From: Lukasz Majewski <l.majewski@samsung.com>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH 05/10] dfu: don't keep freeing/reallocating
Date: Tue, 08 Sep 2015 14:32:26 +0200 [thread overview]
Message-ID: <20150908143226.7151f0e3@amdc2363> (raw)
In-Reply-To: <1441425831-3441-5-git-send-email-swarren@wwwdotorg.org>
Hi Stephen,
> From: Stephen Warren <swarren@nvidia.com>
>
> DFU currently allocates buffer memory at the start of each data
> transfer operation and frees it at the end. Especially since
> memalign() is used to allocate the buffer, and various other
> allocations happen during the transfer, this can expose the code to
> heap fragmentation, which prevents the allocation from succeeding on
> subsequent transfers.
>
> Fix the code to allocate the buffer once when DFU mode is initialized,
> and free the buffer once when DFU mode is exited, to reduce the
> exposure to heap fragmentation.
>
> The failure mode is:
>
> // Internally to memalign(), this allocates a lot more than s to
> guarantee // that alignment can occur, then returns chunks of memory
> at the start/ // end of the allocated buffer to the heap.
> p = memalign(a, s);
> // Various other malloc()s occur here, some of which allocate the RAM
> // immediately before/after "p".
> //
> // DFU transfer is complete, so buffer is released.
> free(p);
> // By chance, no other malloc()/free() here, in DFU at least.
> //
> // A new DFU transfer starts, so the buffer is allocated again.
> // In theory this should succeed since we just free()d a buffer of the
> // same size. However, this fails because memalign() internally
> attempts // to allocate much more than "s", yet free(p) above only
> free()d a // little more than "s".
> p = memalign(a, s);
>
> Signed-off-by: Stephen Warren <swarren@nvidia.com>
> ---
> drivers/dfu/dfu.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/dfu/dfu.c b/drivers/dfu/dfu.c
> index 675162d927d8..d85d3f507a7b 100644
> --- a/drivers/dfu/dfu.c
> +++ b/drivers/dfu/dfu.c
> @@ -164,7 +164,6 @@ static int dfu_write_buffer_drain(struct
> dfu_entity *dfu) void dfu_write_transaction_cleanup(struct dfu_entity
> *dfu) {
> /* clear everything */
> - dfu_free_buf();
> dfu->crc = 0;
> dfu->offset = 0;
> dfu->i_blk_seq_num = 0;
> @@ -385,7 +384,6 @@ int dfu_read(struct dfu_entity *dfu, void *buf,
> int size, int blk_seq_num) dfu_hash_algo->name, dfu->crc);
> puts("\nUPLOAD ... done\nCtrl+C to exit ...\n");
>
> - dfu_free_buf();
> dfu->i_blk_seq_num = 0;
> dfu->crc = 0;
> dfu->offset = 0;
> @@ -433,6 +431,7 @@ static int dfu_fill_entity(struct dfu_entity
> *dfu, char *s, int alt, __func__, interface);
> return -1;
> }
> + dfu_get_buf(dfu);
>
> return 0;
> }
> @@ -441,6 +440,7 @@ void dfu_free_entities(void)
> {
> struct dfu_entity *dfu, *p, *t = NULL;
>
> + dfu_free_buf();
> list_for_each_entry_safe_reverse(dfu, p, &dfu_list, list) {
> list_del(&dfu->list);
> if (dfu->free_entity)
Acked-by: Lukasz Majewski <l.majewski@samsung.com>
Tested-by: Lukasz Majewski <l.majewski@samsung.com>
Test HW: Odroid XU3 - Exynos5433
[DFU tests]
--
Best regards,
Lukasz Majewski
Samsung R&D Institute Poland (SRPOL) | Linux Platform Group
next prev parent reply other threads:[~2015-09-08 12:32 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-09-05 4:03 [U-Boot] [PATCH 01/10] usb: gadget: don't leak configs when unbinding Stephen Warren
2015-09-05 4:03 ` [U-Boot] [PATCH 02/10] ext4: avoid calling ext4fs_mount() twice, which leaks Stephen Warren
2015-09-08 13:22 ` Lukasz Majewski
2015-09-12 12:51 ` [U-Boot] [U-Boot, " Tom Rini
2015-09-05 4:03 ` [U-Boot] [PATCH 03/10] ext4: free allocations by parse_path() Stephen Warren
2015-09-08 13:10 ` Lukasz Majewski
2015-09-12 12:51 ` [U-Boot] [U-Boot,03/10] " Tom Rini
2015-09-05 4:03 ` [U-Boot] [PATCH 04/10] ext4: fix leak in check_filename() Stephen Warren
2015-09-08 13:05 ` Lukasz Majewski
2015-09-12 12:51 ` [U-Boot] [U-Boot,04/10] " Tom Rini
2015-09-05 4:03 ` [U-Boot] [PATCH 05/10] dfu: don't keep freeing/reallocating Stephen Warren
2015-09-08 12:32 ` Lukasz Majewski [this message]
2015-09-12 12:51 ` [U-Boot] [U-Boot,05/10] " Tom Rini
2015-09-05 4:03 ` [U-Boot] [PATCH 06/10] dfu: mmc: buffer file reads too Stephen Warren
2015-09-08 12:57 ` Lukasz Majewski
2015-09-12 12:51 ` [U-Boot] [U-Boot,06/10] " Tom Rini
2015-09-05 4:03 ` [U-Boot] [PATCH 07/10] ARM: tegra: fix malloc region sizing Stephen Warren
2015-09-08 16:53 ` Tom Warren
2015-09-08 21:45 ` Stephen Warren
2015-09-08 21:52 ` Stephen Warren
2015-09-08 21:56 ` Tom Rini
2015-09-08 21:56 ` Stephen Warren
2015-09-09 6:51 ` Lukasz Majewski
2015-09-09 16:08 ` Tom Warren
2015-09-12 12:51 ` [U-Boot] [U-Boot,07/10] " Tom Rini
2015-09-05 4:03 ` [U-Boot] [PATCH 08/10] ARM: tegra: tweak DFU buffer sizes Stephen Warren
2015-09-12 12:51 ` [U-Boot] [U-Boot,08/10] " Tom Rini
2015-09-05 4:03 ` [U-Boot] [PATCH 09/10] ARM: tegra: enable filesystem writing Stephen Warren
2015-09-12 12:51 ` [U-Boot] [U-Boot,09/10] " Tom Rini
2015-09-05 4:03 ` [U-Boot] [PATCH 10/10] ARM: tegra: enable DFU for RAM Stephen Warren
2015-09-12 12:51 ` [U-Boot] [U-Boot,10/10] " Tom Rini
2015-09-08 12:00 ` [U-Boot] [PATCH 01/10] usb: gadget: don't leak configs when unbinding Lukasz Majewski
2015-09-08 21:50 ` Stephen Warren
2015-09-12 12:51 ` [U-Boot] [U-Boot, " Tom Rini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150908143226.7151f0e3@amdc2363 \
--to=l.majewski@samsung.com \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.