[PATCH] x86/amd_node: Fix PCI device reference counting in amd_smn_init()

Yazen Ghannam posted 1 patch 1 month ago
There is a newer version of this series
arch/x86/kernel/amd_node.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
[PATCH] x86/amd_node: Fix PCI device reference counting in amd_smn_init()
Posted by Yazen Ghannam 1 month ago
The local "root" pointer is a temporary variable used during the device
search. Therefore, refcount related to the search iterators should be
cleaned up after the search is complete.

Use the __free() cleanup macro to ensure the refcount is decremented
when the temporary pointer goes out of scope.

Additionally, increment the refcount when caching a root pointer. This
ensures the in-use refcount is separate from the temporary search
refcounting.

Fixes: 0a4b61d9c2e4 ("x86/amd_node: Fix AMD root device caching")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260806160159.230453-1-jason.andryuk%40amd.com
Assisted-by: Claude-Code:claude-opus-5
Signed-off-by: Yazen Ghannam <yazen.ghannam@amd.com>
---
 arch/x86/kernel/amd_node.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/arch/x86/kernel/amd_node.c b/arch/x86/kernel/amd_node.c
index 0be01725a2a4..312adf73313b 100644
--- a/arch/x86/kernel/amd_node.c
+++ b/arch/x86/kernel/amd_node.c
@@ -247,7 +247,7 @@ __setup("amd_smn_debugfs_enable", amd_smn_enable_dfs);
 static int __init amd_smn_init(void)
 {
 	u16 count, num_roots, roots_per_node, node, num_nodes;
-	struct pci_dev *root;
+	struct pci_dev *root __free(pci_dev_put) = NULL;
 
 	if (!cpu_feature_enabled(X86_FEATURE_ZEN))
 		return 0;
@@ -258,7 +258,6 @@ static int __init amd_smn_init(void)
 		return 0;
 
 	num_roots = 0;
-	root = NULL;
 	while ((root = get_next_root(root))) {
 		pci_dbg(root, "Reserving PCI config space\n");
 
@@ -297,7 +296,7 @@ static int __init amd_smn_init(void)
 			continue;
 
 		pci_dbg(root, "is root for AMD node %u\n", node);
-		amd_roots[node++] = root;
+		amd_roots[node++] = pci_dev_get(root);
 	}
 
 	if (enable_dfs) {

base-commit: 8d3ae59288f1e7d58d76558a6ee96d533bc5019f
-- 
2.43.0
Re: [PATCH] x86/amd_node: Fix PCI device reference counting in amd_smn_init()
Posted by Serge Hallyn (AMD) 1 month ago
On Mon, Aug 24, 2026 at 12:50:03PM -0500, Yazen Ghannam wrote:
> The local "root" pointer is a temporary variable used during the device
> search. Therefore, refcount related to the search iterators should be
> cleaned up after the search is complete.
> 
> Use the __free() cleanup macro to ensure the refcount is decremented
> when the temporary pointer goes out of scope.
> 
> Additionally, increment the refcount when caching a root pointer. This
> ensures the in-use refcount is separate from the temporary search
> refcounting.
> 
> Fixes: 0a4b61d9c2e4 ("x86/amd_node: Fix AMD root device caching")
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://sashiko.dev/#/patchset/20260806160159.230453-1-jason.andryuk%40amd.com
> Assisted-by: Claude-Code:claude-opus-5
> Signed-off-by: Yazen Ghannam <yazen.ghannam@amd.com>
> ---
>  arch/x86/kernel/amd_node.c | 5 ++---
>  1 file changed, 2 insertions(+), 3 deletions(-)
> 
> diff --git a/arch/x86/kernel/amd_node.c b/arch/x86/kernel/amd_node.c
> index 0be01725a2a4..312adf73313b 100644
> --- a/arch/x86/kernel/amd_node.c
> +++ b/arch/x86/kernel/amd_node.c
> @@ -247,7 +247,7 @@ __setup("amd_smn_debugfs_enable", amd_smn_enable_dfs);
>  static int __init amd_smn_init(void)
>  {
>  	u16 count, num_roots, roots_per_node, node, num_nodes;
> -	struct pci_dev *root;
> +	struct pci_dev *root __free(pci_dev_put) = NULL;
>  
>  	if (!cpu_feature_enabled(X86_FEATURE_ZEN))
>  		return 0;
> @@ -258,7 +258,6 @@ static int __init amd_smn_init(void)
>  		return 0;
>  
>  	num_roots = 0;
> -	root = NULL;
>  	while ((root = get_next_root(root))) {
>  		pci_dbg(root, "Reserving PCI config space\n");
>  

Will this leak the ref taken on the last get_next_root(root) in the
first loop?  You might need a pci_dev_put(root) before the root = NULL
above the second loop.  Or I could be wrong.

> @@ -297,7 +296,7 @@ static int __init amd_smn_init(void)
>  			continue;
>  
>  		pci_dbg(root, "is root for AMD node %u\n", node);
> -		amd_roots[node++] = root;
> +		amd_roots[node++] = pci_dev_get(root);
>  	}
>  
>  	if (enable_dfs) {
> 
> base-commit: 8d3ae59288f1e7d58d76558a6ee96d533bc5019f
> -- 
> 2.43.0
>
Re: [PATCH] x86/amd_node: Fix PCI device reference counting in amd_smn_init()
Posted by Yazen Ghannam 1 month ago
On Mon, Aug 24, 2026 at 10:59:28PM -0500, Serge Hallyn (AMD) wrote:
> On Mon, Aug 24, 2026 at 12:50:03PM -0500, Yazen Ghannam wrote:
> > The local "root" pointer is a temporary variable used during the device
> > search. Therefore, refcount related to the search iterators should be
> > cleaned up after the search is complete.
> > 
> > Use the __free() cleanup macro to ensure the refcount is decremented
> > when the temporary pointer goes out of scope.
> > 
> > Additionally, increment the refcount when caching a root pointer. This
> > ensures the in-use refcount is separate from the temporary search
> > refcounting.
> > 
> > Fixes: 0a4b61d9c2e4 ("x86/amd_node: Fix AMD root device caching")
> > Reported-by: Sashiko <sashiko-bot@kernel.org>
> > Closes: https://sashiko.dev/#/patchset/20260806160159.230453-1-jason.andryuk%40amd.com
> > Assisted-by: Claude-Code:claude-opus-5
> > Signed-off-by: Yazen Ghannam <yazen.ghannam@amd.com>
> > ---
> >  arch/x86/kernel/amd_node.c | 5 ++---
> >  1 file changed, 2 insertions(+), 3 deletions(-)
> > 
> > diff --git a/arch/x86/kernel/amd_node.c b/arch/x86/kernel/amd_node.c
> > index 0be01725a2a4..312adf73313b 100644
> > --- a/arch/x86/kernel/amd_node.c
> > +++ b/arch/x86/kernel/amd_node.c
> > @@ -247,7 +247,7 @@ __setup("amd_smn_debugfs_enable", amd_smn_enable_dfs);
> >  static int __init amd_smn_init(void)
> >  {
> >  	u16 count, num_roots, roots_per_node, node, num_nodes;
> > -	struct pci_dev *root;
> > +	struct pci_dev *root __free(pci_dev_put) = NULL;
> >  
> >  	if (!cpu_feature_enabled(X86_FEATURE_ZEN))
> >  		return 0;
> > @@ -258,7 +258,6 @@ static int __init amd_smn_init(void)
> >  		return 0;
> >  
> >  	num_roots = 0;
> > -	root = NULL;
> >  	while ((root = get_next_root(root))) {
> >  		pci_dbg(root, "Reserving PCI config space\n");
> >  
> 
> Will this leak the ref taken on the last get_next_root(root) in the
> first loop?  You might need a pci_dev_put(root) before the root = NULL
> above the second loop.  Or I could be wrong.
> 

Yes, I think you're right. Good catch.

I'll send another revision with your suggestion.

Thanks,
Yazen
Re: [PATCH] x86/amd_node: Fix PCI device reference counting in amd_smn_init()
Posted by Yazen Ghannam 1 month ago
On Tue, Aug 25, 2026 at 09:52:06AM -0400, Yazen Ghannam wrote:
> On Mon, Aug 24, 2026 at 10:59:28PM -0500, Serge Hallyn (AMD) wrote:
> > On Mon, Aug 24, 2026 at 12:50:03PM -0500, Yazen Ghannam wrote:
> > > The local "root" pointer is a temporary variable used during the device
> > > search. Therefore, refcount related to the search iterators should be
> > > cleaned up after the search is complete.
> > > 
> > > Use the __free() cleanup macro to ensure the refcount is decremented
> > > when the temporary pointer goes out of scope.
> > > 
> > > Additionally, increment the refcount when caching a root pointer. This
> > > ensures the in-use refcount is separate from the temporary search
> > > refcounting.
> > > 
> > > Fixes: 0a4b61d9c2e4 ("x86/amd_node: Fix AMD root device caching")
> > > Reported-by: Sashiko <sashiko-bot@kernel.org>
> > > Closes: https://sashiko.dev/#/patchset/20260806160159.230453-1-jason.andryuk%40amd.com
> > > Assisted-by: Claude-Code:claude-opus-5
> > > Signed-off-by: Yazen Ghannam <yazen.ghannam@amd.com>
> > > ---
> > >  arch/x86/kernel/amd_node.c | 5 ++---
> > >  1 file changed, 2 insertions(+), 3 deletions(-)
> > > 
> > > diff --git a/arch/x86/kernel/amd_node.c b/arch/x86/kernel/amd_node.c
> > > index 0be01725a2a4..312adf73313b 100644
> > > --- a/arch/x86/kernel/amd_node.c
> > > +++ b/arch/x86/kernel/amd_node.c
> > > @@ -247,7 +247,7 @@ __setup("amd_smn_debugfs_enable", amd_smn_enable_dfs);
> > >  static int __init amd_smn_init(void)
> > >  {
> > >  	u16 count, num_roots, roots_per_node, node, num_nodes;
> > > -	struct pci_dev *root;
> > > +	struct pci_dev *root __free(pci_dev_put) = NULL;
> > >  
> > >  	if (!cpu_feature_enabled(X86_FEATURE_ZEN))
> > >  		return 0;
> > > @@ -258,7 +258,6 @@ static int __init amd_smn_init(void)
> > >  		return 0;
> > >  
> > >  	num_roots = 0;
> > > -	root = NULL;
> > >  	while ((root = get_next_root(root))) {
> > >  		pci_dbg(root, "Reserving PCI config space\n");
> > >  
> > 
> > Will this leak the ref taken on the last get_next_root(root) in the
> > first loop?  You might need a pci_dev_put(root) before the root = NULL
> > above the second loop.  Or I could be wrong.
> > 
> 
> Yes, I think you're right. Good catch.
> 
> I'll send another revision with your suggestion.
> 

Actually, this isn't an issue. An exhaustive search ends with a NULL
pointer. The PCI search helpers would have done the 'put' on the last
device.

This also means that the second 'root = NULL' is redundant. I'll remove
it in the next revision.

Please let me know what you think.

Thanks,
Yazen
Re: [PATCH] x86/amd_node: Fix PCI device reference counting in amd_smn_init()
Posted by Serge E. Hallyn 3 weeks, 6 days ago
On Tue, Aug 25, 2026 at 10:35:38AM -0400, Yazen Ghannam wrote:
> On Tue, Aug 25, 2026 at 09:52:06AM -0400, Yazen Ghannam wrote:
> > On Mon, Aug 24, 2026 at 10:59:28PM -0500, Serge Hallyn (AMD) wrote:
> > > On Mon, Aug 24, 2026 at 12:50:03PM -0500, Yazen Ghannam wrote:
> > > > The local "root" pointer is a temporary variable used during the device
> > > > search. Therefore, refcount related to the search iterators should be
> > > > cleaned up after the search is complete.
> > > > 
> > > > Use the __free() cleanup macro to ensure the refcount is decremented
> > > > when the temporary pointer goes out of scope.
> > > > 
> > > > Additionally, increment the refcount when caching a root pointer. This
> > > > ensures the in-use refcount is separate from the temporary search
> > > > refcounting.
> > > > 
> > > > Fixes: 0a4b61d9c2e4 ("x86/amd_node: Fix AMD root device caching")
> > > > Reported-by: Sashiko <sashiko-bot@kernel.org>
> > > > Closes: https://sashiko.dev/#/patchset/20260806160159.230453-1-jason.andryuk%40amd.com
> > > > Assisted-by: Claude-Code:claude-opus-5
> > > > Signed-off-by: Yazen Ghannam <yazen.ghannam@amd.com>
> > > > ---
> > > >  arch/x86/kernel/amd_node.c | 5 ++---
> > > >  1 file changed, 2 insertions(+), 3 deletions(-)
> > > > 
> > > > diff --git a/arch/x86/kernel/amd_node.c b/arch/x86/kernel/amd_node.c
> > > > index 0be01725a2a4..312adf73313b 100644
> > > > --- a/arch/x86/kernel/amd_node.c
> > > > +++ b/arch/x86/kernel/amd_node.c
> > > > @@ -247,7 +247,7 @@ __setup("amd_smn_debugfs_enable", amd_smn_enable_dfs);
> > > >  static int __init amd_smn_init(void)
> > > >  {
> > > >  	u16 count, num_roots, roots_per_node, node, num_nodes;
> > > > -	struct pci_dev *root;
> > > > +	struct pci_dev *root __free(pci_dev_put) = NULL;
> > > >  
> > > >  	if (!cpu_feature_enabled(X86_FEATURE_ZEN))
> > > >  		return 0;
> > > > @@ -258,7 +258,6 @@ static int __init amd_smn_init(void)
> > > >  		return 0;
> > > >  
> > > >  	num_roots = 0;
> > > > -	root = NULL;
> > > >  	while ((root = get_next_root(root))) {
> > > >  		pci_dbg(root, "Reserving PCI config space\n");
> > > >  
> > > 
> > > Will this leak the ref taken on the last get_next_root(root) in the
> > > first loop?  You might need a pci_dev_put(root) before the root = NULL
> > > above the second loop.  Or I could be wrong.
> > > 
> > 
> > Yes, I think you're right. Good catch.
> > 
> > I'll send another revision with your suggestion.
> > 
> 
> Actually, this isn't an issue. An exhaustive search ends with a NULL
> pointer. The PCI search helpers would have done the 'put' on the last
> device.
> 
> This also means that the second 'root = NULL' is redundant. I'll remove
> it in the next revision.
> 
> Please let me know what you think.

Sorry for the late reply.  I think you're right.  Thanks!

-serge
Re: [PATCH] x86/amd_node: Fix PCI device reference counting in amd_smn_init()
Posted by Mario Limonciello 1 month ago

On 8/24/26 12:50, Yazen Ghannam wrote:
> The local "root" pointer is a temporary variable used during the device
> search. Therefore, refcount related to the search iterators should be
> cleaned up after the search is complete.
> 
> Use the __free() cleanup macro to ensure the refcount is decremented
> when the temporary pointer goes out of scope.
> 
> Additionally, increment the refcount when caching a root pointer. This
> ensures the in-use refcount is separate from the temporary search
> refcounting.
> 
> Fixes: 0a4b61d9c2e4 ("x86/amd_node: Fix AMD root device caching")
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://sashiko.dev/#/patchset/20260806160159.230453-1-jason.andryuk%40amd.com
> Assisted-by: Claude-Code:claude-opus-5
> Signed-off-by: Yazen Ghannam <yazen.ghannam@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>> ---
>   arch/x86/kernel/amd_node.c | 5 ++---
>   1 file changed, 2 insertions(+), 3 deletions(-)
> 
> diff --git a/arch/x86/kernel/amd_node.c b/arch/x86/kernel/amd_node.c
> index 0be01725a2a4..312adf73313b 100644
> --- a/arch/x86/kernel/amd_node.c
> +++ b/arch/x86/kernel/amd_node.c
> @@ -247,7 +247,7 @@ __setup("amd_smn_debugfs_enable", amd_smn_enable_dfs);
>   static int __init amd_smn_init(void)
>   {
>   	u16 count, num_roots, roots_per_node, node, num_nodes;
> -	struct pci_dev *root;
> +	struct pci_dev *root __free(pci_dev_put) = NULL;
>   
>   	if (!cpu_feature_enabled(X86_FEATURE_ZEN))
>   		return 0;
> @@ -258,7 +258,6 @@ static int __init amd_smn_init(void)
>   		return 0;
>   
>   	num_roots = 0;
> -	root = NULL;
>   	while ((root = get_next_root(root))) {
>   		pci_dbg(root, "Reserving PCI config space\n");
>   
> @@ -297,7 +296,7 @@ static int __init amd_smn_init(void)
>   			continue;
>   
>   		pci_dbg(root, "is root for AMD node %u\n", node);
> -		amd_roots[node++] = root;
> +		amd_roots[node++] = pci_dev_get(root);
>   	}
>   
>   	if (enable_dfs) {
> 
> base-commit: 8d3ae59288f1e7d58d76558a6ee96d533bc5019f