Importing a sync_file into a timeline point (DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_IMPORT_SYNC_FILE | DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_TIMELINE) has two bugs since c2d3a7300695:
1. The fence and syncobj references leak if dma_fence_chain_alloc() fails. 2. A sync_file that contains a dma_fence_chain (e.g. one exported from a timeline point) is wrapped in another chain and triggers the WARN_ON in dma_fence_chain_init(). I reported this on 2026-05-20.
These patches were developed completely autonomously by AI. I have reviewed them, but they have not been tested at runtime. They are only compile-tested.
Julian Orth (2): drm/syncobj: fix fence and syncobj leak in drm_syncobj_import_sync_file_fence drm/syncobj: flatten chains when importing sync_file into timeline point
drivers/gpu/drm/drm_syncobj.c | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-)
base-commit: 6ccf996a0dec1852dab94ad865f27b4904750e12