mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 12:44:03 +02:00
drm/v3d: Reject invalid syncobj handles in submit ioctls
drm_sched_job_add_syncobj_dependency() returns -ENOENT both when the handle is zero and when the handle is non-zero but does not find a corresponding existing syncobj (userspace bug). The driver previously ignored -ENOENT in both cases, silently accepting broken handles. Distinguish the two: skip the call entirely when the handle is zero, as there is no dependency, and let -ENOENT propagate for non-zero handles that don't resolve, turning the error into a proper return to userspace. Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com> Link: https://patch.msgid.link/20260604-v3d-sched-misc-fixes-v4-4-c068f5bf5ccf@igalia.com Signed-off-by: Maíra Canal <mcanal@igalia.com>
This commit is contained in:
parent
57d78cbc16
commit
66fc52ba7c
|
|
@ -189,12 +189,11 @@ v3d_job_add_syncobjs(struct v3d_job *job, struct drm_file *file_priv,
|
|||
int ret = 0;
|
||||
|
||||
if (!has_multisync) {
|
||||
ret = drm_sched_job_add_syncobj_dependency(&job->base, file_priv,
|
||||
in_sync, 0);
|
||||
// TODO: Investigate why this was filtered out for the IOCTL.
|
||||
if (ret && ret != -ENOENT)
|
||||
return ret;
|
||||
return 0;
|
||||
/* Ignore syncobj if its handle is zero */
|
||||
if (in_sync)
|
||||
ret = drm_sched_job_add_syncobj_dependency(&job->base, file_priv,
|
||||
in_sync, 0);
|
||||
return ret;
|
||||
}
|
||||
|
||||
if (se->in_sync_count && se->wait_stage == job->queue) {
|
||||
|
|
@ -208,11 +207,13 @@ v3d_job_add_syncobjs(struct v3d_job *job, struct drm_file *file_priv,
|
|||
return -EFAULT;
|
||||
}
|
||||
|
||||
ret = drm_sched_job_add_syncobj_dependency(&job->base,
|
||||
file_priv, in.handle, 0);
|
||||
// TODO: Investigate why this was filtered out for the IOCTL.
|
||||
if (ret && ret != -ENOENT)
|
||||
return ret;
|
||||
/* Ignore syncobj if its handle is zero */
|
||||
if (in.handle) {
|
||||
ret = drm_sched_job_add_syncobj_dependency(&job->base,
|
||||
file_priv, in.handle, 0);
|
||||
if (ret)
|
||||
return ret;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user