[PATCH v2] drm/tegra: fix host1x_bo_pin leak in tegra_dc_pin error path

From: WenTao Liang

Date: Sun Jun 28 2026 - 11:02:57 EST


When map->chunks > 1 triggers an error, the function jumps to unpin
before storing the current map in state->map[i]. The unpin loop only
cleans up previously pinned planes (indices 0 through i-1), so the
current mapping returned by host1x_bo_pin is never released via
host1x_bo_unpin.

Suggested-by: Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx>
Fixes: c6aeaf56f468 ("drm/tegra: Implement correct DMA-BUF semantics")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: WenTao Liang <vulab@xxxxxxxxxxx>
---
Changes in v2:
- Fix patch format based on reviewer feedback
---
drivers/gpu/drm/tegra/plane.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/drivers/gpu/drm/tegra/plane.c b/drivers/gpu/drm/tegra/plane.c
index 0cb30910773f..e61485ee58f6 100644
--- a/drivers/gpu/drm/tegra/plane.c
+++ b/drivers/gpu/drm/tegra/plane.c
@@ -161,6 +161,7 @@ static int tegra_dc_pin(struct tegra_dc *dc, struct tegra_plane_state *state)
*/
if (map->chunks > 1) {
err = -EINVAL;
+ host1x_bo_unpin(map);
goto unpin;
}

--
2.39.5 (Apple Git-154)