drm/pagemap: Clear driver-provided PFNs from migration PFN array

DRM pagemap overloads the migration PFN array to store driver-provided
PFNs before calling migrate_vma_*() to finalize the migration. If an
error occurs during the incremental copy phase, the migration PFN
entries are reverted to their original state. After reverting the
device-folio mutations, clear any remaining driver-provided PFNs to
avoid confusing the migrate_vma_*() helpers.

Also clear any driver-provided PFNs if populate_devmem_pfn() fails, as
a precaution against stale entries being interpreted as migration PFNs.

Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 3902846af3 ("drm/pagemap Fix error paths in drm_pagemap_migrate_to_devmem")
Fixes: ec265e1f1c ("drm/pagemap: Support source migration over interconnect")
Cc: stable@vger.kernel.org
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
Link: https://patch.msgid.link/20260721204353.1082632-1-matthew.brost@intel.com
This commit is contained in:
Matthew Brost 2026-07-21 13:43:53 -07:00
parent 6b7e006629
commit 1f1be4ba64

View File

@ -727,8 +727,10 @@ int drm_pagemap_migrate_to_devmem(struct drm_pagemap_devmem *devmem_allocation,
}
err = ops->populate_devmem_pfn(devmem_allocation, npages, migrate.dst);
if (err)
goto err_aborted_migration;
if (err) {
npages = 0;
goto err_finalize;
}
own_pages = 0;
@ -807,8 +809,11 @@ int drm_pagemap_migrate_to_devmem(struct drm_pagemap_devmem *devmem_allocation,
msecs_to_jiffies(mdetails->timeslice_ms);
err_finalize:
if (err)
if (err) {
drm_pagemap_migration_unlock_put_pages(npages, migrate.dst);
for (i = npages; i < npages_in_range(start, end); ++i)
migrate.dst[i] = 0;
}
err_aborted_migration:
migrate_vma_pages(&migrate);