The mmap callback reads bo->madv without holding madv_lock, racing with
concurrent DRM_IOCTL_VC4_GEM_MADVISE calls that modify the field under
the same lock. Add the missing locking to prevent the data race.

Fixes: b9f19259b84d ("drm/vc4: Add the DRM_IOCTL_VC4_GEM_MADVISE ioctl")
Signed-off-by: Maíra Canal <[email protected]>
---
 drivers/gpu/drm/vc4/vc4_bo.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/gpu/drm/vc4/vc4_bo.c b/drivers/gpu/drm/vc4/vc4_bo.c
index 
f45ba47b4ba8645f371215c083d3ead3ddd5ffe8..9377e58f9bc256ea81e19cc442d04139feec20fe
 100644
--- a/drivers/gpu/drm/vc4/vc4_bo.c
+++ b/drivers/gpu/drm/vc4/vc4_bo.c
@@ -738,12 +738,15 @@ static int vc4_gem_object_mmap(struct drm_gem_object 
*obj, struct vm_area_struct
                return -EINVAL;
        }
 
+       mutex_lock(&bo->madv_lock);
        if (bo->madv != VC4_MADV_WILLNEED) {
                DRM_DEBUG("mmapping of %s BO not allowed\n",
                          bo->madv == VC4_MADV_DONTNEED ?
                          "purgeable" : "purged");
+               mutex_unlock(&bo->madv_lock);
                return -EINVAL;
        }
+       mutex_unlock(&bo->madv_lock);
 
        return drm_gem_dma_mmap(&bo->base, vma);
 }

-- 
2.53.0

Reply via email to