msm: camera: common: Add missing put_cpu_buf calls

Add cam_mem_put_cpu_buf calls in error scenarios to avoid
memory leak.

CRs-Fixed: 3866880
Change-Id: I26ee4c58ab88458d109b13a04cfcaea3502b31a3
Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
This commit is contained in:
Nirmal Abraham 2024-06-26 18:08:57 +05:30 • committed by Prateek Pallav
commit ba6bfdd6ee
7 changed files with 35 additions and 11 deletions

View file

@ -4791,8 +4791,10 @@ static int __cam_isp_ctx_config_dev_in_top_state(
if ((len < sizeof(struct cam_packet)) ||
((size_t)cmd->offset >= len - sizeof(struct cam_packet))) {
CAM_ERR(CAM_ISP, "invalid buff length: %zu or offset", len);
rc = -EINVAL;
goto free_req;
spin_lock_bh(&ctx->lock);
list_add_tail(&req->list, &ctx->free_req_list);
spin_unlock_bh(&ctx->lock);
return -EINVAL;
}
remain_len -= (size_t)cmd->offset;

View file

@ -507,8 +507,10 @@ int32_t cam_actuator_i2c_pkt_parse(struct cam_actuator_ctrl_t *a_ctrl,
/* Loop through multiple command buffers */
for (i = 0; i < csl_packet->num_cmd_buf; i++) {
rc = cam_packet_util_validate_cmd_desc(&cmd_desc[i]);
if (rc)
if (rc) {
cam_mem_put_cpu_buf(config.packet_handle);
return rc;
}
total_cmd_buf_in_bytes = cmd_desc[i].length;
if (!total_cmd_buf_in_bytes)

View file

@ -379,6 +379,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
CAM_ERR(CAM_CSIPHY,
"Inval cam_packet strut size: %zu, len_of_buff: %zu",
sizeof(struct cam_packet), len);
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
rc = -EINVAL;
return rc;
}
@ -390,6 +391,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
if (cam_packet_util_validate_packet(csl_packet,
remain_len)) {
CAM_ERR(CAM_CSIPHY, "Invalid packet params");
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
rc = -EINVAL;
return rc;
}
@ -400,6 +402,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
csl_packet->cmd_buf_offset / 4);
else {
CAM_ERR(CAM_CSIPHY, "num_cmd_buffers = %d", csl_packet->num_cmd_buf);
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
rc = -EINVAL;
return rc;
}
@ -407,6 +410,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
rc = cam_packet_util_validate_cmd_desc(cmd_desc);
if (rc) {
CAM_ERR(CAM_CSIPHY, "Invalid cmd desc ret: %d", rc);
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
return rc;
}
@ -415,6 +419,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
if (rc < 0) {
CAM_ERR(CAM_CSIPHY,
"Failed to get cmd buf Mem address : %d", rc);
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
return rc;
}
@ -422,6 +427,8 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
(cmd_desc->offset > (len - sizeof(struct cam_csiphy_info)))) {
CAM_ERR(CAM_CSIPHY,
"Not enough buffer provided for cam_cisphy_info");
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
rc = -EINVAL;
return rc;
}
@ -433,6 +440,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
index = cam_csiphy_get_instance_offset(csiphy_dev, cfg_dev->dev_handle);
if (index < 0 || index >= csiphy_dev->session_max_device_support) {
CAM_ERR(CAM_CSIPHY, "index in invalid: %d", index);
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
return -EINVAL;
}
@ -443,6 +451,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
CAM_ERR(CAM_CSIPHY,
"Wrong configuration lane_cnt: %u",
cam_cmd_csiphy_info->lane_cnt);
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
return rc;
}

View file

@ -1065,9 +1065,10 @@ int cam_flash_i2c_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
/* Loop through multiple command buffers */
for (i = 1; i < csl_packet->num_cmd_buf; i++) {
rc = cam_packet_util_validate_cmd_desc(&cmd_desc[i]);
if (rc)
if (rc) {
cam_mem_put_cpu_buf(config.packet_handle);
return rc;
}
total_cmd_buf_in_bytes = cmd_desc[i].length;
processed_cmd_buf_in_bytes = 0;
if (!total_cmd_buf_in_bytes)
@ -1278,8 +1279,8 @@ int cam_flash_i2c_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
rc = fctrl->func_tbl.apply_setting(fctrl, 1);
if (rc) {
CAM_ERR(CAM_FLASH, "cannot apply fire settings rc = %d", rc);
return rc;
}
cam_mem_put_cpu_buf(config.packet_handle);
return rc;
}
break;
@ -1344,8 +1345,10 @@ int cam_flash_i2c_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
goto update_req_mgr;
}
case CAM_FLASH_PACKET_OPCODE_STREAM_OFF: {
if (fctrl->streamoff_count > 0)
if (fctrl->streamoff_count > 0) {
cam_mem_put_cpu_buf(config.packet_handle);
return rc;
}
CAM_DBG(CAM_FLASH, "Received Stream off Settings");
i2c_data = &(fctrl->i2c_data);
@ -1362,6 +1365,7 @@ int cam_flash_i2c_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
if (rc) {
CAM_ERR(CAM_FLASH,
"Failed in parsing i2c Stream off packets");
cam_mem_put_cpu_buf(config.packet_handle);
return rc;
}
break;
@ -1638,6 +1642,8 @@ int cam_flash_pmic_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
cmd_buf = (uint32_t *)((uint8_t *)cmd_buf_ptr +
cmd_desc->offset);
if (!cmd_buf) {
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
cam_mem_put_cpu_buf(config.packet_handle);
rc = -EINVAL;
return rc;
}
@ -1654,6 +1660,8 @@ int cam_flash_pmic_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
CAM_WARN(CAM_FLASH,
"Rxed Flash fire ops without linking");
flash_data->cmn_attr.is_settings_valid = false;
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
cam_mem_put_cpu_buf(config.packet_handle);
return -EINVAL;
}
if (remain_len < sizeof(struct cam_flash_set_on_off)) {

View file

@ -544,9 +544,10 @@ static int cam_ois_pkt_parse(struct cam_ois_ctrl_t *o_ctrl, void *arg)
/* Loop through multiple command buffers */
for (i = 0; i < csl_packet->num_cmd_buf; i++) {
rc = cam_packet_util_validate_cmd_desc(&cmd_desc[i]);
if (rc)
if (rc) {
cam_mem_put_cpu_buf(dev_config.packet_handle);
return rc;
}
total_cmd_buf_in_bytes = cmd_desc[i].length;
if (!total_cmd_buf_in_bytes)
continue;

View file

@ -556,8 +556,10 @@ int32_t cam_handle_mem_ptr(uint64_t handle, struct cam_sensor_ctrl_t *s_ctrl)
for (i = 0; i < pkt->num_cmd_buf; i++) {
rc = cam_packet_util_validate_cmd_desc(&cmd_desc[i]);
if (rc)
if (rc) {
cam_mem_put_cpu_buf(handle);
return rc;
}
if (!(cmd_desc[i].length))
continue;

View file

@ -316,12 +316,12 @@ static int32_t cam_sensor_get_io_buffer(
(uint8_t *)buf_addr + io_cfg->offsets[0];
i2c_settings->read_buff_len =
buf_size - io_cfg->offsets[0];
cam_mem_put_cpu_buf(io_cfg->mem_handle[0]);
} else {
CAM_ERR(CAM_SENSOR, "Invalid direction: %d",
io_cfg->direction);
rc = -EINVAL;
}
cam_mem_put_cpu_buf(io_cfg->mem_handle[0]);
return rc;
}