public inbox for netdev@vger.kernel.org
 help / color / mirror / Atom feed
From: Joe Damato <joe@dama.to>
To: Jakub Kicinski <kuba@kernel.org>
Cc: davem@davemloft.net, netdev@vger.kernel.org, edumazet@google.com,
	pabeni@redhat.com, andrew+netdev@lunn.ch, horms@kernel.org
Subject: Re: [PATCH net 1/5] nfc: nci: free skb on nci_transceive early error paths
Date: Tue, 3 Mar 2026 13:02:17 -0800	[thread overview]
Message-ID: <aadMWe0YaCdgFxKF@devvm20253.cco0.facebook.com> (raw)
In-Reply-To: <20260303162346.2071888-2-kuba@kernel.org>

On Tue, Mar 03, 2026 at 08:23:41AM -0800, Jakub Kicinski wrote:
> nci_transceive() takes ownership of the skb passed by the caller,
> but the -EPROTO, -EINVAL, and -EBUSY error paths return without
> freeing it.
> 
> Due to issues clearing NCI_DATA_EXCHANGE fixed by subsequent changes
> the nci/nci_dev selftest hits the error path occasionally in NIPA,
> and kmemleak detects leaks:
> 
> unreferenced object 0xff11000015ce6a40 (size 640):
>   comm "nci_dev", pid 3954, jiffies 4295441246
>   hex dump (first 32 bytes):
>     6b 6b 6b 6b 00 a4 00 0c 02 e1 03 6b 6b 6b 6b 6b  kkkk.......kkkkk
>     6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b  kkkkkkkkkkkkkkkk
>   backtrace (crc 7c40cc2a):
>     kmem_cache_alloc_node_noprof+0x492/0x630
>     __alloc_skb+0x11e/0x5f0
>     alloc_skb_with_frags+0xc6/0x8f0
>     sock_alloc_send_pskb+0x326/0x3f0
>     nfc_alloc_send_skb+0x94/0x1d0
>     rawsock_sendmsg+0x162/0x4c0
>     do_syscall_64+0x117/0xfc0
> 
> Fixes: 6a2968aaf50c ("NFC: basic NCI protocol implementation")
> Signed-off-by: Jakub Kicinski <kuba@kernel.org>
> ---
>  net/nfc/nci/core.c | 9 +++++++--
>  1 file changed, 7 insertions(+), 2 deletions(-)
> 

Reviewed-by: Joe Damato <joe@dama.to>

  reply	other threads:[~2026-03-03 21:02 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-03-03 16:23 [PATCH net 0/5] nfc: fix leaks and races surfaced by NIPA Jakub Kicinski
2026-03-03 16:23 ` [PATCH net 1/5] nfc: nci: free skb on nci_transceive early error paths Jakub Kicinski
2026-03-03 21:02   ` Joe Damato [this message]
2026-03-03 16:23 ` [PATCH net 2/5] nfc: digital: free skb on digital_in_send " Jakub Kicinski
2026-03-03 21:04   ` Joe Damato
2026-03-03 16:23 ` [PATCH net 3/5] nfc: nci: complete pending data exchange on device close Jakub Kicinski
2026-03-03 22:03   ` Joe Damato
2026-03-03 16:23 ` [PATCH net 4/5] nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback Jakub Kicinski
2026-03-03 22:46   ` Joe Damato
2026-03-03 16:23 ` [PATCH net 5/5] nfc: rawsock: cancel tx_work before socket teardown Jakub Kicinski
2026-03-03 22:51   ` Joe Damato
2026-03-24 13:31   ` Guenter Roeck
2026-03-05  2:40 ` [PATCH net 0/5] nfc: fix leaks and races surfaced by NIPA patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aadMWe0YaCdgFxKF@devvm20253.cco0.facebook.com \
    --to=joe@dama.to \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox