Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/4] Convert manual kfree(dev) to put_device()
@ 2026-08-10 16:28 Tarun Sahu
  2026-08-10 16:28 ` [PATCH 1/4] ARM: locomo: use put_device() on device_register() failure Tarun Sahu
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Tarun Sahu @ 2026-08-10 16:28 UTC (permalink / raw)
  To: Greg Kroah-Hartman, Geoff Levand, Christophe Leroy (CS GROUP),
	Nicholas Piggin, Michael Ellerman, dmatlack, Borislav Petkov,
	Madhavan Srinivasan, Shubhrajyoti Datta, djeffery, Tony Luck,
	skhawaja, Russell King, stuart.w.hayes
  Cc: linuxppc-dev, linux-arm-kernel, linux-kernel, driver-core,
	linux-edac, Tarun Sahu

Hello,

As per the guidelines, no devices that are tried to register with
device_register or to add using device_add, must use put_device on their
failure path. These series contains 4 patches that update these
instances.

Tarun Sahu (4):
  ARM: locomo: use put_device() on device_register() failure
  firmware/edd: use kobject_put() on edd_device_register() failure
  EDAC/versalnet: use put_device() on device_register() failure
  powerpc/ps3: use put_device() on device_register() failure in
    ps3_system_bus_device_register

 arch/arm/common/locomo.c                 | 13 ++--
 arch/powerpc/platforms/ps3/device-init.c | 83 ++++++++++++++----------
 arch/powerpc/platforms/ps3/system-bus.c  |  2 +
 drivers/edac/versalnet_edac.c            |  6 +-
 drivers/firmware/edd.c                   |  2 +-
 5 files changed, 63 insertions(+), 43 deletions(-)


base-commit: dbaafe9cc56a996931eedfe043eb34418cc9cd9b
-- 
2.55.0.679.g6767b8d81c-goog



^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH 1/4] ARM: locomo: use put_device() on device_register() failure
  2026-08-10 16:28 [PATCH 0/4] Convert manual kfree(dev) to put_device() Tarun Sahu
@ 2026-08-10 16:28 ` Tarun Sahu
  2026-08-10 16:28 ` [PATCH 2/4] firmware/edd: use kobject_put() on edd_device_register() failure Tarun Sahu
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 5+ messages in thread
From: Tarun Sahu @ 2026-08-10 16:28 UTC (permalink / raw)
  To: Greg Kroah-Hartman, Geoff Levand, Christophe Leroy (CS GROUP),
	Nicholas Piggin, Michael Ellerman, dmatlack, Borislav Petkov,
	Madhavan Srinivasan, Shubhrajyoti Datta, djeffery, Tony Luck,
	skhawaja, Russell King, stuart.w.hayes
  Cc: linuxppc-dev, linux-arm-kernel, linux-kernel, driver-core,
	linux-edac, Tarun Sahu

When device_register() fails, calling kfree(dev) directly bypasses the
device_release() callback (locomo_dev_release) and leaks internal driver
core structures allocated during device initialization.

Fix this by replacing direct kfree(dev) with put_device(&dev->dev) when
device_register() returns an error, ensuring proper refcount decrement
and cleanup via locomo_dev_release().

Signed-off-by: Tarun Sahu <tarunsahu@google.com>
---
 arch/arm/common/locomo.c | 13 ++++++-------
 1 file changed, 6 insertions(+), 7 deletions(-)

diff --git a/arch/arm/common/locomo.c b/arch/arm/common/locomo.c
index 55e360452828..0f6689d343b0 100644
--- a/arch/arm/common/locomo.c
+++ b/arch/arm/common/locomo.c
@@ -223,10 +223,8 @@ locomo_init_one_child(struct locomo *lchip, struct locomo_dev_info *info)
 	int ret;
 
 	dev = kzalloc_obj(struct locomo_dev);
-	if (!dev) {
-		ret = -ENOMEM;
-		goto out;
-	}
+	if (!dev)
+		return -ENOMEM;
 
 	/*
 	 * If the parent device has a DMA mask associated with it,
@@ -255,10 +253,11 @@ locomo_init_one_child(struct locomo *lchip, struct locomo_dev_info *info)
 
 	ret = device_register(&dev->dev);
 	if (ret) {
- out:
-		kfree(dev);
+		put_device(&dev->dev);
+		return ret;
 	}
-	return ret;
+
+	return 0;
 }
 
 #ifdef CONFIG_PM
-- 
2.55.0.679.g6767b8d81c-goog



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 2/4] firmware/edd: use kobject_put() on edd_device_register() failure
  2026-08-10 16:28 [PATCH 0/4] Convert manual kfree(dev) to put_device() Tarun Sahu
  2026-08-10 16:28 ` [PATCH 1/4] ARM: locomo: use put_device() on device_register() failure Tarun Sahu
@ 2026-08-10 16:28 ` Tarun Sahu
  2026-08-10 16:28 ` [PATCH 3/4] EDAC/versalnet: use put_device() on device_register() failure Tarun Sahu
  2026-08-10 16:28 ` [PATCH 4/4] powerpc/ps3: use put_device() on device_register() failure in ps3_system_bus_device_register Tarun Sahu
  3 siblings, 0 replies; 5+ messages in thread
From: Tarun Sahu @ 2026-08-10 16:28 UTC (permalink / raw)
  To: Greg Kroah-Hartman, Geoff Levand, Christophe Leroy (CS GROUP),
	Nicholas Piggin, Michael Ellerman, dmatlack, Borislav Petkov,
	Madhavan Srinivasan, Shubhrajyoti Datta, djeffery, Tony Luck,
	skhawaja, Russell King, stuart.w.hayes
  Cc: linuxppc-dev, linux-arm-kernel, linux-kernel, driver-core,
	linux-edac, Tarun Sahu

When edd_device_register() fails after initializing the kobject with
kobject_init_and_add(), calling kfree(edev) directly bypasses the
kobject release callback (edd_release) and leaks the allocated kobject
resources.

Fix this by replacing direct kfree(edev) with kobject_put(&edev->kobj) on
registration failure.

Signed-off-by: Tarun Sahu <tarunsahu@google.com>
---
 drivers/firmware/edd.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/firmware/edd.c b/drivers/firmware/edd.c
index f980c5b56858..763e7b16d517 100644
--- a/drivers/firmware/edd.c
+++ b/drivers/firmware/edd.c
@@ -748,7 +748,7 @@ edd_init(void)
 
 		rc = edd_device_register(edev, i);
 		if (rc) {
-			kfree(edev);
+			kobject_put(&edev->kobj);
 			goto out;
 		}
 		edd_devices[i] = edev;
-- 
2.55.0.679.g6767b8d81c-goog



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 3/4] EDAC/versalnet: use put_device() on device_register() failure
  2026-08-10 16:28 [PATCH 0/4] Convert manual kfree(dev) to put_device() Tarun Sahu
  2026-08-10 16:28 ` [PATCH 1/4] ARM: locomo: use put_device() on device_register() failure Tarun Sahu
  2026-08-10 16:28 ` [PATCH 2/4] firmware/edd: use kobject_put() on edd_device_register() failure Tarun Sahu
@ 2026-08-10 16:28 ` Tarun Sahu
  2026-08-10 16:28 ` [PATCH 4/4] powerpc/ps3: use put_device() on device_register() failure in ps3_system_bus_device_register Tarun Sahu
  3 siblings, 0 replies; 5+ messages in thread
From: Tarun Sahu @ 2026-08-10 16:28 UTC (permalink / raw)
  To: Greg Kroah-Hartman, Geoff Levand, Christophe Leroy (CS GROUP),
	Nicholas Piggin, Michael Ellerman, dmatlack, Borislav Petkov,
	Madhavan Srinivasan, Shubhrajyoti Datta, djeffery, Tony Luck,
	skhawaja, Russell King, stuart.w.hayes
  Cc: linuxppc-dev, linux-arm-kernel, linux-kernel, driver-core,
	linux-edac, Tarun Sahu

When device_register() fails, calling kfree(dev) directly bypasses the
device_release() callback (versal_edac_release) and leaks the allocated
driver core structures.

Fix this by calling put_device(dev) when device_register() returns an
error, ensuring proper refcount decrement and release cleanup.

Signed-off-by: Tarun Sahu <tarunsahu@google.com>
---
 drivers/edac/versalnet_edac.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/edac/versalnet_edac.c b/drivers/edac/versalnet_edac.c
index 97ec05d68bbb..2912b3658915 100644
--- a/drivers/edac/versalnet_edac.c
+++ b/drivers/edac/versalnet_edac.c
@@ -829,8 +829,10 @@ static int init_one_mc(struct mc_priv *priv, struct platform_device *pdev, int i
 	dev->release = versal_edac_release;
 
 	rc = device_register(dev);
-	if (rc)
+	if (rc) {
+		put_device(dev);
 		goto err_mc_free;
+	}
 
 	mci->pdev = dev;
 	mc_init(mci, dev);
@@ -852,9 +854,9 @@ static int init_one_mc(struct mc_priv *priv, struct platform_device *pdev, int i
 	device_unregister(mci->pdev);
 err_mc_free:
 	edac_mc_free(mci);
+	return rc;
 err_dev_free:
 	kfree(dev);
-
 	return rc;
 }
 
-- 
2.55.0.679.g6767b8d81c-goog



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 4/4] powerpc/ps3: use put_device() on device_register() failure in ps3_system_bus_device_register
  2026-08-10 16:28 [PATCH 0/4] Convert manual kfree(dev) to put_device() Tarun Sahu
                   ` (2 preceding siblings ...)
  2026-08-10 16:28 ` [PATCH 3/4] EDAC/versalnet: use put_device() on device_register() failure Tarun Sahu
@ 2026-08-10 16:28 ` Tarun Sahu
  3 siblings, 0 replies; 5+ messages in thread
From: Tarun Sahu @ 2026-08-10 16:28 UTC (permalink / raw)
  To: Greg Kroah-Hartman, Geoff Levand, Christophe Leroy (CS GROUP),
	Nicholas Piggin, Michael Ellerman, dmatlack, Borislav Petkov,
	Madhavan Srinivasan, Shubhrajyoti Datta, djeffery, Tony Luck,
	skhawaja, Russell King, stuart.w.hayes
  Cc: linuxppc-dev, linux-arm-kernel, linux-kernel, driver-core,
	linux-edac, Tarun Sahu

When device_register() fails, calling put_device() ensures that the
device reference count drops to 0, which invokes the release callback
ps3_system_bus_release_device() to cleanly free the device and its
associated driver core resources.

Signed-off-by: Tarun Sahu <tarunsahu@google.com>
---
 arch/powerpc/platforms/ps3/device-init.c | 83 ++++++++++++++----------
 arch/powerpc/platforms/ps3/system-bus.c  |  2 +
 2 files changed, 52 insertions(+), 33 deletions(-)

diff --git a/arch/powerpc/platforms/ps3/device-init.c b/arch/powerpc/platforms/ps3/device-init.c
index 9109c218a060..8d0c77db1764 100644
--- a/arch/powerpc/platforms/ps3/device-init.c
+++ b/arch/powerpc/platforms/ps3/device-init.c
@@ -90,14 +90,12 @@ static int __init ps3_register_lpm_devices(void)
 	if (result) {
 		pr_debug("%s:%d ps3_system_bus_device_register failed\n",
 			__func__, __LINE__);
-		goto fail_register;
+		return result;
 	}
 
 	pr_debug(" <- %s:%d\n", __func__, __LINE__);
 	return 0;
 
-
-fail_register:
 fail_rights:
 fail_read_repo:
 	kfree(dev);
@@ -121,6 +119,12 @@ static int __init ps3_setup_gelic_device(
 		struct ps3_dma_region d_region;
 	} *p;
 
+	/*
+	 * ps3_system_bus_release_device() calls kfree(&p->dev).
+	 * dev must be at offset 0 so kfree() frees outer p.
+	 */
+	BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
 	pr_debug(" -> %s:%d\n", __func__, __LINE__);
 
 	BUG_ON(repo->bus_type != PS3_BUS_TYPE_SB);
@@ -164,13 +168,12 @@ static int __init ps3_setup_gelic_device(
 	if (result) {
 		pr_debug("%s:%d ps3_system_bus_device_register failed\n",
 			__func__, __LINE__);
-		goto fail_device_register;
+		return result;
 	}
 
 	pr_debug(" <- %s:%d\n", __func__, __LINE__);
 	return result;
 
-fail_device_register:
 fail_dma_init:
 fail_find_interrupt:
 	kfree(p);
@@ -192,6 +195,12 @@ static int __init ps3_setup_uhc_device(
 	u64 bus_addr;
 	u64 len;
 
+	/*
+	 * ps3_system_bus_release_device() calls kfree(&p->dev).
+	 * dev must be at offset 0 so kfree() frees outer p.
+	 */
+	BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
 	pr_debug(" -> %s:%d\n", __func__, __LINE__);
 
 	BUG_ON(repo->bus_type != PS3_BUS_TYPE_SB);
@@ -252,13 +261,12 @@ static int __init ps3_setup_uhc_device(
 	if (result) {
 		pr_debug("%s:%d ps3_system_bus_device_register failed\n",
 			__func__, __LINE__);
-		goto fail_device_register;
+		return result;
 	}
 
 	pr_debug(" <- %s:%d\n", __func__, __LINE__);
 	return result;
 
-fail_device_register:
 fail_mmio_init:
 fail_dma_init:
 fail_find_reg:
@@ -291,6 +299,12 @@ static int __init ps3_setup_vuart_device(enum ps3_match_id match_id,
 		struct ps3_system_bus_device dev;
 	} *p;
 
+	/*
+	 * ps3_system_bus_release_device() calls kfree(&p->dev).
+	 * dev must be at offset 0 so kfree() frees outer p.
+	 */
+	BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
 	pr_debug(" -> %s:%d: match_id %u, port %u\n", __func__, __LINE__,
 		match_id, port_number);
 
@@ -308,15 +322,10 @@ static int __init ps3_setup_vuart_device(enum ps3_match_id match_id,
 	if (result) {
 		pr_debug("%s:%d ps3_system_bus_device_register failed\n",
 			__func__, __LINE__);
-		goto fail_device_register;
+		return result;
 	}
 	pr_debug(" <- %s:%d\n", __func__, __LINE__);
 	return 0;
-
-fail_device_register:
-	kfree(p);
-	pr_debug(" <- %s:%d fail\n", __func__, __LINE__);
-	return result;
 }
 
 static int ps3_setup_storage_dev(const struct ps3_repository_device *repo,
@@ -327,6 +336,12 @@ static int ps3_setup_storage_dev(const struct ps3_repository_device *repo,
 	u64 port, blk_size, num_blocks;
 	unsigned int num_regions, i;
 
+	/*
+	 * ps3_system_bus_release_device() calls kfree(&p->sbd).
+	 * sbd must be at offset 0 so kfree() frees outer p.
+	 */
+	BUILD_BUG_ON(offsetof(struct ps3_storage_device, sbd) != 0);
+
 	pr_debug(" -> %s:%u: match_id %u\n", __func__, __LINE__, match_id);
 
 	result = ps3_repository_read_stor_dev_info(repo->bus_index,
@@ -395,13 +410,12 @@ static int ps3_setup_storage_dev(const struct ps3_repository_device *repo,
 	if (result) {
 		pr_debug("%s:%u ps3_system_bus_device_register failed\n",
 			 __func__, __LINE__);
-		goto fail_device_register;
+		return result;
 	}
 
 	pr_debug(" <- %s:%u\n", __func__, __LINE__);
 	return 0;
 
-fail_device_register:
 fail_read_region:
 fail_find_interrupt:
 	kfree(p);
@@ -445,6 +459,12 @@ static int __init ps3_register_sound_devices(void)
 		struct ps3_mmio_region m_region;
 	} *p;
 
+	/*
+	 * ps3_system_bus_release_device() calls kfree(&p->dev).
+	 * dev must be at offset 0 so kfree() frees outer p.
+	 */
+	BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
 	pr_debug(" -> %s:%d\n", __func__, __LINE__);
 
 	p = kzalloc_obj(*p);
@@ -461,15 +481,10 @@ static int __init ps3_register_sound_devices(void)
 	if (result) {
 		pr_debug("%s:%d ps3_system_bus_device_register failed\n",
 			__func__, __LINE__);
-		goto fail_device_register;
+		return result;
 	}
 	pr_debug(" <- %s:%d\n", __func__, __LINE__);
 	return 0;
-
-fail_device_register:
-	kfree(p);
-	pr_debug(" <- %s:%d failed\n", __func__, __LINE__);
-	return result;
 }
 
 static int __init ps3_register_graphics_devices(void)
@@ -479,6 +494,12 @@ static int __init ps3_register_graphics_devices(void)
 		struct ps3_system_bus_device dev;
 	} *p;
 
+	/*
+	 * ps3_system_bus_release_device() calls kfree(&p->dev).
+	 * dev must be at offset 0 so kfree() frees outer p.
+	 */
+	BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
 	pr_debug(" -> %s:%d\n", __func__, __LINE__);
 
 	p = kzalloc_obj(struct layout);
@@ -495,16 +516,11 @@ static int __init ps3_register_graphics_devices(void)
 	if (result) {
 		pr_debug("%s:%d ps3_system_bus_device_register failed\n",
 			__func__, __LINE__);
-		goto fail_device_register;
+		return result;
 	}
 
 	pr_debug(" <- %s:%d\n", __func__, __LINE__);
 	return 0;
-
-fail_device_register:
-	kfree(p);
-	pr_debug(" <- %s:%d failed\n", __func__, __LINE__);
-	return result;
 }
 
 static int __init ps3_register_ramdisk_device(void)
@@ -514,6 +530,12 @@ static int __init ps3_register_ramdisk_device(void)
 		struct ps3_system_bus_device dev;
 	} *p;
 
+	/*
+	 * ps3_system_bus_release_device() calls kfree(&p->dev).
+	 * dev must be at offset 0 so kfree() frees outer p.
+	 */
+	BUILD_BUG_ON(offsetof(struct layout, dev) != 0);
+
 	pr_debug(" -> %s:%d\n", __func__, __LINE__);
 
 	p = kzalloc_obj(struct layout);
@@ -530,16 +552,11 @@ static int __init ps3_register_ramdisk_device(void)
 	if (result) {
 		pr_debug("%s:%d ps3_system_bus_device_register failed\n",
 			__func__, __LINE__);
-		goto fail_device_register;
+		return result;
 	}
 
 	pr_debug(" <- %s:%d\n", __func__, __LINE__);
 	return 0;
-
-fail_device_register:
-	kfree(p);
-	pr_debug(" <- %s:%d failed\n", __func__, __LINE__);
-	return result;
 }
 
 /**
diff --git a/arch/powerpc/platforms/ps3/system-bus.c b/arch/powerpc/platforms/ps3/system-bus.c
index 0537a678a32f..0918c74d3e19 100644
--- a/arch/powerpc/platforms/ps3/system-bus.c
+++ b/arch/powerpc/platforms/ps3/system-bus.c
@@ -774,6 +774,8 @@ int ps3_system_bus_device_register(struct ps3_system_bus_device *dev)
 	pr_debug("%s:%d add %s\n", __func__, __LINE__, dev_name(&dev->core));
 
 	result = device_register(&dev->core);
+	if (result)
+		put_device(&dev->core);
 	return result;
 }
 
-- 
2.55.0.679.g6767b8d81c-goog



^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-08-10 16:35 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-10 16:28 [PATCH 0/4] Convert manual kfree(dev) to put_device() Tarun Sahu
2026-08-10 16:28 ` [PATCH 1/4] ARM: locomo: use put_device() on device_register() failure Tarun Sahu
2026-08-10 16:28 ` [PATCH 2/4] firmware/edd: use kobject_put() on edd_device_register() failure Tarun Sahu
2026-08-10 16:28 ` [PATCH 3/4] EDAC/versalnet: use put_device() on device_register() failure Tarun Sahu
2026-08-10 16:28 ` [PATCH 4/4] powerpc/ps3: use put_device() on device_register() failure in ps3_system_bus_device_register Tarun Sahu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox