From: Tarun Sahu <tarunsahu@google.com>
To: helgaas@kernel.org, dmatlack@google.com,
Nicholas Piggin <npiggin@gmail.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
sourabhjain@linux.ibm.com,
"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
Pasha Tatashin <pasha.tatashin@soleen.com>,
Russell King <linux@armlinux.org.uk>,
radheys@amd.com, skhawaja@google.com, djeffery@redhat.com,
Geoff Levand <geoff@infradead.org>,
Madhavan Srinivasan <maddy@linux.ibm.com>,
Michael Ellerman <mpe@ellerman.id.au>
Cc: linux-arm-kernel@lists.infradead.org, souravsgl@google.com,
linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org,
driver-core@lists.linux.dev, Tarun Sahu <tarunsahu@google.com>
Subject: [PATCH v3 3/3] powerpc/ps3: use put_device() on device_register() failure in ps3_system_bus_device_register
Date: Fri, 14 Aug 2026 21:00:57 +0000 [thread overview]
Message-ID: <20260814210057.4102768-4-tarunsahu@google.com> (raw)
In-Reply-To: <20260814210057.4102768-1-tarunsahu@google.com>
As per the kernel documentation of device_register() function, it is
important to call put_device even if device_register returns an error.
To follow this guidelines and properly release the resources after
device_register() failure, call put_device() instead of kfree()
Also there are in-function-defined struct layout which make struct device
(core) to be child of layout-child's member (layout.dev.core). Also
definition of struct layout is not unique across functions in the driver.
To be able to free struct layout's dynamic allocation via put_device we
need to make sure that the core's release function must call the free
on parent of core and the parent must be at the location 0 of the struct
layout which will inherently free struct layout. This is to not
complicate the code and keep it as it currently implemented. To check
the location of parent at 0 of struct layout, I have added BUILD_BUG_ON.
Signed-off-by: Tarun Sahu <tarunsahu@google.com>
Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com>
---
arch/powerpc/platforms/ps3/device-init.c | 83 ++++++++++++++----------
arch/powerpc/platforms/ps3/system-bus.c | 2 +
2 files changed, 52 insertions(+), 33 deletions(-)
diff --git a/arch/powerpc/platforms/ps3/device-init.c b/arch/powerpc/platforms/ps3/device-init.c
index 9109c218a060..8d0c77db1764 100644
--- a/arch/powerpc/platforms/ps3/device-init.c
+++ b/arch/powerpc/platforms/ps3/device-init.c
@@ -90,14 +90,12 @@ static int __init ps3_register_lpm_devices(void)
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_register:
fail_rights:
fail_read_repo:
kfree(dev);
@@ -121,6 +119,12 @@ static int __init ps3_setup_gelic_device(
struct ps3_dma_region d_region;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
BUG_ON(repo->bus_type != PS3_BUS_TYPE_SB);
@@ -164,13 +168,12 @@ static int __init ps3_setup_gelic_device(
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return result;
-fail_device_register:
fail_dma_init:
fail_find_interrupt:
kfree(p);
@@ -192,6 +195,12 @@ static int __init ps3_setup_uhc_device(
u64 bus_addr;
u64 len;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
BUG_ON(repo->bus_type != PS3_BUS_TYPE_SB);
@@ -252,13 +261,12 @@ static int __init ps3_setup_uhc_device(
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return result;
-fail_device_register:
fail_mmio_init:
fail_dma_init:
fail_find_reg:
@@ -291,6 +299,12 @@ static int __init ps3_setup_vuart_device(enum ps3_match_id match_id,
struct ps3_system_bus_device dev;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d: match_id %u, port %u\n", __func__, __LINE__,
match_id, port_number);
@@ -308,15 +322,10 @@ static int __init ps3_setup_vuart_device(enum ps3_match_id match_id,
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_device_register:
- kfree(p);
- pr_debug(" <- %s:%d fail\n", __func__, __LINE__);
- return result;
}
static int ps3_setup_storage_dev(const struct ps3_repository_device *repo,
@@ -327,6 +336,12 @@ static int ps3_setup_storage_dev(const struct ps3_repository_device *repo,
u64 port, blk_size, num_blocks;
unsigned int num_regions, i;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->sbd).
+ * sbd must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct ps3_storage_device, sbd) != 0);
+
pr_debug(" -> %s:%u: match_id %u\n", __func__, __LINE__, match_id);
result = ps3_repository_read_stor_dev_info(repo->bus_index,
@@ -395,13 +410,12 @@ static int ps3_setup_storage_dev(const struct ps3_repository_device *repo,
if (result) {
pr_debug("%s:%u ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%u\n", __func__, __LINE__);
return 0;
-fail_device_register:
fail_read_region:
fail_find_interrupt:
kfree(p);
@@ -445,6 +459,12 @@ static int __init ps3_register_sound_devices(void)
struct ps3_mmio_region m_region;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
p = kzalloc_obj(*p);
@@ -461,15 +481,10 @@ static int __init ps3_register_sound_devices(void)
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_device_register:
- kfree(p);
- pr_debug(" <- %s:%d failed\n", __func__, __LINE__);
- return result;
}
static int __init ps3_register_graphics_devices(void)
@@ -479,6 +494,12 @@ static int __init ps3_register_graphics_devices(void)
struct ps3_system_bus_device dev;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
p = kzalloc_obj(struct layout);
@@ -495,16 +516,11 @@ static int __init ps3_register_graphics_devices(void)
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_device_register:
- kfree(p);
- pr_debug(" <- %s:%d failed\n", __func__, __LINE__);
- return result;
}
static int __init ps3_register_ramdisk_device(void)
@@ -514,6 +530,12 @@ static int __init ps3_register_ramdisk_device(void)
struct ps3_system_bus_device dev;
} *p;
+ /*
+ * ps3_system_bus_release_device() calls kfree(&p->dev).
+ * dev must be at offset 0 so kfree() frees outer p.
+ */
+ BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
pr_debug(" -> %s:%d\n", __func__, __LINE__);
p = kzalloc_obj(struct layout);
@@ -530,16 +552,11 @@ static int __init ps3_register_ramdisk_device(void)
if (result) {
pr_debug("%s:%d ps3_system_bus_device_register failed\n",
__func__, __LINE__);
- goto fail_device_register;
+ return result;
}
pr_debug(" <- %s:%d\n", __func__, __LINE__);
return 0;
-
-fail_device_register:
- kfree(p);
- pr_debug(" <- %s:%d failed\n", __func__, __LINE__);
- return result;
}
/**
diff --git a/arch/powerpc/platforms/ps3/system-bus.c b/arch/powerpc/platforms/ps3/system-bus.c
index 0537a678a32f..0918c74d3e19 100644
--- a/arch/powerpc/platforms/ps3/system-bus.c
+++ b/arch/powerpc/platforms/ps3/system-bus.c
@@ -774,6 +774,8 @@ int ps3_system_bus_device_register(struct ps3_system_bus_device *dev)
pr_debug("%s:%d add %s\n", __func__, __LINE__, dev_name(&dev->core));
result = device_register(&dev->core);
+ if (result)
+ put_device(&dev->core);
return result;
}
--
2.55.0.691.gc56d675ccc-goog
prev parent reply other threads:[~2026-08-14 21:01 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 21:00 [PATCH v3 0/3] Convert manual kfree(dev) to put_device() Tarun Sahu
2026-08-14 21:00 ` [PATCH v3 1/3] ARM: locomo: use put_device() on device_register() failure Tarun Sahu
2026-08-14 21:00 ` [PATCH v3 2/3] firmware/edd: use kobject_put() on edd_device_register() failure Tarun Sahu
2026-08-14 22:06 ` Bjorn Helgaas
2026-08-14 21:00 ` Tarun Sahu [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814210057.4102768-4-tarunsahu@google.com \
--to=tarunsahu@google.com \
--cc=chleroy@kernel.org \
--cc=djeffery@redhat.com \
--cc=dmatlack@google.com \
--cc=driver-core@lists.linux.dev \
--cc=geoff@infradead.org \
--cc=gregkh@linuxfoundation.org \
--cc=helgaas@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@armlinux.org.uk \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=maddy@linux.ibm.com \
--cc=mpe@ellerman.id.au \
--cc=npiggin@gmail.com \
--cc=pasha.tatashin@soleen.com \
--cc=radheys@amd.com \
--cc=skhawaja@google.com \
--cc=sourabhjain@linux.ibm.com \
--cc=souravsgl@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox