Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

dma_fence_array: Fix PENDING_ERROR leak in dma_fence_array_signaled()

If a dma_fence_array is reported signaled by a call to
dma_fence_is_signaled(), it may leak the PENDING_ERROR status.

Fix this by clearing the PENDING_ERROR status if we return true in
dma_fence_array_signaled().

v2:
- Update Cc list, and add R-b.

Fixes: 1f70b8b812f3 ("dma-fence: Propagate errors to dma-fence-array container")
Cc: Chris Wilson <chris@chris-wilson.co.uk>
Cc: Sumit Semwal <sumit.semwal@linaro.org>
Cc: Gustavo Padovan <gustavo@padovan.org>
Cc: Christian König <christian.koenig@amd.com>
Cc: "Christian König" <christian.koenig@amd.com>
Cc: linux-media@vger.kernel.org
Cc: dri-devel@lists.freedesktop.org
Cc: linaro-mm-sig@lists.linaro.org
Cc: <stable@vger.kernel.org> # v5.4+
Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20211129152727.448908-1-thomas.hellstrom@linux.intel.com

+5 -1
+5 -1
drivers/dma-buf/dma-fence-array.c
··· 104 104 { 105 105 struct dma_fence_array *array = to_dma_fence_array(fence); 106 106 107 - return atomic_read(&array->num_pending) <= 0; 107 + if (atomic_read(&array->num_pending) > 0) 108 + return false; 109 + 110 + dma_fence_array_clear_pending_error(array); 111 + return true; 108 112 } 109 113 110 114 static void dma_fence_array_release(struct dma_fence *fence)