Skip to content

Commit 141054a

Browse files
Purva Yeshigregkh
authored andcommitted
dmaengine: idxd: cdev: Fix uninitialized use of sva in idxd_cdev_open
[ Upstream commit 9799433 ] Fix Smatch-detected issue: drivers/dma/idxd/cdev.c:321 idxd_cdev_open() error: uninitialized symbol 'sva'. 'sva' pointer may be used uninitialized in error handling paths. Specifically, if PASID support is enabled and iommu_sva_bind_device() returns an error, the code jumps to the cleanup label and attempts to call iommu_sva_unbind_device(sva) without ensuring that sva was successfully assigned. This triggers a Smatch warning about an uninitialized symbol. Initialize sva to NULL at declaration and add a check using IS_ERR_OR_NULL() before unbinding the device. This ensures the function does not use an invalid or uninitialized pointer during cleanup. Signed-off-by: Purva Yeshi <purvayeshi550@gmail.com> Reviewed-by: Dave Jiang <dave.jiang@intel.com> Acked-by: Vinicius Costa Gomes <vinicius.gomes@intel.com> Link: https://lore.kernel.org/r/20250410110216.21592-1-purvayeshi550@gmail.com Signed-off-by: Vinod Koul <vkoul@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
1 parent 510cf09 commit 141054a

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

drivers/dma/idxd/cdev.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -225,7 +225,7 @@ static int idxd_cdev_open(struct inode *inode, struct file *filp)
225225
struct idxd_wq *wq;
226226
struct device *dev, *fdev;
227227
int rc = 0;
228-
struct iommu_sva *sva;
228+
struct iommu_sva *sva = NULL;
229229
unsigned int pasid;
230230
struct idxd_cdev *idxd_cdev;
231231

@@ -322,7 +322,7 @@ static int idxd_cdev_open(struct inode *inode, struct file *filp)
322322
if (device_user_pasid_enabled(idxd))
323323
idxd_xa_pasid_remove(ctx);
324324
failed_get_pasid:
325-
if (device_user_pasid_enabled(idxd))
325+
if (device_user_pasid_enabled(idxd) && !IS_ERR_OR_NULL(sva))
326326
iommu_sva_unbind_device(sva);
327327
failed:
328328
mutex_unlock(&wq->wq_lock);

0 commit comments

Comments
 (0)