From 03bb3d6ddd45e5be1f810dffb4ad7bda80300b46 Mon Sep 17 00:00:00 2001 From: "Isaac J. Manjarres" Date: Mon, 7 Oct 2019 14:49:44 -0700 Subject: [PATCH] ion: msm: Correct OF node refcount handling in error paths The for_each_[available]_child_of_node iterators implicitly increment the reference count on the current OF node at the start of the iteration, and decrements it at the end of the iteration. However, if the control flow is such that the loop can be broken out of prior to finishing an iteration, then the reference count must be decremented in the subsequent code path. Thus, fix the error path in the MSM ION code to decrement the reference on the current OF node when prematurely exiting an of_node loop. Change-Id: I5c2ec02a57eff416c04b1fe63c80d6e573a692d4 Signed-off-by: Isaac J. Manjarres --- drivers/staging/android/ion/heaps/ion_carveout_heap.c | 1 + drivers/staging/android/ion/heaps/msm_ion.c | 1 + 2 files changed, 2 insertions(+) diff --git a/drivers/staging/android/ion/heaps/ion_carveout_heap.c b/drivers/staging/android/ion/heaps/ion_carveout_heap.c index 1b77ae563dbf..2f2b4ad86bdb 100644 --- a/drivers/staging/android/ion/heaps/ion_carveout_heap.c +++ b/drivers/staging/android/ion/heaps/ion_carveout_heap.c @@ -405,6 +405,7 @@ ion_secure_carveout_heap_create(struct ion_platform_heap *heap_data) return &manager->heap.ion_heap; err: + of_node_put(np); ion_secure_carveout_heap_destroy(&manager->heap.ion_heap); return ERR_PTR(-EINVAL); } diff --git a/drivers/staging/android/ion/heaps/msm_ion.c b/drivers/staging/android/ion/heaps/msm_ion.c index bee349fec6a7..73451c032e1e 100644 --- a/drivers/staging/android/ion/heaps/msm_ion.c +++ b/drivers/staging/android/ion/heaps/msm_ion.c @@ -430,6 +430,7 @@ static struct ion_platform_data *msm_ion_parse_dt(struct platform_device *pdev) return pdata; free_heaps: + of_node_put(node); release_reserved_memory_regions(pdata->heaps, idx); free_pdata(pdata); return ERR_PTR(ret);