public inbox for dmaengine@vger.kernel.org
 help / color / mirror / Atom feed
From: Jason Gunthorpe <jgg@nvidia.com>
To: Dave Jiang <dave.jiang@intel.com>
Cc: <vkoul@kernel.org>, Dan Williams <dan.j.williams@intel.com>,
	<dmaengine@vger.kernel.org>
Subject: Re: [PATCH v5] dmaengine: idxd: Do not use devm for 'struct device' object allocation
Date: Thu, 4 Mar 2021 14:03:08 -0400	[thread overview]
Message-ID: <20210304180308.GH4247@nvidia.com> (raw)
In-Reply-To: <161478326635.3900104.2067961356060195664.stgit@djiang5-desk3.ch.intel.com>

On Wed, Mar 03, 2021 at 07:56:30AM -0700, Dave Jiang wrote:
> Remove devm_* allocation of memory of 'struct device' objects.
> The devm_* lifetime is incompatible with device->release() lifetime.
> Address issues flagged by CONFIG_DEBUG_KOBJECT_RELEASE. Add release
> functions for each component in order to free the allocated memory at
> the appropriate time. Each component such as wq, engine, and group now
> needs to be allocated individually in order to setup the lifetime properly.
> In the process also fix up issues from the fallout of the changes.
> 
> Reported-by: Jason Gunthorpe <jgg@nvidia.com>
> Fixes: bfe1d56091c1 ("dmaengine: idxd: Init and probe for Intel data accelerators")
> Signed-off-by: Dave Jiang <dave.jiang@intel.com>
> Reviewed-by: Dan Williams <dan.j.williams@intel.com>
> v5:
> - Rebased against 5.12-rc dmaengine/fixes
> v4:
> - fix up the life time of cdev creation/destruction (Jason)
> - Tested with KASAN and other memory allocation leak detections. (Jason)
> 
> v3:
> - Remove devm_* for irq request and cleanup related bits (Jason)
> v2:
> - Remove all devm_* alloc for idxd_device (Jason)
> - Add kref dep for dma_dev (Jason)
> 
>  drivers/dma/idxd/cdev.c   |   32 +++---
>  drivers/dma/idxd/device.c |   20 ++-
>  drivers/dma/idxd/dma.c    |   13 ++
>  drivers/dma/idxd/idxd.h   |    8 +
>  drivers/dma/idxd/init.c   |  261 +++++++++++++++++++++++++++++++++------------
>  drivers/dma/idxd/irq.c    |    6 +
>  drivers/dma/idxd/sysfs.c  |   77 +++++++++----
>  7 files changed, 290 insertions(+), 127 deletions(-)
> 
> diff --git a/drivers/dma/idxd/cdev.c b/drivers/dma/idxd/cdev.c
> index 0db9b82ed8cf..1b98e06fa228 100644
> +++ b/drivers/dma/idxd/cdev.c
> @@ -259,6 +259,7 @@ static int idxd_wq_cdev_dev_setup(struct idxd_wq *wq)
>  		return -ENOMEM;
>  
>  	dev = idxd_cdev->dev;
> +	device_initialize(dev);
>  	dev->parent = &idxd->pdev->dev;
>  	dev_set_name(dev, "%s/wq%u.%u", idxd_get_dev_name(idxd),
>  		     idxd->id, wq->id);

dev_set_name() can fail

> @@ -268,25 +269,17 @@ static int idxd_wq_cdev_dev_setup(struct idxd_wq *wq)
>  	minor = ida_simple_get(&cdev_ctx->minor_ida, 0, MINORMASK, GFP_KERNEL);
>  	if (minor < 0) {
>  		rc = minor;
> -		kfree(dev);
>  		goto ida_err;

This doesn't work

>  	}
>  
>  	dev->devt = MKDEV(MAJOR(cdev_ctx->devt), minor);
>  	dev->type = &idxd_cdev_device_type;

Because this hasn't been done yet and release is thus NULL, will leak memory.

Also the order here is wrong:

	rc = cdev_device_add(cdev, dev);
	 [..]
	init_waitqueue_head(&idxd_cdev->err_queue);

Userspace can race a call to poll() before err_queue is setup.

And probably more. Please check your code carefully!

Jason

  reply	other threads:[~2021-03-04 18:05 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-03-03 14:56 [PATCH v5] dmaengine: idxd: Do not use devm for 'struct device' object allocation Dave Jiang
2021-03-04 18:03 ` Jason Gunthorpe [this message]
2021-03-04 18:20   ` Dave Jiang
2021-03-24  5:07   ` Dan Williams
2021-03-24 11:56     ` Jason Gunthorpe
2021-03-24 16:13       ` Dan Williams
2021-03-24 16:52         ` Jason Gunthorpe
2021-03-24 17:01           ` Dan Williams
2021-03-24 19:57             ` Dan Carpenter
2021-03-24 20:00               ` Dan Williams
2021-03-25 16:48                 ` Jason Gunthorpe
2021-03-25 18:02                   ` Dan Williams
2021-03-26 23:55                     ` Jason Gunthorpe
2021-03-24 20:07             ` Dan Carpenter
2021-03-24 19:52           ` Dan Carpenter
2021-03-24 20:31             ` Dave Jiang
2021-03-24 23:35             ` Jason Gunthorpe
2021-03-25  6:52               ` Dan Carpenter
2021-03-25 11:45                 ` Jason Gunthorpe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20210304180308.GH4247@nvidia.com \
    --to=jgg@nvidia.com \
    --cc=dan.j.williams@intel.com \
    --cc=dave.jiang@intel.com \
    --cc=dmaengine@vger.kernel.org \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox