[PATCH] usb: dwc2: debugfs: fix memory leak of hsotg->regset

Huang Wei posted 1 patch 1 month, 3 weeks ago
There is a newer version of this series
drivers/usb/dwc2/debugfs.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
[PATCH] usb: dwc2: debugfs: fix memory leak of hsotg->regset
Posted by Huang Wei 1 month, 3 weeks ago
hsotg->regset is allocated in dwc2_debugfs_init() using devm_kzalloc()
but is never explicitly freed. While devres would eventually reclaim
the memory, the regset is logically owned by the debugfs lifetime:
dwc2_debugfs_exit() only removes the debugfs directory and leaves
hsotg->regset dangling.

Switch to kzalloc() and free it explicitly in dwc2_debugfs_exit(),
mirroring the equivalent fix already applied to dwc3 in commit
e6bdf8195b4a ("usb: dwc3: fix memory leak of dwc->regset"). Also set
the pointer to NULL after freeing to avoid a stale dangling pointer.

Reported-by: kakapapa2 <kakapapa2@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=219977
Signed-off-by: Huang Wei <huangwei@kylinos.cn>
---
 drivers/usb/dwc2/debugfs.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/usb/dwc2/debugfs.c b/drivers/usb/dwc2/debugfs.c
index 3116ac72747f..2ecbf6523aaa 100644
--- a/drivers/usb/dwc2/debugfs.c
+++ b/drivers/usb/dwc2/debugfs.c
@@ -9,6 +9,7 @@
 #include <linux/spinlock.h>
 #include <linux/debugfs.h>
 #include <linux/seq_file.h>
+#include <linux/slab.h>
 #include <linux/uaccess.h>
 
 #include "core.h"
@@ -787,8 +788,7 @@ int dwc2_debugfs_init(struct dwc2_hsotg *hsotg)
 	/* Add gadget debugfs nodes */
 	dwc2_hsotg_create_debug(hsotg);
 
-	hsotg->regset = devm_kzalloc(hsotg->dev, sizeof(*hsotg->regset),
-								GFP_KERNEL);
+	hsotg->regset = kzalloc_obj(*hsotg->regset, GFP_KERNEL);
 	if (!hsotg->regset) {
 		ret = -ENOMEM;
 		goto err;
@@ -810,4 +810,6 @@ void dwc2_debugfs_exit(struct dwc2_hsotg *hsotg)
 {
 	debugfs_remove_recursive(hsotg->debug_root);
 	hsotg->debug_root = NULL;
+	kfree(hsotg->regset);
+	hsotg->regset = NULL;
 }
-- 
2.25.1
Re: [PATCH] usb: dwc2: debugfs: fix memory leak of hsotg->regset
Posted by Thinh Nguyen 3 weeks, 3 days ago
On Fri, Aug 07, 2026, Huang Wei wrote:
> hsotg->regset is allocated in dwc2_debugfs_init() using devm_kzalloc()
> but is never explicitly freed. While devres would eventually reclaim
> the memory, the regset is logically owned by the debugfs lifetime:
> dwc2_debugfs_exit() only removes the debugfs directory and leaves
> hsotg->regset dangling.
> 
> Switch to kzalloc() and free it explicitly in dwc2_debugfs_exit(),
> mirroring the equivalent fix already applied to dwc3 in commit
> e6bdf8195b4a ("usb: dwc3: fix memory leak of dwc->regset"). Also set
> the pointer to NULL after freeing to avoid a stale dangling pointer.

This 2nd paragraph sounds as if dwc3 did the same thing (changing
devm_kzalloc -> kzalloc). The mentioned commit is solving a separate
problem. That's misleading. Please remove this paragraph.

> 
> Reported-by: kakapapa2 <kakapapa2@gmail.com>
> Closes: https://urldefense.com/v3/__https://bugzilla.kernel.org/show_bug.cgi?id=219977__;!!A4F2R9G_pg!fZ_fOd6cc_gIWYTIuT9N9wCV-tBbojEsj1lrFMFZZHpEGRwC2EcvZzNOTtFndJI6z1GZYyQQQmn8L4pqnvVgioYL$ 

The report and the commit message are somewhat misleading because regset
is currently allocated with devm_kzalloc(), so it is not expected to be
freed from dwc2_debugfs_exit(). The issue is really about the allocation
lifetime with the debugfs lifetime rather than fixing a memory leak in
the existing implementation.

But overall, IMO, this change is good to have. If you send a v2 with a
fix up commit message and send a v2, you can add this:

Reviewed-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com>

BR,
Thinh

> Signed-off-by: Huang Wei <huangwei@kylinos.cn>
> ---
>  drivers/usb/dwc2/debugfs.c | 6 ++++--
>  1 file changed, 4 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/usb/dwc2/debugfs.c b/drivers/usb/dwc2/debugfs.c
> index 3116ac72747f..2ecbf6523aaa 100644
> --- a/drivers/usb/dwc2/debugfs.c
> +++ b/drivers/usb/dwc2/debugfs.c
> @@ -9,6 +9,7 @@
>  #include <linux/spinlock.h>
>  #include <linux/debugfs.h>
>  #include <linux/seq_file.h>
> +#include <linux/slab.h>
>  #include <linux/uaccess.h>
>  
>  #include "core.h"
> @@ -787,8 +788,7 @@ int dwc2_debugfs_init(struct dwc2_hsotg *hsotg)
>  	/* Add gadget debugfs nodes */
>  	dwc2_hsotg_create_debug(hsotg);
>  
> -	hsotg->regset = devm_kzalloc(hsotg->dev, sizeof(*hsotg->regset),
> -								GFP_KERNEL);
> +	hsotg->regset = kzalloc_obj(*hsotg->regset, GFP_KERNEL);
>  	if (!hsotg->regset) {
>  		ret = -ENOMEM;
>  		goto err;
> @@ -810,4 +810,6 @@ void dwc2_debugfs_exit(struct dwc2_hsotg *hsotg)
>  {
>  	debugfs_remove_recursive(hsotg->debug_root);
>  	hsotg->debug_root = NULL;
> +	kfree(hsotg->regset);
> +	hsotg->regset = NULL;
>  }
> -- 
> 2.25.1
> 
> 
Re: [PATCH] usb: dwc2: debugfs: fix memory leak of hsotg->regset
Posted by Huang Wei 3 weeks, 6 days ago
Hi,

Gentle ping on this one. It's a small debugfs memory leak fix that
mirrors the equivalent dwc3 fix (commit e6bdf8195b4a ("usb: dwc3: fix
memory leak of dwc->regset")). Happy to address any feedback or resend
if needed.

Thanks,
Huang Wei
Re: [PATCH] usb: dwc2: debugfs: fix memory leak of hsotg->regset
Posted by Greg Kroah-Hartman 3 weeks, 6 days ago
On Wed, Sep 02, 2026 at 05:05:41PM +0800, Huang Wei wrote:
> Hi,
> 
> Gentle ping on this one. It's a small debugfs memory leak fix that
> mirrors the equivalent dwc3 fix (commit e6bdf8195b4a ("usb: dwc3: fix
> memory leak of dwc->regset")). Happy to address any feedback or resend
> if needed.

I have 700+ USB patches still to process, it's in the queue...

To help out, please help review other patches!

thanks,

greg k-h
Re: [PATCH] usb: dwc2: debugfs: fix memory leak of hsotg->regset
Posted by Huang Wei 3 weeks, 5 days ago
Hi Greg,

Thanks — no rush on my patch, understood. I'll start helping review
others on the list.

Best regards,
Huang Wei
[PATCH v2] usb: dwc2: debugfs: fix memory leak of hsotg->regset
Posted by Huang Wei 2 weeks, 6 days ago
hsotg->regset is allocated in dwc2_debugfs_init() using devm_kzalloc(),
which ties its lifetime to the device (struct dwc2_hsotg) rather than
to the debugfs entries it serves. dwc2_debugfs_exit() removes the
debugfs directory but leaves hsotg->regset allocated until the device
itself is removed, so the pointer dangles for the remainder of the
device lifetime.

Switch to kzalloc() and free it explicitly in dwc2_debugfs_exit() so
the regset lifetime matches the debugfs lifetime. Set the pointer to
NULL after freeing to avoid a stale dangling pointer.

Reported-by: kakapapa2 <kakapapa2@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=219977
Reviewed-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com>
Signed-off-by: Huang Wei <huangwei@kylinos.cn>

---
Changes in v2:
- Rework the commit message per Thinh Nguyen: the issue is an
  allocation lifetime mismatch with the debugfs lifetime, not a
  traditional memory leak (the devm_kzalloc() allocation is
  eventually reclaimed by devres). Drop the misleading reference to the
  dwc3 regset commit, which addressed a separate problem.
---
 drivers/usb/dwc2/debugfs.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/usb/dwc2/debugfs.c b/drivers/usb/dwc2/debugfs.c
index 3116ac72747f..2ecbf6523aaa 100644
--- a/drivers/usb/dwc2/debugfs.c
+++ b/drivers/usb/dwc2/debugfs.c
@@ -9,6 +9,7 @@
 #include <linux/spinlock.h>
 #include <linux/debugfs.h>
 #include <linux/seq_file.h>
+#include <linux/slab.h>
 #include <linux/uaccess.h>
 
 #include "core.h"
@@ -787,8 +788,7 @@ int dwc2_debugfs_init(struct dwc2_hsotg *hsotg)
 	/* Add gadget debugfs nodes */
 	dwc2_hsotg_create_debug(hsotg);
 
-	hsotg->regset = devm_kzalloc(hsotg->dev, sizeof(*hsotg->regset),
-								GFP_KERNEL);
+	hsotg->regset = kzalloc_obj(*hsotg->regset, GFP_KERNEL);
 	if (!hsotg->regset) {
 		ret = -ENOMEM;
 		goto err;
@@ -810,4 +810,6 @@ void dwc2_debugfs_exit(struct dwc2_hsotg *hsotg)
 {
 	debugfs_remove_recursive(hsotg->debug_root);
 	hsotg->debug_root = NULL;
+	kfree(hsotg->regset);
+	hsotg->regset = NULL;
 }
-- 
2.25.1