[PATCH] dmaengine: img-mdc: Fix runtime PM usage counter leak

Ruoyu Wang posted 1 patch 1 month, 2 weeks ago
drivers/dma/img-mdc-dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH] dmaengine: img-mdc: Fix runtime PM usage counter leak
Posted by Ruoyu Wang 1 month, 2 weeks ago
pm_runtime_get_sync() leaves the IMG MDC device's usage counter
incremented when runtime resume fails. mdc_alloc_chan_resources() returns
that error to the DMA core, so the channel's client count is not
incremented and mdc_free_chan_resources() is not called to drop the
reference. Repeated allocation attempts can therefore accumulate usage
references and prevent runtime suspend.

Use pm_runtime_resume_and_get() so a failed resume does not retain a
usage reference while successful allocations remain paired with
mdc_free_chan_resources(). DMA core only treats negative return values as
allocation failures, so the helper's zero success return preserves
behavior.

This issue was found by a static analysis checker and confirmed by manual
source review.

Fixes: 56d355e6f586 ("dmaengine: img-mdc: Add runtime PM")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
---
 drivers/dma/img-mdc-dma.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/dma/img-mdc-dma.c b/drivers/dma/img-mdc-dma.c
index b3765ba1580308..a3192d49b6c860 100644
--- a/drivers/dma/img-mdc-dma.c
+++ b/drivers/dma/img-mdc-dma.c
@@ -738,7 +738,7 @@ static int mdc_alloc_chan_resources(struct dma_chan *chan)
 	struct mdc_chan *mchan = to_mdc_chan(chan);
 	struct device *dev = mdma2dev(mchan->mdma);
 
-	return pm_runtime_get_sync(dev);
+	return pm_runtime_resume_and_get(dev);
 }
 
 static void mdc_free_chan_resources(struct dma_chan *chan)
-- 
2.51.0
Re: [PATCH] dmaengine: img-mdc: Fix runtime PM usage counter leak
Posted by Vinod Koul 3 weeks, 4 days ago
On Thu, 13 Aug 2026 23:31:43 +0800, Ruoyu Wang wrote:
> pm_runtime_get_sync() leaves the IMG MDC device's usage counter
> incremented when runtime resume fails. mdc_alloc_chan_resources() returns
> that error to the DMA core, so the channel's client count is not
> incremented and mdc_free_chan_resources() is not called to drop the
> reference. Repeated allocation attempts can therefore accumulate usage
> references and prevent runtime suspend.
> 
> [...]

Applied, thanks!

[1/1] dmaengine: img-mdc: Fix runtime PM usage counter leak
      commit: d8dfd04faeb9b49663bd268090df5c7df6bdbae6

Best regards,
-- 
~Vinod
Re: [PATCH] dmaengine: img-mdc: Fix runtime PM usage counter leak
Posted by Frank Li 1 month, 2 weeks ago
On Thu, Aug 13, 2026 at 11:31:43PM +0800, Ruoyu Wang wrote:
> [You don't often get email from ruoyuw560@gmail.com. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
>
> pm_runtime_get_sync() leaves the IMG MDC device's usage counter
> incremented when runtime resume fails. mdc_alloc_chan_resources() returns
> that error to the DMA core, so the channel's client count is not
> incremented and mdc_free_chan_resources() is not called to drop the
> reference. Repeated allocation attempts can therefore accumulate usage
> references and prevent runtime suspend.
>
> Use pm_runtime_resume_and_get() so a failed resume does not retain a
> usage reference while successful allocations remain paired with
> mdc_free_chan_resources(). DMA core only treats negative return values as
> allocation failures, so the helper's zero success return preserves
> behavior.
>
> This issue was found by a static analysis checker and confirmed by manual
> source review.
>
> Fixes: 56d355e6f586 ("dmaengine: img-mdc: Add runtime PM")
> Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
> ---

Reviewed-by: Frank Li <Frank.Li@nxp.com>

>  drivers/dma/img-mdc-dma.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/dma/img-mdc-dma.c b/drivers/dma/img-mdc-dma.c
> index b3765ba1580308..a3192d49b6c860 100644
> --- a/drivers/dma/img-mdc-dma.c
> +++ b/drivers/dma/img-mdc-dma.c
> @@ -738,7 +738,7 @@ static int mdc_alloc_chan_resources(struct dma_chan *chan)
>         struct mdc_chan *mchan = to_mdc_chan(chan);
>         struct device *dev = mdma2dev(mchan->mdma);
>
> -       return pm_runtime_get_sync(dev);
> +       return pm_runtime_resume_and_get(dev);
>  }
>
>  static void mdc_free_chan_resources(struct dma_chan *chan)
> --
> 2.51.0
>