From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 724843E5A1C for ; Wed, 19 Aug 2026 08:02:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.10 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787126529; cv=none; b=LC67pxP/Al1P0F9109friZBOhLqeOC8fXVhNiG7kINfqJbBtyWoQL4yWvSJw6Clo64+skx1P4lyjQC4VruZpc37GNB8If0MaihKm2Bu6mnA+u60V04ieHohDcBP7I/jHqee/Xy88MZq+KzP+WRYQj41ww/ZfNLoBtQnGMB6bMgI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787126529; c=relaxed/simple; bh=ND4wVnq9kHTWnnQ93/pZ5c6Si1aQTx0D6vjuhJP/TmM=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=l+7EcWMJr6g8IA29h85STVSIqUm/ZvrSE8vAPPMSJaVQKbalQxM+Alx6s+9x0onNA74CkuOpReWJgUA3XHtNl4wIUcUIqgsa5Yz9yg28HcyXq2ZLr2Byi6+qLirZrok82d5O1dPGAmYV94O4qwCcHLDF+omUGhNk0S4dt26uLiY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=buGe7iAm; arc=none smtp.client-ip=198.175.65.10 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="buGe7iAm" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787126525; x=1818662525; h=date:from:to:cc:subject:message-id:references: mime-version:in-reply-to; bh=ND4wVnq9kHTWnnQ93/pZ5c6Si1aQTx0D6vjuhJP/TmM=; b=buGe7iAmIX9EBsGCp6aJi2ycclfy/Unc6JSSSE0q4AQaQ658H8MK2e0F oTHdyfdUPpan+akhh8i3sxsrd6gOvaD3NswSH0y/pDNt8yb8cJ+QhilFq dX4Hwv3JmVwzEurc24gNZGrzHmb/+Hw3Z32d9pBCNYyqJpeOQSoAnr9cl ATmlaQQoSStCaA5qqeGk3VQWurAvPNcm/bjd4PRkoI5u+79kbCyGeFhrv LQ5XPt/m2QXA3Y6TViTytvU8xtxjRo0iPTo8DVGvGgTKVZFmbDGHS6ApK 78TN/uGCWMnRnWg7sijFZ6GHWvh5/33x135iBd7QlMt7h9vALvcj4havQ Q==; X-CSE-ConnectionGUID: q1cOmXkhTseYL6yOLoUe8w== X-CSE-MsgGUID: uZjc4Lb9T7imbLX8IUppHQ== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="105013363" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="105013363" Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by orvoesa102.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 01:02:01 -0700 X-CSE-ConnectionGUID: nK/oeakIQDCnMK2zLro59w== X-CSE-MsgGUID: DEROww4tRTm0b2/S35TqQg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="259283785" Received: from amilburn-desk.amilburn-desk (HELO localhost) ([10.245.244.106]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 01:01:58 -0700 Date: Wed, 19 Aug 2026 11:01:56 +0300 From: Andy Shevchenko To: kr494167@gmail.com, Rajat Gupta Cc: andy.shevchenko@gmail.com, andy@kernel.org, geert@linux-m68k.org, chris.packham@alliedtelesis.co.nz, linux-kernel@vger.kernel.org Subject: Re: [PATCH 0/3 1/3] auxdisplay: line-display: add devm_linedisp_register() Message-ID: References: <20260819024556.63534-1-kr494167@gmail.com> <20260819024556.63534-2-kr494167@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260819024556.63534-2-kr494167@gmail.com> Organization: Intel Finland Oy - BIC 0357606-4 - c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo On Wed, Aug 19, 2026 at 08:15:54AM +0530, kr494167@gmail.com wrote: > Add devm_linedisp_register() to manage character line display registration > via devres. This simplifies driver cleanup and prevents use-after-free > bugs when unregistering line displays on driver detach. This is not enough per se. Copied'n'pasted the reply I made to Rajat who reported the issue: -->8----8<-- > > 6. PROPOSED FIX > > > > Replace devm_kzalloc with plain kzalloc and tie the container > > lifetime to the embedded device's refcount: > > > > --- a/drivers/auxdisplay/line-display.c > > +++ b/drivers/auxdisplay/line-display.c > > @@ (linedisp_release callback) > > > > static void linedisp_release(struct device *dev) > > { > > struct linedisp *linedisp = to_linedisp(dev); > > + struct container *priv = container_of(linedisp, ...); > > > > kfree(linedisp->map); > > kfree(linedisp->message); > > kfree(linedisp->buf); > > + kfree(priv); /* free container when refcount reaches 0 */ > > } > > > > Each affected driver (img-ascii-lcd, max6959, seg-led-gpio) must > > change devm_kzalloc to kzalloc for the container struct, and ensure > > the release function frees it. This aligns the container lifetime > > with the embedded device refcount. > > That won't scale as the device drivers are free to call devm_kzalloc() > and similar for their private data structures. What we should do is to > prevent a device from unbinding when one or more files are open (via > sysfs). TL;DR: downgrading devm_kzalloc() is not an option. So, the fix as I see it is much more intrusive. The linedisp_register() should be split to _alloc() and _register() APIs, and then at least the first one being also wrapped with devm_*() for users that want this. See how devm_iio_device_alloc() and devm_iio_device_registers() are implemented. -- With Best Regards, Andy Shevchenko