diff mbox

[iw_cxgb4-4.8] RDMA/iw_cxgb4: Use kfree_skb instead of kfree

Message ID 1467189584-9812-1-git-send-email-hariprasad@chelsio.com (mailing list archive)
State Superseded
Headers show

Commit Message

Hariprasad S June 29, 2016, 8:39 a.m. UTC
The commit 0f8ab0b6e91b4d53 ("RDMA/iw_cxgb4: Low resource fixes for Memory
registration") from Jun 10, 2016, leads to the following static checker
warning:

        drivers/infiniband/hw/cxgb4/mem.c:612 c4iw_alloc_mw()
        error: use kfree_skb() here instead of kfree(mhp->dereg_skb)

Also fixes skb leak in c4iw_dealloc_mw

Fixes: 0f8ab0b6e91b4d53 ("RDMA/iw_cxgb4: Low resource fixes for Memory registration")

Reported-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Steve Wise <swise@opengridcomputing.com>
Signed-off-by: Hariprasad Shenai <hariprasad@chelsio.com>
---
 drivers/infiniband/hw/cxgb4/mem.c | 27 ++++++++++++++++-----------
 1 file changed, 16 insertions(+), 11 deletions(-)

Comments

Leon Romanovsky June 29, 2016, 10:48 a.m. UTC | #1
On Wed, Jun 29, 2016 at 02:09:44PM +0530, Hariprasad Shenai wrote:
> The commit 0f8ab0b6e91b4d53 ("RDMA/iw_cxgb4: Low resource fixes for Memory
> registration") from Jun 10, 2016, leads to the following static checker
> warning:
> 
>         drivers/infiniband/hw/cxgb4/mem.c:612 c4iw_alloc_mw()
>         error: use kfree_skb() here instead of kfree(mhp->dereg_skb)
> 
> Also fixes skb leak in c4iw_dealloc_mw
> 
> Fixes: 0f8ab0b6e91b4d53 ("RDMA/iw_cxgb4: Low resource fixes for Memory registration")
> 
> Reported-by: Dan Carpenter <dan.carpenter@oracle.com>
> Signed-off-by: Steve Wise <swise@opengridcomputing.com>
> Signed-off-by: Hariprasad Shenai <hariprasad@chelsio.com>
> ---
>  drivers/infiniband/hw/cxgb4/mem.c | 27 ++++++++++++++++-----------
>  1 file changed, 16 insertions(+), 11 deletions(-)
> 
> diff --git a/drivers/infiniband/hw/cxgb4/mem.c b/drivers/infiniband/hw/cxgb4/mem.c
> index 5d0aa55e82d4..3a4e6fba3010 100644
> --- a/drivers/infiniband/hw/cxgb4/mem.c
> +++ b/drivers/infiniband/hw/cxgb4/mem.c
> @@ -603,16 +603,13 @@ struct ib_mw *c4iw_alloc_mw(struct ib_pd *pd, enum ib_mw_type type,
>  
>  	mhp->dereg_skb = alloc_skb(SGE_MAX_WR_LEN, GFP_KERNEL);
>  	if (!mhp->dereg_skb) {
> -		kfree(mhp);
> -		return ERR_PTR(-ENOMEM);
> +		ret = -ENOMEM;
> +		goto free_mhp;
>  	}
>  
>  	ret = allocate_window(&rhp->rdev, &stag, php->pdid);
> -	if (ret) {
> -		kfree(mhp->dereg_skb);
> -		kfree(mhp);
> -		return ERR_PTR(ret);
> -	}
> +	if (ret)
> +		goto free_skb;
>  	mhp->rhp = rhp;
>  	mhp->attr.pdid = php->pdid;
>  	mhp->attr.type = FW_RI_STAG_MW;
> @@ -620,13 +617,19 @@ struct ib_mw *c4iw_alloc_mw(struct ib_pd *pd, enum ib_mw_type type,
>  	mmid = (stag) >> 8;
>  	mhp->ibmw.rkey = stag;
>  	if (insert_handle(rhp, &rhp->mmidr, mhp, mmid)) {
> -		deallocate_window(&rhp->rdev, mhp->attr.stag, mhp->dereg_skb);
> -		kfree(mhp->dereg_skb);
> -		kfree(mhp);
> -		return ERR_PTR(-ENOMEM);
> +		ret = -ENOMEM;
> +		goto dealloc_win;
>  	}
>  	PDBG("%s mmid 0x%x mhp %p stag 0x%x\n", __func__, mmid, mhp, stag);
>  	return &(mhp->ibmw);
> +
> +dealloc_win:
> +	deallocate_window(&rhp->rdev, mhp->attr.stag, mhp->dereg_skb);
> +free_skb:
> +	kfree_skb(mhp->dereg_skb);
> +free_mhp:
> +	kfree(mhp);
> +	return ERR_PTR(ret);
>  }
>  
>  int c4iw_dealloc_mw(struct ib_mw *mw)
> @@ -640,6 +643,8 @@ int c4iw_dealloc_mw(struct ib_mw *mw)
>  	mmid = (mw->rkey) >> 8;
>  	remove_handle(rhp, &rhp->mmidr, mmid);
>  	deallocate_window(&rhp->rdev, mhp->attr.stag, mhp->dereg_skb);
> +	if (mhp->dereg_skb)
> +		kfree_skb(mhp->dereg_skb);

You don't need to check existence of mhp->dereg_skb.
kfree_skb will check it by itself.

net/core/skbuff.c:
695 void kfree_skb(struct sk_buff *skb)
696 {
697         if (unlikely(!skb))
698                 return;

>  	kfree(mhp);
>  	PDBG("%s ib_mw %p mmid 0x%x ptr %p\n", __func__, mw, mmid, mhp);
>  	return 0;
> -- 
> 2.3.4
> 
> --
> To unsubscribe from this list: send the line "unsubscribe linux-rdma" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
diff mbox

Patch

diff --git a/drivers/infiniband/hw/cxgb4/mem.c b/drivers/infiniband/hw/cxgb4/mem.c
index 5d0aa55e82d4..3a4e6fba3010 100644
--- a/drivers/infiniband/hw/cxgb4/mem.c
+++ b/drivers/infiniband/hw/cxgb4/mem.c
@@ -603,16 +603,13 @@  struct ib_mw *c4iw_alloc_mw(struct ib_pd *pd, enum ib_mw_type type,
 
 	mhp->dereg_skb = alloc_skb(SGE_MAX_WR_LEN, GFP_KERNEL);
 	if (!mhp->dereg_skb) {
-		kfree(mhp);
-		return ERR_PTR(-ENOMEM);
+		ret = -ENOMEM;
+		goto free_mhp;
 	}
 
 	ret = allocate_window(&rhp->rdev, &stag, php->pdid);
-	if (ret) {
-		kfree(mhp->dereg_skb);
-		kfree(mhp);
-		return ERR_PTR(ret);
-	}
+	if (ret)
+		goto free_skb;
 	mhp->rhp = rhp;
 	mhp->attr.pdid = php->pdid;
 	mhp->attr.type = FW_RI_STAG_MW;
@@ -620,13 +617,19 @@  struct ib_mw *c4iw_alloc_mw(struct ib_pd *pd, enum ib_mw_type type,
 	mmid = (stag) >> 8;
 	mhp->ibmw.rkey = stag;
 	if (insert_handle(rhp, &rhp->mmidr, mhp, mmid)) {
-		deallocate_window(&rhp->rdev, mhp->attr.stag, mhp->dereg_skb);
-		kfree(mhp->dereg_skb);
-		kfree(mhp);
-		return ERR_PTR(-ENOMEM);
+		ret = -ENOMEM;
+		goto dealloc_win;
 	}
 	PDBG("%s mmid 0x%x mhp %p stag 0x%x\n", __func__, mmid, mhp, stag);
 	return &(mhp->ibmw);
+
+dealloc_win:
+	deallocate_window(&rhp->rdev, mhp->attr.stag, mhp->dereg_skb);
+free_skb:
+	kfree_skb(mhp->dereg_skb);
+free_mhp:
+	kfree(mhp);
+	return ERR_PTR(ret);
 }
 
 int c4iw_dealloc_mw(struct ib_mw *mw)
@@ -640,6 +643,8 @@  int c4iw_dealloc_mw(struct ib_mw *mw)
 	mmid = (mw->rkey) >> 8;
 	remove_handle(rhp, &rhp->mmidr, mmid);
 	deallocate_window(&rhp->rdev, mhp->attr.stag, mhp->dereg_skb);
+	if (mhp->dereg_skb)
+		kfree_skb(mhp->dereg_skb);
 	kfree(mhp);
 	PDBG("%s ib_mw %p mmid 0x%x ptr %p\n", __func__, mw, mmid, mhp);
 	return 0;