All of lore.kernel.org
 help / color / mirror / Atom feed
* [merged mm-nonmm-stable] rapidio-clear-mport-net-when-rio_add_net-fails.patch removed from -mm tree
@ 2026-08-04  4:05 Andrew Morton
  0 siblings, 0 replies; only message in thread
From: Andrew Morton @ 2026-08-04  4:05 UTC (permalink / raw)
  To: mm-commits, yangyingliang, mporter, alex.bou9, lgs201920130244,
	akpm


The quilt patch titled
     Subject: rapidio: clear mport->net when rio_add_net() fails
has been removed from the -mm tree.  Its filename was
     rapidio-clear-mport-net-when-rio_add_net-fails.patch

This patch was dropped because it was merged into the mm-nonmm-stable branch
of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm

------------------------------------------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
Subject: rapidio: clear mport->net when rio_add_net() fails
Date: Wed, 8 Jul 2026 15:06:28 +0800

rio_alloc_net() stores the newly allocated rio_net in mport->net before
rio_scan_alloc_net() registers the device.

If rio_add_net() fails, rio_scan_alloc_net() drops the device reference
with put_device(), which releases the rio_net through the device release
callback.  However, mport->net is left pointing at the freed object.

A later mport unregister path can then dereference the dangling mport->net
pointer and may try to free the same rio_net again.

Clear mport->net in the rio_add_net() failure path, matching the cleanup
done for the destID table allocation failure path.

Link: https://lore.kernel.org/20260708070628.721010-1-lgs201920130244@gmail.com
Fixes: e842f9a1edf3 ("rapidio: add check for rio_add_net() in rio_scan_alloc_net()")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Cc: Alexandre Bounine <alex.bou9@gmail.com>
Cc: Matt Porter <mporter@kernel.crashing.org>
Cc: Yang yingliang <yangyingliang@huawei.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---

 drivers/rapidio/rio-scan.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/rapidio/rio-scan.c~rapidio-clear-mport-net-when-rio_add_net-fails
+++ a/drivers/rapidio/rio-scan.c
@@ -874,6 +874,7 @@ static struct rio_net *rio_scan_alloc_ne
 		net->dev.release = rio_scan_release_dev;
 		if (rio_add_net(net)) {
 			put_device(&net->dev);
+			mport->net = NULL;
 			net = NULL;
 		}
 	}
_

Patches currently in -mm which might be from lgs201920130244@gmail.com are



^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-04  4:05 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-04  4:05 [merged mm-nonmm-stable] rapidio-clear-mport-net-when-rio_add_net-fails.patch removed from -mm tree Andrew Morton

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.