Unverified Commit 09a8f3c1 authored by Shuicheng Lin's avatar Shuicheng Lin Committed by Rodrigo Vivi
Browse files

drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked()



When type is ttm_bo_type_device and aligned_size != size, the function
returns an error without freeing a caller-provided bo, violating the
documented contract that bo is freed on failure.

Add xe_bo_free(bo) before returning the error.

Fixes: 4e03b584 ("drm/xe/uapi: Reject bo creation of unaligned size")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.6
Reviewed-by: default avatarMatthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260408175255.3402838-2-shuicheng.lin@intel.com


Signed-off-by: default avatarShuicheng Lin <shuicheng.lin@intel.com>
(cherry picked from commit 601c2aa087b6f21014300a3f107a08ee4dde7bdf)
Signed-off-by: default avatarRodrigo Vivi <rodrigo.vivi@intel.com>
parent f8c4151d
Loading
Loading
Loading
Loading
+3 −1
Original line number Diff line number Diff line
@@ -2342,8 +2342,10 @@ struct xe_bo *xe_bo_init_locked(struct xe_device *xe, struct xe_bo *bo,
		alignment = SZ_4K >> PAGE_SHIFT;
	}

	if (type == ttm_bo_type_device && aligned_size != size)
	if (type == ttm_bo_type_device && aligned_size != size) {
		xe_bo_free(bo);
		return ERR_PTR(-EINVAL);
	}

	if (!bo) {
		bo = xe_bo_alloc();