday, July 14, 2026 10:19 PM Guangshuo Li wrote:
> tegra_bo_alloc_object() allocates bo and passes its embedded GEM object
> to drm_gem_object_init().
> 
> drm_gem_object_init() initializes the GEM private state before creating
> the shmem backing file. If the file creation fails, it returns an error
> with the reservation object and GPUVA mutex still initialized.
> 
> The current error path directly frees bo, bypassing the matching GEM
> private-object cleanup. Finalize the partially initialized GEM object
> with drm_gem_private_object_fini() before freeing bo.
> 
> This issue was found by a static analysis tool I am developing.
> 
> Fixes: c28d4a317fef ("drm/tegra: gem: Extract tegra_bo_alloc_object()")
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
>  drivers/gpu/drm/tegra/gem.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/gpu/drm/tegra/gem.c b/drivers/gpu/drm/tegra/gem.c
> index 436394e04812..eb513cb7521c 100644
> --- a/drivers/gpu/drm/tegra/gem.c
> +++ b/drivers/gpu/drm/tegra/gem.c
> @@ -314,8 +314,10 @@ static struct tegra_bo *tegra_bo_alloc_object(struct drm_device *drm,
>  	size = round_up(size, PAGE_SIZE);
>  
>  	err = drm_gem_object_init(drm, &bo->gem, size);
> -	if (err < 0)
> +	if (err < 0) {
> +		drm_gem_private_object_fini(&bo->gem);
>  		goto free;
> +	}
>  
>  	err = drm_gem_create_mmap_offset(&bo->gem);
>  	if (err < 0)
> -- 
> 2.43.0
> 
> 

This looks correct, but a quick analysis shows a lot of drivers have
the same issue. I think it'd be a good idea to either

1. Fix drm_gem_object_init to clean up after itself (and update
   callers accordingly)

or

2. Fix the same issue at other call sites of drm_gem_object_init
   as well in one go.

In any case,

Reviewed-by: Mikko Perttunen <mperttunen@nvidia.com>

Thank you
Mikko