From: Sasha Levin <sashal@kernel.org>
To: patches@lists.linux.dev, stable@vger.kernel.org
Cc: Pablo Martin-Gomez <pmartin-gomez@freebox.fr>,
Miquel Raynal <miquel.raynal@bootlin.com>,
Sasha Levin <sashal@kernel.org>,
tudor.ambarus@linaro.org, Takahiro.Kuwano@infineon.com,
mmkurbanov@salutedevices.com, chengminglin@mxic.com.tw
Subject: [PATCH AUTOSEL 5.15 10/11] mtd: spinand: fix memory leak of ECC engine conf
Date: Tue, 24 Jun 2025 00:12:58 -0400 [thread overview]
Message-ID: <20250624041259.84940-10-sashal@kernel.org> (raw)
In-Reply-To: <20250624041259.84940-1-sashal@kernel.org>
From: Pablo Martin-Gomez <pmartin-gomez@freebox.fr>
[ Upstream commit 6463cbe08b0cbf9bba8763306764f5fd643023e1 ]
Memory allocated for the ECC engine conf is not released during spinand
cleanup. Below kmemleak trace is seen for this memory leak:
unreferenced object 0xffffff80064f00e0 (size 8):
comm "swapper/0", pid 1, jiffies 4294937458
hex dump (first 8 bytes):
00 00 00 00 00 00 00 00 ........
backtrace (crc 0):
kmemleak_alloc+0x30/0x40
__kmalloc_cache_noprof+0x208/0x3c0
spinand_ondie_ecc_init_ctx+0x114/0x200
nand_ecc_init_ctx+0x70/0xa8
nanddev_ecc_engine_init+0xec/0x27c
spinand_probe+0xa2c/0x1620
spi_mem_probe+0x130/0x21c
spi_probe+0xf0/0x170
really_probe+0x17c/0x6e8
__driver_probe_device+0x17c/0x21c
driver_probe_device+0x58/0x180
__device_attach_driver+0x15c/0x1f8
bus_for_each_drv+0xec/0x150
__device_attach+0x188/0x24c
device_initial_probe+0x10/0x20
bus_probe_device+0x11c/0x160
Fix the leak by calling nanddev_ecc_engine_cleanup() inside
spinand_cleanup().
Signed-off-by: Pablo Martin-Gomez <pmartin-gomez@freebox.fr>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
**YES**
This commit should be backported to stable kernel trees for the
following reasons:
1. **Clear Memory Leak Bug**: The commit fixes a concrete memory leak
where the ECC engine configuration memory (allocated in
`spinand_ondie_ecc_init_ctx()` at line 272 via `kzalloc()`) is never
freed. The kmemleak trace clearly shows this 8-byte allocation is
leaked on every spinand device initialization.
2. **Small and Contained Fix**: The fix is minimal - it only adds a
single line `nanddev_ecc_engine_cleanup(nand);` to the existing
`spinand_cleanup()` function. This follows the established cleanup
pattern already used in the error path (`err_cleanup_ecc_engine:` at
line 1569).
3. **No Architectural Changes**: The commit doesn't introduce any new
features or change any architecture. It simply ensures proper cleanup
of already-allocated resources by calling an existing cleanup
function.
4. **Follows Established Patterns**: The fix mirrors the cleanup already
performed in the error handling path during `spinand_init()`. If
initialization fails after `nanddev_ecc_engine_init()`, the code
already calls `nanddev_ecc_engine_cleanup()`. This commit ensures the
same cleanup happens during normal device removal.
5. **Clear Impact on Users**: Memory leaks affect system stability over
time, especially in systems that frequently probe/remove SPI NAND
devices (e.g., during development, testing, or hot-plug scenarios).
Each leak is small (8 bytes) but cumulative.
6. **Low Risk**: The cleanup function `nanddev_ecc_engine_cleanup()`
already checks if the engine exists before attempting cleanup (`if
(nand->ecc.engine)`), making it safe to call even in edge cases.
7. **Similar to Backported Commits**: Like the backported commit "atm:
idt77252: fix kmemleak when rmmod idt77252", this fixes a clear
resource leak found by kmemleak, with a simple addition of the
appropriate cleanup call in the removal path.
The commit follows stable tree rules perfectly: it's a small, important
bugfix with minimal regression risk that addresses a real memory leak
issue affecting users.
drivers/mtd/nand/spi/core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/mtd/nand/spi/core.c b/drivers/mtd/nand/spi/core.c
index 2c8685f1f2fa7..80d0112d18fa6 100644
--- a/drivers/mtd/nand/spi/core.c
+++ b/drivers/mtd/nand/spi/core.c
@@ -1271,6 +1271,7 @@ static void spinand_cleanup(struct spinand_device *spinand)
{
struct nand_device *nand = spinand_to_nand(spinand);
+ nanddev_ecc_engine_cleanup(nand);
nanddev_cleanup(nand);
spinand_manufacturer_cleanup(spinand);
kfree(spinand->databuf);
--
2.39.5
next prev parent reply other threads:[~2025-06-24 4:13 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-06-24 4:12 [PATCH AUTOSEL 5.15 01/11] drm/msm: Fix a fence leak in submit error path Sasha Levin
2025-06-24 4:12 ` [PATCH AUTOSEL 5.15 02/11] ALSA: sb: Don't allow changing the DMA mode during operations Sasha Levin
2025-06-24 4:12 ` [PATCH AUTOSEL 5.15 03/11] ALSA: sb: Force to disable DMAs once when DMA mode is changed Sasha Levin
2025-06-24 4:12 ` [PATCH AUTOSEL 5.15 04/11] ata: pata_cs5536: fix build on 32-bit UML Sasha Levin
2025-06-24 4:12 ` [PATCH AUTOSEL 5.15 05/11] powerpc: Fix struct termio related ioctl macros Sasha Levin
2025-06-24 4:12 ` [PATCH AUTOSEL 5.15 06/11] scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port() Sasha Levin
2025-06-24 4:12 ` [PATCH AUTOSEL 5.15 07/11] wifi: mac80211: drop invalid source address OCB frames Sasha Levin
2025-06-24 4:12 ` [PATCH AUTOSEL 5.15 08/11] wifi: ath6kl: remove WARN on bad firmware input Sasha Levin
2025-06-24 4:12 ` [PATCH AUTOSEL 5.15 09/11] ACPICA: Refuse to evaluate a method if arguments are missing Sasha Levin
2025-06-24 4:12 ` Sasha Levin [this message]
2025-06-24 4:12 ` [PATCH AUTOSEL 5.15 11/11] rcu: Return early if callback is not specified Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250624041259.84940-10-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=Takahiro.Kuwano@infineon.com \
--cc=chengminglin@mxic.com.tw \
--cc=miquel.raynal@bootlin.com \
--cc=mmkurbanov@salutedevices.com \
--cc=patches@lists.linux.dev \
--cc=pmartin-gomez@freebox.fr \
--cc=stable@vger.kernel.org \
--cc=tudor.ambarus@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.