Commit 9ae85fab authored by Gustavo Padovan's avatar Gustavo Padovan Committed by Greg Kroah-Hartman

dma-buf/sw_sync: clean up list before signaling the fence

commit 3792b7c1 upstream.

If userspace already dropped its own reference by closing the sw_sync
fence fd we might end up in a deadlock where
dma_fence_is_signaled_locked() will trigger the release of the fence and
thus try to hold the lock to remove the fence from the list.

dma_fence_is_signaled_locked() tries to release/free the fence and hold
the lock in the process.

We fix that by changing the order operation and clean up the list and
rb-tree first.

v2: Drop fence get/put dance and manipulate the list first (Chris Wilson)

Cc: Chris Wilson <>
Signed-off-by: default avatarGustavo Padovan <>
Reviewed-by: default avatarChris Wilson <>
[s/dma_fence/fence/g - gregkh]
Cc: Jisheng Zhang <>
Signed-off-by: default avatarGreg Kroah-Hartman <>
......@@ -213,11 +213,21 @@ static void sync_timeline_signal(struct sync_timeline *obj, unsigned int inc)
obj->value += inc;
list_for_each_entry_safe(pt, next, &obj->pt_list, link) {
if (!fence_is_signaled_locked(&pt->base))
if (!timeline_fence_signaled(&pt->base))
rb_erase(&pt->node, &obj->pt_tree);
* A signal callback may release the last reference to this
* fence, causing it to be freed. That operation has to be
* last to avoid a use after free inside this loop, and must
* be after we remove the fence from the timeline in order to
* prevent deadlocking on timeline->lock inside
* timeline_fence_release().
