diff --git a/drivers/staging/android/ion/heaps/ion_system_heap.c b/drivers/staging/android/ion/heaps/ion_system_heap.c index a4034bb31fb9..4885702f5d16 100644 --- a/drivers/staging/android/ion/heaps/ion_system_heap.c +++ b/drivers/staging/android/ion/heaps/ion_system_heap.c @@ -390,11 +390,13 @@ err_free_sg2: buffer->private_flags |= ION_PRIV_FLAG_SHRINKER_FREE; if (vmid > 0) - ion_hyp_unassign_sg(table, &vmid, 1, true); + if (ion_hyp_unassign_sg(table, &vmid, 1, true)) + goto err_free_table_sync; for_each_sg(table->sgl, sg, table->nents, i) free_buffer_page(sys_heap, buffer, sg_page(sg), get_order(sg->length)); +err_free_table_sync: if (nents_sync) sg_free_table(&table_sync); err_free_sg: diff --git a/drivers/staging/android/ion/heaps/ion_system_secure_heap.c b/drivers/staging/android/ion/heaps/ion_system_secure_heap.c index c8f3bcd39421..188b28f6c5d5 100644 --- a/drivers/staging/android/ion/heaps/ion_system_secure_heap.c +++ b/drivers/staging/android/ion/heaps/ion_system_secure_heap.c @@ -1,6 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* - * Copyright (c) 2014-2019, The Linux Foundation. All rights reserved. + * Copyright (c) 2014-2020, The Linux Foundation. All rights reserved. */ #include @@ -120,7 +120,9 @@ static void process_one_prefetch(struct ion_heap *sys_heap, goto out; ret = ion_hyp_assign_sg(buffer.sg_table, &vmid, 1, true); - if (ret) + if (ret == -EADDRNOTAVAIL) + goto out1; + else if (ret < 0) goto out; /* Now free it to the secure heap */ @@ -129,6 +131,12 @@ static void process_one_prefetch(struct ion_heap *sys_heap, out: sys_heap->ops->free(&buffer); +out1: + /* + * The security state of the pages is unknown after a failure; + * They can neither be added back to the secure pool nor buddy system. + */ + return; } /*