mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 21:59:12 -04:00
msm: vidc: Avoid dma_buf memory leak under memory pressure
dma_buf_put does not happen in case of failure while mapping dma_buf. This leads to ion_dma_buf leak as refcount is 1 even after session close. In memory pressure scenario while running concurrency usecase such scenario can occur. Change-Id: I2084538162b54d87acd6fa57bb5cc5bd2096c08d Signed-off-by: Brijesh Patel <pbrijesh@codeaurora.org>
This commit is contained in:
parent
fbff1f488b
commit
cbbf49a6e1
1 changed files with 11 additions and 4 deletions
|
|
@ -216,7 +216,7 @@ int msm_smem_map_dma_buf(struct msm_vidc_inst *inst, struct msm_smem *smem)
|
|||
rc = dma_buf_get_flags(dbuf, &ion_flags);
|
||||
if (rc) {
|
||||
s_vpr_e(inst->sid, "Failed to get dma buf flags: %d\n", rc);
|
||||
goto exit;
|
||||
goto fail_map_dma_buf;
|
||||
}
|
||||
if (ion_flags & ION_FLAG_CACHED)
|
||||
smem->flags |= SMEM_CACHED;
|
||||
|
|
@ -230,7 +230,7 @@ int msm_smem_map_dma_buf(struct msm_vidc_inst *inst, struct msm_smem *smem)
|
|||
smem->flags & SMEM_SECURE ? "secure" : "non-secure",
|
||||
inst->flags & VIDC_SECURE ? "secure" : "non-secure");
|
||||
rc = -EINVAL;
|
||||
goto exit;
|
||||
goto fail_map_dma_buf;
|
||||
}
|
||||
buffer_size = smem->size;
|
||||
|
||||
|
|
@ -240,18 +240,25 @@ int msm_smem_map_dma_buf(struct msm_vidc_inst *inst, struct msm_smem *smem)
|
|||
inst->sid);
|
||||
if (rc) {
|
||||
s_vpr_e(inst->sid, "Failed to get device address: %d\n", rc);
|
||||
goto exit;
|
||||
goto fail_map_dma_buf;
|
||||
}
|
||||
temp = (u32)iova;
|
||||
if ((dma_addr_t)temp != iova) {
|
||||
s_vpr_e(inst->sid, "iova(%pa) truncated to %#x", &iova, temp);
|
||||
rc = -EINVAL;
|
||||
goto exit;
|
||||
goto fail_iova_truncation;
|
||||
}
|
||||
|
||||
smem->device_addr = (u32)iova + smem->offset;
|
||||
|
||||
smem->refcount++;
|
||||
return 0;
|
||||
|
||||
fail_iova_truncation:
|
||||
msm_dma_put_device_address(smem->flags, &smem->mapping_info,
|
||||
smem->buffer_type, inst->sid);
|
||||
fail_map_dma_buf:
|
||||
msm_smem_put_dma_buf(dbuf, inst->sid);
|
||||
exit:
|
||||
return rc;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue