* [PATCH v2] pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map()
@ 2024-04-18 11:34 Zeng Heng
2024-04-18 11:41 ` Andy Shevchenko
0 siblings, 1 reply; 3+ messages in thread
From: Zeng Heng @ 2024-04-18 11:34 UTC (permalink / raw)
To: linus.walleij, dan.carpenter, andriy.shevchenko
Cc: linux-gpio, linux-kernel, liwei391
If we fail to allocate propname buffer, we need to drop the reference
count we just took, otherwise it will lead reference leak. Here the
error exit path is modified to jump to the err label and call
pinctrl_dt_free_maps() which would drop the counter.
In the meantime, if it is found that the property 'pinctrl-0' is not
present, ENODEV is returned and also jump to the err label and call the
free function, in case the Smatch tool complains.
Fixes: 91d5c5060ee2 ("pinctrl: devicetree: fix null pointer dereferencing in pinctrl_dt_to_map")
Suggested-by: Dan Carpenter <dan.carpenter@linaro.org>
Signed-off-by: Zeng Heng <zengheng4@huawei.com>
---
drivers/pinctrl/devicetree.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/pinctrl/devicetree.c b/drivers/pinctrl/devicetree.c
index df1efc2e5202..37069e40af2b 100644
--- a/drivers/pinctrl/devicetree.c
+++ b/drivers/pinctrl/devicetree.c
@@ -220,14 +220,17 @@ int pinctrl_dt_to_map(struct pinctrl *p, struct pinctrl_dev *pctldev)
for (state = 0; ; state++) {
/* Retrieve the pinctrl-* property */
propname = kasprintf(GFP_KERNEL, "pinctrl-%d", state);
- if (!propname)
- return -ENOMEM;
+ if (!propname) {
+ ret = -ENOMEM;
+ goto err;
+ }
prop = of_find_property(np, propname, &size);
kfree(propname);
if (!prop) {
if (state == 0) {
- of_node_put(np);
- return -ENODEV;
+ /* Return -ENODEV if the property 'pinctrl-0' is not present. */
+ ret = -ENODEV;
+ goto err;
}
break;
}
--
2.25.1
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH v2] pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map()
2024-04-18 11:34 [PATCH v2] pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() Zeng Heng
@ 2024-04-18 11:41 ` Andy Shevchenko
2024-04-18 11:54 ` Zeng Heng
0 siblings, 1 reply; 3+ messages in thread
From: Andy Shevchenko @ 2024-04-18 11:41 UTC (permalink / raw)
To: Zeng Heng
Cc: linus.walleij, dan.carpenter, linux-gpio, linux-kernel, liwei391
On Thu, Apr 18, 2024 at 07:34:59PM +0800, Zeng Heng wrote:
> If we fail to allocate propname buffer, we need to drop the reference
> count we just took, otherwise it will lead reference leak. Here the
> error exit path is modified to jump to the err label and call
> pinctrl_dt_free_maps() which would drop the counter.
>
> In the meantime, if it is found that the property 'pinctrl-0' is not
> present, ENODEV is returned and also jump to the err label and call the
> free function, in case the Smatch tool complains.
> ---
You forgot a changelog, but I think this needs to be a followup.
--
With Best Regards,
Andy Shevchenko
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v2] pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map()
2024-04-18 11:41 ` Andy Shevchenko
@ 2024-04-18 11:54 ` Zeng Heng
0 siblings, 0 replies; 3+ messages in thread
From: Zeng Heng @ 2024-04-18 11:54 UTC (permalink / raw)
To: Andy Shevchenko
Cc: linus.walleij, dan.carpenter, linux-gpio, linux-kernel, liwei391
在 2024/4/18 19:41, Andy Shevchenko 写道:
> On Thu, Apr 18, 2024 at 07:34:59PM +0800, Zeng Heng wrote:
>> If we fail to allocate propname buffer, we need to drop the reference
>> count we just took, otherwise it will lead reference leak. Here the
>> error exit path is modified to jump to the err label and call
>> pinctrl_dt_free_maps() which would drop the counter.
>>
>> In the meantime, if it is found that the property 'pinctrl-0' is not
>> present, ENODEV is returned and also jump to the err label and call the
>> free function, in case the Smatch tool complains.
>> ---
> You forgot a changelog, but I think this needs to be a followup.
Oops, the resend patch would come soon.
Thanks,
Zeng Heng
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2024-04-18 11:54 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-04-18 11:34 [PATCH v2] pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() Zeng Heng
2024-04-18 11:41 ` Andy Shevchenko
2024-04-18 11:54 ` Zeng Heng
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox