From: Tarun Sahu <tarunsahu@google.com>
To: helgaas@kernel.org, dmatlack@google.com,
Nicholas Piggin <npiggin@gmail.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
sourabhjain@linux.ibm.com,
"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
Pasha Tatashin <pasha.tatashin@soleen.com>,
Russell King <linux@armlinux.org.uk>,
radheys@amd.com, skhawaja@google.com, djeffery@redhat.com,
Geoff Levand <geoff@infradead.org>,
Madhavan Srinivasan <maddy@linux.ibm.com>,
Michael Ellerman <mpe@ellerman.id.au>
Cc: linux-arm-kernel@lists.infradead.org, souravsgl@google.com,
linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org,
driver-core@lists.linux.dev, Tarun Sahu <tarunsahu@google.com>
Subject: [PATCH v3 3/3] powerpc/ps3: use put_device() on device_register() failure in ps3_system_bus_device_register
Date: Fri, 14 Aug 2026 21:00:57 +0000 [thread overview]
Message-ID: <20260814210057.4102768-4-tarunsahu@google.com> (raw)
In-Reply-To: <20260814210057.4102768-1-tarunsahu@google.com>
As per the kernel documentation of device_register() function, it is
important to call put_device even if device_register returns an error.
To follow this guidelines and properly release the resources after
device_register() failure, call put_device() instead of kfree()
Also there are in-function-defined struct layout which make struct device
(core) to be child of layout-child's member (layout.dev.core). Also
definition of struct layout is not unique across functions in the driver.
To be able to free struct layout's dynamic allocation via put_device we
need to make sure that the core's release function must call the free
on parent of core and the parent must be at the location 0 of the struct
layout which will inherently free struct layout. This is to not
complicate the code and keep it as it currently implemented. To check
the location of parent at 0 of struct layout, I have added BUILD_BUG_ON.
Signed-off-by: Tarun Sahu <tarunsahu@google.com>
Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com>
---
arch/powerpc/platforms/ps3/device-init.c | 83 ++++++++++++++----------
arch/powerpc/platforms/ps3/system-bus.c | 2 +
2 files changed, 52 insertions(+), 33 deletions(-)
diff --git a/arch/powerpc/platforms/ps3/device-init.c b/arch/powerpc/platforms/ps3/device-init.c
index 9109c218a060..8d0c77db1764 100644
--- a/arch/powerpc/platforms/ps3/device-init.c
+++ b/arch/powerpc/platforms/ps3/device-init.c
@@ -90,14 +90,12 @@ static int __init ps3_register_lpm_devices(void)
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_register:
fail_rights:
fail_read_repo:
kfree(dev);
@@ -121,6 +119,12 @@ static int __init ps3_setup_gelic_device(
struct ps3_dma_region d_region;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
BUG_ON(repo->bus_type != PS3_BUS_TYPE_SB);
@@ -164,13 +168,12 @@ static int __init ps3_setup_gelic_device(
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return result;
-fail_device_register:
fail_dma_init:
fail_find_interrupt:
kfree(p);
@@ -192,6 +195,12 @@ static int __init ps3_setup_uhc_device(
u64 bus_addr;
u64 len;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
BUG_ON(repo->bus_type != PS3_BUS_TYPE_SB);
@@ -252,13 +261,12 @@ static int __init ps3_setup_uhc_device(
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return result;
-fail_device_register:
fail_mmio_init:
fail_dma_init:
fail_find_reg:
@@ -291,6 +299,12 @@ static int __init ps3_setup_vuart_device(enum ps3_match_id match_id,
struct ps3_system_bus_device dev;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d: match_id %u, port %u\n", __func__, __LINE__,
match_id, port_number);
@@ -308,15 +322,10 @@ static int __init ps3_setup_vuart_device(enum ps3_match_id match_id,
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_device_register:
- kfree(p);
- pr_debug(" <- %s:%d fail\n", __func__, __LINE__);
- return result;
}
static int ps3_setup_storage_dev(const struct ps3_repository_device *repo,
@@ -327,6 +336,12 @@ static int ps3_setup_storage_dev(const struct ps3_repository_device *repo,
u64 port, blk_size, num_blocks;
unsigned int num_regions, i;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->sbd).
+ * sbd must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct ps3_storage_device, sbd) != 0);
+
pr_debug(" -> %s:%u: match_id %u\n", __func__, __LINE__, match_id);
result = ps3_repository_read_stor_dev_info(repo->bus_index,
@@ -395,13 +410,12 @@ static int ps3_setup_storage_dev(const struct ps3_repository_device *repo,
if (result) {
pr_debug("%s:%u ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%u\n", __func__, __LINE__);
return 0;
-fail_device_register:
fail_read_region:
fail_find_interrupt:
kfree(p);
@@ -445,6 +459,12 @@ static int __init ps3_register_sound_devices(void)
struct ps3_mmio_region m_region;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
p = kzalloc_obj(*p);
@@ -461,15 +481,10 @@ static int __init ps3_register_sound_devices(void)
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_device_register:
- kfree(p);
- pr_debug(" <- %s:%d failed\n", __func__, __LINE__);
- return result;
}
static int __init ps3_register_graphics_devices(void)
@@ -479,6 +494,12 @@ static int __init ps3_register_graphics_devices(void)
struct ps3_system_bus_device dev;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
p = kzalloc_obj(struct layout);
@@ -495,16 +516,11 @@ static int __init ps3_register_graphics_devices(void)
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_device_register:
- kfree(p);
- pr_debug(" <- %s:%d failed\n", __func__, __LINE__);
- return result;
}
static int __init ps3_register_ramdisk_device(void)
@@ -514,6 +530,12 @@ static int __init ps3_register_ramdisk_device(void)
struct ps3_system_bus_device dev;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
p = kzalloc_obj(struct layout);
@@ -530,16 +552,11 @@ static int __init ps3_register_ramdisk_device(void)
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_device_register:
- kfree(p);
- pr_debug(" <- %s:%d failed\n", __func__, __LINE__);
- return result;
}
/**
diff --git a/arch/powerpc/platforms/ps3/system-bus.c b/arch/powerpc/platforms/ps3/system-bus.c
index 0537a678a32f..0918c74d3e19 100644
--- a/arch/powerpc/platforms/ps3/system-bus.c
+++ b/arch/powerpc/platforms/ps3/system-bus.c
@@ -774,6 +774,8 @@ int ps3_system_bus_device_register(struct ps3_system_bus_device *dev)
pr_debug("%s:%d add %s\n", __func__, __LINE__, dev_name(&dev->core));
result = device_register(&dev->core);
+ if (result)
+ put_device(&dev->core);
return result;
}
--
2.55.0.691.gc56d675ccc-goog
prev parent reply other threads:[~2026-08-14 21:01 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 21:00 [PATCH v3 0/3] Convert manual kfree(dev) to put_device() Tarun Sahu
2026-08-14 21:00 ` [PATCH v3 1/3] ARM: locomo: use put_device() on device_register() failure Tarun Sahu
2026-08-14 21:00 ` [PATCH v3 2/3] firmware/edd: use kobject_put() on edd_device_register() failure Tarun Sahu
2026-08-14 22:06 ` Bjorn Helgaas
2026-08-20 10:52 ` tarunsahu
2026-08-14 21:00 ` Tarun Sahu [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814210057.4102768-4-tarunsahu@google.com \
--to=tarunsahu@google.com \
--cc=chleroy@kernel.org \
--cc=djeffery@redhat.com \
--cc=dmatlack@google.com \
--cc=driver-core@lists.linux.dev \
--cc=geoff@infradead.org \
--cc=gregkh@linuxfoundation.org \
--cc=helgaas@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@armlinux.org.uk \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=maddy@linux.ibm.com \
--cc=mpe@ellerman.id.au \
--cc=npiggin@gmail.com \
--cc=pasha.tatashin@soleen.com \
--cc=radheys@amd.com \
--cc=skhawaja@google.com \
--cc=sourabhjain@linux.ibm.com \
--cc=souravsgl@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.