summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMaíra Canal <mcanal@igalia.com>2026-06-04 17:32:17 -0300
committerMaíra Canal <mcanal@igalia.com>2026-06-09 14:43:43 -0300
commit66fc52ba7c3f36dcbd55bf19a788306147e2a318 (patch)
tree6b1fa67acc1c6f648e5133d56fe21f3cc7408b51
parent57d78cbc16c930f698616d4db16aa85a49a356f7 (diff)
downloadlinux-66fc52ba7c3f36dcbd55bf19a788306147e2a318.tar.gz
linux-66fc52ba7c3f36dcbd55bf19a788306147e2a318.zip
drm/v3d: Reject invalid syncobj handles in submit ioctls
drm_sched_job_add_syncobj_dependency() returns -ENOENT both when the handle is zero and when the handle is non-zero but does not find a corresponding existing syncobj (userspace bug). The driver previously ignored -ENOENT in both cases, silently accepting broken handles. Distinguish the two: skip the call entirely when the handle is zero, as there is no dependency, and let -ENOENT propagate for non-zero handles that don't resolve, turning the error into a proper return to userspace. Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com> Link: https://patch.msgid.link/20260604-v3d-sched-misc-fixes-v4-4-c068f5bf5ccf@igalia.com Signed-off-by: Maíra Canal <mcanal@igalia.com>
-rw-r--r--drivers/gpu/drm/v3d/v3d_submit.c23
1 files changed, 12 insertions, 11 deletions
diff --git a/drivers/gpu/drm/v3d/v3d_submit.c b/drivers/gpu/drm/v3d/v3d_submit.c
index 8250376d104c..0babe2e67266 100644
--- a/drivers/gpu/drm/v3d/v3d_submit.c
+++ b/drivers/gpu/drm/v3d/v3d_submit.c
@@ -189,12 +189,11 @@ v3d_job_add_syncobjs(struct v3d_job *job, struct drm_file *file_priv,
int ret = 0;
if (!has_multisync) {
- ret = drm_sched_job_add_syncobj_dependency(&job->base, file_priv,
- in_sync, 0);
- // TODO: Investigate why this was filtered out for the IOCTL.
- if (ret && ret != -ENOENT)
- return ret;
- return 0;
+ /* Ignore syncobj if its handle is zero */
+ if (in_sync)
+ ret = drm_sched_job_add_syncobj_dependency(&job->base, file_priv,
+ in_sync, 0);
+ return ret;
}
if (se->in_sync_count && se->wait_stage == job->queue) {
@@ -208,11 +207,13 @@ v3d_job_add_syncobjs(struct v3d_job *job, struct drm_file *file_priv,
return -EFAULT;
}
- ret = drm_sched_job_add_syncobj_dependency(&job->base,
- file_priv, in.handle, 0);
- // TODO: Investigate why this was filtered out for the IOCTL.
- if (ret && ret != -ENOENT)
- return ret;
+ /* Ignore syncobj if its handle is zero */
+ if (in.handle) {
+ ret = drm_sched_job_add_syncobj_dependency(&job->base,
+ file_priv, in.handle, 0);
+ if (ret)
+ return ret;
+ }
}
}