From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6F92B2DCF43 for ; Wed, 19 Nov 2025 04:07:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1763525234; cv=none; b=FREckfgrgblsXNKN559IYGodHPrGJbQo3RZ4OY17ywMGvGY5yKx1JxteVnONcx4wXpcLLnNGGrwsgjZQ+qeTEurI0PIDYjffYX3hmAivZwRJc/HzI83V7YJBsvEov54YWGKu5shOSnHnDOqd+DcNrnEqtYpWjR4L+JiWNu4+ark= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1763525234; c=relaxed/simple; bh=rU38eKlcL/5UEYk2NS47XN9BNdxIq6d+BoWNaIkjavI=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=dm0lNQfhuhFQmGXHmAie0FcYiaeZ27/6E4sRYYcPzezBQHjMygUMQKssYad1wYZZQjZOJj8Wc4BBjGH97wdeMO2P+VdxvJU5bVkS7vpx16jj7dNffkmFtHml7zfr/joJ8eHuOpFnQ7U12TWV8p+p60FRK/8mD7ESt23Rq9vm0P8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=OjA4LID5; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=UZAOFu0D; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="OjA4LID5"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="UZAOFu0D" Received: from pps.filterd (m0279868.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 5AJ1c8YG3412652 for ; Wed, 19 Nov 2025 04:07:09 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= fS+dGMCJRCHWZtUwrU0gp2ztWLVeW3DxbPgmO/wQHI4=; b=OjA4LID5uscpYRfo BuLyuQsx6TZpgTtPh5uIKrWWelICBJlEGOBgwyfXFCq0M28s0dyoCyg8MXeimjoV p6kjAAyBY09LtT0Vi9Q3PBRH7JKosqDsatoR73+LrsVmy0WgqZLpXzRpU1GfMi5Y cMz0U9OfcNlWVEB6I52056vXo+3yD7iYagQaNkBCe4dd2nskXilIGq797eZb/lak aBKLeYs28rUPEAA0tV+98pNF8pp5Vw5A6dzpWAAfapQBenqREGe2JJK+nZMwSuYu K2sFkJhYdUAjVfWLgJ6yyQ22iHWlZ89Koe0KgMC9wJNRS0c4+lYjWsMhJ/bqIiuH p/E5xA== Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4agv0v1v2n-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 19 Nov 2025 04:07:09 +0000 (GMT) Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-343e262230eso7553425a91.2 for ; Tue, 18 Nov 2025 20:07:09 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1763525228; x=1764130028; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=fS+dGMCJRCHWZtUwrU0gp2ztWLVeW3DxbPgmO/wQHI4=; b=UZAOFu0D78Zp8Tr7hGnW/STh0Z3f+ichFaBn4nSE25GQ7HIbJY3ZyIbW+VITNJFHqb W7767eRHyb7XIuuQCS2SPvwVoNDUu445lHDbOGJTh1qEa423mwmBgrFabUwf5+e+kSs8 2DeWMGIZsAUbwK6feCdGAtTiPgSTpKPzP5Owa5/FM2obgbl2xhOXJcPQrnTgofbkr7Su aZHJcMUHdyOR/XfHI+AhvUph5V4yiY4CCpIZs4Pljx6LGM83YXctnauqhUaAY3TFWgtA Aj0r1+wgPgt86Ss318JOx2rJawvfUfOzysBwE+7XCryH829RnU0JMTXyfBUJTRsZmG+Z kcVA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1763525228; x=1764130028; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=fS+dGMCJRCHWZtUwrU0gp2ztWLVeW3DxbPgmO/wQHI4=; b=rp7Cs6EKZ8P7k9pZ6CBfWXIZ+8Kwt3Rs3cH2IEEoFmmcQoZM9WUI5inPNKRWx1YRVD pczbFXnJuVg9EwbFMnK/Q0qJUAoLnAwKP7XUjPJz41rZg6PCQuj+qGcHC0glX2cJRuBN iqjvBYsOnosa0cOJ//Pu38BYobNwNrSZrvUSC75vGKZFU55Q2FeGmLh0uyXWPbU9kjJt t4wtY6qOCIpymQZTWoDm6HbZnstJg+rf1oowy0cqSVo7ZPPtaP98DrDR+Iv+mw9n6MZh 84JVD4AqeLQFPgZCyA8Ix47rLN79k+egW5uX9mEggcdHbHcEvh+GnMZX+aGWJD1rIoGs whRA== X-Forwarded-Encrypted: i=1; AJvYcCV6LSTUiipukz8aCbcjza7qUz27Ng6yOlpGFYnjMyS6H6rG/2TOt4cIGQIY3fZFFsx7fkmh/0eVIqH2ti8=@vger.kernel.org X-Gm-Message-State: AOJu0YzUCmqYaY3dH5nVxOVJ3vYn4eqe2EsrQr+EMD0LvYIz0WQelkAe VIP6+zCWVXC4vKqchRAq89ySPiOo8oPge1Gd+UofP8zRsgnv6FzT+y+7w6ni6Ijkw8tAFSUS+un cQAGzHcPdJy3f7vOyF/CbvZndSBIp9C4BYs8p4CbBvXa3iSGyF7rBpvttcGMHGI6vcUU= X-Gm-Gg: ASbGnctxZJFPSwRwTMJC+gqd1pxNhgZCUMR2qp3ho7KmVPPtzAOPg/Bf6zRMW9taDi5 RfFwtXulQq9BDb3ssKzBfp0heseUDD3jUKjzkTEn9tj/Zi43l3zhsnQB4xEReJG3FujwneLKSrT 8WN6B0qN+BJ/Uhc7v4Bq/rUh5MyaIVCrTZxpJApw/5MnUla2BKJd6kcqMUkfON4hnwShL7vaSil lSkhp0KKfjKg3wwAvnD6qfwFTPn4j+ZVjLn5RUoxNULEiK2qEONTexIdZvZ5NEHZWwZ0Ai7wSUH BAA8oqtC+TtofZkux2Ls+t2BdiW/dlKjpD2vYG7a4jeBqijVY+bD9u5QWxcHn99oLkiD0jCk4jE Tb6j1srCB4ekYWYl57Hp8t0YDi/7xbE0fVvcT97aZ/pNNzVeOBxHNsfDLsVZWObcVHTiLYXcC4C RRzpLXsA== X-Received: by 2002:a17:90b:2e46:b0:340:66f9:381 with SMTP id 98e67ed59e1d1-343f9eb37ddmr19076484a91.10.1763525228020; Tue, 18 Nov 2025 20:07:08 -0800 (PST) X-Google-Smtp-Source: AGHT+IHETq0FoatOPgD7ViESbnk3ztP2OtHyWXSHvfgh9KYljoPwsVKGXEaYPb5xtSXJRHIf16xPIQ== X-Received: by 2002:a17:90b:2e46:b0:340:66f9:381 with SMTP id 98e67ed59e1d1-343f9eb37ddmr19076452a91.10.1763525227470; Tue, 18 Nov 2025 20:07:07 -0800 (PST) Received: from [10.133.33.174] (tpe-colo-wan-fw-bordernet.qualcomm.com. [103.229.16.4]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-345b04f3b8dsm1589964a91.12.2025.11.18.20.07.04 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 18 Nov 2025 20:07:07 -0800 (PST) Message-ID: <38308885-af2e-4b61-9653-00bfca8ca0e9@oss.qualcomm.com> Date: Wed, 19 Nov 2025 12:07:02 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v4 1/3] rpmsg: char: Fix WARN() in error path of rpmsg_eptdev_add() To: Dawei Li , andersson@kernel.org, mathieu.poirier@linaro.org Cc: linux-remoteproc@vger.kernel.org, linux-kernel@vger.kernel.org, set_pte_at@outlook.com, zhongqiu.han@oss.qualcomm.com References: <20251118154107.3100-1-dawei.li@linux.dev> <20251118154107.3100-2-dawei.li@linux.dev> Content-Language: en-US From: Zhongqiu Han In-Reply-To: <20251118154107.3100-2-dawei.li@linux.dev> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Proofpoint-Spam-Details-Enc: AW1haW4tMjUxMTE5MDAyOCBTYWx0ZWRfX7LX+5hwUxDDh 7iyg4CcgCqPM3qfIF0HwdIrDDzeuGoSORxpezu4H7RtOJHwaAerGx7RX3rlHO22YMW4qvzW5fis LSB5miDOVdSx/r+kDHGPmng5aRL/2qPxX09+0YhIbNIWx03+PHZEVOa5EsHr8wUKhbacrQIM0DH 8ZDMrqofc57D5e5Zn1xWHFQq0hkKB3WZ4UnHfPYrrFPP7ERBpT6CyWJlwm+1pD3oZsHRpU1qo4N iWXfBTj3QUCdOh3MkYbSsrWrlVeLINnHvc4EmZDMjAuXSK1na0g6VabHW5sEJkS+4DcM9+rE0LI Q2n0nIrC6vKGFxRp/ksuUuvHv5PYn0KGyXlLUP5tWoMiFIpQsNQL8XREQDzRnkyoi4OZfZLZDDI GFyPG+Qe6cWwsjPEVI9u5MN+jgpdcw== X-Authority-Analysis: v=2.4 cv=S8XUAYsP c=1 sm=1 tr=0 ts=691d426d cx=c_pps a=vVfyC5vLCtgYJKYeQD43oA==:117 a=nuhDOHQX5FNHPW3J6Bj6AA==:17 a=IkcTkHD0fZMA:10 a=6UeiqGixMTsA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=VwQbUJbxAAAA:8 a=WJ6qqwoD0WRQ6_SRdRYA:9 a=QEXdDO2ut3YA:10 a=rl5im9kqc5Lf4LNbBjHf:22 X-Proofpoint-ORIG-GUID: lsgPt3VovEPzIYxE9pGofYf045LlFVM5 X-Proofpoint-GUID: lsgPt3VovEPzIYxE9pGofYf045LlFVM5 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1121,Hydra:6.1.9,FMLib:17.12.100.49 definitions=2025-11-19_01,2025-11-18_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 malwarescore=0 adultscore=0 suspectscore=0 bulkscore=0 lowpriorityscore=0 priorityscore=1501 impostorscore=0 spamscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2510240001 definitions=main-2511190028 On 11/18/2025 11:41 PM, Dawei Li wrote: > put_device() is called on error path of rpmsg_eptdev_add() to cleanup > resource attached to eptdev->dev, unfortunately it's bogus cause > dev->release() is not set yet. > > When a struct device instance is destroyed, driver core framework checks > the possible release() callback from candidates below: > - struct device::release() > - dev->type->release() > - dev->class->dev_release() > > Rpmsg eptdev owns none of them so WARN() will complain the absence of > release(). > > Fix it by: > - Pre-assign dev->release() before potential error path. > - Check before ida_free() in dev->release(). > > By fixing error path of rpmsg_eptdev_add() and fixing potential memory > leak in rpmsg_anonymous_eptdev_create(), this work paves the way of rework > of rpmsg_eptdev_add() and its callers. > > Fixes: c0cdc19f84a4 ("rpmsg: Driver for user space endpoint interface") > Signed-off-by: Dawei Li > --- > drivers/rpmsg/rpmsg_char.c | 26 +++++++++++++------------- > 1 file changed, 13 insertions(+), 13 deletions(-) > > diff --git a/drivers/rpmsg/rpmsg_char.c b/drivers/rpmsg/rpmsg_char.c > index 34b35ea74aab..373b627581e8 100644 > --- a/drivers/rpmsg/rpmsg_char.c > +++ b/drivers/rpmsg/rpmsg_char.c > @@ -408,8 +408,13 @@ static void rpmsg_eptdev_release_device(struct device *dev) > { > struct rpmsg_eptdev *eptdev = dev_to_eptdev(dev); > > - ida_free(&rpmsg_ept_ida, dev->id); > - if (eptdev->dev.devt) > + /* > + * release() can be invoked from error path of rpmsg_eptdev_add(), > + * WARN() will be fired if ida_free() is feed with invalid ID. > + */ > + if (likely(ida_exists(&rpmsg_ept_ida, dev->id))) > + ida_free(&rpmsg_ept_ida, dev->id); > + if (eptdev->dev.devt && likely(ida_exists(&rpmsg_minor_ida, MINOR(eptdev->dev.devt)))) > ida_free(&rpmsg_minor_ida, MINOR(eptdev->dev.devt)); > kfree(eptdev); > } > @@ -458,6 +463,8 @@ static int rpmsg_eptdev_add(struct rpmsg_eptdev *eptdev, > struct device *dev = &eptdev->dev; > int ret; > > + dev->release = rpmsg_eptdev_release_device; > + > eptdev->chinfo = chinfo; > > if (cdev) { > @@ -471,7 +478,7 @@ static int rpmsg_eptdev_add(struct rpmsg_eptdev *eptdev, > /* Anonymous inode device still need device name for dev_err() and friends */ > ret = ida_alloc(&rpmsg_ept_ida, GFP_KERNEL); > if (ret < 0) > - goto free_minor_ida; > + goto free_eptdev; > dev->id = ret; > dev_set_name(dev, "rpmsg%d", ret); > > @@ -480,22 +487,13 @@ static int rpmsg_eptdev_add(struct rpmsg_eptdev *eptdev, > if (cdev) { > ret = cdev_device_add(&eptdev->cdev, &eptdev->dev); > if (ret) > - goto free_ept_ida; > + goto free_eptdev; > } > > - /* We can now rely on the release function for cleanup */ > - dev->release = rpmsg_eptdev_release_device; > - > return ret; > > -free_ept_ida: > - ida_free(&rpmsg_ept_ida, dev->id); > -free_minor_ida: > - if (cdev) > - ida_free(&rpmsg_minor_ida, MINOR(dev->devt)); > free_eptdev: > put_device(dev); > - kfree(eptdev); Hi Dawei, Thanks for your new version~ Patch 1/3 will introduce a use-after-free of eptdev in func rpmsg_anonymous_eptdev_create(), https://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux.git/tree/drivers/rpmsg/rpmsg_char.c?h=for-next#n548 even though this issue will be resolved in 2/3. However, 1/3, as an independent commit, should not introduce a new bug. > > return ret; > } > @@ -561,6 +559,8 @@ int rpmsg_anonymous_eptdev_create(struct rpmsg_device *rpdev, struct device *par > > if (!ret) > *pfd = fd; > + else > + put_device(&eptdev->dev); > > return ret; > } -- Thx and BRs, Zhongqiu Han