[PATCH] dmaengine: ioat: fix completion pool leak on ring allocation failure

From: Haotian Zhang

Date: Fri Oct 09 2026 - 00:33:29 EST


ioat_alloc_chan_resources() allocates the channel completion writeback
area with dma_pool_zalloc() and then allocates the descriptor ring with
ioat_alloc_ring(). The ring allocation runs under GFP_NOWAIT and can
fail, in which case the function returns -ENOMEM without freeing the
completion area. As the ring pointer stays NULL, the only teardown path,
ioat_free_chan_resources(), bails out early and never releases it; a
subsequent retry overwrites ioat_chan->completion, leaking the previous
allocation permanently. The dmaengine core does not call
device_free_chan_resources() when device_alloc_chan_resources() fails, so
nothing else cleans it up either.

Release the completion area with dma_pool_free() before returning from the
ring allocation error path.

Fixes: 5cbafa65b92e ("ioat2,3: convert to a true ring buffer")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@xxxxxxxxxxx>
---
drivers/dma/ioat/init.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/dma/ioat/init.c b/drivers/dma/ioat/init.c
index 737496391109..000b59f0f04e 100644
--- a/drivers/dma/ioat/init.c
+++ b/drivers/dma/ioat/init.c
@@ -695,8 +695,14 @@ static int ioat_alloc_chan_resources(struct dma_chan *c)

order = IOAT_MAX_ORDER;
ring = ioat_alloc_ring(c, order, GFP_NOWAIT);
- if (!ring)
+ if (!ring) {
+ dma_pool_free(ioat_chan->ioat_dma->completion_pool,
+ ioat_chan->completion,
+ ioat_chan->completion_dma);
+ ioat_chan->completion = NULL;
+ ioat_chan->completion_dma = 0;
return -ENOMEM;
+ }

spin_lock_bh(&ioat_chan->cleanup_lock);
spin_lock_bh(&ioat_chan->prep_lock);
--
2.25.1