diff options
author | David Sin <davidsin@ti.com> | 2010-08-28 13:59:34 -0500 |
---|---|---|
committer | Sebastien Jan <s-jan@ti.com> | 2010-09-03 09:41:46 +0200 |
commit | 42507580b7ab8cef51986ef70ea2d41e6def9def (patch) | |
tree | e3f34bb66f5115985a7b4ceef495bc13156dd9f8 | |
parent | 5e64cdbd268c5ec6b6f2301e29417275a066284e (diff) |
TILER: Don't assign mem struct inside kernel list
It's possible that the mem struct assignment inside of
the kernel list doesn't assigned properly (e.g. NULL), which
causes a deref crash during the free call.
Signed-off-by: David Sin <davidsin@ti.com>
Signed-off-by: Sebastien Jan <s-jan@ti.com>
-rw-r--r-- | drivers/media/video/dmm/tmm_pat.c | 7 |
1 files changed, 4 insertions, 3 deletions
diff --git a/drivers/media/video/dmm/tmm_pat.c b/drivers/media/video/dmm/tmm_pat.c index 4010bdfb2e08..4ee59bde6e60 100644 --- a/drivers/media/video/dmm/tmm_pat.c +++ b/drivers/media/video/dmm/tmm_pat.c @@ -203,16 +203,17 @@ static u32 *tmm_pat_get_pages(struct tmm *tmm, s32 n) */ list_for_each_safe(pos, q, &pvt->free_list.list) { m = list_entry(pos, struct mem, list); - f->mem[i] = m; list_del(pos); break; } mutex_unlock(&pvt->mtx); - if (m != NULL) + if (m != NULL) { + f->mem[i] = m; f->pa[i] = m->pa; - else + } else { goto cleanup; + } } mutex_lock(&pvt->mtx); |