]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
mm/damon/sysfs: dealloc repeat_call_control if damon_call() fails
authorSeongJae Park <sj@kernel.org>
Fri, 27 Mar 2026 00:32:22 +0000 (17:32 -0700)
committerAndrew Morton <akpm@linux-foundation.org>
Mon, 6 Apr 2026 18:13:42 +0000 (11:13 -0700)
damon_call() for repeat_call_control of DAMON_SYSFS could fail if somehow
the kdamond is stopped before the damon_call().  It could happen, for
example, when te damon context was made for monitroing of a virtual
address processes, and the process is terminated immediately, before the
damon_call() invocation.  In the case, the dyanmically allocated
repeat_call_control is not deallocated and leaked.

Fix the leak by deallocating the repeat_call_control under the
damon_call() failure.

This issue is discovered by sashiko [1].

Link: https://lkml.kernel.org/r/20260327003224.55752-1-sj@kernel.org
Link: https://lore.kernel.org/20260320020630.962-1-sj@kernel.org
Fixes: 04a06b139ec0 ("mm/damon/sysfs: use dynamically allocated repeat mode damon_call_control")
Signed-off-by: SeongJae Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> [6.17+]
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
mm/damon/sysfs.c

index 6a44a2f3d8fc9d0f5526b52cb053bdd159fe472f..eefa959aa30aea554cdfa6a0bcb302e9fa794abd 100644 (file)
@@ -1670,7 +1670,8 @@ static int damon_sysfs_turn_damon_on(struct damon_sysfs_kdamond *kdamond)
        repeat_call_control->data = kdamond;
        repeat_call_control->repeat = true;
        repeat_call_control->dealloc_on_cancel = true;
-       damon_call(ctx, repeat_call_control);
+       if (damon_call(ctx, repeat_call_control))
+               kfree(repeat_call_control);
        return err;
 }