drm/amd/display: Fix memory corruption issue.
authorjimqu <Jim.Qu@amd.com>
Mon, 28 Nov 2016 00:05:46 +0000 (08:05 +0800)
committerAlex Deucher <alexander.deucher@amd.com>
Tue, 26 Sep 2017 21:02:02 +0000 (17:02 -0400)
temp_flip_context is always same as current_context,
and the current_context will be freed in
dc_commit_targets(), but  temp_flip_context will be used in
dc_update_surfaces_for_target().

Signed-off-by: JimQu <Jim.Qu@amd.com>
Reviewed-by: Andrey Grodzovsky <Andrey.Grodzovsky@amd.com>
Acked-by: Harry Wentland <Harry.Wentland@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
drivers/gpu/drm/amd/display/dc/core/dc.c

index f7638f8..424a7d4 100644 (file)
@@ -1096,8 +1096,12 @@ bool dc_commit_targets(
 
        resource_validate_ctx_destruct(core_dc->current_context);
 
-       dm_free(core_dc->current_context);
+       if (core_dc->temp_flip_context != core_dc->current_context) {
+               dm_free(core_dc->temp_flip_context);
+               core_dc->temp_flip_context = core_dc->current_context;
+       }
        core_dc->current_context = context;
+       memset(core_dc->temp_flip_context, 0, sizeof(*core_dc->temp_flip_context));
 
        return (result == DC_OK);