The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH] iommu: Fix refcount leak in iommu_device_claim_dma_owner
@ 2022-12-30  8:31 Miaoqian Lin
  2023-01-03  1:26 ` Baolu Lu
  2023-01-13 12:39 ` Joerg Roedel
  0 siblings, 2 replies; 5+ messages in thread
From: Miaoqian Lin @ 2022-12-30  8:31 UTC (permalink / raw)
  To: Joerg Roedel, Will Deacon, Robin Murphy, Lu Baolu, Kevin Tian,
	Eric Auger, Jason Gunthorpe, iommu, linux-kernel
  Cc: linmq006

iommu_group_get() returns the group with the reference incremented.
Move iommu_group_get() after owner check to fix the refcount leak.

Fixes: 89395ccedbc1 ("iommu: Add device-centric DMA ownership interfaces")
Signed-off-by: Miaoqian Lin <linmq006@gmail.com>
---
 drivers/iommu/iommu.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/drivers/iommu/iommu.c b/drivers/iommu/iommu.c
index de91dd88705b..3a7dd8b61fab 100644
--- a/drivers/iommu/iommu.c
+++ b/drivers/iommu/iommu.c
@@ -3185,14 +3185,16 @@ EXPORT_SYMBOL_GPL(iommu_group_claim_dma_owner);
  */
 int iommu_device_claim_dma_owner(struct device *dev, void *owner)
 {
-	struct iommu_group *group = iommu_group_get(dev);
+	struct iommu_group *group = NULL;
 	int ret = 0;
 
-	if (!group)
-		return -ENODEV;
 	if (WARN_ON(!owner))
 		return -EINVAL;
 
+	group = iommu_group_get(dev);
+	if (!group)
+		return -ENODEV;
+
 	mutex_lock(&group->mutex);
 	if (group->owner_cnt) {
 		if (group->owner != owner) {
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread
* [PATCH] iommu: Fix refcount leak in iommu_device_claim_dma_owner
@ 2023-01-03  6:30 Miaoqian Lin
  2023-01-03 23:12 ` Jason Gunthorpe
  0 siblings, 1 reply; 5+ messages in thread
From: Miaoqian Lin @ 2023-01-03  6:30 UTC (permalink / raw)
  To: Joerg Roedel, Will Deacon, Robin Murphy, Lu Baolu, Eric Auger,
	Jason Gunthorpe, Kevin Tian, iommu, linux-kernel
  Cc: linmq006

iommu_group_get() returns the group with the reference incremented.
Also an empty @owner is a more serious problem than refcount leak.
Move iommu_group_get() after owner check to fix the refcount leak.

Fixes: 89395ccedbc1 ("iommu: Add device-centric DMA ownership interfaces")
Signed-off-by: Miaoqian Lin <linmq006@gmail.com>
---
changes in v2:
- Remove set NULL to group as suggested by Baolu Lu.
- Update commit message according to Lu's explanation.
---
 drivers/iommu/iommu.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/drivers/iommu/iommu.c b/drivers/iommu/iommu.c
index de91dd88705b..5f6a85aea501 100644
--- a/drivers/iommu/iommu.c
+++ b/drivers/iommu/iommu.c
@@ -3185,14 +3185,16 @@ EXPORT_SYMBOL_GPL(iommu_group_claim_dma_owner);
  */
 int iommu_device_claim_dma_owner(struct device *dev, void *owner)
 {
-	struct iommu_group *group = iommu_group_get(dev);
+	struct iommu_group *group;
 	int ret = 0;
 
-	if (!group)
-		return -ENODEV;
 	if (WARN_ON(!owner))
 		return -EINVAL;
 
+	group = iommu_group_get(dev);
+	if (!group)
+		return -ENODEV;
+
 	mutex_lock(&group->mutex);
 	if (group->owner_cnt) {
 		if (group->owner != owner) {
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2023-01-13 12:53 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-12-30  8:31 [PATCH] iommu: Fix refcount leak in iommu_device_claim_dma_owner Miaoqian Lin
2023-01-03  1:26 ` Baolu Lu
2023-01-13 12:39 ` Joerg Roedel
  -- strict thread matches above, loose matches on Subject: below --
2023-01-03  6:30 Miaoqian Lin
2023-01-03 23:12 ` Jason Gunthorpe

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox