linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Jani Nikula <jani.nikula@linux.intel.com>
To: 赵军奎 <bernard@vivo.com>,
	"Maarten Lankhorst" <maarten.lankhorst@linux.intel.com>,
	"Maxime Ripard" <mripard@kernel.org>,
	"Thomas Zimmermann" <tzimmermann@suse.de>,
	"David Airlie" <airlied@linux.ie>,
	"Daniel Vetter" <daniel@ffwll.ch>,
	"dri-devel@lists.freedesktop.org"
	<dri-devel@lists.freedesktop.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Subject: Re: 答复: [PATCH] gpu/drm: fix potential memleak in error branch
Date: Tue, 04 Jan 2022 13:25:19 +0200	[thread overview]
Message-ID: <87k0ffu4io.fsf@intel.com> (raw)
In-Reply-To: <PSAPR06MB40216FB1425E72891B6A6B28DF4A9@PSAPR06MB4021.apcprd06.prod.outlook.com>

On Tue, 04 Jan 2022, 赵军奎 <bernard@vivo.com> wrote:
> -----邮件原件-----
> 发件人: bernard@vivo.com <bernard@vivo.com> 代表 Jani Nikula
> 发送时间: 2021年12月31日 19:09
> 收件人: 赵军奎 <bernard@vivo.com>; Maarten Lankhorst <maarten.lankhorst@linux.intel.com>; Maxime Ripard <mripard@kernel.org>; Thomas Zimmermann <tzimmermann@suse.de>; David Airlie <airlied@linux.ie>; Daniel Vetter <daniel@ffwll.ch>; dri-devel@lists.freedesktop.org; linux-kernel@vger.kernel.org
> 抄送: 赵军奎 <bernard@vivo.com>
> 主题: Re: [PATCH] gpu/drm: fix potential memleak in error branch
>
> On Tue, 16 Nov 2021, Bernard Zhao <bernard@vivo.com> wrote:
>> This patch try to fix potential memleak in error branch.
>
>>Please elaborate.
>
> Hi Jani:
>
> This patch try to fix potential memleak in error branch.
> For example:
> nv50_sor_create ->nv50_mstm_new-> drm_dp_mst_topology_mgr_init
> In function drm_dp_mst_topology_mgr_init, there are five error branches, error branch just return error code, no free called. 
> And we see that the caller didn`t do the drm_dp_mst_topology_mgr_destroy job.
> I am not sure if there some gap, I think this may bring in the risk of memleak issue.
> Thanks!

This should be part of the commit message.

>
> BR//Bernard
>
>>BR,
>>Jani.
>
>
>>
>> Signed-off-by: Bernard Zhao <bernard@vivo.com>
>> ---
>>  drivers/gpu/drm/drm_dp_mst_topology.c | 22 ++++++++++++++++------
>>  1 file changed, 16 insertions(+), 6 deletions(-)
>>
>> diff --git a/drivers/gpu/drm/drm_dp_mst_topology.c 
>> b/drivers/gpu/drm/drm_dp_mst_topology.c
>> index f3d79eda94bb..f73b180dee73 100644
>> --- a/drivers/gpu/drm/drm_dp_mst_topology.c
>> +++ b/drivers/gpu/drm/drm_dp_mst_topology.c
>> @@ -5501,7 +5501,10 @@ int drm_dp_mst_topology_mgr_init(struct drm_dp_mst_topology_mgr *mgr,
>>  				 int max_lane_count, int max_link_rate,
>>  				 int conn_base_id)
>>  {
>> -	struct drm_dp_mst_topology_state *mst_state;
>> +	struct drm_dp_mst_topology_state *mst_state = NULL;

This is superfluous.

Other than that,

Reviewed-by: Jani Nikula <jani.nikula@intel.com>


>> +
>> +	mgr->payloads = NULL;
>> +	mgr->proposed_vcpis = NULL;
>>  
>>  	mutex_init(&mgr->lock);
>>  	mutex_init(&mgr->qlock);
>> @@ -5523,7 +5526,7 @@ int drm_dp_mst_topology_mgr_init(struct drm_dp_mst_topology_mgr *mgr,
>>  	 */
>>  	mgr->delayed_destroy_wq = alloc_ordered_workqueue("drm_dp_mst_wq", 0);
>>  	if (mgr->delayed_destroy_wq == NULL)
>> -		return -ENOMEM;
>> +		goto out;
>>  
>>  	INIT_WORK(&mgr->work, drm_dp_mst_link_probe_work);
>>  	INIT_WORK(&mgr->tx_work, drm_dp_tx_work); @@ -5539,18 +5542,18 @@ 
>> int drm_dp_mst_topology_mgr_init(struct drm_dp_mst_topology_mgr *mgr,
>>  	mgr->conn_base_id = conn_base_id;
>>  	if (max_payloads + 1 > sizeof(mgr->payload_mask) * 8 ||
>>  	    max_payloads + 1 > sizeof(mgr->vcpi_mask) * 8)
>> -		return -EINVAL;
>> +		goto failed;
>>  	mgr->payloads = kcalloc(max_payloads, sizeof(struct drm_dp_payload), GFP_KERNEL);
>>  	if (!mgr->payloads)
>> -		return -ENOMEM;
>> +		goto failed;
>>  	mgr->proposed_vcpis = kcalloc(max_payloads, sizeof(struct drm_dp_vcpi *), GFP_KERNEL);
>>  	if (!mgr->proposed_vcpis)
>> -		return -ENOMEM;
>> +		goto failed;
>>  	set_bit(0, &mgr->payload_mask);
>>  
>>  	mst_state = kzalloc(sizeof(*mst_state), GFP_KERNEL);
>>  	if (mst_state == NULL)
>> -		return -ENOMEM;
>> +		goto failed;
>>  
>>  	mst_state->total_avail_slots = 63;
>>  	mst_state->start_slot = 1;
>> @@ -5563,6 +5566,13 @@ int drm_dp_mst_topology_mgr_init(struct drm_dp_mst_topology_mgr *mgr,
>>  				    &drm_dp_mst_topology_state_funcs);
>>  
>>  	return 0;
>> +
>> +failed:
>> +	kfree(mgr->proposed_vcpis);
>> +	kfree(mgr->payloads);
>> +	destroy_workqueue(mgr->delayed_destroy_wq);
>> +out:
>> +	return -ENOMEM;
>>  }
>>  EXPORT_SYMBOL(drm_dp_mst_topology_mgr_init);
>
> --
> Jani Nikula, Intel Open Source Graphics Center

-- 
Jani Nikula, Intel Open Source Graphics Center

  reply	other threads:[~2022-01-04 11:25 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-11-16 12:47 [PATCH] gpu/drm: fix potential memleak in error branch Bernard Zhao
2021-12-31 11:09 ` Jani Nikula
     [not found] ` <ACIArwAdEzJlxV*UItyRxarz.9.1640948962309.Hmail.bernard@vivo.com.@PDg3emdvaGh2emEuZnNmQGludGVsLmNvbT4=>
2022-01-04  9:38   ` 答复: " 赵军奎
2022-01-04 11:25     ` Jani Nikula [this message]
     [not found]     ` <AO6AtwCGE3lpmasg9JDLUKqP.9.1641295527410.Hmail.bernard@vivo.com.@PDg3azBmZnU0aW8uZnNmQGludGVsLmNvbT4=>
2022-01-05  1:17       ` 答复: " 赵军奎

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87k0ffu4io.fsf@intel.com \
    --to=jani.nikula@linux.intel.com \
    --cc=airlied@linux.ie \
    --cc=bernard@vivo.com \
    --cc=daniel@ffwll.ch \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=maarten.lankhorst@linux.intel.com \
    --cc=mripard@kernel.org \
    --cc=tzimmermann@suse.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).