]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
drm/i915: Only destroy a constructed mmap offset
authorChris Wilson <chris@chris-wilson.co.uk>
Thu, 10 Sep 2009 07:53:04 +0000 (08:53 +0100)
committerGreg Kroah-Hartman <gregkh@suse.de>
Mon, 5 Oct 2009 16:32:05 +0000 (09:32 -0700)
commit 7e61615857c6fb3afbcb43f5c4e97511a923f5a8 upstream.

drm_ht_remove_item() does not handle removing an absent item and the hlist
in particular is incorrectly initialised. The easy remedy is simply skip
calling i915_gem_free_mmap_offset() unless we have actually created the
offset and associated ht entry.

This also fixes the mishandling of a partially constructed offset which
leaves pointers initialized after freeing them along the
i915_gem_create_mmap_offset() error paths.

In particular this should fix the oops found here:
https://bugs.launchpad.net/ubuntu/+source/xserver-xorg-video-intel/+bug/415357/comments/8

Signed-off-by: Chris Wilson <chris@chris-wilson.co.uk>
Signed-off-by: Eric Anholt <eric@anholt.net>
drivers/gpu/drm/i915/i915_gem.c

index 80e5ba490dc28c8a15c4619865f4872f82a6625e..81cc7ac745a7d2e530f6344b33704c897416088c 100644 (file)
@@ -3837,7 +3837,8 @@ void i915_gem_free_object(struct drm_gem_object *obj)
 
        i915_gem_object_unbind(obj);
 
-       i915_gem_free_mmap_offset(obj);
+       if (obj_priv->mmap_offset)
+               i915_gem_free_mmap_offset(obj);
 
        kfree(obj_priv->page_cpu_valid);
        kfree(obj_priv->bit_17);