r600g: Drop references to destroyed blend state
authorMichel Dänzer <michel.daenzer@amd.com>
Tue, 21 Oct 2014 03:40:15 +0000 (12:40 +0900)
committerMichel Dänzer <michel@daenzer.net>
Wed, 22 Oct 2014 08:09:43 +0000 (17:09 +0900)
Fixes use-after-free when the currently bound blend state is destroyed.

Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=85267
Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=84140

Reviewed-by: Marek Olšák <marek.olsak@amd.com>
Tested-by: Dieter Nützel <Dieter@nuetzel-hh.de>
Cc: mesa-stable@lists.freedesktop.org
src/gallium/drivers/r600/r600_state_common.c

index 68365f9d9afc78610fb0a7fdf5e6526f142dbfd5..879ec3522ee4388a728a57c16170d9dbbc6c19f3 100644 (file)
@@ -158,8 +158,10 @@ static void r600_bind_blend_state(struct pipe_context *ctx, void *state)
        struct r600_context *rctx = (struct r600_context *)ctx;
        struct r600_blend_state *blend = (struct r600_blend_state *)state;
 
-       if (blend == NULL)
+       if (blend == NULL) {
+               r600_set_cso_state_with_cb(&rctx->blend_state, NULL, NULL);
                return;
+       }
 
        r600_bind_blend_state_internal(rctx, blend, rctx->force_blend_disable);
 }
@@ -447,8 +449,13 @@ static void r600_delete_sampler_state(struct pipe_context *ctx, void *state)
 
 static void r600_delete_blend_state(struct pipe_context *ctx, void *state)
 {
+       struct r600_context *rctx = (struct r600_context *)ctx;
        struct r600_blend_state *blend = (struct r600_blend_state*)state;
 
+       if (rctx->blend_state.cso == state) {
+               ctx->bind_blend_state(ctx, NULL);
+       }
+
        r600_release_command_buffer(&blend->buffer);
        r600_release_command_buffer(&blend->buffer_no_blend);
        FREE(blend);