From: Fenghua Yu <fenghuay@nvidia.com>
To: Shuai Xue <xueshuai@linux.alibaba.com>,
vinicius.gomes@intel.com, dave.jiang@intel.com,
Markus.Elfring@web.de, vkoul@kernel.org
Cc: dmaengine@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v3 1/9] dmaengine: idxd: fix memory leak in error handling path of idxd_setup_wqs
Date: Wed, 2 Apr 2025 16:22:41 -0700 [thread overview]
Message-ID: <ed88358a-36cd-412f-9a09-baaf68297fcf@nvidia.com> (raw)
In-Reply-To: <20250309062058.58910-2-xueshuai@linux.alibaba.com>
On 3/8/25 22:20, Shuai Xue wrote:
> Memory allocated for wqs is not freed if an error occurs during
> idxd_setup_wqs(). To fix it, free the allocated memory in the reverse
> order of allocation before exiting the function in case of an error.
>
> Fixes: 7c5dd23e57c1 ("dmaengine: idxd: fix wq conf_dev 'struct device' lifetime")
> Fixes: 700af3a0a26c ("dmaengine: idxd: add 'struct idxd_dev' as wrapper for conf_dev")
> Fixes: de5819b99489 ("dmaengine: idxd: track enabled workqueues in bitmap")
> Fixes: b0325aefd398 ("dmaengine: idxd: add WQ operation cap restriction support")
> Cc: stable@vger.kernel.org
> Signed-off-by: Shuai Xue <xueshuai@linux.alibaba.com>
> Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Reviewed-by: Fenghua Yu <fenghuay@nvidia.com>
Thanks.
-Fenghua
> ---
> drivers/dma/idxd/init.c | 30 +++++++++++++++++++++---------
> 1 file changed, 21 insertions(+), 9 deletions(-)
>
> diff --git a/drivers/dma/idxd/init.c b/drivers/dma/idxd/init.c
> index b946f78f85e1..8b775c4a43fc 100644
> --- a/drivers/dma/idxd/init.c
> +++ b/drivers/dma/idxd/init.c
> @@ -169,8 +169,8 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
>
> idxd->wq_enable_map = bitmap_zalloc_node(idxd->max_wqs, GFP_KERNEL, dev_to_node(dev));
> if (!idxd->wq_enable_map) {
> - kfree(idxd->wqs);
> - return -ENOMEM;
> + rc = -ENOMEM;
> + goto err_bitmap;
> }
>
> for (i = 0; i < idxd->max_wqs; i++) {
> @@ -189,10 +189,8 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
> conf_dev->bus = &dsa_bus_type;
> conf_dev->type = &idxd_wq_device_type;
> rc = dev_set_name(conf_dev, "wq%d.%d", idxd->id, wq->id);
> - if (rc < 0) {
> - put_device(conf_dev);
> + if (rc < 0)
> goto err;
> - }
>
> mutex_init(&wq->wq_lock);
> init_waitqueue_head(&wq->err_queue);
> @@ -203,7 +201,6 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
> wq->enqcmds_retries = IDXD_ENQCMDS_RETRIES;
> wq->wqcfg = kzalloc_node(idxd->wqcfg_size, GFP_KERNEL, dev_to_node(dev));
> if (!wq->wqcfg) {
> - put_device(conf_dev);
> rc = -ENOMEM;
> goto err;
> }
> @@ -211,9 +208,8 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
> if (idxd->hw.wq_cap.op_config) {
> wq->opcap_bmap = bitmap_zalloc(IDXD_MAX_OPCAP_BITS, GFP_KERNEL);
> if (!wq->opcap_bmap) {
> - put_device(conf_dev);
> rc = -ENOMEM;
> - goto err;
> + goto err_opcap_bmap;
> }
> bitmap_copy(wq->opcap_bmap, idxd->opcap_bmap, IDXD_MAX_OPCAP_BITS);
> }
> @@ -224,12 +220,28 @@ static int idxd_setup_wqs(struct idxd_device *idxd)
>
> return 0;
>
> - err:
> +err_opcap_bmap:
> + kfree(wq->wqcfg);
> +
> +err:
> + put_device(conf_dev);
> + kfree(wq);
> +
> while (--i >= 0) {
> wq = idxd->wqs[i];
> + if (idxd->hw.wq_cap.op_config)
> + bitmap_free(wq->opcap_bmap);
> + kfree(wq->wqcfg);
> conf_dev = wq_confdev(wq);
> put_device(conf_dev);
> + kfree(wq);
> +
> }
> + bitmap_free(idxd->wq_enable_map);
> +
> +err_bitmap:
> + kfree(idxd->wqs);
> +
> return rc;
> }
>
next prev parent reply other threads:[~2025-04-02 23:22 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-03-09 6:20 [PATCH v3 0/9] dmaengine: idxd: fix memory leak in error handling path Shuai Xue
2025-03-09 6:20 ` [PATCH v3 1/9] dmaengine: idxd: fix memory leak in error handling path of idxd_setup_wqs Shuai Xue
2025-03-09 9:10 ` [PATCH v3 1/9] dmaengine: idxd: fix memory leak in error handling path of idxd_setup_wqs() Markus Elfring
2025-03-10 1:42 ` Shuai Xue
2025-03-10 9:50 ` [v3 " Markus Elfring
2025-04-02 23:22 ` Fenghua Yu [this message]
2025-03-09 6:20 ` [PATCH v3 2/9] dmaengine: idxd: fix memory leak in error handling path of idxd_setup_engines Shuai Xue
2025-03-09 6:20 ` [PATCH v3 3/9] dmaengine: idxd: fix memory leak in error handling path of idxd_setup_groups Shuai Xue
2025-04-02 23:24 ` Fenghua Yu
2025-03-09 6:20 ` [PATCH v3 4/9] dmaengine: idxd: Add missing cleanup for early error out in idxd_setup_internals Shuai Xue
2025-03-10 15:33 ` Dave Jiang
2025-04-02 23:26 ` Fenghua Yu
2025-04-04 11:47 ` Shuai Xue
2025-03-09 6:20 ` [PATCH v3 5/9] dmaengine: idxd: Add missing cleanups in cleanup internals Shuai Xue
2025-03-10 15:34 ` Dave Jiang
2025-04-02 23:27 ` Fenghua Yu
2025-03-09 6:20 ` [PATCH v3 6/9] dmaengine: idxd: fix memory leak in error handling path of idxd_alloc Shuai Xue
2025-04-02 23:31 ` Fenghua Yu
2025-03-09 6:20 ` [PATCH v3 7/9] dmaengine: idxd: fix memory leak in error handling path of idxd_pci_probe Shuai Xue
2025-04-02 23:31 ` Fenghua Yu
2025-03-09 6:20 ` [PATCH v3 8/9] dmaengine: idxd: Add missing idxd cleanup to fix memory leak in remove call Shuai Xue
2025-03-10 15:35 ` Dave Jiang
2025-04-02 23:31 ` Fenghua Yu
2025-03-09 6:20 ` [PATCH v3 9/9] dmaengine: idxd: Refactor remove call with idxd_cleanup() helper Shuai Xue
2025-03-10 15:36 ` Dave Jiang
2025-04-02 23:32 ` Fenghua Yu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ed88358a-36cd-412f-9a09-baaf68297fcf@nvidia.com \
--to=fenghuay@nvidia.com \
--cc=Markus.Elfring@web.de \
--cc=dave.jiang@intel.com \
--cc=dmaengine@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=vinicius.gomes@intel.com \
--cc=vkoul@kernel.org \
--cc=xueshuai@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.