From nobody Wed Oct 8 11:02:04 2025 Received: from mail-pf1-f178.google.com (mail-pf1-f178.google.com [209.85.210.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D92BB22E3FA; Sun, 29 Jun 2025 14:41:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1751208079; cv=none; b=sd5kT3IYzDqo7KUh/6sCPBDM6NlPn6ZQ5wjwMugSL5aEYGe5OGw9CUmnREqgOTh2cN8UnRo+BOp6fhFLto177cY/iGToan97nQToANq61I0JSYS/igZb6Dj/gH2cQZMIU356vD1Gawr2ssO9upX1qdIL8QvR60XoIGQgzsVyso4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1751208079; c=relaxed/simple; bh=HOnI86sZjsx6xFz6HUkJ6Y/S0K2+grzeifCdZ0x8xRo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EbROaxv9QJbjbmSgLWRhcMB9dnP1ChWNJnj6KSid6+DH/eNdvwmSELlpEJjRhu1rvmdYT+ULFM4u/LKpU9LAwx8iCFY6nszfWjFWdr1mReaZKTq37vvpvBOt6wfH4vYeoG2/TsdMI5SJYHibAZNJvr2MjmsqHmc6I+wMFYqWYDU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=bPVypMaE; arc=none smtp.client-ip=209.85.210.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="bPVypMaE" Received: by mail-pf1-f178.google.com with SMTP id d2e1a72fcca58-7494999de5cso2895813b3a.3; Sun, 29 Jun 2025 07:41:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1751208077; x=1751812877; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=4ZlX6oH8dce3MqKqn1FEplwlovX0z97sZ7lCxjfOmHQ=; b=bPVypMaEdYxWFYzuIug4ntIRjthPRVPQuvoJJlk6YOmka9ECelyHZI3EQQro8ZoPz3 rk5elgxeCQnJtYf3n+10GlrSR+mdPVQhqyb6O9AxeJonARDeTgtUSGYcEPoXjNzoo6oD eok2soUdmYKm4IALmt9gu1APhffRrWj0JiQ5UqXxNGq5gfAelR7y4tYTOjHM4ZF7984P IZ+TecHeyviOAdDXe2fli6Jh7Zy9YnCCPcpLksEg0CRQ9i9gh0QxpeSOFO/b+LWpiTZn gjlRxWByLwCJiIBhDykXVkl/zge3VId+RzVFHp89kagjVf9S2B8bX/gyFeqrt0Q8EIXP sP1Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1751208077; x=1751812877; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=4ZlX6oH8dce3MqKqn1FEplwlovX0z97sZ7lCxjfOmHQ=; b=cIJJVA4zF68Uv0xeZRpA0mTwh0hHXMPl3lPSx88NxNCwi+lbeZNJYp6NI/XS620ypt E15bMTgMgTG45Kxkd/iC2I/SAOJRos8BUXrZrv5UR2vMNeHOPiFPNlratCAt8fW4Zc2I Jq2RWnSNL9xQze2aLjFrU5l7siE2Es0igTyYhBSDX+PjJNJw+E470+6rzbltpcHDcFwY zsI0AreOFrS3xE7Ev8hvhpIWSNPy2RU1Feh9yyx9PBFWLJ55+tKh8GaEW/VpKc14OQbX +Ruy3XMP2at2fekeBhgVoM1donjHmuYvDgR11eqyM5J08D7zZ/gd5/QdIIOtqB6WLcDY 2mhw== X-Forwarded-Encrypted: i=1; AJvYcCUX0dRsx+rJY2wbG+KWe3fDpO/BrRs4qRv7dI754nRvwlXlDNX71gUjYK69y3jtfw+ZuNuNrU8OpcL3vg==@vger.kernel.org, AJvYcCUtF/h78aLsbylShL6xpj9pQKKgUZ4aKzEfz3+GVRtZOzKcLUg7eGtQdwspwUIB3ee9M4d7eXyTP3OlEMgQ@vger.kernel.org X-Gm-Message-State: AOJu0YwrKc2M3/qh6uH5LoMjnRak/prBAiQlfDYFnWsyOb8RfCC7bs2W wqnnagzUI2VgObHTPv/rxYChxnkZIEM6LPPevDOFaEwX5aknLqMYRt2J X-Gm-Gg: ASbGncvjPRjzzZ+3W/fkTnZIiOpoIWX0SfPuwM8KJzwudoxKjZ97b/mBN4B/6CKBL9a Wi0AFI8iesihoW1PcvX+WozkRHnk8uwaRjHRAbRix4Y38fwlxkFgMMuzUXqSqqfgjcdoQM2Hh2J hcGYoF8FYCn+N0loFkQBMv1ohBl2K1dv6F+AFNqV9Gsixc9BBMANOABjTIfycC4EWxdy4i0koS/ T8+H7Au9QhBInbEdTAkEyvcT7k75I3WXtLXUQp9zZpc9H4gskFSU7PjELt7hrV7Fpjb1H1Cy4VS UsFIDaq3tHj8NxxOqCpLPcJWp5WDVZuv14w+UT7LvT7RYqZIqblgk0aYB+HyEz2JO3rnx+q0Oci sMoh7qfP95RAe X-Google-Smtp-Source: AGHT+IEdbEmJ+1xilLUoHHztIEeRjjOpIEv3s8aocZ+HWOglf6JfXuWncmoSPjHPoauzqRoD+CjaUA== X-Received: by 2002:a05:6a00:c90:b0:736:4e67:d631 with SMTP id d2e1a72fcca58-74af6fde138mr16238310b3a.23.1751208077090; Sun, 29 Jun 2025 07:41:17 -0700 (PDT) Received: from localhost.localdomain ([49.37.221.186]) by smtp.googlemail.com with ESMTPSA id d2e1a72fcca58-74af55c7e89sm7039127b3a.109.2025.06.29.07.41.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 29 Jun 2025 07:41:16 -0700 (PDT) From: Abdun Nihaal To: andy@kernel.org Cc: Abdun Nihaal , dan.carpenter@linaro.org, gregkh@linuxfoundation.org, lorenzo.stoakes@oracle.com, tzimmermann@suse.de, riyandhiman14@gmail.com, willy@infradead.org, notro@tronnes.org, thomas.petazzoni@free-electrons.com, dri-devel@lists.freedesktop.org, linux-fbdev@vger.kernel.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org Subject: [PATCH v3 1/2] staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() Date: Sun, 29 Jun 2025 20:10:10 +0530 Message-ID: X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" After commit 56c134f7f1b5 ("fbdev: Track deferred-I/O pages in pageref struct"), fb_deferred_io_init() allocates memory for info->pagerefs as well as return an error code on failure. However the error code is ignored here and the memory allocated could leak because of not calling fb_deferred_io_cleanup() on the error path. Fix them by adding the cleanup function on the error path, and handling the error code returned by fb_deferred_io_init(). Fixes: 56c134f7f1b5 ("fbdev: Track deferred-I/O pages in pageref struct") Signed-off-by: Abdun Nihaal Reviewed-by: Andy Shevchenko Reviewed-by: Dan Carpenter --- v2->v3: No change v1->v2: - Handle the error code returned by fb_deferred_io_init correctly - Update Fixes tag to point to the commit that introduced the memory allocation which leads to the leak. drivers/staging/fbtft/fbtft-core.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/staging/fbtft/fbtft-core.c b/drivers/staging/fbtft/fbt= ft-core.c index da9c64152a60..8538b6bab6a5 100644 --- a/drivers/staging/fbtft/fbtft-core.c +++ b/drivers/staging/fbtft/fbtft-core.c @@ -612,7 +612,8 @@ struct fb_info *fbtft_framebuffer_alloc(struct fbtft_di= splay *display, info->fix.line_length =3D width * bpp / 8; info->fix.accel =3D FB_ACCEL_NONE; info->fix.smem_len =3D vmem_size; - fb_deferred_io_init(info); + if (fb_deferred_io_init(info)) + goto release_framebuf; =20 info->var.rotate =3D pdata->rotate; info->var.xres =3D width; @@ -652,7 +653,7 @@ struct fb_info *fbtft_framebuffer_alloc(struct fbtft_di= splay *display, if (par->gamma.curves && gamma) { if (fbtft_gamma_parse_str(par, par->gamma.curves, gamma, strlen(gamma))) - goto release_framebuf; + goto cleanup_deferred; } =20 /* Transmit buffer */ @@ -669,7 +670,7 @@ struct fb_info *fbtft_framebuffer_alloc(struct fbtft_di= splay *display, if (txbuflen > 0) { txbuf =3D devm_kzalloc(par->info->device, txbuflen, GFP_KERNEL); if (!txbuf) - goto release_framebuf; + goto cleanup_deferred; par->txbuf.buf =3D txbuf; par->txbuf.len =3D txbuflen; } @@ -691,6 +692,8 @@ struct fb_info *fbtft_framebuffer_alloc(struct fbtft_di= splay *display, =20 return info; =20 +cleanup_deferred: + fb_deferred_io_cleanup(info); release_framebuf: framebuffer_release(info); =20 --=20 2.43.0 From nobody Wed Oct 8 11:02:04 2025 Received: from mail-pf1-f182.google.com (mail-pf1-f182.google.com [209.85.210.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 12AA323183B; Sun, 29 Jun 2025 14:41:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1751208087; cv=none; b=bjBBMW9t4eyZGNod3wIjIDV0EQsfpJaykOo/GbNNRfCaZpasXqxm1GUpy3usdvWlTwqOfYcWk6OSObbeGMeQxUqya4vQCZj/XICDwyPEFqJKejb7/iRMb9lB3V7wX6AlTfMQarB0mCQyngmOKo4md8cPSOHZwZ3V+yB2UVT5O0s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1751208087; c=relaxed/simple; bh=4iptySoXMXJs2UzWlhwIPyIT0WKR/AuX6Cj72Rs0gYU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=OXlPI2JHWmNvxMFM49VXF5KxCrIz6Hq7sYyVYvXS77CWFytkUIPAlzOwgDYTxFVWnxI5UhuMXx1mRHlfA2XzLl00mdDUJ9qXrDNPIUHrnQ17bw6CyZxdEiW1vVwn4vf5Q/9ohPMaN1AbJ1hfrBn4GQrARCfk7sP7RoMVhVdr2QQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=cKuEWC4D; arc=none smtp.client-ip=209.85.210.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="cKuEWC4D" Received: by mail-pf1-f182.google.com with SMTP id d2e1a72fcca58-747c2cc3419so3604712b3a.2; Sun, 29 Jun 2025 07:41:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1751208085; x=1751812885; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=AkH6WZ47tB33hOq1ktfgw4nXcDuqU5IvVV0uN0/lGcY=; b=cKuEWC4DJxs19wI2H3cULpmVMG8N4950MJRhuXBPFDi1dIGwWdbCJByAcMUq09E7YG REN0tcRsecCGI0wRsme/fxn3TmLrRL3QCPuCuKkFyTnP/FkCHJKxtQbQnqmJzpD7SVi6 f/PJ+h6ILauHcaxu0pIdHQbNXPWKdFlrdzNLeBWkbgTvkbQR4S4FoXj/DA8rdzoSzig7 AEPve/tm3sw3/SO/wOlc91cgRAQs7tM5o58Edeyz2n2pKcMHC1Oglx8Lg+zROB7b+riU AEDjZXBcGQdJCFWlgNAivcHvvQmv/nvVoLu+Pnf5p+V75JgaipoVlq8xkMBX3obzHhfE 6pkw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1751208085; x=1751812885; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=AkH6WZ47tB33hOq1ktfgw4nXcDuqU5IvVV0uN0/lGcY=; b=dJCIC54nohxQ9ZMmhlvskY5BKUtkozhvN3j6tVDhKrTucIFp6pc/GG6GceE2kpd91e cOCIe430UZ3Zl5n/dAkmnSm0VSJQhyWouhNmmyjOR1MUH4s3eTfgHrZayFeYejCGV90b QBmoyEnBSR8lDofPs8oHY6wnhEB+CgMVqnszWHewTbrCecem/3LrXvs00AcxmFoAbAw6 bPN0/ogZV0fOhcTh62PE+4xzdsMeBf48gWJQ/TCyzq32r7WcmAwpg41wY9rCy5Idpy3h JbyPSUxejpUPFdCmiWkeTZt78XUl/Cd07uS0Zm6n7gLwIyAjAg1eGDDsUFHKOJraYnMk kU/A== X-Forwarded-Encrypted: i=1; AJvYcCVskIql5ueI9e6M9NHG0tLZhkXYkbhsujVcOlbky4lPT+AdzHFEzvjAmnvl2B0BsAWuT0WA0YmfjGwdFmVC@vger.kernel.org, AJvYcCXeY482NSkrYRyg+CYjwukXNCQ70RPRcIcYSmJ2AbYgWEVfw5ndovj4wB4M/9rgnmzDld/tJiLXnZzfZg==@vger.kernel.org X-Gm-Message-State: AOJu0YxtNs7xNLraRH2tx7Qia0iF4Kh9aqtx4Sn1ZgZPfTV/gr1Q1h/O vXtnldzQlmWaVvg/oK6oloJvds+eT7Al6zvwCKYvtLASOs9gKIvsfIgo X-Gm-Gg: ASbGncvxs8oIKd1z/qtsm9rlQ1mOjIP8YO8zPh37Uvdn6y+NL8g86mDNCTnKLWz5iVi DgoBWjDsxGSGmiz1n8dIzISJnyCCtDd/vO2HORSQeBsBMVxmONO1M3j3fnpvp8kqQ676sdfNHtz lOt9uWQOMsQkLU/+qvxRBx5N6KT/U+sX4OI4lUcBU7+F7fXUIuTGK8K2AgqpnilSMIQbsW/PDLV 0R6CQLbsNsokH8dbs67HFRlVk7ZqAdQjLg9T9sfsUIBNpB1mqx/ezOMwuhESSxPCUG7OaAlrGqe /fG+z5+FXsTsXbKAxjJgXBlmzFBWlBrvzwq2hB2w8YJjcNmnbNHXpBP6QMGPLEuUZSkCMocI+Ap Skw== X-Google-Smtp-Source: AGHT+IFBiKmBx9yH5kYGSYjeMY9rQSEBpTMve8iNeUO9mG9D8vqHt/VBUqvbXcqaLSd2ovKMv+M48A== X-Received: by 2002:a05:6a00:2d07:b0:736:8c0f:7758 with SMTP id d2e1a72fcca58-74af6e6659bmr12804699b3a.10.1751208085209; Sun, 29 Jun 2025 07:41:25 -0700 (PDT) Received: from localhost.localdomain ([49.37.221.186]) by smtp.googlemail.com with ESMTPSA id d2e1a72fcca58-74af55c7e89sm7039127b3a.109.2025.06.29.07.41.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 29 Jun 2025 07:41:24 -0700 (PDT) From: Abdun Nihaal To: andy@kernel.org Cc: Abdun Nihaal , dan.carpenter@linaro.org, gregkh@linuxfoundation.org, lorenzo.stoakes@oracle.com, tzimmermann@suse.de, riyandhiman14@gmail.com, willy@infradead.org, notro@tronnes.org, thomas.petazzoni@free-electrons.com, dri-devel@lists.freedesktop.org, linux-fbdev@vger.kernel.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org, Andy Shevchenko Subject: [PATCH v3 2/2] staging: fbtft: cleanup error handling in fbtft_framebuffer_alloc() Date: Sun, 29 Jun 2025 20:10:11 +0530 Message-ID: <4e062d040806dc29d6124ac0309e741c63f13ac0.1751207100.git.abdun.nihaal@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The error handling in fbtft_framebuffer_alloc() mixes managed allocation and plain allocation, and performs error handling in an order different from the order in fbtft_framebuffer_release(). Fix them by moving vmem allocation closer to where it is used, and using plain kzalloc() for txbuf allocation. Suggested-by: Andy Shevchenko Suggested-by: Dan Carpenter Signed-off-by: Abdun Nihaal Reviewed-by: Andy Shevchenko Reviewed-by: Dan Carpenter --- v2->v3:=20 - Remove the if check before kfree of txbuf.buf, because it is zero initialized on allocation, and kfree is NULL aware. Newly added in v2 drivers/staging/fbtft/fbtft-core.c | 31 +++++++++++++++--------------- 1 file changed, 16 insertions(+), 15 deletions(-) diff --git a/drivers/staging/fbtft/fbtft-core.c b/drivers/staging/fbtft/fbt= ft-core.c index 8538b6bab6a5..9e7b84071174 100644 --- a/drivers/staging/fbtft/fbtft-core.c +++ b/drivers/staging/fbtft/fbtft-core.c @@ -568,18 +568,13 @@ struct fb_info *fbtft_framebuffer_alloc(struct fbtft_= display *display, height =3D display->height; } =20 - vmem_size =3D display->width * display->height * bpp / 8; - vmem =3D vzalloc(vmem_size); - if (!vmem) - goto alloc_fail; - fbdefio =3D devm_kzalloc(dev, sizeof(struct fb_deferred_io), GFP_KERNEL); if (!fbdefio) - goto alloc_fail; + return NULL; =20 buf =3D devm_kzalloc(dev, 128, GFP_KERNEL); if (!buf) - goto alloc_fail; + return NULL; =20 if (display->gamma_num && display->gamma_len) { gamma_curves =3D devm_kcalloc(dev, @@ -588,12 +583,17 @@ struct fb_info *fbtft_framebuffer_alloc(struct fbtft_= display *display, sizeof(gamma_curves[0]), GFP_KERNEL); if (!gamma_curves) - goto alloc_fail; + return NULL; } =20 info =3D framebuffer_alloc(sizeof(struct fbtft_par), dev); if (!info) - goto alloc_fail; + return NULL; + + vmem_size =3D display->width * display->height * bpp / 8; + vmem =3D vzalloc(vmem_size); + if (!vmem) + goto release_framebuf; =20 info->screen_buffer =3D vmem; info->fbops =3D &fbtft_ops; @@ -613,7 +613,7 @@ struct fb_info *fbtft_framebuffer_alloc(struct fbtft_di= splay *display, info->fix.accel =3D FB_ACCEL_NONE; info->fix.smem_len =3D vmem_size; if (fb_deferred_io_init(info)) - goto release_framebuf; + goto release_screen_buffer; =20 info->var.rotate =3D pdata->rotate; info->var.xres =3D width; @@ -668,7 +668,7 @@ struct fb_info *fbtft_framebuffer_alloc(struct fbtft_di= splay *display, #endif =20 if (txbuflen > 0) { - txbuf =3D devm_kzalloc(par->info->device, txbuflen, GFP_KERNEL); + txbuf =3D kzalloc(txbuflen, GFP_KERNEL); if (!txbuf) goto cleanup_deferred; par->txbuf.buf =3D txbuf; @@ -694,12 +694,10 @@ struct fb_info *fbtft_framebuffer_alloc(struct fbtft_= display *display, =20 cleanup_deferred: fb_deferred_io_cleanup(info); +release_screen_buffer: + vfree(info->screen_buffer); release_framebuf: framebuffer_release(info); - -alloc_fail: - vfree(vmem); - return NULL; } EXPORT_SYMBOL(fbtft_framebuffer_alloc); @@ -712,6 +710,9 @@ EXPORT_SYMBOL(fbtft_framebuffer_alloc); */ void fbtft_framebuffer_release(struct fb_info *info) { + struct fbtft_par *par =3D info->par; + + kfree(par->txbuf.buf); fb_deferred_io_cleanup(info); vfree(info->screen_buffer); framebuffer_release(info); --=20 2.43.0