From: Anton Vorontsov <cbouatmailru@gmail.com>
To: Roy Zang <tie-fei.zang@freescale.com>
Cc: B07421@freescale.com, dedekind1@gmail.com, B25806@freescale.com,
linuxppc-dev@ozlabs.org, linux-mtd@lists.infradead.org,
akpm@linux-foundation.org, dwmw2@infradead.org,
B11780@freescale.com
Subject: Re: [PATCH 2/3 v4] P4080/mtd: Only make elbc nand driver detect nand flash partitions
Date: Mon, 20 Sep 2010 17:19:07 +0400 [thread overview]
Message-ID: <20100920131907.GA2184@oksana.dev.rtsoft.ru> (raw)
In-Reply-To: <1284706869-12555-2-git-send-email-tie-fei.zang@freescale.com>
On Fri, Sep 17, 2010 at 03:01:08PM +0800, Roy Zang wrote:
[...]
> +static struct mutex fsl_elbc_nand_mutex;
> +
> +static int __devinit fsl_elbc_nand_probe(struct platform_device *dev)
> {
> - struct fsl_lbc_regs __iomem *lbc = ctrl->regs;
> + struct fsl_lbc_regs __iomem *lbc;
> struct fsl_elbc_mtd *priv;
> struct resource res;
> + struct fsl_elbc_fcm_ctrl *elbc_fcm_ctrl = NULL;
No need for = NULL.
[...]
> - ctrl->chips[bank] = priv;
> + mutex_init(&fsl_elbc_nand_mutex);
This may cause all sorts of misbehaviours, e.g.
A: mutex_init(foo)
A: mutex_lock(foo)
B: mutex_init(foo) <- destroyed "A"-context mutex.
A: mutex_unlock(foo) <- oops
Instead of dynamically initializing the mutex, just define it
with DEFINE_MUTEX() above.
(Btw, #include <linux/mutex.h> is needed.)
> +
> + mutex_lock(&fsl_elbc_nand_mutex);
[...]
> -static int __devinit fsl_elbc_ctrl_init(struct fsl_elbc_ctrl *ctrl)
> +static int fsl_elbc_nand_remove(struct platform_device *dev)
[...]
> + struct fsl_elbc_fcm_ctrl *elbc_fcm_ctrl = fsl_lbc_ctrl_dev->nand;
[...]
> + if (elbc_fcm_ctrl->chips[i])
> + fsl_elbc_chip_remove(elbc_fcm_ctrl->chips[i]);
[...]
> + fsl_lbc_ctrl_dev->nand = NULL;
> + kfree(elbc_fcm_ctrl);
Will cause NULL dereference and/or use-after-free for other
elbc nand instances. To avoid that, reference counting for
elbc_fcm_ctrl is required.
Thanks,
--
Anton Vorontsov
email: cbouatmailru@gmail.com
irc://irc.freenode.net/bd2
next prev parent reply other threads:[~2010-09-20 13:19 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-09-17 7:01 [PATCH 1/3 v4] P4080/eLBC: Make Freescale elbc interrupt common to elbc devices Roy Zang
2010-09-17 7:01 ` Roy Zang
2010-09-17 7:01 ` [PATCH 2/3 v4] P4080/mtd: Only make elbc nand driver detect nand flash partitions Roy Zang
2010-09-17 7:01 ` Roy Zang
2010-09-17 7:01 ` [PATCH 3/3 v4] P4080/mtd: Fix the freescale lbc issue with 36bit mode Roy Zang
2010-09-17 7:01 ` Roy Zang
2010-09-20 13:19 ` Anton Vorontsov [this message]
2010-10-02 12:36 ` [PATCH 2/3 v4] P4080/mtd: Only make elbc nand driver detect nand flash partitions Zang Roy-R61911
2010-10-02 12:36 ` Zang Roy-R61911
2010-10-04 15:38 ` Scott Wood
2010-10-04 15:38 ` Scott Wood
2010-10-14 3:09 ` Zang Roy-R61911
2010-10-14 3:09 ` Zang Roy-R61911
2010-10-14 16:01 ` Scott Wood
2010-10-14 16:01 ` Scott Wood
2010-10-15 2:15 ` Zang Roy-R61911
2010-10-15 2:15 ` Zang Roy-R61911
2010-10-14 4:14 ` Zang Roy-R61911
2010-10-14 4:14 ` Zang Roy-R61911
2010-09-20 15:37 ` [PATCH 1/3 v4] P4080/eLBC: Make Freescale elbc interrupt common to elbc devices Anton Vorontsov
2010-10-14 6:43 ` Zang Roy-R61911
2010-10-14 6:43 ` Zang Roy-R61911
2010-10-14 16:02 ` Scott Wood
2010-10-14 16:02 ` Scott Wood
2010-10-15 5:03 ` Zang Roy-R61911
2010-10-15 5:03 ` Zang Roy-R61911
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20100920131907.GA2184@oksana.dev.rtsoft.ru \
--to=cbouatmailru@gmail.com \
--cc=B07421@freescale.com \
--cc=B11780@freescale.com \
--cc=B25806@freescale.com \
--cc=akpm@linux-foundation.org \
--cc=dedekind1@gmail.com \
--cc=dwmw2@infradead.org \
--cc=linux-mtd@lists.infradead.org \
--cc=linuxppc-dev@ozlabs.org \
--cc=tie-fei.zang@freescale.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.