summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDavid Sin <davidsin@ti.com>2010-08-28 13:59:34 -0500
committerSebastien Jan <s-jan@ti.com>2010-09-03 09:41:46 +0200
commit42507580b7ab8cef51986ef70ea2d41e6def9def (patch)
treee3f34bb66f5115985a7b4ceef495bc13156dd9f8
parent5e64cdbd268c5ec6b6f2301e29417275a066284e (diff)
TILER: Don't assign mem struct inside kernel list
It's possible that the mem struct assignment inside of the kernel list doesn't assigned properly (e.g. NULL), which causes a deref crash during the free call. Signed-off-by: David Sin <davidsin@ti.com> Signed-off-by: Sebastien Jan <s-jan@ti.com>
-rw-r--r--drivers/media/video/dmm/tmm_pat.c7
1 files changed, 4 insertions, 3 deletions
diff --git a/drivers/media/video/dmm/tmm_pat.c b/drivers/media/video/dmm/tmm_pat.c
index 4010bdfb2e08..4ee59bde6e60 100644
--- a/drivers/media/video/dmm/tmm_pat.c
+++ b/drivers/media/video/dmm/tmm_pat.c
@@ -203,16 +203,17 @@ static u32 *tmm_pat_get_pages(struct tmm *tmm, s32 n)
*/
list_for_each_safe(pos, q, &pvt->free_list.list) {
m = list_entry(pos, struct mem, list);
- f->mem[i] = m;
list_del(pos);
break;
}
mutex_unlock(&pvt->mtx);
- if (m != NULL)
+ if (m != NULL) {
+ f->mem[i] = m;
f->pa[i] = m->pa;
- else
+ } else {
goto cleanup;
+ }
}
mutex_lock(&pvt->mtx);