A sync_file exported from a timeline point can contain a dma_fence_chain. Importing such a sync_file into a timeline point with DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_IMPORT_SYNC_FILE | DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_TIMELINE passes the chain directly to dma_fence_chain_init() and triggers
WARNING: drivers/dma-buf/dma-fence-chain.c:286 at dma_fence_chain_init
because chain fences must not be wrapped in other chain fences.
Flatten the fence with dma_fence_unwrap_merge() before adding it to the timeline, as drm_syncobj_transfer_to_timeline() already does.
Reproducer:
1. Export a sync_file from a point > 0 of a timeline syncobj with DRM_IOCTL_SYNCOBJ_HANDLE_TO_FD. 2. Import it into a point > 0 of another timeline syncobj with DRM_IOCTL_SYNCOBJ_FD_TO_HANDLE.
Fixes: c2d3a7300695 ("drm/syncobj: Extend EXPORT_SYNC_FILE for timeline syncobjs") Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Julian Orth ju.orth@gmail.com --- drivers/gpu/drm/drm_syncobj.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/drm_syncobj.c b/drivers/gpu/drm/drm_syncobj.c index 5ca5163d0..c545af77e 100644 --- a/drivers/gpu/drm/drm_syncobj.c +++ b/drivers/gpu/drm/drm_syncobj.c @@ -742,8 +742,18 @@ static int drm_syncobj_import_sync_file_fence(struct drm_file *file_private, }
if (point) { - struct dma_fence_chain *chain = dma_fence_chain_alloc(); + struct dma_fence_chain *chain; + struct dma_fence *tmp; + + tmp = dma_fence_unwrap_merge(fence); + dma_fence_put(fence); + fence = tmp; + if (!fence) { + drm_syncobj_put(syncobj); + return -ENOMEM; + }
+ chain = dma_fence_chain_alloc(); if (!chain) { ret = -ENOMEM; goto out;