mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] dmaengine: ioat: fix completion pool leak on ring allocation failure
@ 2026-10-09  4:32 Haotian Zhang
  2026-10-09  5:55 ` Krzysztof Kozlowski
  2026-10-09  6:09 ` Krzysztof Kozlowski
  0 siblings, 2 replies; 3+ messages in thread
From: Haotian Zhang @ 2026-10-09  4:32 UTC (permalink / raw)
  To: Vinod Koul, Frank Li, Dan Williams, Maciej Sosnowski
  Cc: dmaengine, linux-kernel

ioat_alloc_chan_resources() allocates the channel completion writeback
area with dma_pool_zalloc() and then allocates the descriptor ring with
ioat_alloc_ring().  The ring allocation runs under GFP_NOWAIT and can
fail, in which case the function returns -ENOMEM without freeing the
completion area.  As the ring pointer stays NULL, the only teardown path,
ioat_free_chan_resources(), bails out early and never releases it; a
subsequent retry overwrites ioat_chan->completion, leaking the previous
allocation permanently.  The dmaengine core does not call
device_free_chan_resources() when device_alloc_chan_resources() fails, so
nothing else cleans it up either.

Release the completion area with dma_pool_free() before returning from the
ring allocation error path.

Fixes: 5cbafa65b92e ("ioat2,3: convert to a true ring buffer")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
---
 drivers/dma/ioat/init.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/dma/ioat/init.c b/drivers/dma/ioat/init.c
index 737496391109..000b59f0f04e 100644
--- a/drivers/dma/ioat/init.c
+++ b/drivers/dma/ioat/init.c
@@ -695,8 +695,14 @@ static int ioat_alloc_chan_resources(struct dma_chan *c)
 
 	order = IOAT_MAX_ORDER;
 	ring = ioat_alloc_ring(c, order, GFP_NOWAIT);
-	if (!ring)
+	if (!ring) {
+		dma_pool_free(ioat_chan->ioat_dma->completion_pool,
+			      ioat_chan->completion,
+			      ioat_chan->completion_dma);
+		ioat_chan->completion = NULL;
+		ioat_chan->completion_dma = 0;
 		return -ENOMEM;
+	}
 
 	spin_lock_bh(&ioat_chan->cleanup_lock);
 	spin_lock_bh(&ioat_chan->prep_lock);
-- 
2.25.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-09  6:10 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09  4:32 [PATCH] dmaengine: ioat: fix completion pool leak on ring allocation failure Haotian Zhang
2026-10-09  5:55 ` Krzysztof Kozlowski
2026-10-09  6:09 ` Krzysztof Kozlowski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®