From nobody Mon Sep 28 05:45:46 2026 Received: from va-1-112.ptr.blmpb.com (va-1-112.ptr.blmpb.com [209.127.230.112]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F3A792C3757 for ; Wed, 26 Aug 2026 03:53:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.112 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787716429; cv=none; b=N1Xn+Yf5nWr5q4GZDrJQ+vjKLjY81QnLdsbXaJ0/W+brRQ+A7wb2aaeAo6/FOFWjCJ2aoI6O2HPqZu0PHBk+6sjWgyVnlRFp46bl0FD1dJLjNz77wIdipmBBCbPjE4FeB/z2KISaDCrLaUxLVYuFOtuDXIA9sJHuulO2hvZhmKg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787716429; c=relaxed/simple; bh=XIhRMq2clZ19aR6ASYiRZB8iIkryXIMbTdHMER7D0pE=; h=To:Cc:Mime-Version:Date:In-Reply-To:References:Content-Type:From: Subject:Message-Id; b=Z1Pvt9C8OOAgAHwZ3+NwXDzGcnhwMn3RD0bgXOJm8DkvdUV6TyciG6Dy1WWgMSjF4GACJ0cTYKZ2qJCm8Pdt8ulm3iqh+QTuVLNSP/6jEc0Fr1OEiiUOfiqSwJknC1OJbMiJ0kyH+QvxGrTejnTXIrMgBgkiaUw5kItQf6iaelg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=amta/Prz; arc=none smtp.client-ip=209.127.230.112 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="amta/Prz" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1787716416; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=hXQ2RGC+EMz7OMTzABp+Wr7+AqgogaxAooS9n7iKBww=; b=amta/PrzM9x40jE5GOuQkwT1cE5pvyPBfABwLPoTFk7kIbqnweXZKbVVMK0QrBMVmpjtr5 d9v9uveG9he0dplzHXvzPyDVVOIaNupkSaSwrgdIdNyfiKrFbi4g10LfO5In9n9IYDSiwa FtTgg30+5zuu6JBLqWR42hqHTI3PVLFfqWBiZsNkyKyXr9iwqVn15BFIP/zFdL/aeS1G92 RzcdXF5G/UsvhpSCsNH/cOqPPBmR1AG4sOs9zseM0FJ0KxGfmprOooMV0FhIV2v/RV/YuQ zLjfRs9N+6zvqNUR9A871rbnQQJgFP3JjE6Xt4rHuumLIEwCA5LLw8Mn0pj/Zw== To: Cc: , , , , "Rui Qi" Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Lms-Return-Path: Date: Wed, 26 Aug 2026 11:53:11 +0800 In-Reply-To: <20260826035314.1536340-1-qirui.001@bytedance.com> References: <20260821094748.145394-1-qirui.001@bytedance.com> <20260826035314.1536340-1-qirui.001@bytedance.com> From: "Rui Qi" Subject: [PATCH v2 1/4] RAS/AMD/FMPM: Fix out-of-bounds read in for_each_fru macro Message-Id: <20260826035314.1536340-2-qirui.001@bytedance.com> X-Mailer: git-send-email 2.20.1 X-Original-From: Rui Qi Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The for_each_fru macro evaluates the array access "rec =3D fru_records[i]" before the bounds check "i < max_nr_fru" due to the comma operator's left-to-right evaluation order. When the loop terminates, i equals max_nr_fru, causing fru_records[max_nr_fru] to be read before the condition is checked. While the garbage pointer value assigned to rec is never dereferenced (the loop exits immediately), this is technically undefined behavior and would be flagged by KASAN and static analyzers. Fix by using short-circuit evaluation with && to check the bound first, only accessing the array when i is within range: for (i =3D 0; i < max_nr_fru && ((rec =3D fru_records[i]), true); i++) Fixes: 6f15e617cc99 ("RAS: Introduce a FRU memory poison manager") Signed-off-by: Rui Qi Reviewed-by: Yazen Ghannam --- drivers/ras/amd/fmpm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/ras/amd/fmpm.c b/drivers/ras/amd/fmpm.c index 4ccaaf7b70bf..81d7f02c053d 100644 --- a/drivers/ras/amd/fmpm.c +++ b/drivers/ras/amd/fmpm.c @@ -169,7 +169,7 @@ static unsigned int spa_nr_entries; static DEFINE_MUTEX(fmpm_update_mutex); =20 #define for_each_fru(i, rec) \ - for (i =3D 0; rec =3D fru_records[i], i < max_nr_fru; i++) + for (i =3D 0; i < max_nr_fru && ((rec =3D fru_records[i]), true); i++) =20 static inline u32 get_fmp_len(struct fru_rec *rec) { --=20 2.20.1 From nobody Mon Sep 28 05:45:46 2026 Received: from va-1-111.ptr.blmpb.com (va-1-111.ptr.blmpb.com [209.127.230.111]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7D7F92EEE73 for ; Wed, 26 Aug 2026 03:53:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.111 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787716431; cv=none; b=TKssX907pVhA60Ecx1GHdzVcnUkjMw6O2EYHZbZVYOxHsMudZ29Iac1IGWj+0aMn0J6t9MnRb9vn5TSlgFIUXfCinYvnjLFJABKFAkXlueg9YZn3B2kjWoXJn1qaov/9QBJd0b1FXCHaTFQIIQmFZ/tLsPKJB0i5B8b2eDpaIA4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787716431; c=relaxed/simple; bh=LzlNA+vTYMinB+5oqKzjJDtR8oSJGlnQrdWrAfNzQCE=; h=Cc:Subject:Message-Id:To:From:Date:References:Mime-Version: In-Reply-To:Content-Type; b=tDio0VoTEqGlG5c4DGZA22MtE2UILYFCyNuFbmKG17CAFAmEzLJ6alMcxTmFgVtyUNR9q/rs5j0ZPUmh72n5qOeHsWCaiS0kgWcr1IhOPa58b7TT3CGZOMmsb+0U+ArfnkHSDYK4PDy2efF5c5gHDiQbuu6CXqHnl31/uAZTUic= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=LtDS4hp2; arc=none smtp.client-ip=209.127.230.111 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="LtDS4hp2" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1787716425; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=YiFsJm98mSe94RNuH7SDN6xSZlINuqUUPUSly9lgma0=; b=LtDS4hp2fZMn8a/9Cm498I0ijj4UIrmEwdIluQLC14/0C9EKSr6Ui4n+JCp4I0jBmQ2eBo 0xhquZQmNqIKSnlWa+lifJRW1mYe/i0y3jtgdguVw+r/V0zUVNuBRxpcIZknMzMpDNqRQ6 0PsKZM0zFZ+is+Vbfpvtb+xY2fuPiwcIzZaZzFUMj4VHepfy4iEKEFZYb9VwhRr/MW5buB cYAtijy1J1dGw2SyJqp7fkh+Dqo8XuMQrvDwewvtmdAnj+PoUact31RiDyjQmkFIUNjh0V 4SNngzXnWm2MsSIG1vS3my09Nsj+jk0aonVMhvrDBz6OdTtpYvRNcKjmoojicw== Cc: , , , , "Rui Qi" Subject: [PATCH v2 2/4] RAS/AMD/FMPM: Clear new records bitmap before rollback Message-Id: <20260826035314.1536340-3-qirui.001@bytedance.com> X-Lms-Return-Path: Content-Transfer-Encoding: quoted-printable To: From: "Rui Qi" Date: Wed, 26 Aug 2026 11:53:12 +0800 References: <20260821094748.145394-1-qirui.001@bytedance.com> <20260826035314.1536340-1-qirui.001@bytedance.com> X-Mailer: git-send-email 2.20.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Original-From: Rui Qi In-Reply-To: <20260826035314.1536340-1-qirui.001@bytedance.com> Content-Type: text/plain; charset="utf-8" save_new_records() uses a stack bitmap to track which ERST records were created during the current initialization pass. If a later write fails, the rollback path tests this bitmap to decide which records should be removed again. DECLARE_BITMAP() does not initialize stack storage, so the rollback path can observe stale bits and attempt to clear records that were not created by this function. Initialize the bitmap to zero at declaration so that only records successfully written in the current pass are rolled back. Fixes: 6f15e617cc99 ("RAS: Introduce a FRU memory poison manager") Signed-off-by: Rui Qi Reviewed-by: Yazen Ghannam --- drivers/ras/amd/fmpm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/ras/amd/fmpm.c b/drivers/ras/amd/fmpm.c index 81d7f02c053d..e3f7bd053479 100644 --- a/drivers/ras/amd/fmpm.c +++ b/drivers/ras/amd/fmpm.c @@ -528,7 +528,7 @@ static void set_rec_fields(struct fru_rec *rec) =20 static int save_new_records(void) { - DECLARE_BITMAP(new_records, FMPM_MAX_NR_FRU); + DECLARE_BITMAP(new_records, FMPM_MAX_NR_FRU) =3D { 0 }; struct fru_rec *rec; unsigned int i; int ret =3D 0; --=20 2.20.1 From nobody Mon Sep 28 05:45:46 2026 Received: from va-1-113.ptr.blmpb.com (va-1-113.ptr.blmpb.com [209.127.230.113]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3E8512C3757 for ; Wed, 26 Aug 2026 03:54:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.113 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787716446; cv=none; b=iB0vNnJVRaYsNS51KfcFvdOynIPGMt+Ot4MQ1jaqEa0J3MjxfXlPPVH8LK/Itekyu+zw9wJwleRkdRrDEAAtksT9vw9odZo4LhpPJoTnwJAKXCes1wAZqeQjBl5FFHeueoN/OhKOLbk0rzJDhtluiRa1EwpjktdYvbABi/UMKyM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787716446; c=relaxed/simple; bh=Eo/jSTkhSXYGsAXzzJb97akxKG79oMYaZwIRXS+sp3Y=; h=To:From:Subject:Date:Cc:Message-Id:Content-Type:Mime-Version: References:In-Reply-To; b=XdnvbQOudB9OsPD5xHr/ji/uPOWtAcvjiMmBNIdZpcn6EAu23hOV2pTkI7sBPOOk9qz2MeF0ok6K5dbN77UuKt7nimlQYQdqwp9UQotbICBQpjXPMztIoUERKkk+VIetyMLIIjMVdbJPQ+pYP08By76Atsvmph8neL0eQBTG2Cs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=UXCRWmCI; arc=none smtp.client-ip=209.127.230.113 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="UXCRWmCI" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1787716434; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=tYTS7ob5V3gZ1fuo9ohaWTruH7XTJOLasgUxqkVxVJg=; b=UXCRWmCI8SvD63Iyvjjt9TxvO6KUH/a3yxoLt5p45K8rQp107LUGRAoZXtpO+sR62/O9tz 6A3Zz+7rcAD6ohbHNWrRm/gli24VroH3aP4+hYK4Ukfi1jdExLrc/iHRcULTL5xIZZMmhJ PtzyKK65/iqRVq+7V4WNBLsXvVciyrQxkILJZm4n5vEroh25EC7t+xEacoUez3gxcZWJv3 jfWCNqQWUO3+4VzZaSfmuXjJTVac34qQK5GP7WuC8CZ/xZE/Ql8GUrhP/ZZ83qY2ZFQrLa cx2BGyWnxZsc5h5LdJaV5LjAWeIwDaIPLd1XwLNyG91yz6et0yhAXylp/3cXTA== To: From: "Rui Qi" Subject: [PATCH v2 3/4] RAS/AMD/FMPM: Make max_nr_entries read-only Date: Wed, 26 Aug 2026 11:53:13 +0800 X-Original-From: Rui Qi Content-Transfer-Encoding: quoted-printable Cc: , , , , "Rui Qi" Message-Id: <20260826035314.1536340-4-qirui.001@bytedance.com> X-Lms-Return-Path: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260821094748.145394-1-qirui.001@bytedance.com> <20260826035314.1536340-1-qirui.001@bytedance.com> In-Reply-To: <20260826035314.1536340-1-qirui.001@bytedance.com> X-Mailer: git-send-email 2.20.1 Content-Type: text/plain; charset="utf-8" max_nr_entries is used during module init to calculate max_rec_len. That length determines the size of each allocated FRU record and is not resized after init. Leaving the parameter writable lets a later sysfs write raise the runtime limit used by update_fru_record(), allowing entries beyond the allocated flexible array to be written. Expose the parameter as read-only so it can still be set at module load time, but cannot diverge from the allocation size afterwards. Fixes: 6f15e617cc99 ("RAS: Introduce a FRU memory poison manager") Signed-off-by: Rui Qi Reviewed-by: Yazen Ghannam --- drivers/ras/amd/fmpm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/ras/amd/fmpm.c b/drivers/ras/amd/fmpm.c index e3f7bd053479..c13db1f743e5 100644 --- a/drivers/ras/amd/fmpm.c +++ b/drivers/ras/amd/fmpm.c @@ -138,7 +138,7 @@ static struct dentry *fmpm_dfs_entries; * No input or '0' will default to FMPM_DEFAULT_MAX_NR_ENTRIES. */ static u8 max_nr_entries; -module_param(max_nr_entries, byte, 0644); +module_param(max_nr_entries, byte, 0444); MODULE_PARM_DESC(max_nr_entries, "Maximum number of memory poison descriptor entries per FRU"); =20 --=20 2.20.1 From nobody Mon Sep 28 05:45:46 2026 Received: from va-1-114.ptr.blmpb.com (va-1-114.ptr.blmpb.com [209.127.230.114]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EF5882C3757 for ; Wed, 26 Aug 2026 03:54:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.114 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787716450; cv=none; b=lXVtogrVjW4NwmZoEfvxvq2ZxEupI9Sq4NIdPDPBMKlJ6eN0/RGUewCdwLpzJcRvofiJM1xeMfr4aao4lOR1Epu0VLxLGgUtOJxFpjH9n3+2cXbWUos/hlToQ6/970ze6ULctxRnR+dkugFb0CRfu/KgDxoTmcJfMB+G067CzTM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787716450; c=relaxed/simple; bh=eyy2Z87w8WUkDbNBqXBx4Fib2Kzk0jBHrPjpnjJ2m7I=; h=From:Subject:Date:Message-Id:Cc:In-Reply-To:Content-Type: Mime-Version:To:References; b=MRqJsJyz8yeYw5h52PEXknGWm4VXtFAqlgT7oRMJZkaU0iGjrKdxPbHUk9yoFazO5kekzzZ/ZnyrK1k9k+I9i5ikvh54SLEgLs63cpIP7KT+BUkyqRmzwfHCElNyHmO1KQugpWCJpxhC4dNn/vA10J1XqJYu/UGzoOYQi7xAviM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=Wpipw/Ae; arc=none smtp.client-ip=209.127.230.114 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="Wpipw/Ae" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1787716443; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=HdqJcOoT3zgDkOVHdBRoCSbC2PLCueacyrx6yLLDzsM=; b=Wpipw/Aevxrxij2TKgRm9uh2Q5ANsNLJIbpBxbNqCFBs6kOfAf3t4/1GyGITwSgFJnG7dx 11qyEI75Kwh3GHE3aQgk4T1+ypEyrvI0Q1qfN5JpvTUvkddDcRROmy422zk08RZaR0HM9b uoRgnPLaU1fD1/V+CZwrS184TOeVBle87/NLlqRO4B7s2RgJh2e7npChGQbrcZYAGqbQkB /WaZRjJGUYb+yOJ088hYWmuuvyyQJb+YBKt7Jo6Ovl5VGmMPlRjz6E2RLVOBmxmiG/s13q D+N1sD0awI7G7ziDIrxrkJu9tXZb7jekbN8huHKPCMJy82sm7F0sW/0XOIVdEA== From: "Rui Qi" Subject: [PATCH v2 4/4] RAS/AMD/FMPM: Fix spurious BUG when ERST record enumeration fails Date: Wed, 26 Aug 2026 11:53:14 +0800 Message-Id: <20260826035314.1536340-5-qirui.001@bytedance.com> X-Lms-Return-Path: Cc: , , , , "Rui Qi" X-Mailer: git-send-email 2.20.1 In-Reply-To: <20260826035314.1536340-1-qirui.001@bytedance.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable To: References: <20260821094748.145394-1-qirui.001@bytedance.com> <20260826035314.1536340-1-qirui.001@bytedance.com> X-Original-From: Rui Qi Content-Type: text/plain; charset="utf-8" When erst_get_record_id_begin() returns an error, get_saved_records() jumps to the out_end label which unconditionally calls erst_get_record_id_end(). This is wrong because: - If erst_disable is true, begin() returns -ENODEV without incrementing the refcount. Then end() hits BUG_ON(erst_disable) and panics. - If mutex_lock_interruptible() is interrupted, begin() returns -EINTR without incrementing the refcount. Then end() decrements refcount below zero, hitting BUG_ON(refcount < 0). The comment in erst_get_record_id_end() warns that it should not be called when erst_disable is true, so callers must not invoke it after begin() fails. Fix by jumping to the out label when begin() fails, skipping the erst_get_record_id_end() call. This is safe because kfree() handles NULL pointers. Fixes: 6f15e617cc99 ("RAS: Introduce a FRU memory poison manager") Signed-off-by: Rui Qi --- drivers/ras/amd/fmpm.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/ras/amd/fmpm.c b/drivers/ras/amd/fmpm.c index c13db1f743e5..48a437042953 100644 --- a/drivers/ras/amd/fmpm.c +++ b/drivers/ras/amd/fmpm.c @@ -673,7 +673,7 @@ static int get_saved_records(void) =20 ret =3D erst_get_record_id_begin(&pos); if (ret < 0) - goto out_end; + goto out; =20 while (!erst_get_record_id_next(&pos, &record_id)) { if (record_id =3D=3D APEI_ERST_INVALID_RECORD_ID) @@ -714,8 +714,8 @@ static int get_saved_records(void) =20 out_end: erst_get_record_id_end(); - kfree(old); out: + kfree(old); return ret; } =20 --=20 2.20.1