summaryrefslogtreecommitdiff
path: root/drivers/dma
diff options
context:
space:
mode:
authorRosen Penev <rosenp@gmail.com>2026-09-09 16:49:24 -0700
committerVinod Koul <vkoul@kernel.org>2026-09-10 19:32:33 +0530
commit5d5f4b3407d6ec86e76d094c332301135f493636 (patch)
tree9a4d260128d5374487609f00c473cf2ac945a7d8 /drivers/dma
parentdb1a748a3509da959c547689af40e8a064a19c6b (diff)
downloadlinux-next-5d5f4b3407d6ec86e76d094c332301135f493636.tar.gz
linux-next-5d5f4b3407d6ec86e76d094c332301135f493636.zip
dmaengine: mv_xor: return descriptor to free pool on io_win failure
When mv_xor_prep_dma_xor() allocates a descriptor slot and then mv_xor_add_io_win() fails in the source-address loop, the slot stays on the allocated list and is never reclaimed, leaking a descriptor resource. Return the slot to the free pool under the channel lock before returning NULL on failure. Assisted-by: opencode:big-pickle Signed-off-by: Rosen Penev <rosenp@gmail.com> Reviewed-by: Frank Li <Frank.Li@nxp.com> Link: https://patch.msgid.link/20260909234924.103418-1-rosenp@gmail.com Signed-off-by: Vinod Koul <vkoul@kernel.org>
Diffstat (limited to 'drivers/dma')
-rw-r--r--drivers/dma/mv_xor.c7
1 files changed, 6 insertions, 1 deletions
diff --git a/drivers/dma/mv_xor.c b/drivers/dma/mv_xor.c
index 25ed61f1b089..dd4f150d5fb1 100644
--- a/drivers/dma/mv_xor.c
+++ b/drivers/dma/mv_xor.c
@@ -583,8 +583,13 @@ mv_xor_prep_dma_xor(struct dma_chan *chan, dma_addr_t dest, dma_addr_t *src,
while (src_cnt--) {
/* Check if a new window needs to get added for 'src' */
ret = mv_xor_add_io_win(mv_chan, src[src_cnt]);
- if (ret)
+ if (ret) {
+ spin_lock_bh(&mv_chan->lock);
+ list_move_tail(&sw_desc->node,
+ &mv_chan->free_slots);
+ spin_unlock_bh(&mv_chan->lock);
return NULL;
+ }
mv_desc_set_src_addr(sw_desc, src_cnt, src[src_cnt]);
}
}