Skip to content

Commit 227ad6d

Browse files
committed
drm: Reorder set_property_atomic to avoid returning with an active ww_ctx
Delay the drm_modeset_acquire_init() until after we check for an allocation failure so that we can return immediately upon error without having to unwind. WARNING: lock held when returning to user space! 4.20.0+ #174 Not tainted ------------------------------------------------ syz-executor556/8153 is leaving the kernel with locks still held! 1 lock held by syz-executor556/8153: #0: 000000005100c85c (crtc_ww_class_acquire){+.+.}, at: set_property_atomic+0xb3/0x330 drivers/gpu/drm/drm_mode_object.c:462 Reported-by: [email protected] Fixes: 144a799 ("drm: Handle properties in the core for atomic drivers") Signed-off-by: Chris Wilson <[email protected]> Cc: Daniel Vetter <[email protected]> Cc: Maarten Lankhorst <[email protected]> Cc: Sean Paul <[email protected]> Cc: David Airlie <[email protected]> Cc: <[email protected]> # v4.14+ Reviewed-by: Maarten Lankhorst <[email protected]> Link: https://patchwork.freedesktop.org/patch/msgid/[email protected]
1 parent ecb2e2f commit 227ad6d

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

drivers/gpu/drm/drm_mode_object.c

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -459,12 +459,13 @@ static int set_property_atomic(struct drm_mode_object *obj,
459459
struct drm_modeset_acquire_ctx ctx;
460460
int ret;
461461

462-
drm_modeset_acquire_init(&ctx, 0);
463-
464462
state = drm_atomic_state_alloc(dev);
465463
if (!state)
466464
return -ENOMEM;
465+
466+
drm_modeset_acquire_init(&ctx, 0);
467467
state->acquire_ctx = &ctx;
468+
468469
retry:
469470
if (prop == state->dev->mode_config.dpms_property) {
470471
if (obj->type != DRM_MODE_OBJECT_CONNECTOR) {

0 commit comments

Comments
 (0)