drivers/mtd/ubi/build.c | 1 + 1 file changed, 1 insertion(+)
ubi_detach_mtd_dev() obtains a device reference through ubi_get_device()
before checking whether the UBI device is busy. The busy return path drops
ubi->ref_count but leaves the device reference held, so the device object
cannot be released after a later detach.
Drop the device reference before returning -EBUSY.
Fixes: 7e84c961b2eb ("mtd: ubi: introduce pre-removal notification for UBI volumes")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
---
drivers/mtd/ubi/build.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/mtd/ubi/build.c b/drivers/mtd/ubi/build.c
index 674ad87809df..ee6ce4471b25 100644
--- a/drivers/mtd/ubi/build.c
+++ b/drivers/mtd/ubi/build.c
@@ -1105,6 +1105,7 @@ int ubi_detach_mtd_dev(int ubi_num, int anyway)
ubi->ref_count -= 1;
if (ubi->ref_count) {
if (!anyway) {
+ put_device(&ubi->dev);
spin_unlock(&ubi_devices_lock);
return -EBUSY;
}
--
2.43.0
On Fri, 07 Aug 2026 16:45:50 -0400, Yuho Choi wrote:
> ubi_detach_mtd_dev() obtains a device reference through ubi_get_device()
> before checking whether the UBI device is busy. The busy return path drops
> ubi->ref_count but leaves the device reference held, so the device object
> cannot be released after a later detach.
>
> Drop the device reference before returning -EBUSY.
>
> [...]
Applied, thanks!
[1/1] mtd: ubi: Release device reference on busy detach
commit: 31dd710cd84d5dd63c49f640d3a9f36c9699ca95
在 2026/8/8 4:45, Yuho Choi 写道:
> ubi_detach_mtd_dev() obtains a device reference through ubi_get_device()
> before checking whether the UBI device is busy. The busy return path drops
> ubi->ref_count but leaves the device reference held, so the device object
> cannot be released after a later detach.
>
> Drop the device reference before returning -EBUSY.
>
> Fixes: 7e84c961b2eb ("mtd: ubi: introduce pre-removal notification for UBI volumes")
> Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
> ---
> drivers/mtd/ubi/build.c | 1 +
> 1 file changed, 1 insertion(+)
I think you have sent this patch before?
https://lore.kernel.org/linux-mtd/26c9c959-a3b6-e1de-1215-887990a46870@huawei.com/
>
> diff --git a/drivers/mtd/ubi/build.c b/drivers/mtd/ubi/build.c
> index 674ad87809df..ee6ce4471b25 100644
> --- a/drivers/mtd/ubi/build.c
> +++ b/drivers/mtd/ubi/build.c
> @@ -1105,6 +1105,7 @@ int ubi_detach_mtd_dev(int ubi_num, int anyway)
> ubi->ref_count -= 1;
> if (ubi->ref_count) {
> if (!anyway) {
> + put_device(&ubi->dev);
> spin_unlock(&ubi_devices_lock);
> return -EBUSY;
> }
>
© 2016 - 2026 Red Hat, Inc.