From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from out-180.mta0.migadu.com (out-180.mta0.migadu.com [91.218.175.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 339CF3BE644 for ; Fri, 7 Aug 2026 08:09:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.180 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786090158; cv=none; b=ekAzDnE6bHd8e/c+BYOXyqoqN6F2Ip7hzDUUlUd81Dr01m3c3v72TK9039S1UUoatCgV3R4MsC6PBgKBJdBjHh8xsEybvV4yNjY8+MKiABfdARas7tpPu34piS5cEAjBkQSkkIpyNPEaSmDPNJP6EICbHJVskswPlSlrALsyZZc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786090158; c=relaxed/simple; bh=uGyD+TovFB5XBQBNeQxUpioGXyDA5F713e7BT6uAjnY=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Kn0cp/xz26sObfCiAbz9IJm25iFkgwOBbrYX/zOQlWpDYHyZyBex2kg1NtlOvggkpCQ2Fv/8C1C7v1JGeuoeNqSuHtoGbZMoB6eUMo8Cth3QodHMhNQsgw7ZYhEAHMXSBTcDJ51OzTtu33YCxPjplUWA+VXpaAauv40/xRK5BLs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=P3iy2IMG; arc=none smtp.client-ip=91.218.175.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="P3iy2IMG" X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1786090152; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=OLApd8O0C0ZNoJJX5e81sYqyCBasqXIso5bBazmCshc=; b=P3iy2IMGVL/hokyZ2bDPeg1E+gnPIamfQdlf1NUf3xOvhdWpoyrctMMCRJCirOEExBSkAn /LYv+RqHSzSSHPNfpM/VUTkXYC5L96SF2TOkPTYbKIGFqIibE0GonqtwhtsjnDrTiSPENC mRrGAroT+sV67lOOZsPc12JE63ih+6k= From: Atish Patra Date: Fri, 07 Aug 2026 01:08:56 -0700 Subject: [PATCH v9 01/20] RISC-V: perf: fix resource cleanup on driver probe failure Precedence: bulk X-Mailing-List: devicetree@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260807-counter_delegation-v9-1-58658104e487@meta.com> References: <20260807-counter_delegation-v9-0-58658104e487@meta.com> In-Reply-To: <20260807-counter_delegation-v9-0-58658104e487@meta.com> To: Will Deacon , Atish Patra , Arnaldo Carvalho de Melo , Anup Patel , Ian Rogers , Rob Herring , Paul Walmsley , Mark Rutland , Jiri Olsa , Krzysztof Kozlowski , James Clark , Namhyung Kim Cc: linux-riscv@lists.infradead.org, linux-arm-kernel@lists.infradead.org, Conor Dooley , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, devicetree@vger.kernel.org X-Migadu-Flow: FLOW_OUT From: Atish Patra Sashiko pointed out various UAF and memory leak issues around pmu_sbi_device_probe() error paths. If the probe fails, here are list of cleanups needed. a. Already registered pmu must be freed b. per cpu IRQ must be released c. pmu_ctr_list data structure must be freed d. cpu hotplug state must be cleaned up only if added. Fix the resource cleanup by reorganizing the code around probe failure. Reported-by: Sashiko AI Link: https://patch.msgid.link/20260701-counter_delegation-v8-1-7909f863a645@meta.com Signed-off-by: Paul Walmsley Reviewed-by: Charlie Jenkins Signed-off-by: Atish Patra --- drivers/perf/riscv_pmu_sbi.c | 33 +++++++++++++++++++++++++++------ 1 file changed, 27 insertions(+), 6 deletions(-) diff --git a/drivers/perf/riscv_pmu_sbi.c b/drivers/perf/riscv_pmu_sbi.c index dfc886dee5ad..50220f7b46d9 100644 --- a/drivers/perf/riscv_pmu_sbi.c +++ b/drivers/perf/riscv_pmu_sbi.c @@ -1219,22 +1219,29 @@ static int pmu_sbi_setup_irqs(struct riscv_pmu *pmu, struct platform_device *pde DOMAIN_BUS_ANY); if (!domain) { pr_err("Failed to find INTC IRQ root domain\n"); - return -ENODEV; + ret = -ENODEV; + goto err; } riscv_pmu_irq = irq_create_mapping(domain, riscv_pmu_irq_num); if (!riscv_pmu_irq) { pr_err("Failed to map PMU interrupt for node\n"); - return -ENODEV; + ret = -ENODEV; + goto err; } ret = request_percpu_irq(riscv_pmu_irq, pmu_sbi_ovf_handler, "riscv-pmu", hw_events); if (ret) { pr_err("registering percpu irq failed [%d]\n", ret); - return ret; + irq_dispose_mapping(riscv_pmu_irq); + riscv_pmu_irq = 0; + goto err; } return 0; +err: + riscv_pmu_use_irq = false; + return ret; } #ifdef CONFIG_CPU_PM @@ -1301,7 +1308,8 @@ static void riscv_pmu_destroy(struct riscv_pmu *pmu) } } riscv_pm_pmu_unregister(pmu); - cpuhp_state_remove_instance(CPUHP_AP_PERF_RISCV_STARTING, &pmu->node); + if (!hlist_unhashed(&pmu->node)) + cpuhp_state_remove_instance(CPUHP_AP_PERF_RISCV_STARTING, &pmu->node); } static void pmu_sbi_event_init(struct perf_event *event) @@ -1423,6 +1431,7 @@ static int pmu_sbi_device_probe(struct platform_device *pdev) struct riscv_pmu *pmu = NULL; int ret = -ENODEV; int num_counters; + bool irq_requested = false; pr_info("SBI PMU extension is available\n"); pmu = riscv_pmu_alloc(); @@ -1451,6 +1460,7 @@ static int pmu_sbi_device_probe(struct platform_device *pdev) pmu->pmu.capabilities |= PERF_PMU_CAP_NO_INTERRUPT; pmu->pmu.capabilities |= PERF_PMU_CAP_NO_EXCLUDE; } + irq_requested = (ret == 0); pmu->pmu.attr_groups = riscv_pmu_attr_groups; pmu->pmu.parent = &pdev->dev; @@ -1469,11 +1479,11 @@ static int pmu_sbi_device_probe(struct platform_device *pdev) ret = riscv_pm_pmu_register(pmu); if (ret) - goto out_unregister; + goto out_destroy; ret = perf_pmu_register(&pmu->pmu, "cpu", PERF_TYPE_RAW); if (ret) - goto out_unregister; + goto out_destroy; /* SBI PMU Snapsphot is only available in SBI v2.0 */ if (sbi_v2_available) { @@ -1514,9 +1524,20 @@ static int pmu_sbi_device_probe(struct platform_device *pdev) return 0; out_unregister: + perf_pmu_unregister(&pmu->pmu); + +out_destroy: riscv_pmu_destroy(pmu); + if (irq_requested) { + free_percpu_irq(riscv_pmu_irq, pmu->hw_events); + irq_dispose_mapping(riscv_pmu_irq); + riscv_pmu_irq = 0; + } out_free: + free_percpu(pmu->hw_events); + kfree(pmu_ctr_list); + pmu_ctr_list = NULL; kfree(pmu); return ret; } -- 2.53.0-Meta