Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1256613 > unrolled thread

Re: [PATCH 2/3] usb: chipidea: udc: improve error handling on ep_queue

Started byFelipe Ferreri Tonello <eu@felipetonello.com>
First post2015-10-27 10:30 +0100
Last post2015-10-27 10:40 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: [PATCH 2/3] usb: chipidea: udc: improve error handling on  ep_queue Felipe Ferreri Tonello <eu@felipetonello.com> - 2015-10-27 10:30 +0100
    RE: [PATCH 2/3] usb: chipidea: udc: improve error handling on  ep_queue Peter Chen <Peter.Chen@freescale.com> - 2015-10-27 10:40 +0100

#1256613 — Re: [PATCH 2/3] usb: chipidea: udc: improve error handling on ep_queue

FromFelipe Ferreri Tonello <eu@felipetonello.com>
Date2015-10-27 10:30 +0100
SubjectRe: [PATCH 2/3] usb: chipidea: udc: improve error handling on ep_queue
Message-ID<qo8JR-3sW-9@gated-at.bofh.it>
Hi Peter,

Have you seen this patch? I saw that you didn't apply it to your tree,
so I wonder if it is good or do I have to change anything.

This patch is a bug fix for a memory leak, so it is quite important.

-- 
Felipe

On 18/09/15 18:30, eu@felipetonello.com wrote:
> From: "Felipe F. Tonello" <eu@felipetonello.com>
> 
> _ep_queue() didn't check for errors when using add_td_to_list()
> which can fail if dma_pool_alloc fails, thus causing a kernel
> panic when lastnode->ptr is NULL.
> 
> Signed-off-by: Felipe F. Tonello <eu@felipetonello.com>
> ---
> 
> Changes for v2:
>   - Use separate patch for cleanups.
> 
>  drivers/usb/chipidea/udc.c | 18 +++++++++++++-----
>  1 file changed, 13 insertions(+), 5 deletions(-)
> 
> diff --git a/drivers/usb/chipidea/udc.c b/drivers/usb/chipidea/udc.c
> index c936c72..7169113e 100644
> --- a/drivers/usb/chipidea/udc.c
> +++ b/drivers/usb/chipidea/udc.c
> @@ -435,19 +435,27 @@ static int _hardware_enqueue(struct ci_hw_ep *hwep, struct ci_hw_req *hwreq)
>  	if (hwreq->req.dma % PAGE_SIZE)
>  		pages--;
>  
> -	if (rest == 0)
> -		add_td_to_list(hwep, hwreq, 0);
> +	if (rest == 0) {
> +		ret = add_td_to_list(hwep, hwreq, 0);
> +		if (ret < 0)
> +			goto done;
> +	}
>  
>  	while (rest > 0) {
>  		unsigned count = min(hwreq->req.length - hwreq->req.actual,
>  					(unsigned)(pages * CI_HDRC_PAGE_SIZE));
> -		add_td_to_list(hwep, hwreq, count);
> +		ret = add_td_to_list(hwep, hwreq, count);
> +		if (ret < 0)
> +			goto done;
>  		rest -= count;
>  	}
>  
>  	if (hwreq->req.zero && hwreq->req.length
> -	    && (hwreq->req.length % hwep->ep.maxpacket == 0))
> -		add_td_to_list(hwep, hwreq, 0);
> +	    && (hwreq->req.length % hwep->ep.maxpacket == 0)) {
> +		ret = add_td_to_list(hwep, hwreq, 0);
> +		if (ret < 0)
> +			goto done;
> +	}
>  
>  	firstnode = list_first_entry(&hwreq->tds, struct td_node, td);
>  
> 
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1256623

FromPeter Chen <Peter.Chen@freescale.com>
Date2015-10-27 10:40 +0100
Message-ID<qo8Tx-3we-33@gated-at.bofh.it>
In reply to#1256613
 
> Hi Peter,
> 
> Have you seen this patch? I saw that you didn't apply it to your tree, so I
> wonder if it is good or do I have to change anything.
> 
> This patch is a bug fix for a memory leak, so it is quite important.
> 

Would you please create it based on my tree, branch ci-for-usb-next?
I can't apply it.

Peter

> --
> Felipe
> 
> On 18/09/15 18:30, eu@felipetonello.com wrote:
> > From: "Felipe F. Tonello" <eu@felipetonello.com>
> >
> > _ep_queue() didn't check for errors when using add_td_to_list() which
> > can fail if dma_pool_alloc fails, thus causing a kernel panic when
> > lastnode->ptr is NULL.
> >
> > Signed-off-by: Felipe F. Tonello <eu@felipetonello.com>
> > ---
> >
> > Changes for v2:
> >   - Use separate patch for cleanups.
> >
> >  drivers/usb/chipidea/udc.c | 18 +++++++++++++-----
> >  1 file changed, 13 insertions(+), 5 deletions(-)
> >
> > diff --git a/drivers/usb/chipidea/udc.c b/drivers/usb/chipidea/udc.c
> > index c936c72..7169113e 100644
> > --- a/drivers/usb/chipidea/udc.c
> > +++ b/drivers/usb/chipidea/udc.c
> > @@ -435,19 +435,27 @@ static int _hardware_enqueue(struct ci_hw_ep
> *hwep, struct ci_hw_req *hwreq)
> >  	if (hwreq->req.dma % PAGE_SIZE)
> >  		pages--;
> >
> > -	if (rest == 0)
> > -		add_td_to_list(hwep, hwreq, 0);
> > +	if (rest == 0) {
> > +		ret = add_td_to_list(hwep, hwreq, 0);
> > +		if (ret < 0)
> > +			goto done;
> > +	}
> >
> >  	while (rest > 0) {
> >  		unsigned count = min(hwreq->req.length - hwreq->req.actual,
> >  					(unsigned)(pages *
> CI_HDRC_PAGE_SIZE));
> > -		add_td_to_list(hwep, hwreq, count);
> > +		ret = add_td_to_list(hwep, hwreq, count);
> > +		if (ret < 0)
> > +			goto done;
> >  		rest -= count;
> >  	}
> >
> >  	if (hwreq->req.zero && hwreq->req.length
> > -	    && (hwreq->req.length % hwep->ep.maxpacket == 0))
> > -		add_td_to_list(hwep, hwreq, 0);
> > +	    && (hwreq->req.length % hwep->ep.maxpacket == 0)) {
> > +		ret = add_td_to_list(hwep, hwreq, 0);
> > +		if (ret < 0)
> > +			goto done;
> > +	}
> >
> >  	firstnode = list_first_entry(&hwreq->tds, struct td_node, td);
> >
> >
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web