|
@@ -1294,12 +1294,14 @@ static netdev_tx_t kvaser_usb_start_xmit(struct sk_buff *skb,
|
|
|
if (!urb) {
|
|
|
netdev_err(netdev, "No memory left for URBs\n");
|
|
|
stats->tx_dropped++;
|
|
|
- goto nourbmem;
|
|
|
+ dev_kfree_skb(skb);
|
|
|
+ return NETDEV_TX_OK;
|
|
|
}
|
|
|
|
|
|
buf = kmalloc(sizeof(struct kvaser_msg), GFP_ATOMIC);
|
|
|
if (!buf) {
|
|
|
stats->tx_dropped++;
|
|
|
+ dev_kfree_skb(skb);
|
|
|
goto nobufmem;
|
|
|
}
|
|
|
|
|
@@ -1334,6 +1336,7 @@ static netdev_tx_t kvaser_usb_start_xmit(struct sk_buff *skb,
|
|
|
}
|
|
|
}
|
|
|
|
|
|
+ /* This should never happen; it implies a flow control bug */
|
|
|
if (!context) {
|
|
|
netdev_warn(netdev, "cannot find free context\n");
|
|
|
ret = NETDEV_TX_BUSY;
|
|
@@ -1364,9 +1367,6 @@ static netdev_tx_t kvaser_usb_start_xmit(struct sk_buff *skb,
|
|
|
if (unlikely(err)) {
|
|
|
can_free_echo_skb(netdev, context->echo_index);
|
|
|
|
|
|
- skb = NULL; /* set to NULL to avoid double free in
|
|
|
- * dev_kfree_skb(skb) */
|
|
|
-
|
|
|
atomic_dec(&priv->active_tx_urbs);
|
|
|
usb_unanchor_urb(urb);
|
|
|
|
|
@@ -1388,8 +1388,6 @@ releasebuf:
|
|
|
kfree(buf);
|
|
|
nobufmem:
|
|
|
usb_free_urb(urb);
|
|
|
-nourbmem:
|
|
|
- dev_kfree_skb(skb);
|
|
|
return ret;
|
|
|
}
|
|
|
|