From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B6E663438BD for ; Wed, 10 Jun 2026 06:08:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781071708; cv=none; b=uf5eK37rF029d32hZeWymB0cjt8j0lpZ52MTs2gk5imkv7i4gBmeN6eNB5Xdgcm35jgi8Abbdrr5DegL6gMcChIpX8O3jQNY44/xeoP/9yqLMpR2ziTtKh8XcVKvE7ffiDO7qekmP5ObQC3vE6KxMV7NOmpx4N+XhvVHKL2ilOc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781071708; c=relaxed/simple; bh=UMQtwPMNwypvjd+hpUNKCCQoPz2Pn5C4juiimaXiHMg=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Y6w3TwCNt8rSffs2qUMgOprN9d+vF6C1LsqK8WQnwYtjPHiFvV9YZJ9CWPMJG4AiXoJebj4mIP2SXHCUqFTBWHkZWXAZHt23uOujMZ/lr88LRubu7tyB9MsheJXoNtLYF4JHbt/1EOpm4QWvmNTGPWfaaOTkbgE6p2+Tqiptn54= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=MMSvb5wb; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="MMSvb5wb" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CFF291F00893; Wed, 10 Jun 2026 06:08:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1781071707; bh=U2Gf7Ua5R6Pwpgcv/ZAFw8mbtp+kDMSCe8BO4W2gQyo=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=MMSvb5wbtzNUgsRHrUWXjztNCbsRHYe9p476cvo5M4j5A1lJAuc34OF1EAyNE1r73 FuN0hILJXiRpIuLIta+uK1U3CCVwNYsJ/z+4+YyBBSS+4WD1vlNFbs8Mwe9FzvNjw7 Ab2OYe5i5eI3+1r0WxTfvEhp2JfDdRw2VYk1bbXc= Date: Wed, 10 Jun 2026 08:07:27 +0200 From: Greg Kroah-Hartman To: "NG, TZE YEE" Cc: Dinh Nguyen , Alan Tull , Richard Gong , "linux-kernel@vger.kernel.org" , "NG, ADRIAN HO YIN" , "Nazle Asmade, Muhammad Nazim Amirul" Subject: Re: [PATCH] firmware: stratix10-svc: fix memory leaks and list corruption bugs Message-ID: <2026061051-seismic-lyricism-7b77@gregkh> References: <6e13c57d085f61fc97c90ab5121b6dcc5119e035.1780996415.git.tze.yee.ng@altera.com> <2026060950-blooming-scalping-0bdc@gregkh> <0603b48f-b96b-4cc8-b51d-b9a9515c6790@altera.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <0603b48f-b96b-4cc8-b51d-b9a9515c6790@altera.com> On Wed, Jun 10, 2026 at 01:47:44AM +0000, NG, TZE YEE wrote: > On 9/6/2026 6:13 pm, Greg Kroah-Hartman wrote: > > [Some people who received this message don't often get email from gregkh@linuxfoundation.org. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ] > > > > On Tue, Jun 09, 2026 at 02:19:44AM -0700, tze.yee.ng@altera.com wrote: > >> From: Tze Yee Ng > >> > >> Fix a memory leak when gen_pool_alloc() fails by freeing pmem on the error > >> path. Switch pmem allocation from devm_kzalloc() to kzalloc() with > >> explicit kfree() in the free path to match its list-managed life time. > >> Remove the erroneous list_del(&svc_data_mem) which corrupted the list head > >> on failed lookups. Add NULL guards instratix10_svc_free_memory(). > >> > >> Fixes: 7ca5ce896524 ("firmware: add Intel Stratix10 service layer driver") > >> > >> Signed-off-by: Tze Yee Ng > >> --- > >> drivers/firmware/stratix10-svc.c | 12 ++++++++---- > >> 1 file changed, 8 insertions(+), 4 deletions(-) > >> > >> diff --git a/drivers/firmware/stratix10-svc.c b/drivers/firmware/stratix10-svc.c > >> index 1ef65bf845fc..3b0e2b14180f 100644 > >> --- a/drivers/firmware/stratix10-svc.c > >> +++ b/drivers/firmware/stratix10-svc.c > >> @@ -1912,14 +1912,16 @@ void *stratix10_svc_allocate_memory(struct stratix10_svc_chan *chan, > >> struct gen_pool *genpool = chan->ctrl->genpool; > >> size_t s = roundup(size, 1 << genpool->min_alloc_order); > >> > >> - pmem = devm_kzalloc(chan->ctrl->dev, sizeof(*pmem), GFP_KERNEL); > >> + pmem = kzalloc_obj(*pmem); > >> if (!pmem) > >> return ERR_PTR(-ENOMEM); > >> > >> guard(mutex)(&svc_mem_lock); > >> va = gen_pool_alloc(genpool, s); > >> - if (!va) > >> + if (!va) { > >> + kfree(pmem); > >> return ERR_PTR(-ENOMEM); > >> + } > >> > >> memset((void *)va, 0, s); > >> pa = gen_pool_virt_to_phys(genpool, va); > >> @@ -1945,6 +1947,9 @@ EXPORT_SYMBOL_GPL(stratix10_svc_allocate_memory); > >> void stratix10_svc_free_memory(struct stratix10_svc_chan *chan, void *kaddr) > >> { > >> struct stratix10_svc_data_mem *pmem; > >> + > >> + if (!chan || !kaddr) > >> + return; > > > > What if one is not NULL but the other is? Will you not leak memory here > > now? > > > > thanks, > > > > greg k-h > Hi Greg, > > Good catch on the asymmetric case. The guard is not meant to support > callers passing one NULL and one non-NULL argument. > > kaddr == NULL: no-op, nothing to free. The guard prevents the old bug > where a failed lookup fell through to list_del(&svc_data_mem) and > corrupted the list head. > > chan == NULL with valid kaddr: would leak, but that is invalid API > usage. The previous code would oops on chan->ctrl->genpool instead of > freeing. In-tree callers always pass both valid pointers from > stratix10_svc_allocate_memory(). > > If you prefer not to silently swallow misuse, I can change this to > WARN_ON_ONCE(!chan || !kaddr) before returning, or drop the !chan check > and only guard !kaddr so a NULL channel still faults on dereference per > normal kernel API expectations. WARN_ON() will panic a box if it ever triggers, loosing all data, so please do not do that. If this is something that can happen, handle it properly, don't just crash. thanks, greg k-h