From 387fa7403c715b1dbff0193988bf4c75a64c57f3 Mon Sep 17 00:00:00 2001 From: "Isaac J. Manjarres" Date: Mon, 23 Nov 2020 12:35:50 -0800 Subject: [PATCH] ion: Restore secure system heap buffers' heap pointer after being freed When a secure system heap buffer is freed, the buffer's heap pointer is changed to the system heap, so that the buffer's pages can be freed into the secure pools properly. However, the buffer's heap pointer is not reset back to the secure system heap after the buffer has been freed. This is problematic, as the ION buffer tracking code uses the buffer's heap pointer to figure out which heap's memory accounting stats it has to decrement when a buffer is freed. In this case, we end up not decrementing the system secure heap's memory accounting stats, but instead, decrement the system heap's accounting stats, which is not correct. After freeing a buffer's pages, restore the buffer's heap pointer to the secure system heap, to ensure that the correct heap's accounting stats are adjusted. Change-Id: I4ade80660fb5585a2be93be4929db5c534351c2d Signed-off-by: Isaac J. Manjarres --- drivers/staging/android/ion/heaps/ion_system_secure_heap.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/staging/android/ion/heaps/ion_system_secure_heap.c b/drivers/staging/android/ion/heaps/ion_system_secure_heap.c index 470bc53a2bb3..e9683a3aa161 100644 --- a/drivers/staging/android/ion/heaps/ion_system_secure_heap.c +++ b/drivers/staging/android/ion/heaps/ion_system_secure_heap.c @@ -68,6 +68,12 @@ static void ion_system_secure_heap_free(struct ion_buffer *buffer) buffer->heap = secure_heap->sys_heap; secure_heap->sys_heap->ops->free(buffer); + /* + * Restore buffer's heap pointer to the system secure heap, so that + * the ION memory accounting code uses the system secure heap's stats + * instead of the system heap stats. + */ + buffer->heap = heap; } static int ion_system_secure_heap_allocate(struct ion_heap *heap,