aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorAlexey Minnekhanov <alexeymin@postmarketos.org>2021-05-18 13:26:24 +0300
committerRob Clark <robdclark@chromium.org>2021-06-08 10:08:04 -0700
commit45f56690051c108e3e9a50e34b61aac05d55583d (patch)
tree2e55920679f69e884657712ca6f26bb771f81d9a
parentf2f46b878777e0d3f885c7ddad48f477b4dea247 (diff)
downloadlinux-45f56690051c108e3e9a50e34b61aac05d55583d.tar.gz
drm/msm: Init mm_list before accessing it for use_vram path
Fix NULL pointer dereference caused by update_inactive() trying to list_del() an uninitialized mm_list who's prev/next pointers are NULL. Fixes: 64fcbde772c7 ("drm/msm: Track potentially evictable objects") Signed-off-by: Alexey Minnekhanov <alexeymin@postmarketos.org> Link: https://lore.kernel.org/r/20210518102624.1193955-1-alexeymin@postmarketos.org Signed-off-by: Rob Clark <robdclark@chromium.org>
-rw-r--r--drivers/gpu/drm/msm/msm_gem.c7
1 files changed, 7 insertions, 0 deletions
diff --git a/drivers/gpu/drm/msm/msm_gem.c b/drivers/gpu/drm/msm/msm_gem.c
index 56df86e5f7400..369d91e6361ec 100644
--- a/drivers/gpu/drm/msm/msm_gem.c
+++ b/drivers/gpu/drm/msm/msm_gem.c
@@ -1241,6 +1241,13 @@ static struct drm_gem_object *_msm_gem_new(struct drm_device *dev,
to_msm_bo(obj)->vram_node = &vma->node;
+ /* Call chain get_pages() -> update_inactive() tries to
+ * access msm_obj->mm_list, but it is not initialized yet.
+ * To avoid NULL pointer dereference error, initialize
+ * mm_list to be empty.
+ */
+ INIT_LIST_HEAD(&msm_obj->mm_list);
+
msm_gem_lock(obj);
pages = get_pages(obj);
msm_gem_unlock(obj);