Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1633309

Re: [PATCH] w1: w1-gpio: Fix double-free of platform_data

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Evgeniy Polyakov <zbr@ioremap.net>
Newsgroups linux.kernel
Subject Re: [PATCH] w1: w1-gpio: Fix double-free of platform_data
Date Sat, 29 Apr 2017 18:50:01 +0200
Message-ID <tBDJf-c0-5@gated-at.bofh.it> (permalink)
References <toXw5-3WR-9@gated-at.bofh.it>
X-Original-To Alexey Ignatov <lexszero@gmail.com>, "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
X-Greylist delayed 423 seconds by postgrey-1.27 at vger.kernel.org; Sat, 29 Apr 2017 12:45:28 EDT
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=yandex.ru; s=mail; t=1493483903; bh=FHVmNv6wr+vSMXF/GdDvQRKYJXMZZGmLmMYJ3vz/jow=; h=From:To:In-Reply-To:References:Subject:Message-Id:Date; b=K2L4nuROZM2z8r1CvFwHbvPl+VJmUNNtYFabw71Plb/Y23hqo32nqwC4NC3mhLgfW 6B7wIN8UGrrekzVVIxJUeE3iZ7kZccPEcR1tNN39niY6p4ytqDwKjxVC+a9rpplLhQ MPftiVLhamcmUrtFDqmVGNUqjVq0+YtQMVMIOWc4=
Authentication-Results mxback9j.mail.yandex.net; dkim=pass header.i=@yandex.ru
Envelope-From drustafa@yandex.ru
MIME-Version 1.0
X-Mailer Yamail [ http://yandex.ru ] 5.0
Content-Transfer-Encoding 8bit
Content-Type text/plain; charset=utf-8
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 25
Organization linux.* mail to news gateway
X-Original-Date Sat, 29 Apr 2017 19:38:23 +0300
X-Original-Message-ID <5485571493483903@web21g.yandex.ru>
X-Original-References <20170325170645.16073-1-lexszero@gmail.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1633309

Show key headers only | View raw


Hi Alexey

25.03.2017, 20:08, "Alexey Ignatov" <lexszero@gmail.com>:
> struct w1_gpio_platform_data was allocated using devres when using
> device tree. Then it was assigned to dev.platform_data, which leaded
> to double free on device removal by devres and by direct
> kfree(platform_data) in platform_device_release)

If this patch is still relevant, please add someone from device-tree into copy, I would think this bug
affect anyone and we see alot of bug reports since probe failure ends up with double free.

Also a nit:

> @@ -143,12 +141,12 @@ static int w1_gpio_probe(struct platform_device *pdev)
>          int err;
>
>          if (of_have_populated_dt()) {
> - err = w1_gpio_probe_dt(pdev);
> - if (err < 0)
> - return err;
> + pdata = w1_gpio_probe_dt(pdev);
> + if (IS_ERR(pdata) < 0)
> + return PTR_ERR(pdata);

IS_ERR() should not be used this way

Back to linux.kernel | Previous | Next | Find similar | Unroll thread


Thread

Re: [PATCH] w1: w1-gpio: Fix double-free of platform_data Evgeniy Polyakov <zbr@ioremap.net> - 2017-04-29 18:50 +0200

csiph-web