misc: ocxl: fix possible refcount leak in afu_ioctl()
authorHangyu Hua <hbh25y@gmail.com>
Wed, 24 Aug 2022 08:26:00 +0000 (16:26 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 1 Sep 2022 14:29:50 +0000 (16:29 +0200)
eventfd_ctx_put need to be called to put the refcount that gotten by
eventfd_ctx_fdget when ocxl_irq_set_handler fails.

Fixes: 060146614643 ("ocxl: move event_fd handling to frontend")
Acked-by: Frederic Barrat <fbarrat@linux.ibm.com>
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Link: https://lore.kernel.org/r/20220824082600.36159-1-hbh25y@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/misc/ocxl/file.c

index 6777c419a8da2a3ac3d24bd11da7da28ae7e9d3e..d46dba2df5a10af576e1156516643e4423c66136 100644 (file)
@@ -257,6 +257,8 @@ static long afu_ioctl(struct file *file, unsigned int cmd,
                if (IS_ERR(ev_ctx))
                        return PTR_ERR(ev_ctx);
                rc = ocxl_irq_set_handler(ctx, irq_id, irq_handler, irq_free, ev_ctx);
+               if (rc)
+                       eventfd_ctx_put(ev_ctx);
                break;
 
        case OCXL_IOCTL_GET_METADATA: