mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 06:09:23 -04:00
msm: camera: common: Add missing put_cpu_buf calls
Add cam_mem_put_cpu_buf calls in error scenarios to avoid memory leak. CRs-Fixed: 3866880 Change-Id: I26ee4c58ab88458d109b13a04cfcaea3502b31a3 Signed-off-by: Nirmal Abraham <quic_c_nabrah@quicinc.com>
This commit is contained in:
parent
4bc8ff3984
commit
ba6bfdd6ee
7 changed files with 35 additions and 11 deletions
|
|
@ -4791,8 +4791,10 @@ static int __cam_isp_ctx_config_dev_in_top_state(
|
|||
if ((len < sizeof(struct cam_packet)) ||
|
||||
((size_t)cmd->offset >= len - sizeof(struct cam_packet))) {
|
||||
CAM_ERR(CAM_ISP, "invalid buff length: %zu or offset", len);
|
||||
rc = -EINVAL;
|
||||
goto free_req;
|
||||
spin_lock_bh(&ctx->lock);
|
||||
list_add_tail(&req->list, &ctx->free_req_list);
|
||||
spin_unlock_bh(&ctx->lock);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
remain_len -= (size_t)cmd->offset;
|
||||
|
|
|
|||
|
|
@ -507,8 +507,10 @@ int32_t cam_actuator_i2c_pkt_parse(struct cam_actuator_ctrl_t *a_ctrl,
|
|||
/* Loop through multiple command buffers */
|
||||
for (i = 0; i < csl_packet->num_cmd_buf; i++) {
|
||||
rc = cam_packet_util_validate_cmd_desc(&cmd_desc[i]);
|
||||
if (rc)
|
||||
if (rc) {
|
||||
cam_mem_put_cpu_buf(config.packet_handle);
|
||||
return rc;
|
||||
}
|
||||
|
||||
total_cmd_buf_in_bytes = cmd_desc[i].length;
|
||||
if (!total_cmd_buf_in_bytes)
|
||||
|
|
|
|||
|
|
@ -379,6 +379,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
|
|||
CAM_ERR(CAM_CSIPHY,
|
||||
"Inval cam_packet strut size: %zu, len_of_buff: %zu",
|
||||
sizeof(struct cam_packet), len);
|
||||
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
|
||||
rc = -EINVAL;
|
||||
return rc;
|
||||
}
|
||||
|
|
@ -390,6 +391,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
|
|||
if (cam_packet_util_validate_packet(csl_packet,
|
||||
remain_len)) {
|
||||
CAM_ERR(CAM_CSIPHY, "Invalid packet params");
|
||||
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
|
||||
rc = -EINVAL;
|
||||
return rc;
|
||||
}
|
||||
|
|
@ -400,6 +402,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
|
|||
csl_packet->cmd_buf_offset / 4);
|
||||
else {
|
||||
CAM_ERR(CAM_CSIPHY, "num_cmd_buffers = %d", csl_packet->num_cmd_buf);
|
||||
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
|
||||
rc = -EINVAL;
|
||||
return rc;
|
||||
}
|
||||
|
|
@ -407,6 +410,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
|
|||
rc = cam_packet_util_validate_cmd_desc(cmd_desc);
|
||||
if (rc) {
|
||||
CAM_ERR(CAM_CSIPHY, "Invalid cmd desc ret: %d", rc);
|
||||
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
|
||||
return rc;
|
||||
}
|
||||
|
||||
|
|
@ -415,6 +419,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
|
|||
if (rc < 0) {
|
||||
CAM_ERR(CAM_CSIPHY,
|
||||
"Failed to get cmd buf Mem address : %d", rc);
|
||||
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
|
||||
return rc;
|
||||
}
|
||||
|
||||
|
|
@ -422,6 +427,8 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
|
|||
(cmd_desc->offset > (len - sizeof(struct cam_csiphy_info)))) {
|
||||
CAM_ERR(CAM_CSIPHY,
|
||||
"Not enough buffer provided for cam_cisphy_info");
|
||||
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
|
||||
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
|
||||
rc = -EINVAL;
|
||||
return rc;
|
||||
}
|
||||
|
|
@ -433,6 +440,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
|
|||
index = cam_csiphy_get_instance_offset(csiphy_dev, cfg_dev->dev_handle);
|
||||
if (index < 0 || index >= csiphy_dev->session_max_device_support) {
|
||||
CAM_ERR(CAM_CSIPHY, "index in invalid: %d", index);
|
||||
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
|
||||
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
|
@ -443,6 +451,7 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
|
|||
CAM_ERR(CAM_CSIPHY,
|
||||
"Wrong configuration lane_cnt: %u",
|
||||
cam_cmd_csiphy_info->lane_cnt);
|
||||
cam_mem_put_cpu_buf((int32_t)cfg_dev->packet_handle);
|
||||
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
|
||||
return rc;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -1065,9 +1065,10 @@ int cam_flash_i2c_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
|
|||
/* Loop through multiple command buffers */
|
||||
for (i = 1; i < csl_packet->num_cmd_buf; i++) {
|
||||
rc = cam_packet_util_validate_cmd_desc(&cmd_desc[i]);
|
||||
if (rc)
|
||||
if (rc) {
|
||||
cam_mem_put_cpu_buf(config.packet_handle);
|
||||
return rc;
|
||||
|
||||
}
|
||||
total_cmd_buf_in_bytes = cmd_desc[i].length;
|
||||
processed_cmd_buf_in_bytes = 0;
|
||||
if (!total_cmd_buf_in_bytes)
|
||||
|
|
@ -1278,8 +1279,8 @@ int cam_flash_i2c_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
|
|||
rc = fctrl->func_tbl.apply_setting(fctrl, 1);
|
||||
if (rc) {
|
||||
CAM_ERR(CAM_FLASH, "cannot apply fire settings rc = %d", rc);
|
||||
return rc;
|
||||
}
|
||||
cam_mem_put_cpu_buf(config.packet_handle);
|
||||
return rc;
|
||||
}
|
||||
break;
|
||||
|
|
@ -1344,8 +1345,10 @@ int cam_flash_i2c_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
|
|||
goto update_req_mgr;
|
||||
}
|
||||
case CAM_FLASH_PACKET_OPCODE_STREAM_OFF: {
|
||||
if (fctrl->streamoff_count > 0)
|
||||
if (fctrl->streamoff_count > 0) {
|
||||
cam_mem_put_cpu_buf(config.packet_handle);
|
||||
return rc;
|
||||
}
|
||||
|
||||
CAM_DBG(CAM_FLASH, "Received Stream off Settings");
|
||||
i2c_data = &(fctrl->i2c_data);
|
||||
|
|
@ -1362,6 +1365,7 @@ int cam_flash_i2c_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
|
|||
if (rc) {
|
||||
CAM_ERR(CAM_FLASH,
|
||||
"Failed in parsing i2c Stream off packets");
|
||||
cam_mem_put_cpu_buf(config.packet_handle);
|
||||
return rc;
|
||||
}
|
||||
break;
|
||||
|
|
@ -1638,6 +1642,8 @@ int cam_flash_pmic_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
|
|||
cmd_buf = (uint32_t *)((uint8_t *)cmd_buf_ptr +
|
||||
cmd_desc->offset);
|
||||
if (!cmd_buf) {
|
||||
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
|
||||
cam_mem_put_cpu_buf(config.packet_handle);
|
||||
rc = -EINVAL;
|
||||
return rc;
|
||||
}
|
||||
|
|
@ -1654,6 +1660,8 @@ int cam_flash_pmic_pkt_parser(struct cam_flash_ctrl *fctrl, void *arg)
|
|||
CAM_WARN(CAM_FLASH,
|
||||
"Rxed Flash fire ops without linking");
|
||||
flash_data->cmn_attr.is_settings_valid = false;
|
||||
cam_mem_put_cpu_buf(cmd_desc->mem_handle);
|
||||
cam_mem_put_cpu_buf(config.packet_handle);
|
||||
return -EINVAL;
|
||||
}
|
||||
if (remain_len < sizeof(struct cam_flash_set_on_off)) {
|
||||
|
|
|
|||
|
|
@ -544,9 +544,10 @@ static int cam_ois_pkt_parse(struct cam_ois_ctrl_t *o_ctrl, void *arg)
|
|||
/* Loop through multiple command buffers */
|
||||
for (i = 0; i < csl_packet->num_cmd_buf; i++) {
|
||||
rc = cam_packet_util_validate_cmd_desc(&cmd_desc[i]);
|
||||
if (rc)
|
||||
if (rc) {
|
||||
cam_mem_put_cpu_buf(dev_config.packet_handle);
|
||||
return rc;
|
||||
|
||||
}
|
||||
total_cmd_buf_in_bytes = cmd_desc[i].length;
|
||||
if (!total_cmd_buf_in_bytes)
|
||||
continue;
|
||||
|
|
|
|||
|
|
@ -556,8 +556,10 @@ int32_t cam_handle_mem_ptr(uint64_t handle, struct cam_sensor_ctrl_t *s_ctrl)
|
|||
|
||||
for (i = 0; i < pkt->num_cmd_buf; i++) {
|
||||
rc = cam_packet_util_validate_cmd_desc(&cmd_desc[i]);
|
||||
if (rc)
|
||||
if (rc) {
|
||||
cam_mem_put_cpu_buf(handle);
|
||||
return rc;
|
||||
}
|
||||
|
||||
if (!(cmd_desc[i].length))
|
||||
continue;
|
||||
|
|
|
|||
|
|
@ -316,12 +316,12 @@ static int32_t cam_sensor_get_io_buffer(
|
|||
(uint8_t *)buf_addr + io_cfg->offsets[0];
|
||||
i2c_settings->read_buff_len =
|
||||
buf_size - io_cfg->offsets[0];
|
||||
cam_mem_put_cpu_buf(io_cfg->mem_handle[0]);
|
||||
} else {
|
||||
CAM_ERR(CAM_SENSOR, "Invalid direction: %d",
|
||||
io_cfg->direction);
|
||||
rc = -EINVAL;
|
||||
}
|
||||
cam_mem_put_cpu_buf(io_cfg->mem_handle[0]);
|
||||
return rc;
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue