From nobody Wed Oct 8 09:43:01 2025 Received: from mail-qt1-f170.google.com (mail-qt1-f170.google.com [209.85.160.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 531142E54D9; Mon, 30 Jun 2025 17:31:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1751304720; cv=none; b=Z6X1XYKf5/nwVdKgXniT6pv9kEc0Pw8s07VaMtGrSSJP9HmiZRL1jMQN9CCzkGxmBGyalgkrPLmqpqrEVRpGmN/eQm2Kb2WPYZf8Q/XtaQetu23lYAjI85vj6xFPBXoBis0wIQjtMUYIRYg51X6CyaukyTsZRCHbsiker+Ra5HE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1751304720; c=relaxed/simple; bh=WhrQT0XcjA48So7VV8f3CLepQJj/6oaWUaubJg1pcSI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=jQBAY+oFs0ukpkQMRcp0qMECQM2Y9z29l0gQlh3tdwZojKaEAGSlLQuwqhGwgKTtFymqG1Z4aw+UDqLBUootxLuqNx7bONybUgjKBdHGX3ZYWnEm+ebC+UhClDtuk7qo7QBm06Qa0KCE4vYRbKBEzpyqmBa6UY7Zt90yzUVudX0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ncVYymp4; arc=none smtp.client-ip=209.85.160.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ncVYymp4" Received: by mail-qt1-f170.google.com with SMTP id d75a77b69052e-4a745fc9bafso67137091cf.1; Mon, 30 Jun 2025 10:31:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1751304715; x=1751909515; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=FWYXpI/1WvU7LThqEa5N6KoGudK8x9uuTgmTBk7pvaA=; b=ncVYymp4wXA/n8XdK4wwNrvzGpuhBqcKFkz4mQSrvk1/95cW2Ovn2JsFpZiiC3sx6O 0KFGVKJoKclt1bfyl5nY6+Fknmf9jjrVaA9zUUefeKn5Wc/PqZ3/e/RCyGhsgNoM1E7o zXRlOqUeaY+JlKVveuoVyqxdBLSQqqJuyQ6VzLZF32tB8HPerROCzfA3A3jXru3q9eqj fQAZip++ZOoG+T1GUK7tSe8cqVB7ODjbGD9xP3ccBv5prZhcBSoZpNdVGScSxQEb6BtB TLFCerd+36OAB6iRlfadvTKcE5etc6IV7zAWZ9X4HzgIlqqcywsm7rbQa8rWEQIzmilN 3oUQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1751304715; x=1751909515; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=FWYXpI/1WvU7LThqEa5N6KoGudK8x9uuTgmTBk7pvaA=; b=jRPxkXgLmOmBKRW/1zL0XtHK6D5rJIs/PXs/WeaOz9RxP110Yf7wz3mj5VvsBl1Y/y blz4B0d8yrCsVHiZAVY9FwflcjS7fOYT0eb3MQOv8qbdi+EhwxbCZvTO7uZs3XZYay9d gKnFKgvxOMHqQs8RTElieE1ShAxTEYUb/HcbFjyuFBdQ8rBgcbNNlKg1W5ueZhPAnVeR iJT3ZvO6vr0eWjCcDt+c6U7EgExS55h3P5g1OxFd9oyRl97LjEa3VX2CwNWM9oPVkfv6 AX3QtbH58N06OasCCEg6YfNqtZWivgILUGRrPUOJCHPpi7R/7qTj8aHXk6Wh9nWk8c8j LuGg== X-Forwarded-Encrypted: i=1; AJvYcCVfCXqcfFKqBfeZsCrZ+eMb44vLHKrB7YtFEKNgHeU6AOOMMQqetv4ulkTglfq4la/jQEp83Vxh6F5wTxY=@vger.kernel.org, AJvYcCW1EzzIG8zz/ZLoEmE2EQ4l5eyyLnZfFZSSV5Pj4uO6ZA/QO0ueNSaxaeaybL5Im9rNyYpVoBN0@vger.kernel.org X-Gm-Message-State: AOJu0YxuStcxennxfL2ascMEyYLqDYGFhcUuoWmTdDrGdRxpHwa83wsO JQ/N5mN535iUd5Wx7uaKfdw+yxI9S4PwWONJHt4Db57G1j8DeaMTmbF2FMACClpi X-Gm-Gg: ASbGncvdC1vdQDCDqs8jfB2IBmU++XzKWZrcH32f7EX4gyJKVv94MagXAUZg96B8XrV txUmCVZOZZE37pnyvMrOXFgRND7SHeepEL+EjxSLCW8OgD+kmVAF3Qd0s9SDYeyFajiv0GLfEyf FFqk0cI/fY/CAccmQJWTOe/UIos45KSFlcpku/IwtIdF0YYfar6bVMyOZL3K0ZA3JNpOfAzWKt0 mRYVPMMTOrLY2BXTD/dLfCsFRnxpZJXbKQqFmNRtok0ck5OItQlwJo5FDMbuJkRIf72RciRe+ng oLs64JFWMZRN2pcoi+jDYc45sk6XWVZMOGA2UJqMtLEuZI6l0L40hxhAPAc/WA== X-Google-Smtp-Source: AGHT+IG92KzcDWTz7z7ThEbKog2vKx31iUOwDYoOHxc6XaYUqLU4+lxJyyfelJpkUe4vY3ksx8Z/AA== X-Received: by 2002:a05:622a:5143:b0:4a5:9993:ede8 with SMTP id d75a77b69052e-4a82eaa4ac3mr7688821cf.15.1751304714795; Mon, 30 Jun 2025 10:31:54 -0700 (PDT) Received: from [192.168.1.26] ([181.88.247.122]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-4a7fdadb11bsm59784521cf.17.2025.06.30.10.31.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 30 Jun 2025 10:31:54 -0700 (PDT) From: Kurt Borja Date: Mon, 30 Jun 2025 14:31:20 -0300 Subject: [PATCH v3 2/3] platform/x86: think-lmi: Fix kobject cleanup Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20250630-lmi-fix-v3-2-ce4f81c9c481@gmail.com> References: <20250630-lmi-fix-v3-0-ce4f81c9c481@gmail.com> In-Reply-To: <20250630-lmi-fix-v3-0-ce4f81c9c481@gmail.com> To: Mark Pearson , =?utf-8?q?Ilpo_J=C3=A4rvinen?= , Hans de Goede Cc: platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org, Kurt Borja , stable@vger.kernel.org X-Mailer: b4 0.14.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=5846; i=kuurtb@gmail.com; h=from:subject:message-id; bh=WhrQT0XcjA48So7VV8f3CLepQJj/6oaWUaubJg1pcSI=; b=owGbwMvMwCUmluBs8WX+lTTG02pJDBlJp5gLZvWIbDBa37WYl+mkuH++V9ULux0dH55/uXtse +cqzTdJHaUsDGJcDLJiiiztCYu+PYrKe+t3IPQ+zBxWJpAhDFycAjCRLw8Z/ilNld6Vp7F8X/XZ mo+aEsUNmZ/n20RoLjHoDrAtLTvw9zLDP1N98d933yc7eNw+m5JiY8YTvtKUdytjQ2joDrvfs5b mMwAA X-Developer-Key: i=kuurtb@gmail.com; a=openpgp; fpr=54D3BE170AEF777983C3C63B57E3B6585920A69A In tlmi_analyze(), allocated structs with an embedded kobject are freed in error paths after the they were already initialized. Fix this by first by avoiding the initialization of kobjects in tlmi_analyze() and then by correctly cleaning them up in tlmi_release_attr() using their kset's kobject list. Cc: stable@vger.kernel.org Fixes: a40cd7ef22fb ("platform/x86: think-lmi: Add WMI interface support on= Lenovo platforms") Fixes: 30e78435d3bf ("platform/x86: think-lmi: Split kobject_init() and kob= ject_add() calls") Reviewed-by: Mark Pearson Reviewed-by: Ilpo J=C3=A4rvinen Signed-off-by: Kurt Borja --- drivers/platform/x86/think-lmi.c | 35 +++++++++++++++++++---------------- 1 file changed, 19 insertions(+), 16 deletions(-) diff --git a/drivers/platform/x86/think-lmi.c b/drivers/platform/x86/think-= lmi.c index 4c10a26e7e5e3471f286136d671606acf68b401e..3e5e6e6031efcefe6b3d31bc144= e738599566d98 100644 --- a/drivers/platform/x86/think-lmi.c +++ b/drivers/platform/x86/think-lmi.c @@ -1380,13 +1380,13 @@ static struct kobj_attribute debug_cmd =3D __ATTR_W= O(debug_cmd); /* ---- Initialisation ---------------------------------------------------= ------ */ static void tlmi_release_attr(void) { + struct kobject *pos, *n; int i; =20 /* Attribute structures */ for (i =3D 0; i < TLMI_SETTINGS_COUNT; i++) { if (tlmi_priv.setting[i]) { sysfs_remove_group(&tlmi_priv.setting[i]->kobj, &tlmi_attr_group); - kobject_put(&tlmi_priv.setting[i]->kobj); } } sysfs_remove_file(&tlmi_priv.attribute_kset->kobj, &pending_reboot.attr); @@ -1395,6 +1395,9 @@ static void tlmi_release_attr(void) if (tlmi_priv.can_debug_cmd && debug_support) sysfs_remove_file(&tlmi_priv.attribute_kset->kobj, &debug_cmd.attr); =20 + list_for_each_entry_safe(pos, n, &tlmi_priv.attribute_kset->list, entry) + kobject_put(pos); + kset_unregister(tlmi_priv.attribute_kset); =20 /* Free up any saved signatures */ @@ -1403,19 +1406,17 @@ static void tlmi_release_attr(void) =20 /* Authentication structures */ sysfs_remove_group(&tlmi_priv.pwd_admin->kobj, &auth_attr_group); - kobject_put(&tlmi_priv.pwd_admin->kobj); sysfs_remove_group(&tlmi_priv.pwd_power->kobj, &auth_attr_group); - kobject_put(&tlmi_priv.pwd_power->kobj); =20 if (tlmi_priv.opcode_support) { sysfs_remove_group(&tlmi_priv.pwd_system->kobj, &auth_attr_group); - kobject_put(&tlmi_priv.pwd_system->kobj); sysfs_remove_group(&tlmi_priv.pwd_hdd->kobj, &auth_attr_group); - kobject_put(&tlmi_priv.pwd_hdd->kobj); sysfs_remove_group(&tlmi_priv.pwd_nvme->kobj, &auth_attr_group); - kobject_put(&tlmi_priv.pwd_nvme->kobj); } =20 + list_for_each_entry_safe(pos, n, &tlmi_priv.authentication_kset->list, en= try) + kobject_put(pos); + kset_unregister(tlmi_priv.authentication_kset); } =20 @@ -1479,8 +1480,8 @@ static int tlmi_sysfs_init(void) =20 /* Build attribute */ tlmi_priv.setting[i]->kobj.kset =3D tlmi_priv.attribute_kset; - ret =3D kobject_add(&tlmi_priv.setting[i]->kobj, NULL, - "%s", tlmi_priv.setting[i]->display_name); + ret =3D kobject_init_and_add(&tlmi_priv.setting[i]->kobj, &tlmi_attr_set= ting_ktype, + NULL, "%s", tlmi_priv.setting[i]->display_name); if (ret) goto fail_create_attr; =20 @@ -1505,7 +1506,8 @@ static int tlmi_sysfs_init(void) =20 /* Create authentication entries */ tlmi_priv.pwd_admin->kobj.kset =3D tlmi_priv.authentication_kset; - ret =3D kobject_add(&tlmi_priv.pwd_admin->kobj, NULL, "%s", "Admin"); + ret =3D kobject_init_and_add(&tlmi_priv.pwd_admin->kobj, &tlmi_pwd_settin= g_ktype, + NULL, "%s", "Admin"); if (ret) goto fail_create_attr; =20 @@ -1514,7 +1516,8 @@ static int tlmi_sysfs_init(void) goto fail_create_attr; =20 tlmi_priv.pwd_power->kobj.kset =3D tlmi_priv.authentication_kset; - ret =3D kobject_add(&tlmi_priv.pwd_power->kobj, NULL, "%s", "Power-on"); + ret =3D kobject_init_and_add(&tlmi_priv.pwd_power->kobj, &tlmi_pwd_settin= g_ktype, + NULL, "%s", "Power-on"); if (ret) goto fail_create_attr; =20 @@ -1524,7 +1527,8 @@ static int tlmi_sysfs_init(void) =20 if (tlmi_priv.opcode_support) { tlmi_priv.pwd_system->kobj.kset =3D tlmi_priv.authentication_kset; - ret =3D kobject_add(&tlmi_priv.pwd_system->kobj, NULL, "%s", "System"); + ret =3D kobject_init_and_add(&tlmi_priv.pwd_system->kobj, &tlmi_pwd_sett= ing_ktype, + NULL, "%s", "System"); if (ret) goto fail_create_attr; =20 @@ -1533,7 +1537,8 @@ static int tlmi_sysfs_init(void) goto fail_create_attr; =20 tlmi_priv.pwd_hdd->kobj.kset =3D tlmi_priv.authentication_kset; - ret =3D kobject_add(&tlmi_priv.pwd_hdd->kobj, NULL, "%s", "HDD"); + ret =3D kobject_init_and_add(&tlmi_priv.pwd_hdd->kobj, &tlmi_pwd_setting= _ktype, + NULL, "%s", "HDD"); if (ret) goto fail_create_attr; =20 @@ -1542,7 +1547,8 @@ static int tlmi_sysfs_init(void) goto fail_create_attr; =20 tlmi_priv.pwd_nvme->kobj.kset =3D tlmi_priv.authentication_kset; - ret =3D kobject_add(&tlmi_priv.pwd_nvme->kobj, NULL, "%s", "NVMe"); + ret =3D kobject_init_and_add(&tlmi_priv.pwd_nvme->kobj, &tlmi_pwd_settin= g_ktype, + NULL, "%s", "NVMe"); if (ret) goto fail_create_attr; =20 @@ -1579,8 +1585,6 @@ static struct tlmi_pwd_setting *tlmi_create_auth(cons= t char *pwd_type, new_pwd->maxlen =3D tlmi_priv.pwdcfg.core.max_length; new_pwd->index =3D 0; =20 - kobject_init(&new_pwd->kobj, &tlmi_pwd_setting_ktype); - return new_pwd; } =20 @@ -1685,7 +1689,6 @@ static int tlmi_analyze(struct wmi_device *wdev) if (setting->possible_values) strreplace(setting->possible_values, ',', ';'); =20 - kobject_init(&setting->kobj, &tlmi_attr_setting_ktype); tlmi_priv.setting[i] =3D setting; kfree(item); } --=20 2.50.0