From nobody Fri Aug 14 15:49:51 2026 Received: from mail-pg1-f174.google.com (mail-pg1-f174.google.com [209.85.215.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D95084749DD for ; Fri, 14 Aug 2026 13:41:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.174 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786714900; cv=none; b=s//petXs4BCFijkP4HE9ynLgPw44ufTFwVA6lxhCPVv/Q/MEum4v9YnkVGUgE2Wco02yQyyZrEJrAbO3Pyg20vHLmrphwBPVhb76tUPoskpqrAp/Agt/vQFt0KYyRGeTFlOJk7zvZUn3jf+v0jFSJwwCIxkY5ny8GL5H3llvE4A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786714900; c=relaxed/simple; bh=ia16VK3zFYq1FnJMXcRU+weZbqwlo4duDCMMKKCE8R0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=pw0SEBpr88fcWfCDKEktodz9J6UYxlc9o7hLd0PbmlG05c3Mj/nrdeHJ8SgH9sxtWT2wLiBMCXgwNRb/WlwLyLEja/Uguesd3KatIqQssgGkU4sPgmm8xJY35YGsabjPOZGf0jrRSAoFQ9BYDq/0AOZcx6J3t/qKwBzhr9sCmM8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=lbuhb2LT; arc=none smtp.client-ip=209.85.215.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="lbuhb2LT" Received: by mail-pg1-f174.google.com with SMTP id 41be03b00d2f7-ca766c1c9ccso570839a12.0 for ; Fri, 14 Aug 2026 06:41:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786714898; x=1787319698; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=ZHoa1K49NDPsNuWHGok7ahf8ilm7bb0+sIWpxa8JDrA=; b=lbuhb2LT8LcDksP8VyidLrHr1gIfFmbO1Cj95HymSYhLYN3/muzJoF6kBoqpvEDPD0 w2/al8/eqrkCW55sfWS/XSdkPfeWTOKpnEKNo17u4JNxSllXA189TSXdNzfFeUGxrOVO a5XYaFmfPeOUVF6WApeAaHKgNZ/GJjvFfRqHIVOMORKdCxx7MgFqDLef/R4k6rVH4Zsm 8UyRj7vlkXmLznEvPp0dE9hJEGcpsoOjf/B56Goqm/Uls6OlAEmMLAIKQmrAyqK7SfHG 2jW6TGdqt7MTLHxzS1wsBsxkvO/aZ3xMKZNZPI9CfHu5ewAK/9snUJ4HIfEWLHINSPYu L9Aw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786714898; x=1787319698; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ZHoa1K49NDPsNuWHGok7ahf8ilm7bb0+sIWpxa8JDrA=; b=nCcT+yRYCSPAeuIJl4ojJ4UzibRyHqzquzupwwAnePMhqpNiNt7UO4xAmOOftziPS0 5a3ReV5bIhHc6+y4OZa1SWivhA0kylEoY1HIeI9RCo2T74mW9N3Wbz2qhJdMk1Qb4RUh NU6a3Id0SC1seHsdX2rUI+njWQtydEDwV9CHlfvDaiIi+9sfQV5FWxgcYN5MrSd/ciXQ qErrHoZgNFIhiJK9eW2mJ/PAYQg7W3iYDu2OTyc0D5nHsmacduhj5IF0tNYfFARsMTmQ 3jfESKFJhYiiyue3t3CzfQqgtDe+2tWDyf5BmZsPjvv0DraWIOHkvoXk8dcc9v8Pc3En 3ayA== X-Forwarded-Encrypted: i=1; AHgh+RqiDuj4Bgiq33q7PeVwsP0msQa29CWzQox3QPlZKJq+bpI5Y/mJedy2qYH89g2AFN1oc6LOMg5BKiZyLZU=@vger.kernel.org X-Gm-Message-State: AOJu0Yx91msfA1SBzuhkSpoX+xPBpCGgYQzSwf2ae1/21RJ7coDXxqvb qT4X0deh3xJ4dgmh2YXKcsaqwsfiQ/FgibEOcw+jTFD2ua+LJ+//h+lj X-Gm-Gg: AR+sD13JaVzQ3InHjCsQn0x3F/PzgT6Tj/ritH/RxVrRys+ygUJSEiK07JgEZ7K5om2 Ovf7uvmRFd31B4J753nSHKqUWcsB7MBA6jyLkU+KHRQtld+aqm7QOD62Z7PxuS4ulrCdJ4AF9rQ o7kEHCkYIFL+13KTZhFzkeytMTURrEngYov88+vGWkLOKhUCyKzOqtaiVvnv6vhJkgImJsVcnU8 yHtDzjiq+AGQHc24PQtzWLFqLI6/7Y5sX4iJoNYt/jBDA+jnUjmPLJulc1IQGJWcdgvuZuV0MIn 3MwayArZTaXWy5l58tvlEyi9Xwb6EyNWta84lEv3noltkDwyRSXS+eQnIp7erXoJqGIsEHPa4aL R1OsKuOhezovJ99kUq8LIUJ/DnBDm5VZPOOD7wyuOtD3xmUGNABvH7puN71vQi85Ix+FTRwQe13 I5oWSFsFgsOp0+O0TUW54wbjlWNG3wpsJNt+Cj1DHidxbmdu/W2NjwrHzRcS1eQsBiCcDfcW2VT xjYdDu4 X-Received: by 2002:a05:6a00:3a12:b0:848:498b:e0d4 with SMTP id d2e1a72fcca58-84fde7d2ecemr5658625b3a.38.1786714897998; Fri, 14 Aug 2026 06:41:37 -0700 (PDT) Received: from haichao.tail057a43.ts.net ([2001:da8:e000:1206:e9af:7c0e:be31:2c3f]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cc095a43327sm592201a12.28.2026.08.14.06.41.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 06:41:37 -0700 (PDT) From: Ruoyu Wang To: Greg Kroah-Hartman , "Rafael J. Wysocki" , Danilo Krummrich , Russell King Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Ruoyu Wang Subject: [PATCH] component: Release match data on add failure Date: Fri, 14 Aug 2026 21:41:32 +0800 Message-ID: <20260814134132.1387952-1-ruoyuw560@gmail.com> X-Mailer: git-send-email 2.51.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" component_match_add_release() accepts a release callback so callers can transfer ownership of resources held by the match data. However, __component_match_add() returns without invoking that callback when the match is already an error pointer or when allocating the match or its array fails. This leaks resources acquired before the call. For example, drm_of_component_match_add() takes a reference to its device node before adding the match, and ERR_PTR-aware callers can return from probe with that reference still held. Calls made after the first allocation failure can leak further references. Invoke the release callback whenever the match data cannot be added, and document the failure-path ownership rule. Successful match lifetime semantics remain unchanged. This issue was found by a static analysis checker and confirmed by manual source review. Fixes: ce657b1cddf1 ("component: add support for releasing match data") Signed-off-by: Ruoyu Wang --- drivers/base/component.c | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/drivers/base/component.c b/drivers/base/component.c index 655d68deb590c..2b455d7499926 100644 --- a/drivers/base/component.c +++ b/drivers/base/component.c @@ -388,14 +388,14 @@ static void __component_match_add(struct device *pare= nt, struct component_match *match =3D *matchptr; =20 if (IS_ERR(match)) - return; + goto err_release; =20 if (!match) { match =3D devres_alloc(devm_component_match_release, sizeof(*match), GFP_KERNEL); if (!match) { *matchptr =3D ERR_PTR(-ENOMEM); - return; + goto err_release; } =20 devres_add(parent, match); @@ -410,7 +410,7 @@ static void __component_match_add(struct device *parent, ret =3D component_match_realloc(match, new_size); if (ret) { *matchptr =3D ERR_PTR(ret); - return; + goto err_release; } } =20 @@ -420,6 +420,11 @@ static void __component_match_add(struct device *paren= t, match->compare[match->num].data =3D compare_data; match->compare[match->num].component =3D NULL; match->num++; + return; + +err_release: + if (release) + release(parent, compare_data); } =20 /** @@ -438,7 +443,8 @@ static void __component_match_add(struct device *parent, * The allocated match list in @matchptr is automatically released using d= evm * actions, where upon @release will be called to free any references held= by * @compare_data, e.g. when @compare_data is a &device_node that must be - * released with of_node_put(). + * released with of_node_put(). @release is also called if the match canno= t be + * added. * * See also component_match_add() and component_match_add_typed(). */ --=20 2.51.0