From e666d158ebfbc64bf3bc3a1ee590b000d3808615 Mon Sep 17 00:00:00 2001 From: Prakash Gupta Date: Thu, 9 Jan 2020 16:16:15 +0530 Subject: [PATCH 1/2] ion: fix hyp_assign_sg failure handling In case of ion_hyp_assign_sg fails with partial buffers assigned to destination vmid, we can't return back the buffer back to pool or buddy. Let this leak to avoid fatal issue. Change-Id: Ice499af55ecf781db7d066c8553e377507795177 Signed-off-by: Prakash Gupta [isaacm@codeaurora.org: resolved trivial merge conflicts] Signed-off-by: Isaac J. Manjarres --- .../android/ion/heaps/ion_system_secure_heap.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/drivers/staging/android/ion/heaps/ion_system_secure_heap.c b/drivers/staging/android/ion/heaps/ion_system_secure_heap.c index c8f3bcd39421..188b28f6c5d5 100644 --- a/drivers/staging/android/ion/heaps/ion_system_secure_heap.c +++ b/drivers/staging/android/ion/heaps/ion_system_secure_heap.c @@ -1,6 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* - * Copyright (c) 2014-2019, The Linux Foundation. All rights reserved. + * Copyright (c) 2014-2020, The Linux Foundation. All rights reserved. */ #include @@ -120,7 +120,9 @@ static void process_one_prefetch(struct ion_heap *sys_heap, goto out; ret = ion_hyp_assign_sg(buffer.sg_table, &vmid, 1, true); - if (ret) + if (ret == -EADDRNOTAVAIL) + goto out1; + else if (ret < 0) goto out; /* Now free it to the secure heap */ @@ -129,6 +131,12 @@ static void process_one_prefetch(struct ion_heap *sys_heap, out: sys_heap->ops->free(&buffer); +out1: + /* + * The security state of the pages is unknown after a failure; + * They can neither be added back to the secure pool nor buddy system. + */ + return; } /* From c801746d9c54a23e1dc8fc7a876b6a40e997c798 Mon Sep 17 00:00:00 2001 From: Charan Teja Reddy Date: Thu, 13 Feb 2020 13:51:41 +0530 Subject: [PATCH 2/2] ion: don't call free_buffer_page on failure of ion_hyp_unassign_sg As we don't know the state of pages after failure from ion_hyp_unassign_sg, don't try to free them to buddy or pool. Change-Id: I54113ef13e25818301bdbe033468070b15cefa55 Signed-off-by: Charan Teja Reddy [isaacm@codeaurora.org: resolved trivial merge conflicts] Signed-off-by: Isaac J. Manjarres --- drivers/staging/android/ion/heaps/ion_system_heap.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/staging/android/ion/heaps/ion_system_heap.c b/drivers/staging/android/ion/heaps/ion_system_heap.c index a4034bb31fb9..4885702f5d16 100644 --- a/drivers/staging/android/ion/heaps/ion_system_heap.c +++ b/drivers/staging/android/ion/heaps/ion_system_heap.c @@ -390,11 +390,13 @@ err_free_sg2: buffer->private_flags |= ION_PRIV_FLAG_SHRINKER_FREE; if (vmid > 0) - ion_hyp_unassign_sg(table, &vmid, 1, true); + if (ion_hyp_unassign_sg(table, &vmid, 1, true)) + goto err_free_table_sync; for_each_sg(table->sgl, sg, table->nents, i) free_buffer_page(sys_heap, buffer, sg_page(sg), get_order(sg->length)); +err_free_table_sync: if (nents_sync) sg_free_table(&table_sync); err_free_sg: