From nobody Sun Jun 14 02:35:30 2026 Received: from mail-pg1-f169.google.com (mail-pg1-f169.google.com [209.85.215.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 458AE3D6495 for ; Mon, 4 May 2026 12:59:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777899578; cv=none; b=KCPIc0csqY8WtmPiqr1NdXrRtx/THKVLN+5hUhsHLvaGMxqe3ONmqbSSVtdkbbn8cF8iDZnwbLaNNHq1G+z3orQL6iZTAb3W30WaCD9kpTHqHVSe5ITKe2t6IsU4/6PvqYgH/Y2A/qzwTsE0sedvaisByKN1++ruvW3eR0c/hfE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777899578; c=relaxed/simple; bh=C3Kz5qTzZkB+SC+9hZnM3gfu9srJJQ7bGN4QKH1fps8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Qb2hluMtFEqTDi3EniBHqIDGFZ4CEMMcTCniynJChU0Ob6BRS19+UmV4cb63KoSWNGxSCJZDqkbpi7pGQkBymMFB0qHcZx6egARHiuUCFGHIie4LN9US+tBC0p4+2M6lBsE5tMh+ifgSR5YZ4Trol3xO9F08NubrLQjARGhf1jQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Jv0+wAO+; arc=none smtp.client-ip=209.85.215.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Jv0+wAO+" Received: by mail-pg1-f169.google.com with SMTP id 41be03b00d2f7-c8026aa4d53so836763a12.3 for ; Mon, 04 May 2026 05:59:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1777899576; x=1778504376; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=eKZVhHxD7xRzXNoGtRypXUUEsdwehShk5FlRxtbxB7o=; b=Jv0+wAO+3tmNecmKFUNVY/quzP/AzNKl2Bk1o8jFYzTIRph7yePrXMh313VSfUtKF+ unhvvassZVeLbU4dI3TI3d1fXrxjMhp06KzHetmntW3RdQpC5mld9FKt/D7Kcnv1w5Zg VI4MXBWVMeIfFMaDoGJUTDWE2JasyLHWH30hkUAlrZh+bx25vwcsuL7mzU9+oNs3HsJP AuNEhLu3EoLzofUgwTEfmS4KPKhTBD3AZy+038Dt6byksnpAXsPvHld1b09rqNhoYxQZ AZFkk8gdFKkzUv20Z+wYTUwohejbt39oFFnVLYxS/a2JrVrLmd5/TW1HrtJ4xw5GdsYk IFdw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1777899576; x=1778504376; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=eKZVhHxD7xRzXNoGtRypXUUEsdwehShk5FlRxtbxB7o=; b=gvAUgsaXH81uLNliIz1tRqjyQgYPbGA8e/r6dLl/DfFiTPAGznTBoEeOTb8nxRbJub nVBaj/cNest9i/iT2nw9Sdk0hybd6WxaCnaSMUgkNmpzKbQUqEh+WV/YTfAK6sL3B7j5 B5kfFtOMNlYCPRACp3eKosF9E6aG4YOjWFRd9YFBvTom/DROwi/WEecuC1O8DDR09pnQ 3lV9BQVOCEZUeGglD9fgWeB3H3KD4FDygbDUmrtDcHhGZdPWROldXeC8/kS+3nA2uCqf miKTz79HNKqOdmVJRc5FgU3Kz4RDXMe6LVJHQx55RosGN1MoS9JLOpWe6rJCxLIdxNqZ 160Q== X-Forwarded-Encrypted: i=1; AFNElJ+YMAf4hKwPoJyq6ePYscfPY16x3NyKNwFMHgFkjtUr2HN0uyk89m5KbLq1xO0sebmIbLYg8Iwue+z1+xI=@vger.kernel.org X-Gm-Message-State: AOJu0YyuasmAaUr5+JlN0oiux49U8WKQnBZwu5WNFzu8vlOVKYSAf2u1 EykR+qVDrfkj6t5FbPAXi+FYFjH2UenyWX5uCZyk4wd7YsVcbw3PGdsC X-Gm-Gg: AeBDietpiMKHSy6mO23Lm6NfQsS1M/3Qg1T1+x5k/q0GmvcDxWoooegFKlRGE8n5bpl 27q55hdC4vvB8tB7Xt07C1/5H1lnDeb8e1+2CpjKMUpFt76VHNLxBBWBNDGNgGBFETylARD+ExS RQUmkmSg/DEJLBGEp2ZkRV698AHFKPIMp/9XMXxMSM4tsugogMW3BpftQNE4a8f4MV+oXkTmUGE qC2iFoOPLa4iqyzc02CSVt7KDS6c8hP+klAOKiY5aZJ9lYFD/xpKaitKFtXYgFIwX5BCC9Xp2s6 W76xzR60RzXERizbttrm1S6DJAtYwuC5R8zCChnEj0sDSYuZ69u8ofmj9GYw+H/UpFGefMffG15 cqpEN3QRTPAzUngzBrDSJElBu7xSOj7mnMBZw694zz8qt4ablUSJb3YQPaRbDJPS+ac1WC8+No9 MDHkke+hPEEZc0y4zk6B36LFWaQxm6qGg= X-Received: by 2002:a05:6a20:7491:b0:3a2:dabf:fef9 with SMTP id adf61e73a8af0-3a7f1c97a99mr9968814637.27.1777899576509; Mon, 04 May 2026 05:59:36 -0700 (PDT) Received: from lgs.. ([223.99.13.245]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-c7ffbc6f84asm9192517a12.19.2026.05.04.05.59.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 04 May 2026 05:59:36 -0700 (PDT) From: Guangshuo Li To: Sakari Ailus , Bingbu Cao , Mauro Carvalho Chehab , Greg Kroah-Hartman , Hans Verkuil , linux-media@vger.kernel.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org Cc: Guangshuo Li Subject: [PATCH v2] media: staging/ipu7: Fix pdata double free in init error paths Date: Mon, 4 May 2026 20:59:05 +0800 Message-ID: <20260504125905.580124-1-lgs201920130244@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ipu7_bus_initialize_device() stores the caller allocated pdata pointer in adev->pdata and installs ipu7_bus_release() as the device release callback. After auxiliary_device_init() succeeds, pdata is released by ipu7_bus_release(). The isys and psys init error paths still call kfree(pdata) after put_device() or after ipu7_bus_add_device() fails. In both cases the auxiliary device release callback has already been invoked, so pdata has already been freed through adev->pdata. Remove the duplicate kfree(pdata) calls. Also cache the MMU init error before calling put_device(), since put_device() may release the auxiliary device container. This issue was found by a static analysis tool I am developing. Fixes: b7fe4c0019b1 ("media: staging/ipu7: add Intel IPU7 PCI device driver= ") Signed-off-by: Guangshuo Li --- v2: - Use ERR_PTR(ret) instead of ERR_CAST(ret) after caching PTR_ERR(), fixing the build errors reported by kernel test robot. drivers/staging/media/ipu7/ipu7.c | 20 ++++++++------------ 1 file changed, 8 insertions(+), 12 deletions(-) diff --git a/drivers/staging/media/ipu7/ipu7.c b/drivers/staging/media/ipu7= /ipu7.c index c771e763f8c5..21746752a2b0 100644 --- a/drivers/staging/media/ipu7/ipu7.c +++ b/drivers/staging/media/ipu7/ipu7.c @@ -2169,21 +2169,19 @@ ipu7_isys_init(struct pci_dev *pdev, struct device = *parent, isys_adev->mmu =3D ipu7_mmu_init(dev, base, ISYS_MMID, &ipdata->hw_variant); if (IS_ERR(isys_adev->mmu)) { - dev_err_probe(dev, PTR_ERR(isys_adev->mmu), + ret =3D PTR_ERR(isys_adev->mmu); + dev_err_probe(dev, ret, "ipu7_mmu_init(isys_adev->mmu) failed\n"); put_device(&isys_adev->auxdev.dev); - kfree(pdata); - return ERR_CAST(isys_adev->mmu); + return ERR_PTR(ret); } =20 isys_adev->mmu->dev =3D &isys_adev->auxdev.dev; isys_adev->subsys =3D IPU_IS; =20 ret =3D ipu7_bus_add_device(isys_adev); - if (ret) { - kfree(pdata); + if (ret) return ERR_PTR(ret); - } =20 return isys_adev; } @@ -2216,21 +2214,19 @@ ipu7_psys_init(struct pci_dev *pdev, struct device = *parent, psys_adev->mmu =3D ipu7_mmu_init(&pdev->dev, base, PSYS_MMID, &ipdata->hw_variant); if (IS_ERR(psys_adev->mmu)) { - dev_err_probe(&pdev->dev, PTR_ERR(psys_adev->mmu), + ret =3D PTR_ERR(psys_adev->mmu); + dev_err_probe(&pdev->dev, ret, "ipu7_mmu_init(psys_adev->mmu) failed\n"); put_device(&psys_adev->auxdev.dev); - kfree(pdata); - return ERR_CAST(psys_adev->mmu); + return ERR_PTR(ret); } =20 psys_adev->mmu->dev =3D &psys_adev->auxdev.dev; psys_adev->subsys =3D IPU_PS; =20 ret =3D ipu7_bus_add_device(psys_adev); - if (ret) { - kfree(pdata); + if (ret) return ERR_PTR(ret); - } =20 return psys_adev; } --=20 2.43.0