All of lore.kernel.org
 help / color / mirror / Atom feed
From: Haren Myneni <haren@linux.ibm.com>
To: sashiko-reviews@lists.linux.dev
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org,
	tyreld@linux.ibm.com
Subject: Re: [PATCH 1/2] drivers/of: Add of_detach_node_no_notify()
Date: Wed, 16 Sep 2026 21:11:13 -0700	[thread overview]
Message-ID: <cc4cba7c4d0d1c45879fdeb90f732469a98cc723.camel@linux.ibm.com> (raw)
In-Reply-To: <20260916044334.3EA551F000FF@smtp.kernel.org>

On Wed, 2026-09-16 at 04:43 +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential
> issue(s) to consider:
> - [High] of: state corruption and resource leak via
> of_detach_node_no_notify()
> --
> 
> commit 900ccea33cdd682696cd3ae6fb47477962cee9f0
> Author: Haren Myneni <haren@linux.ibm.com>
> 
>     drivers/of: Add of_detach_node_no_notify()
> 
> This commit introduces the of_detach_node_no_notify() interface. It
> allows
> callers to remove nodes from the device tree without triggering
> reconfiguration
> notifiers, intending to provide a cleanup path when node addition
> fails.
> 
> > diff --git a/drivers/of/dynamic.c b/drivers/of/dynamic.c
> > index 744ce0e1eb24a..fc6f22371a97c 100644
> > --- a/drivers/of/dynamic.c
> > +++ b/drivers/of/dynamic.c
> [ ... ]
> > @@ -318,6 +318,22 @@ int of_detach_node(struct device_node *np)
> >  }
> >  EXPORT_SYMBOL_GPL(of_detach_node);
> >  
> > +/**
> > + * of_detach_node_no_notify() - "Unplug" a node from the device
> > + * and return without running notifiers.
> > + * @np:	Pointer to the caller's Device Node
> > + */
> > +int of_detach_node_no_notify(struct device_node *np)
> > +{
> > +	mutex_lock(&of_mutex);
> > +	if (!of_node_check_flag(np, OF_DETACHED))
> > +		__of_detach_node(np);
> > +	mutex_unlock(&of_mutex);
> > +
> > +	return 0;
> > +}
> 
> [Severity: High]
> Does this bypass of of_reconfig_notify(OF_RECONFIG_DETACH_NODE) cause
> state
> corruption and resource leaks?
> 
> When of_changeset_apply() fails during the notification phase (for
> example,
> if a subsystem returns an error for OF_RECONFIG_ATTACH_NODE), earlier
> subsystems in the blocking_notifier_call_chain may have already
> successfully
> processed the ATTACH_NODE event and allocated resources such as
> platform
> devices or cached node pointers.
> 
> If of_detach_node_no_notify() is subsequently used to undo the
> changeset, the
> required OF_RECONFIG_DETACH_NODE signal is intentionally suppressed.
> Will this
> leave the successfully attached subsystems blind to the removal,
> resulting in
> permanent resource leaks and potential use-after-free of the device
> nodes via
> dangling pointers?
> 
> This path can be reached through userspace-initiated CPU hotplug
> operations
> (DLPAR) that exercise this error path.

Yes, of_changeset_apply() can add  and have successful notifiers for
some nodes. of_detach_node_no_notify() is called for each node ( its
children first and then the parent node) in dlpar_detach_node() and up
to the caller. 

For CPU nodes, only the parent CPU node has the notifier. and 
of_detach_node_no_notify() is issued only for the failure from the
notifier. So should not be an issue. 

      reply	other threads:[~2026-09-17  4:11 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-16  4:32 [PATCH 1/2] drivers/of: Add of_detach_node_no_notify() Haren Myneni
2026-09-16  4:32 ` [PATCH 2/2] powerpc/pseries/dlpar: Remove DT entries if failure from CPU ADD notifier Haren Myneni
2026-09-16  4:47   ` sashiko-bot
2026-09-17  3:57     ` Haren Myneni
2026-09-16 21:33   ` Rob Herring
2026-09-17  3:42     ` Haren Myneni
2026-09-16  4:43 ` [PATCH 1/2] drivers/of: Add of_detach_node_no_notify() sashiko-bot
2026-09-17  4:11   ` Haren Myneni [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cc4cba7c4d0d1c45879fdeb90f732469a98cc723.camel@linux.ibm.com \
    --to=haren@linux.ibm.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=tyreld@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.