* [PATCH] dmaengine: qcom_hidma: Fix runtime PM leak in hidma_issue_task()
@ 2026-09-16 9:30 Wentao Liang
2026-09-16 9:43 ` sashiko-bot
2026-09-16 15:55 ` Frank Li
0 siblings, 2 replies; 3+ messages in thread
From: Wentao Liang @ 2026-09-16 9:30 UTC (permalink / raw)
To: Frank.Li
Cc: andy.shevchenko, dmaengine, linux-arm-kernel, linux-arm-msm,
linux-kernel, okaya, vkoul, Wentao Liang, stable
hidma_issue_task() bumps the device usage counter with
pm_runtime_get_sync() without checking the return value. The counter
is incremented even when the resume fails, e.g. when runtime PM has
been disabled or the device is suspending, and nothing drops it in
that case, so each failure leaves the device with an elevated usage
count and it can no longer runtime suspend.
Bail out and drop the leaked increment with pm_runtime_put_noidle()
when the resume fails, and only start the transfer when the device is
actually resumed. The counter for a successful resume is still
dropped by hidma_callback() as before.
Fixes: 67a2003e0607 ("dmaengine: add Qualcomm Technologies HIDMA channel driver")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/dma/qcom/hidma.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/qcom/hidma.c b/drivers/dma/qcom/hidma.c
index 5a8dca8db5ce..03a73dc9b066 100644
--- a/drivers/dma/qcom/hidma.c
+++ b/drivers/dma/qcom/hidma.c
@@ -220,7 +220,10 @@ static void hidma_issue_task(struct tasklet_struct *t)
{
struct hidma_dev *dmadev = from_tasklet(dmadev, t, task);
- pm_runtime_get_sync(dmadev->ddev.dev);
+ if (pm_runtime_get_sync(dmadev->ddev.dev) < 0) {
+ pm_runtime_put_noidle(dmadev->ddev.dev);
+ return;
+ }
hidma_ll_start(dmadev->lldev);
}
--
2.34.1
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] dmaengine: qcom_hidma: Fix runtime PM leak in hidma_issue_task()
2026-09-16 9:30 [PATCH] dmaengine: qcom_hidma: Fix runtime PM leak in hidma_issue_task() Wentao Liang
@ 2026-09-16 9:43 ` sashiko-bot
2026-09-16 15:55 ` Frank Li
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-16 9:43 UTC (permalink / raw)
To: Wentao Liang; +Cc: dmaengine, vkoul, Frank.Li
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] dmaengine: qcom_hidma: stranded active descriptors on pm_runtime_get_sync() failure
--
commit 77de19698670459fd2543b487a29198a77d2c2e6
Author: Wentao Liang <vulab@iscas.ac.cn>
dmaengine: qcom_hidma: Fix runtime PM leak in hidma_issue_task()
This commit fixes a runtime PM usage counter leak in hidma_issue_task() by
checking the return value of pm_runtime_get_sync(). If it fails, it drops
the counter with pm_runtime_put_noidle() and returns early to avoid starting
the transfer.
> diff --git a/drivers/dma/qcom/hidma.c b/drivers/dma/qcom/hidma.c
> index c939635be21d2..5ed6c77e2b212 100644
> --- a/drivers/dma/qcom/hidma.c
> +++ b/drivers/dma/qcom/hidma.c
> @@ -219,7 +219,10 @@ static void hidma_issue_task(struct tasklet_struct *t)
> {
> struct hidma_dev *dmadev = from_tasklet(dmadev, t, task);
>
> - pm_runtime_get_sync(dmadev->ddev.dev);
> + if (pm_runtime_get_sync(dmadev->ddev.dev) < 0) {
> + pm_runtime_put_noidle(dmadev->ddev.dev);
> + return;
[Severity: Medium]
Does this early return leave active descriptors stranded without cleaning
them up?
When a DMA client queues a transaction, the descriptors are moved to the
active list before hidma_issue_task() is scheduled. Aborting the state
machine here without initiating the hardware transfer or failing the
descriptors can leave them permanently stuck.
This could cause DMA clients to hang indefinitely while waiting for
completion callbacks that will never arrive.
> + }
> hidma_ll_start(dmadev->lldev);
> }
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916093032.2003397-1-vulab@iscas.ac.cn?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH] dmaengine: qcom_hidma: Fix runtime PM leak in hidma_issue_task()
2026-09-16 9:30 [PATCH] dmaengine: qcom_hidma: Fix runtime PM leak in hidma_issue_task() Wentao Liang
2026-09-16 9:43 ` sashiko-bot
@ 2026-09-16 15:55 ` Frank Li
1 sibling, 0 replies; 3+ messages in thread
From: Frank Li @ 2026-09-16 15:55 UTC (permalink / raw)
To: Wentao Liang
Cc: Frank.Li, andy.shevchenko, dmaengine, linux-arm-kernel,
linux-arm-msm, linux-kernel, okaya, vkoul, stable
On Wed, Sep 16, 2026 at 09:30:32AM +0000, Wentao Liang wrote:
> [You don't often get email from vulab@iscas.ac.cn. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
>
> hidma_issue_task() bumps the device usage counter with
> pm_runtime_get_sync() without checking the return value. The counter
> is incremented even when the resume fails, e.g. when runtime PM has
> been disabled or the device is suspending, and nothing drops it in
> that case, so each failure leaves the device with an elevated usage
> count and it can no longer runtime suspend.
>
> Bail out and drop the leaked increment with pm_runtime_put_noidle()
> when the resume fails, and only start the transfer when the device is
> actually resumed. The counter for a successful resume is still
> dropped by hidma_callback() as before.
>
> Fixes: 67a2003e0607 ("dmaengine: add Qualcomm Technologies HIDMA channel driver")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
> ---
> drivers/dma/qcom/hidma.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/dma/qcom/hidma.c b/drivers/dma/qcom/hidma.c
> index 5a8dca8db5ce..03a73dc9b066 100644
> --- a/drivers/dma/qcom/hidma.c
> +++ b/drivers/dma/qcom/hidma.c
> @@ -220,7 +220,10 @@ static void hidma_issue_task(struct tasklet_struct *t)
> {
> struct hidma_dev *dmadev = from_tasklet(dmadev, t, task);
>
> - pm_runtime_get_sync(dmadev->ddev.dev);
> + if (pm_runtime_get_sync(dmadev->ddev.dev) < 0) {
use pm_runtime_resume_and_get()
Frank
> + pm_runtime_put_noidle(dmadev->ddev.dev);
> + return;
> + }
> hidma_ll_start(dmadev->lldev);
> }
>
> --
> 2.34.1
>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-16 15:56 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 9:30 [PATCH] dmaengine: qcom_hidma: Fix runtime PM leak in hidma_issue_task() Wentao Liang
2026-09-16 9:43 ` sashiko-bot
2026-09-16 15:55 ` Frank Li
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox