From: kernel test robot <lkp@intel.com>
To: oe-kbuild@lists.linux.dev
Cc: lkp@intel.com, Dan Carpenter <error27@gmail.com>
Subject: Re: [PATCH] misc: hpilo: Fix use after free bug in ilo_remove due to race condition with ilo_open
Date: Sun, 30 Apr 2023 09:11:11 +0800 [thread overview]
Message-ID: <202304300909.ALHN6Vry-lkp@intel.com> (raw)
BCC: lkp@intel.com
CC: oe-kbuild-all@lists.linux.dev
In-Reply-To: <20230417165246.467723-1-zyytlz.wz@163.com>
References: <20230417165246.467723-1-zyytlz.wz@163.com>
TO: Zheng Wang <zyytlz.wz@163.com>
TO: matt.hsiao@hpe.com
CC: arnd@arndb.de
CC: gregkh@linuxfoundation.org
CC: linux-kernel@vger.kernel.org
CC: hackerzheng666@gmail.com
CC: 1395428693sheep@gmail.com
CC: alex000young@gmail.com
CC: Zheng Wang <zyytlz.wz@163.com>
Hi Zheng,
kernel test robot noticed the following build warnings:
[auto build test WARNING on char-misc/char-misc-testing]
[also build test WARNING on char-misc/char-misc-next char-misc/char-misc-linus soc/for-next linus/master v6.3 next-20230428]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Zheng-Wang/misc-hpilo-Fix-use-after-free-bug-in-ilo_remove-due-to-race-condition-with-ilo_open/20230418-005502
base: char-misc/char-misc-testing
patch link: https://lore.kernel.org/r/20230417165246.467723-1-zyytlz.wz%40163.com
patch subject: [PATCH] misc: hpilo: Fix use after free bug in ilo_remove due to race condition with ilo_open
:::::: branch date: 12 days ago
:::::: commit date: 12 days ago
config: i386-randconfig-m021 (https://download.01.org/0day-ci/archive/20230430/202304300909.ALHN6Vry-lkp@intel.com/config)
compiler: gcc-11 (Debian 11.3.0-12) 11.3.0
If you fix the issue, kindly add following tag where applicable
| Reported-by: kernel test robot <lkp@intel.com>
| Reported-by: Dan Carpenter <error27@gmail.com>
| Link: https://lore.kernel.org/r/202304300909.ALHN6Vry-lkp@intel.com/
smatch warnings:
drivers/misc/hpilo.c:755 ilo_delete() warn: can 'ilo_hw' even be NULL?
vim +/ilo_hw +755 drivers/misc/hpilo.c
13a22f45e6cb1e Zheng Wang 2023-04-18 748
13a22f45e6cb1e Zheng Wang 2023-04-18 749 static void ilo_delete(struct kref *kref)
13a22f45e6cb1e Zheng Wang 2023-04-18 750 {
13a22f45e6cb1e Zheng Wang 2023-04-18 751 int i, minor;
13a22f45e6cb1e Zheng Wang 2023-04-18 752 struct ilo_hwinfo *ilo_hw = container_of(kref, struct ilo_hwinfo, refcnt);
13a22f45e6cb1e Zheng Wang 2023-04-18 753 struct pci_dev *pdev = ilo_hw->ilo_dev;
89bcb05d9bbf8b David Altobelli 2008-07-02 754
ebf1b764aa5cb3 Mark Rusk 2012-11-06 @755 if (!ilo_hw)
ebf1b764aa5cb3 Mark Rusk 2012-11-06 756 return;
ebf1b764aa5cb3 Mark Rusk 2012-11-06 757
89bcb05d9bbf8b David Altobelli 2008-07-02 758 clear_device(ilo_hw);
89bcb05d9bbf8b David Altobelli 2008-07-02 759
89bcb05d9bbf8b David Altobelli 2008-07-02 760 minor = MINOR(ilo_hw->cdev.dev);
98dcd59dd063dd Camuso, Tony 2012-06-10 761 for (i = minor; i < minor + max_ccb; i++)
89bcb05d9bbf8b David Altobelli 2008-07-02 762 device_destroy(ilo_class, MKDEV(ilo_major, i));
89bcb05d9bbf8b David Altobelli 2008-07-02 763
89bcb05d9bbf8b David Altobelli 2008-07-02 764 cdev_del(&ilo_hw->cdev);
9f7048412163d8 David Altobelli 2009-08-17 765 ilo_disable_interrupts(ilo_hw);
9f7048412163d8 David Altobelli 2009-08-17 766 free_irq(pdev->irq, ilo_hw);
89bcb05d9bbf8b David Altobelli 2008-07-02 767 ilo_unmap_device(pdev, ilo_hw);
89bcb05d9bbf8b David Altobelli 2008-07-02 768 pci_release_regions(pdev);
bcdee04ea7ae04 Jiri Slaby 2012-09-13 769 /*
bcdee04ea7ae04 Jiri Slaby 2012-09-13 770 * pci_disable_device(pdev) used to be here. But this PCI device has
bcdee04ea7ae04 Jiri Slaby 2012-09-13 771 * two functions with interrupt lines connected to a single pin. The
bcdee04ea7ae04 Jiri Slaby 2012-09-13 772 * other one is a USB host controller. So when we disable the PIN here
bcdee04ea7ae04 Jiri Slaby 2012-09-13 773 * e.g. by rmmod hpilo, the controller stops working. It is because
bcdee04ea7ae04 Jiri Slaby 2012-09-13 774 * the interrupt link is disabled in ACPI since it is not refcounted
bcdee04ea7ae04 Jiri Slaby 2012-09-13 775 * yet. See acpi_pci_link_free_irq called from acpi_pci_irq_disable.
bcdee04ea7ae04 Jiri Slaby 2012-09-13 776 */
89bcb05d9bbf8b David Altobelli 2008-07-02 777 kfree(ilo_hw);
98dcd59dd063dd Camuso, Tony 2012-06-10 778 ilo_hwdev[(minor / max_ccb)] = 0;
89bcb05d9bbf8b David Altobelli 2008-07-02 779 }
89bcb05d9bbf8b David Altobelli 2008-07-02 780
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests
next reply other threads:[~2023-04-30 1:11 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-04-30 1:11 kernel test robot [this message]
-- strict thread matches above, loose matches on Subject: below --
2023-04-17 16:52 [PATCH] misc: hpilo: Fix use after free bug in ilo_remove due to race condition with ilo_open Zheng Wang
2023-04-17 17:43 ` Greg KH
2023-04-19 5:29 ` Zheng Hacker
2023-05-02 11:46 ` Dan Carpenter
2023-05-05 4:01 ` Zheng Hacker
2023-05-05 7:30 ` Dan Carpenter
2023-05-05 7:35 ` Zheng Hacker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=202304300909.ALHN6Vry-lkp@intel.com \
--to=lkp@intel.com \
--cc=error27@gmail.com \
--cc=oe-kbuild@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.