From nobody Fri Jul 24 23:31:00 2026 Received: from cstnet.cn (smtp25.cstnet.cn [159.226.251.25]) (using TLSv1.2 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 09CAE3DBD41 for ; Wed, 22 Jul 2026 04:14:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=159.226.251.25 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784693642; cv=none; b=OdhESdnvxM/xH/tNb53xaxb2daOYAmvXdluf4E4soPb82ZvHMDCNaoVKZxSsl9FXefSLARnlFA9w3uuNeoakcn1kb6F4qjOT5KgahxvHJ9+warpy7MM5NNPNsgxz+d9a6VDw+stC4iCA16Ry+2QrBXKMJEm8NX33epHgX+wLqXU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784693642; c=relaxed/simple; bh=GVNZ2GPbZ5JDZFjhBY/Z0yvhjGvOPsWnXDPy5bLAKPs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=DOb1GrLU8rESGAeEdShW6jdaez8YQTinjWGZG2+CVJhS723Bwmsv74XoIkOVpM/rkE+LnoKHskFIfOLIta6hZqsjWAwkNrl4RkApQ8MAK5oyj9ZtqdS+zkoVvbUQ7WLtEdweok5X9Wbj8JFgdT5NdSnEXEb39QDr2vf5JrGT5Fc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn; spf=pass smtp.mailfrom=iscas.ac.cn; arc=none smtp.client-ip=159.226.251.25 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=iscas.ac.cn Received: from localhost.localdomain (unknown [111.196.245.140]) by APP-05 (Coremail) with SMTP id zQCowAAHOEKAQ2BqvyK7AA--.33885S2; Wed, 22 Jul 2026 12:13:52 +0800 (CST) From: Pengpeng Hou To: Jani Nikula Cc: Joonas Lahtinen , Rodrigo Vivi , Tvrtko Ursulin , David Airlie , Simona Vetter , intel-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Pengpeng Hou Subject: [PATCH] drm/i915: retain user exec count for relocation cleanup Date: Wed, 22 Jul 2026 12:13:52 +0800 Message-ID: <20260722041352.5612-1-pengpeng@iscas.ac.cn> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: zQCowAAHOEKAQ2BqvyK7AA--.33885S2 X-Coremail-Antispam: 1UD129KBjvJXoW7Aw1DuFy8Ww4Utr4xCFy7trb_yoW8Wr4fp3 W5Kr4jyrWktr1Uta9rXa15ZF1akas2qFy3K3yUGw1fCFnFyFnIvFyY9ryjyr1UAF4Iqry2 vr40gFy093W7Jr7anT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUU9214x267AKxVW8JVW5JwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2AK02 1l84ACjcxK6xIIjxv20xvE14v26r4j6ryUM28EF7xvwVC0I7IYx2IY6xkF7I0E14v26F4j 6r4UJwA2z4x0Y4vEx4A2jsIE14v26F4UJVW0owA2z4x0Y4vEx4A2jsIEc7CjxVAFwI0_Cr 1j6rxdM2AIxVAIcxkEcVAq07x20xvEncxIr21l5I8CrVACY4xI64kE6c02F40Ex7xfMcIj 6xIIjxv20xvE14v26r126r1DMcIj6I8E87Iv67AKxVWUJVW8JwAm72CE4IkC6x0Yz7v_Jr 0_Gr1lF7xvr2IYc2Ij64vIr41lF7I21c0EjII2zVCS5cI20VAGYxC7M4IIrI8v6xkF7I0E 8cxan2IY04v7MxkF7I0En4kS14v26r1q6r43MxAIw28IcxkI7VAKI48JMxC20s026xCaFV Cjc4AY6r1j6r4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCjr7xvwVAFwI0_JrI_JrWl x4CE17CEb7AF67AKxVWUtVW8ZwCIc40Y0x0EwIxGrwCI42IY6xIIjxv20xvE14v26r1I6r 4UMIIF0xvE2Ix0cI8IcVCY1x0267AKxVWxJVW8Jr1lIxAIcVCF04k26cxKx2IYs7xG6r1j 6r1xMIIF0xvEx4A2jsIE14v26r1j6r4UMIIF0xvEx4A2jsIEc7CjxVAFwI0_Gr0_Gr1UYx BIdaVFxhVjvjDU0xZFpf9x0JUL0edUUUUU= X-CM-SenderInfo: pshqw1xhqjqxpvfd2hldfou0/ Content-Type: text/plain; charset="utf-8" The exec array contains one entry for each userspace object. eb_parse() can append internal VMAs by increasing buffer_count after relocation arrays have been copied only for the original userspace entries. The cleanup path currently uses the enlarged count and can index beyond the copied exec array. Preserve the original userspace count and use it when freeing copied relocation arrays. Signed-off-by: Pengpeng Hou --- drivers/gpu/drm/i915/gem/i915_gem_execbuffer.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/i915/gem/i915_gem_execbuffer.c b/drivers/gpu/d= rm/i915/gem/i915_gem_execbuffer.c index 65ce54b20ec2..b991f4e82ae6 100644 --- a/drivers/gpu/drm/i915/gem/i915_gem_execbuffer.c +++ b/drivers/gpu/drm/i915/gem/i915_gem_execbuffer.c @@ -1768,6 +1768,7 @@ static int eb_reinit_userptr(struct i915_execbuffer *= eb) =20 static noinline int eb_relocate_parse_slow(struct i915_execbuffer *eb) { + const unsigned int exec_count =3D eb->buffer_count; bool have_copy =3D false; struct eb_vma *ev; int err =3D 0; @@ -1870,10 +1871,10 @@ static noinline int eb_relocate_parse_slow(struct i= 915_execbuffer *eb) =20 out: if (have_copy) { - const unsigned int count =3D eb->buffer_count; unsigned int i; =20 - for (i =3D 0; i < count; i++) { + /* eb_parse() may append internal VMAs without appending eb->exec. */ + for (i =3D 0; i < exec_count; i++) { const struct drm_i915_gem_exec_object2 *entry =3D &eb->exec[i]; struct drm_i915_gem_relocation_entry *relocs; --=20 2.43.0