* [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths @ 2026-08-24 9:05 liupeng 2026-08-24 9:12 ` sashiko-bot 2026-09-17 22:10 ` lyude 0 siblings, 2 replies; 11+ messages in thread From: liupeng @ 2026-08-24 9:05 UTC (permalink / raw) To: Lyude Paul, Danilo Krummrich, Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann, David Airlie, Simona Vetter, Guenter Roeck, open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS, open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS, open list, open list:HARDWARE MONITORING:Keyword:(devm_)?hwmon_device_(un)?register(|_with_groups|_with_info) Cc: liupeng In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously allocated drm->debugfs is leaked because the function returns the error code directly. In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, the allocated hwmon structure is leaked because the function returns the error code directly. Fix both by freeing the allocated memory and clearing the pointer on the error paths. Signed-off-by: liupeng <liupeng01@kylinos.cn> --- drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++--- drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++ 2 files changed, 14 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c index 47d5579c568d..88223931f382 100644 --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c @@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor *minor) int nouveau_debugfs_init(struct nouveau_drm *drm) { + int ret; + drm->debugfs = kzalloc_obj(*drm->debugfs); if (!drm->debugfs) return -ENOMEM; - return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0, - NVIF_CLASS_CONTROL, NULL, 0, - &drm->debugfs->ctrl); + ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0, + NVIF_CLASS_CONTROL, NULL, 0, + &drm->debugfs->ctrl); + if (ret) { + kfree(drm->debugfs); + drm->debugfs = NULL; + return ret; + } + + return 0; } void diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c index 726397ab035d..ffbe7f542ab0 100644 --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev) if (IS_ERR(hwmon_dev)) { ret = PTR_ERR(hwmon_dev); NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret); + drm->hwmon = NULL; + kfree(hwmon); return ret; } -- 2.53.0 ^ permalink raw reply related [flat|nested] 11+ messages in thread
* Re: [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-08-24 9:05 [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths liupeng @ 2026-08-24 9:12 ` sashiko-bot 2026-09-17 22:10 ` lyude 1 sibling, 0 replies; 11+ messages in thread From: sashiko-bot @ 2026-08-24 9:12 UTC (permalink / raw) To: liupeng; +Cc: linux-hwmon, dri-devel > In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously > allocated drm->debugfs is leaked because the function returns the > error code directly. > > In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, > the allocated hwmon structure is leaked because the function returns > the error code directly. > > Fix both by freeing the allocated memory and clearing the pointer on > the error paths. > > Signed-off-by: liupeng <liupeng01@kylinos.cn> Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review · https://sashiko.dev/#/patchset/20260824090505.49913-1-liupeng01@kylinos.cn?part=1 ^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-08-24 9:05 [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths liupeng 2026-08-24 9:12 ` sashiko-bot @ 2026-09-17 22:10 ` lyude 2026-09-22 4:40 ` [PATCH v2] " liupeng 1 sibling, 1 reply; 11+ messages in thread From: lyude @ 2026-09-17 22:10 UTC (permalink / raw) To: liupeng, Danilo Krummrich, Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann, David Airlie, Simona Vetter, Guenter Roeck, open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS, open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS, open list, open list:HARDWARE MONITORING:Keyword:(devm_)?hwmon_device_(un)?register(|_with_groups|_with_info) Mind adding the proper Fixes: tags and Cc: tags here? On Mon, 2026-08-24 at 17:05 +0800, liupeng wrote: > In nouveau_debugfs_init(), if nvif_object_ctor() fails, the > previously > allocated drm->debugfs is leaked because the function returns the > error code directly. > > In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, > the allocated hwmon structure is leaked because the function returns > the error code directly. > > Fix both by freeing the allocated memory and clearing the pointer on > the error paths. > > Signed-off-by: liupeng <liupeng01@kylinos.cn> > --- > drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++--- > drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++ > 2 files changed, 14 insertions(+), 3 deletions(-) > > diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c > b/drivers/gpu/drm/nouveau/nouveau_debugfs.c > index 47d5579c568d..88223931f382 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c > +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c > @@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor > *minor) > int > nouveau_debugfs_init(struct nouveau_drm *drm) > { > + int ret; > + > drm->debugfs = kzalloc_obj(*drm->debugfs); > if (!drm->debugfs) > return -ENOMEM; > > - return nvif_object_ctor(&drm->client.device.object, > "debugfsCtrl", 0, > - NVIF_CLASS_CONTROL, NULL, 0, > - &drm->debugfs->ctrl); > + ret = nvif_object_ctor(&drm->client.device.object, > "debugfsCtrl", 0, > + NVIF_CLASS_CONTROL, NULL, 0, > + &drm->debugfs->ctrl); > + if (ret) { > + kfree(drm->debugfs); > + drm->debugfs = NULL; > + return ret; > + } > + > + return 0; > } > > void > diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c > b/drivers/gpu/drm/nouveau/nouveau_hwmon.c > index 726397ab035d..ffbe7f542ab0 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c > +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c > @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev) > if (IS_ERR(hwmon_dev)) { > ret = PTR_ERR(hwmon_dev); > NV_ERROR(drm, "Unable to register hwmon device: > %d\n", ret); > + drm->hwmon = NULL; > + kfree(hwmon); > return ret; > } > ^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v2] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-09-17 22:10 ` lyude @ 2026-09-22 4:40 ` liupeng 2026-09-22 4:46 ` sashiko-bot 2026-10-08 21:45 ` lyude 0 siblings, 2 replies; 11+ messages in thread From: liupeng @ 2026-09-22 4:40 UTC (permalink / raw) To: lyude, dakr Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux, nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon, stable, liupeng In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously allocated drm->debugfs is leaked because the function returns the error code directly. In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, the allocated hwmon structure is leaked because the function returns the error code directly. Fix both by freeing the allocated memory and clearing the pointer on the error paths. Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs") Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM") Cc: stable@vger.kernel.org Signed-off-by: liupeng <liupeng01@kylinos.cn> --- Changes in v2: - Add Fixes: tags for the commits that introduced the leaks - Add Cc: stable@vger.kernel.org for stable backporting drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++--- drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++ 2 files changed, 14 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c index 47d5579c568d..88223931f382 100644 --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c @@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor *minor) int nouveau_debugfs_init(struct nouveau_drm *drm) { + int ret; + drm->debugfs = kzalloc_obj(*drm->debugfs); if (!drm->debugfs) return -ENOMEM; - return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0, - NVIF_CLASS_CONTROL, NULL, 0, - &drm->debugfs->ctrl); + ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0, + NVIF_CLASS_CONTROL, NULL, 0, + &drm->debugfs->ctrl); + if (ret) { + kfree(drm->debugfs); + drm->debugfs = NULL; + return ret; + } + + return 0; } void diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c index 726397ab035d..ffbe7f542ab0 100644 --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev) if (IS_ERR(hwmon_dev)) { ret = PTR_ERR(hwmon_dev); NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret); + drm->hwmon = NULL; + kfree(hwmon); return ret; } -- 2.53.0 ^ permalink raw reply related [flat|nested] 11+ messages in thread
* Re: [PATCH v2] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-09-22 4:40 ` [PATCH v2] " liupeng @ 2026-09-22 4:46 ` sashiko-bot 2026-10-08 21:45 ` lyude 1 sibling, 0 replies; 11+ messages in thread From: sashiko-bot @ 2026-09-22 4:46 UTC (permalink / raw) To: liupeng; +Cc: linux-hwmon, dri-devel > In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously > allocated drm->debugfs is leaked because the function returns the > error code directly. > > In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, > the allocated hwmon structure is leaked because the function returns > the error code directly. > > Fix both by freeing the allocated memory and clearing the pointer on > the error paths. > > Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs") > Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM") > Cc: stable@vger.kernel.org > Signed-off-by: liupeng <liupeng01@kylinos.cn> Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review · https://sashiko.dev/#/patchset/20260922044044.21442-1-liupeng01@kylinos.cn?part=1 ^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH v2] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-09-22 4:40 ` [PATCH v2] " liupeng 2026-09-22 4:46 ` sashiko-bot @ 2026-10-08 21:45 ` lyude 2026-10-09 11:51 ` [PATCH v3] " liupeng 1 sibling, 1 reply; 11+ messages in thread From: lyude @ 2026-10-08 21:45 UTC (permalink / raw) To: liupeng, dakr Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux, nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon, stable One nit-pick below: On Tue, 2026-09-22 at 12:40 +0800, liupeng wrote: > In nouveau_debugfs_init(), if nvif_object_ctor() fails, the > previously > allocated drm->debugfs is leaked because the function returns the > error code directly. > > In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, > the allocated hwmon structure is leaked because the function returns > the error code directly. > > Fix both by freeing the allocated memory and clearing the pointer on > the error paths. > > Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for > debugfs") > Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except > the hwmon interfaces to THERM") > Cc: stable@vger.kernel.org > Signed-off-by: liupeng <liupeng01@kylinos.cn> > --- > Changes in v2: > - Add Fixes: tags for the commits that introduced the leaks > - Add Cc: stable@vger.kernel.org for stable backporting > > drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++--- > drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++ > 2 files changed, 14 insertions(+), 3 deletions(-) > > diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c > b/drivers/gpu/drm/nouveau/nouveau_debugfs.c > index 47d5579c568d..88223931f382 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c > +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c > @@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor > *minor) > int > nouveau_debugfs_init(struct nouveau_drm *drm) > { > + int ret; > + > drm->debugfs = kzalloc_obj(*drm->debugfs); > if (!drm->debugfs) > return -ENOMEM; > > - return nvif_object_ctor(&drm->client.device.object, > "debugfsCtrl", 0, > - NVIF_CLASS_CONTROL, NULL, 0, > - &drm->debugfs->ctrl); > + ret = nvif_object_ctor(&drm->client.device.object, > "debugfsCtrl", 0, > + NVIF_CLASS_CONTROL, NULL, 0, > + &drm->debugfs->ctrl); > + if (ret) { > + kfree(drm->debugfs); > + drm->debugfs = NULL; > + return ret; ^ We could get rid of this extra return… > + } > + > + return 0; …and just return ret here With that fixed: Reviewed-by: Lyude Paul <lyude@redhat.com> > } > > void > diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c > b/drivers/gpu/drm/nouveau/nouveau_hwmon.c > index 726397ab035d..ffbe7f542ab0 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c > +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c > @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev) > if (IS_ERR(hwmon_dev)) { > ret = PTR_ERR(hwmon_dev); > NV_ERROR(drm, "Unable to register hwmon device: > %d\n", ret); > + drm->hwmon = NULL; > + kfree(hwmon); > return ret; > } > ^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-10-08 21:45 ` lyude @ 2026-10-09 11:51 ` liupeng 2026-10-09 12:00 ` sashiko-bot 2026-10-09 21:35 ` lyude 0 siblings, 2 replies; 11+ messages in thread From: liupeng @ 2026-10-09 11:51 UTC (permalink / raw) To: lyude, dakr Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux, nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon, stable, liupeng In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously allocated drm->debugfs is leaked because the function returns the error code directly. In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, the allocated hwmon structure is leaked because the function returns the error code directly. Fix both by freeing the allocated memory and clearing the pointer on the error paths. Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs") Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM") Cc: stable@vger.kernel.org Reviewed-by: Lyude Paul <lyude@redhat.com> Signed-off-by: liupeng <liupeng01@kylinos.cn> --- Changes in v3: - Drop the extra return in nouveau_debugfs_init() as suggested by Lyude. - Add Reviewed-by tag. drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++--- drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++ 2 files changed, 13 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c index 47d5579c568d..338421e52f69 100644 --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor *minor) int nouveau_debugfs_init(struct nouveau_drm *drm) { + int ret; + drm->debugfs = kzalloc_obj(*drm->debugfs); if (!drm->debugfs) return -ENOMEM; - return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0, - NVIF_CLASS_CONTROL, NULL, 0, - &drm->debugfs->ctrl); + ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0, + NVIF_CLASS_CONTROL, NULL, 0, + &drm->debugfs->ctrl); + if (ret) { + kfree(drm->debugfs); + drm->debugfs = NULL; + } + + return ret; } void diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c index 726397ab035d..ffbe7f542ab0 100644 --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev) if (IS_ERR(hwmon_dev)) { ret = PTR_ERR(hwmon_dev); NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret); + drm->hwmon = NULL; + kfree(hwmon); return ret; } -- 2.53.0 ^ permalink raw reply related [flat|nested] 11+ messages in thread
* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-10-09 11:51 ` [PATCH v3] " liupeng @ 2026-10-09 12:00 ` sashiko-bot 2026-10-09 21:35 ` lyude 1 sibling, 0 replies; 11+ messages in thread From: sashiko-bot @ 2026-10-09 12:00 UTC (permalink / raw) To: liupeng; +Cc: dri-devel, linux-hwmon > In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously > allocated drm->debugfs is leaked because the function returns the > error code directly. > > In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, > the allocated hwmon structure is leaked because the function returns > the error code directly. > > Fix both by freeing the allocated memory and clearing the pointer on > the error paths. > > Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs") > Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM") > Cc: stable@vger.kernel.org > Reviewed-by: Lyude Paul <lyude@redhat.com> > Signed-off-by: liupeng <liupeng01@kylinos.cn> Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review · https://sashiko.dev/#/patchset/20261009115151.13877-1-liupeng01@kylinos.cn?part=1 ^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-10-09 11:51 ` [PATCH v3] " liupeng 2026-10-09 12:00 ` sashiko-bot @ 2026-10-09 21:35 ` lyude 2026-10-09 21:40 ` Danilo Krummrich 1 sibling, 1 reply; 11+ messages in thread From: lyude @ 2026-10-09 21:35 UTC (permalink / raw) To: liupeng, dakr Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux, nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon, stable Reviewed-by: Lyude Paul <lyude@redhat.com> Will push to drm-misc-fixes in a moment On Fri, 2026-10-09 at 19:51 +0800, liupeng wrote: > In nouveau_debugfs_init(), if nvif_object_ctor() fails, the > previously > allocated drm->debugfs is leaked because the function returns the > error code directly. > > In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, > the allocated hwmon structure is leaked because the function returns > the error code directly. > > Fix both by freeing the allocated memory and clearing the pointer on > the error paths. > > Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for > debugfs") > Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except > the hwmon interfaces to THERM") > Cc: stable@vger.kernel.org > Reviewed-by: Lyude Paul <lyude@redhat.com> > Signed-off-by: liupeng <liupeng01@kylinos.cn> > --- > Changes in v3: > - Drop the extra return in nouveau_debugfs_init() as suggested by > Lyude. > - Add Reviewed-by tag. > > drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++--- > drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++ > 2 files changed, 13 insertions(+), 3 deletions(-) > > diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c > b/drivers/gpu/drm/nouveau/nouveau_debugfs.c > index 47d5579c568d..338421e52f69 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c > +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c > @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor > *minor) > int > nouveau_debugfs_init(struct nouveau_drm *drm) > { > + int ret; > + > drm->debugfs = kzalloc_obj(*drm->debugfs); > if (!drm->debugfs) > return -ENOMEM; > > - return nvif_object_ctor(&drm->client.device.object, > "debugfsCtrl", 0, > - NVIF_CLASS_CONTROL, NULL, 0, > - &drm->debugfs->ctrl); > + ret = nvif_object_ctor(&drm->client.device.object, > "debugfsCtrl", 0, > + NVIF_CLASS_CONTROL, NULL, 0, > + &drm->debugfs->ctrl); > + if (ret) { > + kfree(drm->debugfs); > + drm->debugfs = NULL; > + } > + > + return ret; > } > > void > diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c > b/drivers/gpu/drm/nouveau/nouveau_hwmon.c > index 726397ab035d..ffbe7f542ab0 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c > +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c > @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev) > if (IS_ERR(hwmon_dev)) { > ret = PTR_ERR(hwmon_dev); > NV_ERROR(drm, "Unable to register hwmon device: > %d\n", ret); > + drm->hwmon = NULL; > + kfree(hwmon); > return ret; > } > ^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-10-09 21:35 ` lyude @ 2026-10-09 21:40 ` Danilo Krummrich 2026-10-09 21:43 ` lyude 0 siblings, 1 reply; 11+ messages in thread From: Danilo Krummrich @ 2026-10-09 21:40 UTC (permalink / raw) To: lyude Cc: liupeng, maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux, nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon, stable On Fri Oct 9, 2026 at 11:35 PM CEST, lyude wrote: > Reviewed-by: Lyude Paul <lyude@redhat.com> > > Will push to drm-misc-fixes in a moment Please wait, those are two unrelated fixes with two different Fixes: tags, so those should be two separate patches. I'm also not sure this is -fixes material. A memory leak in an unwind path for -rc7 feels wrong. Thanks, Danilo > On Fri, 2026-10-09 at 19:51 +0800, liupeng wrote: >> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the >> previously >> allocated drm->debugfs is leaked because the function returns the >> error code directly. >> >> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails, >> the allocated hwmon structure is leaked because the function returns >> the error code directly. >> >> Fix both by freeing the allocated memory and clearing the pointer on >> the error paths. >> >> Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for >> debugfs") >> Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except >> the hwmon interfaces to THERM") >> Cc: stable@vger.kernel.org >> Reviewed-by: Lyude Paul <lyude@redhat.com> >> Signed-off-by: liupeng <liupeng01@kylinos.cn> >> --- >> Changes in v3: >> - Drop the extra return in nouveau_debugfs_init() as suggested by >> Lyude. >> - Add Reviewed-by tag. >> >> drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++--- >> drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++ >> 2 files changed, 13 insertions(+), 3 deletions(-) >> >> diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c >> b/drivers/gpu/drm/nouveau/nouveau_debugfs.c >> index 47d5579c568d..338421e52f69 100644 >> --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c >> +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c >> @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor >> *minor) >> int >> nouveau_debugfs_init(struct nouveau_drm *drm) >> { >> + int ret; >> + >> drm->debugfs = kzalloc_obj(*drm->debugfs); >> if (!drm->debugfs) >> return -ENOMEM; >> >> - return nvif_object_ctor(&drm->client.device.object, >> "debugfsCtrl", 0, >> - NVIF_CLASS_CONTROL, NULL, 0, >> - &drm->debugfs->ctrl); >> + ret = nvif_object_ctor(&drm->client.device.object, >> "debugfsCtrl", 0, >> + NVIF_CLASS_CONTROL, NULL, 0, >> + &drm->debugfs->ctrl); >> + if (ret) { >> + kfree(drm->debugfs); >> + drm->debugfs = NULL; >> + } >> + >> + return ret; >> } >> >> void >> diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c >> b/drivers/gpu/drm/nouveau/nouveau_hwmon.c >> index 726397ab035d..ffbe7f542ab0 100644 >> --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c >> +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c >> @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev) >> if (IS_ERR(hwmon_dev)) { >> ret = PTR_ERR(hwmon_dev); >> NV_ERROR(drm, "Unable to register hwmon device: >> %d\n", ret); >> + drm->hwmon = NULL; >> + kfree(hwmon); >> return ret; >> } >> ^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths 2026-10-09 21:40 ` Danilo Krummrich @ 2026-10-09 21:43 ` lyude 0 siblings, 0 replies; 11+ messages in thread From: lyude @ 2026-10-09 21:43 UTC (permalink / raw) To: Danilo Krummrich Cc: liupeng, maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux, nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon, stable On Fri, 2026-10-09 at 23:40 +0200, Danilo Krummrich wrote: > On Fri Oct 9, 2026 at 11:35 PM CEST, lyude wrote: > > Reviewed-by: Lyude Paul <lyude@redhat.com> > > > > Will push to drm-misc-fixes in a moment > > Please wait, those are two unrelated fixes with two different Fixes: > tags, so > those should be two separate patches. Thanks, I think my brain just glossed over the tags while looking at this. liupeng, could you split these patches up? > > I'm also not sure this is -fixes material. A memory leak in an unwind > path for > -rc7 feels wrong. > > Thanks, > Danilo > > > On Fri, 2026-10-09 at 19:51 +0800, liupeng wrote: > > > In nouveau_debugfs_init(), if nvif_object_ctor() fails, the > > > previously > > > allocated drm->debugfs is leaked because the function returns the > > > error code directly. > > > > > > In nouveau_hwmon_init(), if hwmon_device_register_with_info() > > > fails, > > > the allocated hwmon structure is leaked because the function > > > returns > > > the error code directly. > > > > > > Fix both by freeing the allocated memory and clearing the pointer > > > on > > > the error paths. > > > > > > Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object > > > for > > > debugfs") > > > Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything > > > except > > > the hwmon interfaces to THERM") > > > Cc: stable@vger.kernel.org > > > Reviewed-by: Lyude Paul <lyude@redhat.com> > > > Signed-off-by: liupeng <liupeng01@kylinos.cn> > > > --- > > > Changes in v3: > > > - Drop the extra return in nouveau_debugfs_init() as suggested by > > > Lyude. > > > - Add Reviewed-by tag. > > > > > > drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++--- > > > drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++ > > > 2 files changed, 13 insertions(+), 3 deletions(-) > > > > > > diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c > > > b/drivers/gpu/drm/nouveau/nouveau_debugfs.c > > > index 47d5579c568d..338421e52f69 100644 > > > --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c > > > +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c > > > @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor > > > *minor) > > > int > > > nouveau_debugfs_init(struct nouveau_drm *drm) > > > { > > > + int ret; > > > + > > > drm->debugfs = kzalloc_obj(*drm->debugfs); > > > if (!drm->debugfs) > > > return -ENOMEM; > > > > > > - return nvif_object_ctor(&drm->client.device.object, > > > "debugfsCtrl", 0, > > > - NVIF_CLASS_CONTROL, NULL, 0, > > > - &drm->debugfs->ctrl); > > > + ret = nvif_object_ctor(&drm->client.device.object, > > > "debugfsCtrl", 0, > > > + NVIF_CLASS_CONTROL, NULL, 0, > > > + &drm->debugfs->ctrl); > > > + if (ret) { > > > + kfree(drm->debugfs); > > > + drm->debugfs = NULL; > > > + } > > > + > > > + return ret; > > > } > > > > > > void > > > diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c > > > b/drivers/gpu/drm/nouveau/nouveau_hwmon.c > > > index 726397ab035d..ffbe7f542ab0 100644 > > > --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c > > > +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c > > > @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev) > > > if (IS_ERR(hwmon_dev)) { > > > ret = PTR_ERR(hwmon_dev); > > > NV_ERROR(drm, "Unable to register hwmon device: > > > %d\n", ret); > > > + drm->hwmon = NULL; > > > + kfree(hwmon); > > > return ret; > > > } > > > ^ permalink raw reply [flat|nested] 11+ messages in thread
end of thread, other threads:[~2026-10-09 21:44 UTC | newest] Thread overview: 11+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-08-24 9:05 [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths liupeng 2026-08-24 9:12 ` sashiko-bot 2026-09-17 22:10 ` lyude 2026-09-22 4:40 ` [PATCH v2] " liupeng 2026-09-22 4:46 ` sashiko-bot 2026-10-08 21:45 ` lyude 2026-10-09 11:51 ` [PATCH v3] " liupeng 2026-10-09 12:00 ` sashiko-bot 2026-10-09 21:35 ` lyude 2026-10-09 21:40 ` Danilo Krummrich 2026-10-09 21:43 ` lyude
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox