* [PATCH v2] clk: tegra: tegra124-emc: fix krealloc() memory leak
[not found] <ahilgKKwkttOd9H6@orome>
@ 2026-05-31 19:52 ` Alexander A. Klimov
2026-07-30 15:55 ` Thierry Reding
0 siblings, 1 reply; 2+ messages in thread
From: Alexander A. Klimov @ 2026-05-31 19:52 UTC (permalink / raw)
Cc: Alexander A. Klimov, Peter De Schrijver, Prashant Gaikwad,
Michael Turquette, Stephen Boyd, Brian Masney, Thierry Reding,
Jonathan Hunter, Nathan Chancellor, Nick Desaulniers,
Bill Wendling, Justin Stitt, Dmitry Osipenko,
open list:COMMON CLK FRAMEWORK,
open list:TEGRA ARCHITECTURE SUPPORT, open list,
open list:CLANG/LLVM BUILD SUPPORT:Keyword:b(?i:clang|llvm)b
Don't just overwrite the original pointer passed to krealloc()
with its return value without checking latter:
MEM = krealloc(MEM, SZ, GFP);
If krealloc() returns NULL, that erases the pointer
to the still allocated memory, hence leaks this memory.
Instead, use a temporary variable, check it's not NULL
and only then assign it to the original pointer:
TMP = krealloc(MEM, SZ, GFP);
if (!TMP) return;
MEM = TMP;
Fixes: 888ca40e2843 ("clk: tegra: emc: Support multiple RAM codes")
Signed-off-by: Alexander A. Klimov <grandmaster@al2klimov.de>
---
v2: Separate variable declaration/init
v2: While on it, enhance variable name
v2: While on it, explicit variable type
v2: While on it, re-order variables (reverse Xmas tree)
[✓] scripts/checkpatch.pl --strict
[✓] allmodconfig compiled (i686, LLVM)
[✓] localyesconfig booted (IBM T43)
Note to myself: use --in-reply-to=ahilgKKwkttOd9H6@orome
drivers/clk/tegra/clk-tegra124-emc.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/clk/tegra/clk-tegra124-emc.c b/drivers/clk/tegra/clk-tegra124-emc.c
index f3b2c96fdcfc..81e4c02a807c 100644
--- a/drivers/clk/tegra/clk-tegra124-emc.c
+++ b/drivers/clk/tegra/clk-tegra124-emc.c
@@ -445,15 +445,17 @@ static int load_timings_from_dt(struct tegra_clk_emc *tegra,
{
struct emc_timing *timings_ptr;
int child_count = of_get_child_count(node);
+ struct emc_timing *timings;
int i = 0, err;
size_t size;
size = (tegra->num_timings + child_count) * sizeof(struct emc_timing);
- tegra->timings = krealloc(tegra->timings, size, GFP_KERNEL);
- if (!tegra->timings)
+ timings = krealloc(tegra->timings, size, GFP_KERNEL);
+ if (!timings)
return -ENOMEM;
+ tegra->timings = timings;
timings_ptr = tegra->timings + tegra->num_timings;
tegra->num_timings += child_count;
--
2.54.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH v2] clk: tegra: tegra124-emc: fix krealloc() memory leak
2026-05-31 19:52 ` [PATCH v2] clk: tegra: tegra124-emc: fix krealloc() memory leak Alexander A. Klimov
@ 2026-07-30 15:55 ` Thierry Reding
0 siblings, 0 replies; 2+ messages in thread
From: Thierry Reding @ 2026-07-30 15:55 UTC (permalink / raw)
To: Alexander A. Klimov
Cc: Peter De Schrijver, Prashant Gaikwad, Michael Turquette,
Stephen Boyd, Brian Masney, Jonathan Hunter, Nathan Chancellor,
Nick Desaulniers, Bill Wendling, Justin Stitt, Dmitry Osipenko,
open list:COMMON CLK FRAMEWORK,
open list:TEGRA ARCHITECTURE SUPPORT, open list,
open list:CLANG/LLVM BUILD SUPPORT:Keyword:b(?i:clang|llvm)b
[-- Attachment #1: Type: text/plain, Size: 2614 bytes --]
On Sun, May 31, 2026 at 09:52:52PM +0200, Alexander A. Klimov wrote:
> Don't just overwrite the original pointer passed to krealloc()
> with its return value without checking latter:
>
> MEM = krealloc(MEM, SZ, GFP);
>
> If krealloc() returns NULL, that erases the pointer
> to the still allocated memory, hence leaks this memory.
> Instead, use a temporary variable, check it's not NULL
> and only then assign it to the original pointer:
>
> TMP = krealloc(MEM, SZ, GFP);
> if (!TMP) return;
> MEM = TMP;
>
> Fixes: 888ca40e2843 ("clk: tegra: emc: Support multiple RAM codes")
> Signed-off-by: Alexander A. Klimov <grandmaster@al2klimov.de>
> ---
> v2: Separate variable declaration/init
> v2: While on it, enhance variable name
> v2: While on it, explicit variable type
> v2: While on it, re-order variables (reverse Xmas tree)
>
> [✓] scripts/checkpatch.pl --strict
> [✓] allmodconfig compiled (i686, LLVM)
> [✓] localyesconfig booted (IBM T43)
The latter two are a bit pointless because they are not going to hit
this because the driver depends on ARCH_TEGRA which doesn't exist on
i686 allmodconfig and booting this on a T43 isn't going to hit this
either.
> Note to myself: use --in-reply-to=ahilgKKwkttOd9H6@orome
It's not generally useful to send as replies to earlier versions. Just
regular sending is good enough. We have tools to track versions and
such.
>
> drivers/clk/tegra/clk-tegra124-emc.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/clk/tegra/clk-tegra124-emc.c b/drivers/clk/tegra/clk-tegra124-emc.c
> index f3b2c96fdcfc..81e4c02a807c 100644
> --- a/drivers/clk/tegra/clk-tegra124-emc.c
> +++ b/drivers/clk/tegra/clk-tegra124-emc.c
> @@ -445,15 +445,17 @@ static int load_timings_from_dt(struct tegra_clk_emc *tegra,
> {
> struct emc_timing *timings_ptr;
> int child_count = of_get_child_count(node);
> + struct emc_timing *timings;
I guess we could've reused timings_ptr. Or remove timings_ptr and use
the new one, but I guess this is fine, too:
Reviewed-by: Thierry Reding <treding@nvidia.com>
> int i = 0, err;
> size_t size;
>
> size = (tegra->num_timings + child_count) * sizeof(struct emc_timing);
>
> - tegra->timings = krealloc(tegra->timings, size, GFP_KERNEL);
> - if (!tegra->timings)
> + timings = krealloc(tegra->timings, size, GFP_KERNEL);
> + if (!timings)
> return -ENOMEM;
>
> + tegra->timings = timings;
> timings_ptr = tegra->timings + tegra->num_timings;
> tegra->num_timings += child_count;
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-07-30 15:55 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <ahilgKKwkttOd9H6@orome>
2026-05-31 19:52 ` [PATCH v2] clk: tegra: tegra124-emc: fix krealloc() memory leak Alexander A. Klimov
2026-07-30 15:55 ` Thierry Reding
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox