From nobody Sat Sep 26 04:30:04 2026 Received: from mail-ej1-f72.google.com (mail-ej1-f72.google.com [209.85.218.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 29A0850C282 for ; Fri, 4 Sep 2026 17:16:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.72 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542178; cv=none; b=g90drKr6qrEA7KpTOPKV3GVnrt9HjOzioGstAcHAMKDtkyiD8s8idJq5zgKr7JJRzVtqOWFUYumAIrZksJ2XIirLreEhv3huxuOEQWhqucwlHbyaFGFtGLe35DDLmK8rkq5GhgpDwdvEi3gTV1+fNBlkl6Xpi7snljBGx9xkUqU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542178; c=relaxed/simple; bh=FbkHPsmiA5zHnxxsfR1WWOP8m5F0e1gDkF8K+pc1He4=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=nvTk+P1WbvXCuqErQDGWWUy6wl0djtAN4paIwkFLHmnlwh3yIjW1/02cFzEcTPIsdcG/QYCBilktspp//L5knIJNAGQA7pPiHt+UnFQAC7LTAuRDpRLTqZ1thocklbiaVig0xQ9eqpOKnN6ttlU+57gxJLAtvF04pDVcb1eNAlg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tarunsahu.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=CAVtU12T; arc=none smtp.client-ip=209.85.218.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tarunsahu.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="CAVtU12T" Received: by mail-ej1-f72.google.com with SMTP id a640c23a62f3a-c2580a59d0dso110570266b.0 for ; Fri, 04 Sep 2026 10:16:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788542174; x=1789146974; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=lHu65GRGtE9tAA3U30k5Ff4J4ZEkOWgVLpTedANrfZQ=; b=CAVtU12Tdrkbj1KCzZDFoaEELIcVKtZoa/Yds2vbG2QTuElOPeahUQ/HkVf9UDmaLW VrRHZNcz6cz+wN0ETyRwbn2c/S2YHMen8qo9CoSb8QZU0GudIWS0Bpe35kaPbjydJDbW HYPnBayzI2soAhAMc0Kqo3rCORXa7KiI+0z8n90f9MwBv4yaRQyTZlpHWdUSMjDWM7wQ XRYA7sH73Oe0knAxF2ZkVMZ0kvakQMpp2RCkUCAzjSqQAROwK8bmEITi/JHwrywkCtru mRfJR+iC60KtjU+Mcu0XQpEdJYr70d6SQdiR2T27Av4cCodp+aT1x20ejc0Hp5KRVOq4 V3ew== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788542174; x=1789146974; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=lHu65GRGtE9tAA3U30k5Ff4J4ZEkOWgVLpTedANrfZQ=; b=nMiO2ttJSjzHOG1h/wL/bTAEQ/xcYAQfFp/hHqKZ9ZCaGFN/6dMetU3/W2oOkwGYGp AxHtKuIBU8zUTMqJRRYjgIWd/gzO33KBB7dIVMll+QeSOylqjIwxqgIjoYeM2Kz51eYc t2zn0wKwMke8FNbWtM9PNfcrDJVaokjCTR7/7zRTXEhHwPHDELbPWQHILmM9ioTUfXWI R10Q30CwGUcMjanDeiJiVoCXtxisCu0xMeTk3D1I1KVEbIXG9YE68C3H6WanNaXxMWZk JeHkk3KO5EISPJkbrD0IcIG8qVpbMWJ3RxvFvJhurJEjNQjLGh6liSAqi3RWw1vAO0le ym4g== X-Forwarded-Encrypted: i=1; AKwUvBwpWqgv25k3EV7qkkUSRmo7EN0SiBrFMD0QU4TTTA0Fkk8nDXHnkhrbzveB0fsnb8UJu+tuKBOsi5I2YtU=@vger.kernel.org X-Gm-Message-State: AFuF++l2O57eBDnG3woeCAjN5IuB1V5AASQPyqk41SRm86ubgOFo5nl+ JIdO4tEua+N8c7RgTA2cbyILwFbxSwrpjvPPjKp03yU7EbdIoVbZqqcgfcIwTeHWYvbLyUvaEo4 jNr0am9vCKiXb/kzdFA== X-Received: from ejczw3-n1.prod.google.com ([2002:a17:907:e003:10b0:c25:d60:eff0]) (user=tarunsahu job=prod-delivery.src-stubby-dispatcher) by 2002:a17:907:c16:b0:c1f:e9d9:64d4 with SMTP id a640c23a62f3a-c260c9cb978mr352987066b.11.1788542173879; Fri, 04 Sep 2026 10:16:13 -0700 (PDT) Date: Fri, 4 Sep 2026 17:16:07 +0000 In-Reply-To: <20260904171610.3342398-1-tarunsahu@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260904171610.3342398-1-tarunsahu@google.com> X-Mailer: git-send-email 2.55.0.979.g7e5102b832-goog Message-ID: <20260904171610.3342398-2-tarunsahu@google.com> Subject: [PATCH v4 1/3] ARM: locomo: Fix device reference leak on registration failure From: Tarun Sahu To: Russell King , Geoff Levand , Masakazu Mokuno , "Christophe Leroy (CS GROUP)" , Madhavan Srinivasan , Michael Ellerman , Paul Mackerras , helgaas@kernel.org, Nicholas Piggin , sourabhjain@linux.ibm.com Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, Tarun Sahu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" As per device_register() kernel-doc, calling kfree() directly on error bypasses reference counting and skips the device release callback, leaking the reference. Even in case of device_register() failure, Calling the put_device is advised. Fix this by calling put_device() on device_registration failure instead of kfree(). Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Reviewed-by: Sourabh Jain Signed-off-by: Tarun Sahu --- arch/arm/common/locomo.c | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/arch/arm/common/locomo.c b/arch/arm/common/locomo.c index 55e360452828..0f6689d343b0 100644 --- a/arch/arm/common/locomo.c +++ b/arch/arm/common/locomo.c @@ -223,10 +223,8 @@ locomo_init_one_child(struct locomo *lchip, struct loc= omo_dev_info *info) int ret; =20 dev =3D kzalloc_obj(struct locomo_dev); - if (!dev) { - ret =3D -ENOMEM; - goto out; - } + if (!dev) + return -ENOMEM; =20 /* * If the parent device has a DMA mask associated with it, @@ -255,10 +253,11 @@ locomo_init_one_child(struct locomo *lchip, struct lo= como_dev_info *info) =20 ret =3D device_register(&dev->dev); if (ret) { - out: - kfree(dev); + put_device(&dev->dev); + return ret; } - return ret; + + return 0; } =20 #ifdef CONFIG_PM --=20 2.55.0.979.g7e5102b832-goog From nobody Sat Sep 26 04:30:04 2026 Received: from mail-ed1-f70.google.com (mail-ed1-f70.google.com [209.85.208.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9E85E511E7F for ; Fri, 4 Sep 2026 17:16:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542180; cv=none; b=t+U+tIAJ+Y2whfYDTQx6qhoKt9Q8kuPQWux0i+gc0QBVDwr9q0kR1RyfErzhyMF6o+o5nUjkdqvAZZSmvjzZck/6b1ddmAPDVKp+c+8nmCj90FrwNYF9IWgumgOIWQECR3tqJC5mqlj+BIoThEvWgI+B51u0r5Xngu6oVsv7FPs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542180; c=relaxed/simple; bh=G+GFIjnCZ3YyuiaSWyY0S/quGmILiAjsmkVR5HblglM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=prBbYPcY4gpdC5/R94SNgyqnCfWElzWs71SU00yQfEJEc+NcOJnC+wCXuTPw0GP7bxl2kAcny9Qja32anpyyQl78j6tEuQMIJqChroN0cESBIIWsEUwvljSSvZh9zp8QXJlAL09QhY4O3gRmYRxZQzw8Oko+NBgbSB6vTY8j4B0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tarunsahu.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=RFf5VU8r; arc=none smtp.client-ip=209.85.208.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tarunsahu.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="RFf5VU8r" Received: by mail-ed1-f70.google.com with SMTP id 4fb4d7f45d1cf-6a5d46edd1eso1285282a12.1 for ; Fri, 04 Sep 2026 10:16:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788542175; x=1789146975; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=9g3ixuSdmQCpOEGBBcnV25oj0cDJNzVy8Tk+QtmySWs=; b=RFf5VU8rvFCBmxsEt3H4FrmL6qsHiOj5t2IeDhLiLKgsez9wdHgNQlRAc9EQqInwCM 1U35WwB571Q+M3S52yddUPJmNkNPJi51VCzpL+ISNSJWi6hglutQ728qhoP6CqjfSRj/ 3uYwhZnjkh5eF5WvUaxnIBNRk4e+SP8PdEagjxCEKu2AZAJ47FMcG7LCKnCHNN+WX4nn 3rYHSAOdd4JE6QvqCz8GTtt7KpUGQTsIEmzyd2A6pOospuqnNwexrR5y2zEAiMhogQQ0 e+ETQ3hbLBXU6d//RlNdap/3FoPugbqa20Wzf2Qh8vogpl2O8AGjrbYAMv0vSlVMUJ+/ sDSw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788542175; x=1789146975; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9g3ixuSdmQCpOEGBBcnV25oj0cDJNzVy8Tk+QtmySWs=; b=aQM5pL4RWz6jAQiRuAh7xLyrYd6TGK1fk789He78FupK+yhZrtrtVRRSBkgirxS+eA U+JwlYk0eXRH3Ax8DogLIb5ppNIVP6Ysa5ryMUZBOKU/WVgopB7WXj5hQe6dtcBsaPv8 WF3wXTS1knyFvo+fr7M2zfrCgfwHBQ8eSGOUyOn5uGXec5oMtUS1Lfc02rqwlGdEfUUm 0jLWzoWV7T9ObZOkW1ipviDvFs9xaTkNL0eeEarrmpGVm62EPp7hx0CCjeeDwSm2ayxM KFTII4kPBKIMNqzgo8/yMdqQv3vO/N4kMKTLNBiGmZu4ZAOPy70Dw+anHvQ6EMyrtNFX EMfw== X-Forwarded-Encrypted: i=1; AKwUvBzmDMV6GQnC6zmzAfYq6ziM7AZAoV5PfgDiKgcfxLBzMq6KTeZDGEuZMjNFv1KtiaU41N7k5E4bEp5O9zM=@vger.kernel.org X-Gm-Message-State: AFuF++lTz4tOvW8GzKYg3uRhr1aKjcXCii2+AZd5gHdZYWOgDW2AWJbR oTezTUjR17MX+r90VE9wxfaCa3X1T2M5momrSECRiTWgxdBVY0pdvJ+TcfDXyVgPAspx2jDNGPo o9gzGzkJWvApqvd9/MQ== X-Received: from edgi4-n2.prod.google.com ([2002:a05:6402:a584:20b0:6a5:f01e:c622]) (user=tarunsahu job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6402:3203:b0:6a5:f9ab:bdfd with SMTP id 4fb4d7f45d1cf-6a7e8cb104fmr3745516a12.0.1788542175250; Fri, 04 Sep 2026 10:16:15 -0700 (PDT) Date: Fri, 4 Sep 2026 17:16:08 +0000 In-Reply-To: <20260904171610.3342398-1-tarunsahu@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260904171610.3342398-1-tarunsahu@google.com> X-Mailer: git-send-email 2.55.0.979.g7e5102b832-goog Message-ID: <20260904171610.3342398-3-tarunsahu@google.com> Subject: [PATCH v4 2/3] firmware: edd: Fix kobject reference leak on registration failure From: Tarun Sahu To: Russell King , Geoff Levand , Masakazu Mokuno , "Christophe Leroy (CS GROUP)" , Madhavan Srinivasan , Michael Ellerman , Paul Mackerras , helgaas@kernel.org, Nicholas Piggin , sourabhjain@linux.ibm.com Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, Tarun Sahu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Per kobject_init_and_add() kernel-doc, calling kfree() directly on error bypasses reference counting and skips the kobject's release callback, leaking the reference. Use kobject_put() instead of kfree() on registration failure to fix this. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Reviewed-by: Sourabh Jain Signed-off-by: Tarun Sahu --- drivers/firmware/edd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/firmware/edd.c b/drivers/firmware/edd.c index f980c5b56858..763e7b16d517 100644 --- a/drivers/firmware/edd.c +++ b/drivers/firmware/edd.c @@ -748,7 +748,7 @@ edd_init(void) =20 rc =3D edd_device_register(edev, i); if (rc) { - kfree(edev); + kobject_put(&edev->kobj); goto out; } edd_devices[i] =3D edev; --=20 2.55.0.979.g7e5102b832-goog From nobody Sat Sep 26 04:30:04 2026 Received: from mail-ed1-f70.google.com (mail-ed1-f70.google.com [209.85.208.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9D8D9511E84 for ; Fri, 4 Sep 2026 17:16:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542183; cv=none; b=ZSHw29zhnaRAxq6vdZpFL12qt8If2zTCQRfjLqxZCs2dL6zBV3H7usEFlsqWl+HuFtEvW6rDlonKbAzumGXr3CUpi7vT7XvWos3M/Tig+KMIv9eUqUYyKlAAX/tUqlCiDj8kZwQuEAIld6L+Ng33lRMOVjBVp9cSHI+pJZcTTl0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788542183; c=relaxed/simple; bh=a2UdRo64Nhr6RoZuxvwyT+i6GcExSXCf3YBAO8Exug4=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=D9Cf6WIGqCpMhWWnZ5Yc1zfcVQux8UiZcqb4m4CXjgZ6wY0ZtJ9l1b11qDKkslOCHUVejZtiyZ1hLRDQ/OYyuO4rYWIztDhD3K4mirJqNLWGmsMbxooftMO5kmRsu5nV0nssQnlQrKmUskaFLtT2EhUgZwZXY/aBky4PdeJN4dE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tarunsahu.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=FahOE8N3; arc=none smtp.client-ip=209.85.208.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tarunsahu.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="FahOE8N3" Received: by mail-ed1-f70.google.com with SMTP id 4fb4d7f45d1cf-6a64cb77b0aso1145739a12.3 for ; Fri, 04 Sep 2026 10:16:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788542177; x=1789146977; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=NikJEXjNYjtOdRdsXEH0yQrsx5J1yuBuYOZC90aY1Z4=; b=FahOE8N3j2eIwvE2xVSm9KF/mg3Tco0fEBPd+HJA/+AH3E2phBxUzGsKfN9fwhCJyq ZkwqW/PkFgociOsgzSQAAVBZ+ngW6R8gSIeLe7etmOlPDq8XLTB7hdJEYPwrgRw3yXR5 1zrWH5YCC+2yqtRTf14sPCmFOcFrcaL3qNoL5IlEyktlogV+V5iAUiiGJ92dlzICbzqU Po9qS31KBtTEDzrq4yNWnDN8aBbEUMZm8DLDbO6EjOfx+LxY79JkDCSnTlAtqS1TBMQ6 K3vk7EQ+Ao6MMP8z5ChBEwPaYcpKgu7oD0ZhgBfZUVStT04MScZ8zWV4zkBf7HAzXwMs +CWQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788542177; x=1789146977; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NikJEXjNYjtOdRdsXEH0yQrsx5J1yuBuYOZC90aY1Z4=; b=oHP0uWlUksd+c/Ivwa5mafXODE2vPR40BHdT3OAezrKjm1yhOYtGeANHhWpZPcPj4s FPKOfuAuZvUZAJsgZEwiDLh1MckC7J9tl/35B7+YtuKXFhtBLrip8L3Rr9smmz9IQ/Re xf4GuTfulnqjZRIXM9fxnarbyy4AnJn1BvtXny+ZRepw8eddff2g3nbGK3rGR+C7NVWa P+ea1MB3+ZR3nqpyHS5rqEczxDCrzqmOLRQ86hBcDb849iqksR67km+EP+Ux5SrnK/ti vX2pTH65c3ETDHfgUDu81ACfn0vSRDR0u04/vOB35jEz2htJPng/HptvMpkAtU4QQK1K iopg== X-Forwarded-Encrypted: i=1; AKwUvBwU43U6g3aQqC4/MxbhKUwi2HkDL3CWAW8ON53xkl19yyU1vhHkwmOrDqE5em9q+73ETikv3mynNZbUiZI=@vger.kernel.org X-Gm-Message-State: AFuF++nIw4EEuSm6GQI7T6t+65O9Lyo4JWjgn8pleP6iE/XUkNHPo2Wy YnTSAqhhuR+K81HUxt5+kX/zPd7BOuwAKbMSONDmulVwhBZOVZTOVSizu5u1n9fSEn1GRFOj8jo 4Q4gnMZ/nIAXjifLSxw== X-Received: from edfy24.prod.google.com ([2002:a05:6402:a3d8:b0:6a7:e348:5a70]) (user=tarunsahu job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6402:a256:20b0:6a7:ee54:f8a6 with SMTP id 4fb4d7f45d1cf-6a7ee55000fmr1421309a12.42.1788542176533; Fri, 04 Sep 2026 10:16:16 -0700 (PDT) Date: Fri, 4 Sep 2026 17:16:09 +0000 In-Reply-To: <20260904171610.3342398-1-tarunsahu@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260904171610.3342398-1-tarunsahu@google.com> X-Mailer: git-send-email 2.55.0.979.g7e5102b832-goog Message-ID: <20260904171610.3342398-4-tarunsahu@google.com> Subject: [PATCH v4 3/3] powerpc/ps3: use put_device() on device_register() failure in ps3_system_bus_device_register From: Tarun Sahu To: Russell King , Geoff Levand , Masakazu Mokuno , "Christophe Leroy (CS GROUP)" , Madhavan Srinivasan , Michael Ellerman , Paul Mackerras , helgaas@kernel.org, Nicholas Piggin , sourabhjain@linux.ibm.com Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, Tarun Sahu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" As per the kernel documentation of device_register() function, it is important to call put_device even if device_register returns an error. To follow this guidelines and properly release the resources after device_register() failure, call put_device() instead of kfree() Also there are in-function-defined struct layout which make struct device (core) to be child of layout-child's member (layout.dev.core). Also definition of struct layout is not unique across functions in the driver. To be able to free struct layout's dynamic allocation via put_device we need to make sure that the core's release function must call the free on parent of core and the parent must be at the location 0 of the struct layout which will inherently free struct layout. This is to not complicate the code and keep it as it currently implemented. To check the location of parent at 0 of struct layout, I have added BUILD_BUG_ON. Fixes: d4ad304841a9 ("powerpc/ps3: Fix memory leak in device init") Reviewed-by: Sourabh Jain Signed-off-by: Tarun Sahu --- arch/powerpc/platforms/ps3/device-init.c | 83 ++++++++++++++---------- arch/powerpc/platforms/ps3/system-bus.c | 2 + 2 files changed, 52 insertions(+), 33 deletions(-) diff --git a/arch/powerpc/platforms/ps3/device-init.c b/arch/powerpc/platfo= rms/ps3/device-init.c index 9109c218a060..8d0c77db1764 100644 --- a/arch/powerpc/platforms/ps3/device-init.c +++ b/arch/powerpc/platforms/ps3/device-init.c @@ -90,14 +90,12 @@ static int __init ps3_register_lpm_devices(void) if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_register; + return result; } =20 pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; =20 - -fail_register: fail_rights: fail_read_repo: kfree(dev); @@ -121,6 +119,12 @@ static int __init ps3_setup_gelic_device( struct ps3_dma_region d_region; } *p; =20 + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) !=3D 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); =20 BUG_ON(repo->bus_type !=3D PS3_BUS_TYPE_SB); @@ -164,13 +168,12 @@ static int __init ps3_setup_gelic_device( if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } =20 pr_debug(" <- %s:%d\n", __func__, __LINE__); return result; =20 -fail_device_register: fail_dma_init: fail_find_interrupt: kfree(p); @@ -192,6 +195,12 @@ static int __init ps3_setup_uhc_device( u64 bus_addr; u64 len; =20 + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) !=3D 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); =20 BUG_ON(repo->bus_type !=3D PS3_BUS_TYPE_SB); @@ -252,13 +261,12 @@ static int __init ps3_setup_uhc_device( if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } =20 pr_debug(" <- %s:%d\n", __func__, __LINE__); return result; =20 -fail_device_register: fail_mmio_init: fail_dma_init: fail_find_reg: @@ -291,6 +299,12 @@ static int __init ps3_setup_vuart_device(enum ps3_matc= h_id match_id, struct ps3_system_bus_device dev; } *p; =20 + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) !=3D 0); + pr_debug(" -> %s:%d: match_id %u, port %u\n", __func__, __LINE__, match_id, port_number); =20 @@ -308,15 +322,10 @@ static int __init ps3_setup_vuart_device(enum ps3_mat= ch_id match_id, if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; - -fail_device_register: - kfree(p); - pr_debug(" <- %s:%d fail\n", __func__, __LINE__); - return result; } =20 static int ps3_setup_storage_dev(const struct ps3_repository_device *repo, @@ -327,6 +336,12 @@ static int ps3_setup_storage_dev(const struct ps3_repo= sitory_device *repo, u64 port, blk_size, num_blocks; unsigned int num_regions, i; =20 + /* + * ps3_system_bus_release_device() calls kfree(&p->sbd). + * sbd must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct ps3_storage_device, sbd) !=3D 0); + pr_debug(" -> %s:%u: match_id %u\n", __func__, __LINE__, match_id); =20 result =3D ps3_repository_read_stor_dev_info(repo->bus_index, @@ -395,13 +410,12 @@ static int ps3_setup_storage_dev(const struct ps3_rep= ository_device *repo, if (result) { pr_debug("%s:%u ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } =20 pr_debug(" <- %s:%u\n", __func__, __LINE__); return 0; =20 -fail_device_register: fail_read_region: fail_find_interrupt: kfree(p); @@ -445,6 +459,12 @@ static int __init ps3_register_sound_devices(void) struct ps3_mmio_region m_region; } *p; =20 + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) !=3D 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); =20 p =3D kzalloc_obj(*p); @@ -461,15 +481,10 @@ static int __init ps3_register_sound_devices(void) if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; - -fail_device_register: - kfree(p); - pr_debug(" <- %s:%d failed\n", __func__, __LINE__); - return result; } =20 static int __init ps3_register_graphics_devices(void) @@ -479,6 +494,12 @@ static int __init ps3_register_graphics_devices(void) struct ps3_system_bus_device dev; } *p; =20 + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) !=3D 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); =20 p =3D kzalloc_obj(struct layout); @@ -495,16 +516,11 @@ static int __init ps3_register_graphics_devices(void) if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } =20 pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; - -fail_device_register: - kfree(p); - pr_debug(" <- %s:%d failed\n", __func__, __LINE__); - return result; } =20 static int __init ps3_register_ramdisk_device(void) @@ -514,6 +530,12 @@ static int __init ps3_register_ramdisk_device(void) struct ps3_system_bus_device dev; } *p; =20 + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) !=3D 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); =20 p =3D kzalloc_obj(struct layout); @@ -530,16 +552,11 @@ static int __init ps3_register_ramdisk_device(void) if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } =20 pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; - -fail_device_register: - kfree(p); - pr_debug(" <- %s:%d failed\n", __func__, __LINE__); - return result; } =20 /** diff --git a/arch/powerpc/platforms/ps3/system-bus.c b/arch/powerpc/platfor= ms/ps3/system-bus.c index 0537a678a32f..0918c74d3e19 100644 --- a/arch/powerpc/platforms/ps3/system-bus.c +++ b/arch/powerpc/platforms/ps3/system-bus.c @@ -774,6 +774,8 @@ int ps3_system_bus_device_register(struct ps3_system_bu= s_device *dev) pr_debug("%s:%d add %s\n", __func__, __LINE__, dev_name(&dev->core)); =20 result =3D device_register(&dev->core); + if (result) + put_device(&dev->core); return result; } =20 --=20 2.55.0.979.g7e5102b832-goog