Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [Medium] io_uring: memory leak of io_regbuf_dma in io_release_reg_dmabuf() --
commit 9778a7461fd88cbd1c8b6991ebea933808628a8d Author: Pavel Begunkov <[email protected]> io_uring/rsrc: add dmabuf backed registered buffers This commit implements dmabuf-backed registered buffers, allowing them to be used with io_uring fixed read/write requests. It introduces a new buffer type IO_REGBUF_TYPE_DMABUF to set up a DMA map against a specific target file. > diff --git a/io_uring/rsrc.c b/io_uring/rsrc.c > index 79e3c686ecc15..cb7495df13b71 100644 > --- a/io_uring/rsrc.c > +++ b/io_uring/rsrc.c [ ... ] > +static void io_release_reg_dmabuf(void *priv) > +{ > + struct io_regbuf_dma *db = priv; > + > + fput(db->target_file); > + dma_buf_io_ctx_release(db->ctx); [Severity: Medium] Does this code leak the io_regbuf_dma structure? The db structure is dynamically allocated via kzalloc() in io_register_dmabuf() and assigned to imu->priv. When a user unregisters a dmabuf-backed registered buffer, this release callback drops the file and context references, but doesn't seem to free the db structure itself. Should this include a call to kfree(db)? > +} > + > +static struct io_rsrc_node *io_register_dmabuf(struct io_ring_ctx *ctx, > + struct io_uring_regbuf_desc > *desc) > +{ [ ... ] > + regbuf = kzalloc(sizeof(*regbuf), GFP_KERNEL); > + if (!regbuf) > + goto err; [ ... ] > + imu->release = io_release_reg_dmabuf; > + imu->priv = regbuf; > + imu->flags = IO_REGBUF_F_DMABUF; > + imu->dir = IO_BUF_DEST | IO_BUF_SOURCE; > + refcount_set(&imu->refs, 1); > + node->buf = imu; > + dma_buf_put(dmabuf); > + return node; -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=13
