[PATCH v1] mtd: ubi: Release device reference on busy detach

Yuho Choi posted 1 patch 1 month, 3 weeks ago
drivers/mtd/ubi/build.c | 1 +
1 file changed, 1 insertion(+)
[PATCH v1] mtd: ubi: Release device reference on busy detach
Posted by Yuho Choi 1 month, 3 weeks ago
ubi_detach_mtd_dev() obtains a device reference through ubi_get_device()
before checking whether the UBI device is busy. The busy return path drops
ubi->ref_count but leaves the device reference held, so the device object
cannot be released after a later detach.

Drop the device reference before returning -EBUSY.

Fixes: 7e84c961b2eb ("mtd: ubi: introduce pre-removal notification for UBI volumes")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
---
 drivers/mtd/ubi/build.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/mtd/ubi/build.c b/drivers/mtd/ubi/build.c
index 674ad87809df..ee6ce4471b25 100644
--- a/drivers/mtd/ubi/build.c
+++ b/drivers/mtd/ubi/build.c
@@ -1105,6 +1105,7 @@ int ubi_detach_mtd_dev(int ubi_num, int anyway)
 	ubi->ref_count -= 1;
 	if (ubi->ref_count) {
 		if (!anyway) {
+			put_device(&ubi->dev);
 			spin_unlock(&ubi_devices_lock);
 			return -EBUSY;
 		}
-- 
2.43.0
Re: [PATCH v1] mtd: ubi: Release device reference on busy detach
Posted by Richard Weinberger 1 month, 2 weeks ago
On Fri, 07 Aug 2026 16:45:50 -0400, Yuho Choi wrote:
> ubi_detach_mtd_dev() obtains a device reference through ubi_get_device()
> before checking whether the UBI device is busy. The busy return path drops
> ubi->ref_count but leaves the device reference held, so the device object
> cannot be released after a later detach.
> 
> Drop the device reference before returning -EBUSY.
> 
> [...]

Applied, thanks!

[1/1] mtd: ubi: Release device reference on busy detach
      commit: 31dd710cd84d5dd63c49f640d3a9f36c9699ca95
Re: [PATCH v1] mtd: ubi: Release device reference on busy detach
Posted by Zhihao Cheng 1 month, 3 weeks ago
在 2026/8/8 4:45, Yuho Choi 写道:
> ubi_detach_mtd_dev() obtains a device reference through ubi_get_device()
> before checking whether the UBI device is busy. The busy return path drops
> ubi->ref_count but leaves the device reference held, so the device object
> cannot be released after a later detach.
> 
> Drop the device reference before returning -EBUSY.
> 
> Fixes: 7e84c961b2eb ("mtd: ubi: introduce pre-removal notification for UBI volumes")
> Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
> ---
>   drivers/mtd/ubi/build.c | 1 +
>   1 file changed, 1 insertion(+)

I think you have sent this patch before?
https://lore.kernel.org/linux-mtd/26c9c959-a3b6-e1de-1215-887990a46870@huawei.com/
> 
> diff --git a/drivers/mtd/ubi/build.c b/drivers/mtd/ubi/build.c
> index 674ad87809df..ee6ce4471b25 100644
> --- a/drivers/mtd/ubi/build.c
> +++ b/drivers/mtd/ubi/build.c
> @@ -1105,6 +1105,7 @@ int ubi_detach_mtd_dev(int ubi_num, int anyway)
>   	ubi->ref_count -= 1;
>   	if (ubi->ref_count) {
>   		if (!anyway) {
> +			put_device(&ubi->dev);
>   			spin_unlock(&ubi_devices_lock);
>   			return -EBUSY;
>   		}
>