From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 82B09C79F87 for ; Fri, 4 Sep 2026 17:16:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Type:Cc:To:From: Subject:Message-ID:References:Mime-Version:In-Reply-To:Date:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=NikJEXjNYjtOdRdsXEH0yQrsx5J1yuBuYOZC90aY1Z4=; b=Bh9qswAN9xCSqWjarQWsKqXxdR ejjPup/J4ftaSEOr2pckF8Zs37apRmVUC6sXTGBeNiDg3bfAgBCDJG6lUHgKbMObUgNUlBPOuDsGw Zw6piVMcv+Wjo3YdSVu8iWbbjin2y7wpWD/6K3ZtUS30E1mlxsrnpY2DfqNLbafaXN2jzYppjw0HY i8djl1xCc7P/X1J0JeoqNQi7OHWXzBzfSeJVpHwE+h29Cr8f1but+iSW/5DyLeZ+Y0HT2nM4xOoVK uTNGnsa7yvz4UbezrMba5+0hUOijmmtoQAByuF5zulDS/ED1r4DuO2iaQE9snYIKKp4xYMERuQEjR /NO5grEg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x2XWa-00000002qKy-18kB; Fri, 04 Sep 2026 17:16:24 +0000 Received: from mail-ed1-x548.google.com ([2a00:1450:4864:20::548]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1x2XWV-00000002qIB-0KKI for linux-arm-kernel@lists.infradead.org; Fri, 04 Sep 2026 17:16:20 +0000 Received: by mail-ed1-x548.google.com with SMTP id 4fb4d7f45d1cf-6a6735afb87so1167530a12.2 for ; Fri, 04 Sep 2026 10:16:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788542177; x=1789146977; darn=lists.infradead.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=NikJEXjNYjtOdRdsXEH0yQrsx5J1yuBuYOZC90aY1Z4=; b=dd/2n14PJzHn+fl5EuG3+k5mm7Y8Ki3LnhZWw1qJJtAmeaCU6Jaz5bxVDm4vswnhQ/ zj8uEN7J2Ow60rzfF+eTf33PSfD+oBbiYSPCfHSU1OPQ838CGRO8ac9hx7gyuVN3tedo nNkJgSDSyDape1bxQIvvUrFZuhVOjhCr+0H8jvRvM+tQl+AOL0v/4F/2WUZCF2my/r2b NQJO2smgZTcGko2lPV4kl5AlA3pH1lbKWxI65880raNZv01wyAC+oIHNRmq2RGBx8OQO pqZ3yqmtPZAN8JTACO803ZDunJ6U2WGh3d0IJ9PHLg6SpATcy7TkCGBe3YuDIT3mgE7z kd+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788542177; x=1789146977; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NikJEXjNYjtOdRdsXEH0yQrsx5J1yuBuYOZC90aY1Z4=; b=HXkEkmYX2Pci0enuToKUiIvlC7VuXvA1swNOifUVRs361Ds5D14k8kyHhBPeE9Q9XC tXTR9Q5/g0VOAebi/hsz8hKnYtiV/ZOq2Zveczxcdm0sMJmlVDY3XWeV2kSfE+rG59uf V20YmU65mOEfYErFNUiIPuJhXx/elJyQ2IRFflFINrYzPW1/QBBP4IxzDQwuk5FUjN00 Rpl3PHzp5Tsvq0KQnEJU9WMBQo4/KvZt/HK1oQDTgQNEzpY+2J24HUjKjbHK1u2LO1Hn vMkUPXfLeluleGs9mLRl3dIpbMaQ4NFIG4IYjshg6e7j20T2H2M8R70xKfiNoUzEF/af Z41g== X-Forwarded-Encrypted: i=1; AKwUvBy5FfrRGXS1kcBocZScp+e/cvvj0QALLZ64F74EbWPr5iPVHU8bvEjWG3aKev0R5UU4s01cHGRV7a5obPm4LL42@lists.infradead.org X-Gm-Message-State: AFuF++mx7GLf//5iIwZVkCTUXSgehI0GYa8aNh3LnaNT087F6ThcIwur wkFf0sbFQQWaCgwtab3w8dlum7itNSxVorwspzU7DF+/xj1G6Jl+EJVho1jeItlvz7Fuwtd6Rld nJN82HaUHeMRK2n86xw== X-Received: from edfy24.prod.google.com ([2002:a05:6402:a3d8:b0:6a7:e348:5a70]) (user=tarunsahu job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6402:a256:20b0:6a7:ee54:f8a6 with SMTP id 4fb4d7f45d1cf-6a7ee55000fmr1421309a12.42.1788542176533; Fri, 04 Sep 2026 10:16:16 -0700 (PDT) Date: Fri, 4 Sep 2026 17:16:09 +0000 In-Reply-To: <20260904171610.3342398-1-tarunsahu@google.com> Mime-Version: 1.0 References: <20260904171610.3342398-1-tarunsahu@google.com> X-Mailer: git-send-email 2.55.0.979.g7e5102b832-goog Message-ID: <20260904171610.3342398-4-tarunsahu@google.com> Subject: [PATCH v4 3/3] powerpc/ps3: use put_device() on device_register() failure in ps3_system_bus_device_register From: Tarun Sahu To: Russell King , Geoff Levand , Masakazu Mokuno , "Christophe Leroy (CS GROUP)" , Madhavan Srinivasan , Michael Ellerman , Paul Mackerras , helgaas@kernel.org, Nicholas Piggin , sourabhjain@linux.ibm.com Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, Tarun Sahu Content-Type: text/plain; charset="UTF-8" X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260904_101619_155409_DFF06AFB X-CRM114-Status: GOOD ( 18.23 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org As per the kernel documentation of device_register() function, it is important to call put_device even if device_register returns an error. To follow this guidelines and properly release the resources after device_register() failure, call put_device() instead of kfree() Also there are in-function-defined struct layout which make struct device (core) to be child of layout-child's member (layout.dev.core). Also definition of struct layout is not unique across functions in the driver. To be able to free struct layout's dynamic allocation via put_device we need to make sure that the core's release function must call the free on parent of core and the parent must be at the location 0 of the struct layout which will inherently free struct layout. This is to not complicate the code and keep it as it currently implemented. To check the location of parent at 0 of struct layout, I have added BUILD_BUG_ON. Fixes: d4ad304841a9 ("powerpc/ps3: Fix memory leak in device init") Reviewed-by: Sourabh Jain Signed-off-by: Tarun Sahu --- arch/powerpc/platforms/ps3/device-init.c | 83 ++++++++++++++---------- arch/powerpc/platforms/ps3/system-bus.c | 2 + 2 files changed, 52 insertions(+), 33 deletions(-) diff --git a/arch/powerpc/platforms/ps3/device-init.c b/arch/powerpc/platforms/ps3/device-init.c index 9109c218a060..8d0c77db1764 100644 --- a/arch/powerpc/platforms/ps3/device-init.c +++ b/arch/powerpc/platforms/ps3/device-init.c @@ -90,14 +90,12 @@ static int __init ps3_register_lpm_devices(void) if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_register; + return result; } pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; - -fail_register: fail_rights: fail_read_repo: kfree(dev); @@ -121,6 +119,12 @@ static int __init ps3_setup_gelic_device( struct ps3_dma_region d_region; } *p; + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) != 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); BUG_ON(repo->bus_type != PS3_BUS_TYPE_SB); @@ -164,13 +168,12 @@ static int __init ps3_setup_gelic_device( if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } pr_debug(" <- %s:%d\n", __func__, __LINE__); return result; -fail_device_register: fail_dma_init: fail_find_interrupt: kfree(p); @@ -192,6 +195,12 @@ static int __init ps3_setup_uhc_device( u64 bus_addr; u64 len; + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) != 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); BUG_ON(repo->bus_type != PS3_BUS_TYPE_SB); @@ -252,13 +261,12 @@ static int __init ps3_setup_uhc_device( if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } pr_debug(" <- %s:%d\n", __func__, __LINE__); return result; -fail_device_register: fail_mmio_init: fail_dma_init: fail_find_reg: @@ -291,6 +299,12 @@ static int __init ps3_setup_vuart_device(enum ps3_match_id match_id, struct ps3_system_bus_device dev; } *p; + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) != 0); + pr_debug(" -> %s:%d: match_id %u, port %u\n", __func__, __LINE__, match_id, port_number); @@ -308,15 +322,10 @@ static int __init ps3_setup_vuart_device(enum ps3_match_id match_id, if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; - -fail_device_register: - kfree(p); - pr_debug(" <- %s:%d fail\n", __func__, __LINE__); - return result; } static int ps3_setup_storage_dev(const struct ps3_repository_device *repo, @@ -327,6 +336,12 @@ static int ps3_setup_storage_dev(const struct ps3_repository_device *repo, u64 port, blk_size, num_blocks; unsigned int num_regions, i; + /* + * ps3_system_bus_release_device() calls kfree(&p->sbd). + * sbd must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct ps3_storage_device, sbd) != 0); + pr_debug(" -> %s:%u: match_id %u\n", __func__, __LINE__, match_id); result = ps3_repository_read_stor_dev_info(repo->bus_index, @@ -395,13 +410,12 @@ static int ps3_setup_storage_dev(const struct ps3_repository_device *repo, if (result) { pr_debug("%s:%u ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } pr_debug(" <- %s:%u\n", __func__, __LINE__); return 0; -fail_device_register: fail_read_region: fail_find_interrupt: kfree(p); @@ -445,6 +459,12 @@ static int __init ps3_register_sound_devices(void) struct ps3_mmio_region m_region; } *p; + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) != 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); p = kzalloc_obj(*p); @@ -461,15 +481,10 @@ static int __init ps3_register_sound_devices(void) if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; - -fail_device_register: - kfree(p); - pr_debug(" <- %s:%d failed\n", __func__, __LINE__); - return result; } static int __init ps3_register_graphics_devices(void) @@ -479,6 +494,12 @@ static int __init ps3_register_graphics_devices(void) struct ps3_system_bus_device dev; } *p; + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) != 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); p = kzalloc_obj(struct layout); @@ -495,16 +516,11 @@ static int __init ps3_register_graphics_devices(void) if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; - -fail_device_register: - kfree(p); - pr_debug(" <- %s:%d failed\n", __func__, __LINE__); - return result; } static int __init ps3_register_ramdisk_device(void) @@ -514,6 +530,12 @@ static int __init ps3_register_ramdisk_device(void) struct ps3_system_bus_device dev; } *p; + /* + * ps3_system_bus_release_device() calls kfree(&p->dev). + * dev must be at offset 0 so kfree() frees outer p. + */ + BUILD_BUG_ON(offsetof(struct layout, dev) != 0); + pr_debug(" -> %s:%d\n", __func__, __LINE__); p = kzalloc_obj(struct layout); @@ -530,16 +552,11 @@ static int __init ps3_register_ramdisk_device(void) if (result) { pr_debug("%s:%d ps3_system_bus_device_register failed\n", __func__, __LINE__); - goto fail_device_register; + return result; } pr_debug(" <- %s:%d\n", __func__, __LINE__); return 0; - -fail_device_register: - kfree(p); - pr_debug(" <- %s:%d failed\n", __func__, __LINE__); - return result; } /** diff --git a/arch/powerpc/platforms/ps3/system-bus.c b/arch/powerpc/platforms/ps3/system-bus.c index 0537a678a32f..0918c74d3e19 100644 --- a/arch/powerpc/platforms/ps3/system-bus.c +++ b/arch/powerpc/platforms/ps3/system-bus.c @@ -774,6 +774,8 @@ int ps3_system_bus_device_register(struct ps3_system_bus_device *dev) pr_debug("%s:%d add %s\n", __func__, __LINE__, dev_name(&dev->core)); result = device_register(&dev->core); + if (result) + put_device(&dev->core); return result; } -- 2.55.0.979.g7e5102b832-goog