Importing a sync_file into a timeline point (DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_IMPORT_SYNC_FILE | DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_TIMELINE) has two bugs since c2d3a7300695:
1. The fence and syncobj references leak if dma_fence_chain_alloc() fails. 2. A sync_file that contains a dma_fence_chain (e.g. one exported from a timeline point) is wrapped in another chain and triggers the WARN_ON in dma_fence_chain_init(). I reported this on 2026-05-20.
These patches were developed completely autonomously by AI. I have reviewed them, but they have not been tested at runtime. They are only compile-tested.
Julian Orth (2): drm/syncobj: fix fence and syncobj leak in drm_syncobj_import_sync_file_fence drm/syncobj: flatten chains when importing sync_file into timeline point
drivers/gpu/drm/drm_syncobj.c | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-)
base-commit: 6ccf996a0dec1852dab94ad865f27b4904750e12
If dma_fence_chain_alloc() fails, the function returns -ENOMEM without dropping the references to the imported fence and the syncobj.
Fixes: c2d3a7300695 ("drm/syncobj: Extend EXPORT_SYNC_FILE for timeline syncobjs") Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Julian Orth ju.orth@gmail.com --- drivers/gpu/drm/drm_syncobj.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/drm_syncobj.c b/drivers/gpu/drm/drm_syncobj.c index c23a5de27..5ca5163d0 100644 --- a/drivers/gpu/drm/drm_syncobj.c +++ b/drivers/gpu/drm/drm_syncobj.c @@ -730,6 +730,7 @@ static int drm_syncobj_import_sync_file_fence(struct drm_file *file_private, { struct dma_fence *fence = sync_file_get_fence(fd); struct drm_syncobj *syncobj; + int ret = 0;
if (!fence) return -EINVAL; @@ -743,17 +744,20 @@ static int drm_syncobj_import_sync_file_fence(struct drm_file *file_private, if (point) { struct dma_fence_chain *chain = dma_fence_chain_alloc();
- if (!chain) - return -ENOMEM; + if (!chain) { + ret = -ENOMEM; + goto out; + }
drm_syncobj_add_point(syncobj, chain, fence, point); } else { drm_syncobj_replace_fence(syncobj, fence); }
+out: dma_fence_put(fence); drm_syncobj_put(syncobj); - return 0; + return ret; }
static int drm_syncobj_export_sync_file(struct drm_file *file_private,
A sync_file exported from a timeline point can contain a dma_fence_chain. Importing such a sync_file into a timeline point with DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_IMPORT_SYNC_FILE | DRM_SYNCOBJ_FD_TO_HANDLE_FLAGS_TIMELINE passes the chain directly to dma_fence_chain_init() and triggers
WARNING: drivers/dma-buf/dma-fence-chain.c:286 at dma_fence_chain_init
because chain fences must not be wrapped in other chain fences.
Flatten the fence with dma_fence_unwrap_merge() before adding it to the timeline, as drm_syncobj_transfer_to_timeline() already does.
Reproducer:
1. Export a sync_file from a point > 0 of a timeline syncobj with DRM_IOCTL_SYNCOBJ_HANDLE_TO_FD. 2. Import it into a point > 0 of another timeline syncobj with DRM_IOCTL_SYNCOBJ_FD_TO_HANDLE.
Fixes: c2d3a7300695 ("drm/syncobj: Extend EXPORT_SYNC_FILE for timeline syncobjs") Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Julian Orth ju.orth@gmail.com --- drivers/gpu/drm/drm_syncobj.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/drm_syncobj.c b/drivers/gpu/drm/drm_syncobj.c index 5ca5163d0..c545af77e 100644 --- a/drivers/gpu/drm/drm_syncobj.c +++ b/drivers/gpu/drm/drm_syncobj.c @@ -742,8 +742,18 @@ static int drm_syncobj_import_sync_file_fence(struct drm_file *file_private, }
if (point) { - struct dma_fence_chain *chain = dma_fence_chain_alloc(); + struct dma_fence_chain *chain; + struct dma_fence *tmp; + + tmp = dma_fence_unwrap_merge(fence); + dma_fence_put(fence); + fence = tmp; + if (!fence) { + drm_syncobj_put(syncobj); + return -ENOMEM; + }
+ chain = dma_fence_chain_alloc(); if (!chain) { ret = -ENOMEM; goto out;
linaro-mm-sig@lists.linaro.org