mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] dmaengine: fix a reference leak in __dma_async_device_channel_register()
@ 2025-12-22  4:08 Haoxiang Li
  2025-12-29 16:30 ` Markus Elfring
  0 siblings, 1 reply; 2+ messages in thread
From: Haoxiang Li @ 2025-12-22  4:08 UTC (permalink / raw)
  To: vkoul, dave.jiang; +Cc: dmaengine, linux-kernel, Haoxiang Li, stable

After device_register() is called, put_device() is required to drop the
device reference. In this case, put_device() -> chan_dev_release() will
finally release chan->dev. Thus there is no need to call kfree again to
release the chan->dev.

Found by code review.

Fixes: d2fb0a043838 ("dmaengine: break out channel registration")
Cc: stable@vger.kernel.org
Signed-off-by: Haoxiang Li <lihaoxiang@isrc.iscas.ac.cn>
---
 drivers/dma/dmaengine.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index ca13cd39330b..9d7cea1d6e91 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -1071,6 +1071,7 @@ static int __dma_async_device_channel_register(struct dma_device *device,
 					       const char *name)
 {
 	int rc;
+	bool dev_registered = false;
 
 	chan->local = alloc_percpu(typeof(*chan->local));
 	if (!chan->local)
@@ -1102,6 +1103,7 @@ static int __dma_async_device_channel_register(struct dma_device *device,
 	else
 		dev_set_name(&chan->dev->device, "%s", name);
 	rc = device_register(&chan->dev->device);
+	dev_registered = true;
 	if (rc)
 		goto err_out_ida;
 	chan->client_count = 0;
@@ -1112,7 +1114,10 @@ static int __dma_async_device_channel_register(struct dma_device *device,
  err_out_ida:
 	ida_free(&device->chan_ida, chan->chan_id);
  err_free_dev:
-	kfree(chan->dev);
+	if (dev_registered)
+		put_device(&chan->dev->device);
+	else
+		kfree(chan->dev);
  err_free_local:
 	free_percpu(chan->local);
 	chan->local = NULL;
-- 
2.25.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2025-12-29 16:30 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-12-22  4:08 [PATCH] dmaengine: fix a reference leak in __dma_async_device_channel_register() Haoxiang Li
2025-12-29 16:30 ` Markus Elfring

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®