From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754324AbbIRRR3 (ORCPT ); Fri, 18 Sep 2015 13:17:29 -0400 Received: from comal.ext.ti.com ([198.47.26.152]:47584 "EHLO comal.ext.ti.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753937AbbIRRR1 (ORCPT ); Fri, 18 Sep 2015 13:17:27 -0400 Date: Fri, 18 Sep 2015 12:17:20 -0500 From: Felipe Balbi To: CC: , , Peter Chen , Greg Kroah-Hartman , Felipe Balbi , Andrzej Pietrasiewicz Subject: Re: [PATCH 1/2] usb: chipidea: udc: improve error handling on ep_queue Message-ID: <20150918171720.GB7636@saruman.tx.rr.com> Reply-To: References: <1442596361-404-1-git-send-email-eu@felipetonello.com> <1442596361-404-2-git-send-email-eu@felipetonello.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="7iMSBzlTiPOCCT2k" Content-Disposition: inline In-Reply-To: <1442596361-404-2-git-send-email-eu@felipetonello.com> User-Agent: Mutt/1.5.23 (2014-03-12) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org --7iMSBzlTiPOCCT2k Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Hi, On Fri, Sep 18, 2015 at 06:12:40PM +0100, eu@felipetonello.com wrote: > From: "Felipe F. Tonello" >=20 > _ep_queue() didn't check for errors when using add_td_to_list() > which can fail if dma_pool_alloc fails, thus causing a kernel > panic when lastnode->ptr is NULL. >=20 > Signed-off-by: Felipe F. Tonello this can still be split down further. > --- > drivers/usb/chipidea/udc.c | 26 +++++++++++++++++++------- > 1 file changed, 19 insertions(+), 7 deletions(-) >=20 > diff --git a/drivers/usb/chipidea/udc.c b/drivers/usb/chipidea/udc.c > index 764f668..7169113e 100644 > --- a/drivers/usb/chipidea/udc.c > +++ b/drivers/usb/chipidea/udc.c > @@ -404,9 +404,9 @@ static inline u8 _usb_addr(struct ci_hw_ep *ep) > } > =20 > /** > - * _hardware_queue: configures a request at hardware level > - * @gadget: gadget > + * _hardware_enqueue: configures a request at hardware level > * @hwep: endpoint > + * @hwreq: request this is a cleanup and you shouldn't have a fix depending on a cleanup. Fixes are merged during the -rc cycle, while cleanups will be deferred to the following merge window. > * > * This function returns an error code > */ > @@ -435,19 +435,27 @@ static int _hardware_enqueue(struct ci_hw_ep *hwep,= struct ci_hw_req *hwreq) > if (hwreq->req.dma % PAGE_SIZE) > pages--; > =20 > - if (rest =3D=3D 0) > - add_td_to_list(hwep, hwreq, 0); > + if (rest =3D=3D 0) { > + ret =3D add_td_to_list(hwep, hwreq, 0); > + if (ret < 0) > + goto done; > + } this is your fix. > =20 > while (rest > 0) { > unsigned count =3D min(hwreq->req.length - hwreq->req.actual, > (unsigned)(pages * CI_HDRC_PAGE_SIZE)); > - add_td_to_list(hwep, hwreq, count); > + ret =3D add_td_to_list(hwep, hwreq, count); > + if (ret < 0) > + goto done; and this > rest -=3D count; > } > =20 > if (hwreq->req.zero && hwreq->req.length > - && (hwreq->req.length % hwep->ep.maxpacket =3D=3D 0)) > - add_td_to_list(hwep, hwreq, 0); > + && (hwreq->req.length % hwep->ep.maxpacket =3D=3D 0)) { > + ret =3D add_td_to_list(hwep, hwreq, 0); > + if (ret < 0) > + goto done; > + } > and this. > firstnode =3D list_first_entry(&hwreq->tds, struct td_node, td); > =20 > @@ -750,8 +758,12 @@ static void isr_get_status_complete(struct usb_ep *e= p, struct usb_request *req) > =20 > /** > * _ep_queue: queues (submits) an I/O request to an endpoint > + * @ep: endpoint > + * @req: request > + * @gfp_flags: GFP flags (not used) cleanup > * > * Caller must hold lock > + * This function returns an error code somewhat pointless, but could come with the cleanup, no strong feelings. > */ > static int _ep_queue(struct usb_ep *ep, struct usb_request *req, > gfp_t __maybe_unused gfp_flags) > --=20 > 2.1.4 >=20 --=20 balbi --7iMSBzlTiPOCCT2k Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJV/EcgAAoJEIaOsuA1yqREedAQALbLgajsC3/6rCJgrza2B5gf 2oqzAoavvdn+dfCuoxje3ZqDktzHg3jDfhH6QZ96C2RlpeObo+mT/qcPKNts/Czl lPwQPM6xstEckZDN6+kV//4iwDe2oN+ehwnl3gIoBRYH97hAHcLyz7sNOKq1f32Z ZZz8eCEgX1Xwz0Ok5Q9RSAl+1uvmWDUeOA/S1jUNDbUtYkrgJWyJjSxlXab2T5NS tUqkEhudCjnDQzCeXQmezyKJh5XiYw9CYKCMMrmpkojGatjp+muzjmwohPkjt7p+ X2rxR18yoLyvw4h6clJK9QBSq0kvDRz8DdZrpY3OOT4IvQ4nZqiBONV101rmvtr1 uYf7qAbtJ/cSGXiiBkWqL9QKP0o8DIYEz5yN46AXGqZvWCX0CaU1nToPKGXDaVzT hoNCupb8t05f88s0guelZD7MJJxIEExLvfj0S17IIscP9iNYtm/GDwUMlbDoU8SG YZKb7dseJPG1uS8b9+zchdsCvBiJ0mqZtiwzeBZNTbD2C6H5vtgplHObzFCQhdiX e+AJeYuAjiPwXq4ncANWx7dQWDdXc/U4zpOM/OKLfwFCZ1Qm0QIzDzVAWJi1RYJt zojKWUMiSBt7oNTZsDYK38MOmX8qgldl1iuo5uVbNOxU4bJ3y2UVnhrP+vF/FaQb /Yy7iKQpV9b5gyiqUr1/ =UZC2 -----END PGP SIGNATURE----- --7iMSBzlTiPOCCT2k--