Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1270037 > unrolled thread
| Started by | Julia Lawall <Julia.Lawall@lip6.fr> |
|---|---|
| First post | 2015-11-16 12:50 +0100 |
| Last post | 2015-11-16 18:20 +0100 |
| Articles | 18 — 8 participants |
Back to article view | Back to linux.kernel
[PATCH 0/7] add missing of_node_put Julia Lawall <Julia.Lawall@lip6.fr> - 2015-11-16 12:50 +0100
[PATCH 3/7] phy: berlin-sata: add missing of_node_put Julia Lawall <Julia.Lawall@lip6.fr> - 2015-11-16 12:50 +0100
Re: [PATCH 3/7] phy: berlin-sata: add missing of_node_put Sebastian Hesselbarth <sebastian.hesselbarth@gmail.com> - 2015-11-19 21:50 +0100
[PATCH 1/7] phy: brcmstb-sata: add missing of_node_put Julia Lawall <Julia.Lawall@lip6.fr> - 2015-11-16 12:50 +0100
Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put Brian Norris <computersforpeace@gmail.com> - 2015-11-17 02:40 +0100
Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put Julia Lawall <julia.lawall@lip6.fr> - 2015-11-17 07:20 +0100
Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put Julia Lawall <julia.lawall@lip6.fr> - 2015-11-17 18:50 +0100
Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put Brian Norris <computersforpeace@gmail.com> - 2015-11-17 19:40 +0100
Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put Brian Norris <computersforpeace@gmail.com> - 2015-11-17 19:40 +0100
Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put Julia Lawall <julia.lawall@lip6.fr> - 2015-11-17 23:40 +0100
device_node lifetime (was: Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put) Brian Norris <computersforpeace@gmail.com> - 2015-11-18 20:10 +0100
Re: device_node lifetime (was: Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put) Julia Lawall <julia.lawall@lip6.fr> - 2015-11-18 21:50 +0100
Re: device_node lifetime (was: Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put) Rob Herring <robh@kernel.org> - 2015-11-19 19:50 +0100
Re: device_node lifetime (was: Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put) Russell King - ARM Linux <linux@arm.linux.org.uk> - 2015-11-19 20:20 +0100
Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put Brian Norris <computersforpeace@gmail.com> - 2015-11-17 18:50 +0100
Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put Kishon Vijay Abraham I <kishon@ti.com> - 2015-11-27 15:20 +0100
[PATCH 7/7] phy: cygnus: pcie: add missing of_node_put Julia Lawall <Julia.Lawall@lip6.fr> - 2015-11-16 12:50 +0100
Re: [PATCH 7/7] phy: cygnus: pcie: add missing of_node_put Ray Jui <rjui@broadcom.com> - 2015-11-16 18:20 +0100
| From | Julia Lawall <Julia.Lawall@lip6.fr> |
|---|---|
| Date | 2015-11-16 12:50 +0100 |
| Subject | [PATCH 0/7] add missing of_node_put |
| Message-ID | <qvqsh-6MZ-3@gated-at.bofh.it> |
The various for_each device_node iterators performs an of_node_get on each
iteration, so a break out of the loop requires an of_node_put.
The complete semantic patch that finds this problem is
(http://coccinelle.lip6.fr):
// <smpl>
@r@
local idexpression n;
expression e1,e2;
iterator name for_each_node_by_name, for_each_node_by_type,
for_each_compatible_node, for_each_matching_node,
for_each_matching_node_and_match, for_each_child_of_node,
for_each_available_child_of_node, for_each_node_with_property;
iterator i;
statement S;
expression list [n1] es;
@@
(
(
for_each_node_by_name(n,e1) S
|
for_each_node_by_type(n,e1) S
|
for_each_compatible_node(n,e1,e2) S
|
for_each_matching_node(n,e1) S
|
for_each_matching_node_and_match(n,e1,e2) S
|
for_each_child_of_node(e1,n) S
|
for_each_available_child_of_node(e1,n) S
|
for_each_node_with_property(n,e1) S
)
&
i(es,n,...) S
)
@@
local idexpression r.n;
iterator r.i;
expression e;
expression list [r.n1] es;
@@
i(es,n,...) {
...
(
of_node_put(n);
|
e = n
|
return n;
|
+ of_node_put(n);
? return ...;
)
...
}
@@
local idexpression r.n;
iterator r.i;
expression e;
expression list [r.n1] es;
@@
i(es,n,...) {
...
(
of_node_put(n);
|
e = n
|
+ of_node_put(n);
? break;
)
...
}
... when != n
@@
local idexpression r.n;
iterator r.i;
expression e;
identifier l;
expression list [r.n1] es;
@@
i(es,n,...) {
...
(
of_node_put(n);
|
e = n
|
+ of_node_put(n);
? goto l;
)
...
}
...
l: ... when != n
// </smpl>
This semantic patch puts an of_node_put before a return, but in each of
these patches, we have grouped the multiple resulting of_node_puts into a
single call at an error exit label.
---
drivers/phy/phy-bcm-cygnus-pcie.c | 16 ++++++++++++----
drivers/phy/phy-berlin-sata.c | 20 ++++++++++++++------
drivers/phy/phy-brcmstb-sata.c | 17 ++++++++++++-----
drivers/phy/phy-miphy28lp.c | 16 +++++++++++-----
drivers/phy/phy-miphy365x.c | 16 +++++++++++-----
drivers/phy/phy-mt65xx-usb3.c | 20 +++++++++++++-------
drivers/phy/phy-rockchip-usb.c | 17 ++++++++++++-----
7 files changed, 85 insertions(+), 37 deletions(-)
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [next] | [standalone]
| From | Julia Lawall <Julia.Lawall@lip6.fr> |
|---|---|
| Date | 2015-11-16 12:50 +0100 |
| Subject | [PATCH 3/7] phy: berlin-sata: add missing of_node_put |
| Message-ID | <qvqsi-6MZ-21@gated-at.bofh.it> |
| In reply to | #1270037 |
for_each_available_child_of_node performs an of_node_get on each iteration,
so a return from the middle of the loop requires an of_node_put.
A simplified version of the semantic patch that finds this problem is as
follows (http://coccinelle.lip6.fr):
// <smpl>
@@
expression root,e;
local idexpression child;
@@
for_each_available_child_of_node(root, child) {
... when != of_node_put(child)
when != e = child
(
return child;
|
* return ...;
)
...
}
// </smpl>
Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
---
drivers/phy/phy-berlin-sata.c | 20 ++++++++++++++------
1 file changed, 14 insertions(+), 6 deletions(-)
diff --git a/drivers/phy/phy-berlin-sata.c b/drivers/phy/phy-berlin-sata.c
index 77a2e05..f84a33a 100644
--- a/drivers/phy/phy-berlin-sata.c
+++ b/drivers/phy/phy-berlin-sata.c
@@ -195,7 +195,7 @@ static int phy_berlin_sata_probe(struct platform_device *pdev)
struct phy_provider *phy_provider;
struct phy_berlin_priv *priv;
struct resource *res;
- int i = 0;
+ int ret, i = 0;
u32 phy_id;
priv = devm_kzalloc(dev, sizeof(*priv), GFP_KERNEL);
@@ -237,22 +237,27 @@ static int phy_berlin_sata_probe(struct platform_device *pdev)
if (of_property_read_u32(child, "reg", &phy_id)) {
dev_err(dev, "missing reg property in node %s\n",
child->name);
- return -EINVAL;
+ ret = -EINVAL;
+ goto put_child;
}
if (phy_id >= ARRAY_SIZE(phy_berlin_power_down_bits)) {
dev_err(dev, "invalid reg in node %s\n", child->name);
- return -EINVAL;
+ ret = -EINVAL;
+ goto put_child;
}
phy_desc = devm_kzalloc(dev, sizeof(*phy_desc), GFP_KERNEL);
- if (!phy_desc)
- return -ENOMEM;
+ if (!phy_desc) {
+ ret = -ENOMEM;
+ goto put_child;
+ }
phy = devm_phy_create(dev, NULL, &phy_berlin_sata_ops);
if (IS_ERR(phy)) {
dev_err(dev, "failed to create PHY %d\n", phy_id);
- return PTR_ERR(phy);
+ ret = PTR_ERR(phy);
+ goto put_child;
}
phy_desc->phy = phy;
@@ -269,6 +274,9 @@ static int phy_berlin_sata_probe(struct platform_device *pdev)
phy_provider =
devm_of_phy_provider_register(dev, phy_berlin_sata_phy_xlate);
return PTR_ERR_OR_ZERO(phy_provider);
+put_child:
+ of_node_put(child);
+ return ret;
}
static const struct of_device_id phy_berlin_sata_of_match[] = {
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Sebastian Hesselbarth <sebastian.hesselbarth@gmail.com> |
|---|---|
| Date | 2015-11-19 21:50 +0100 |
| Subject | Re: [PATCH 3/7] phy: berlin-sata: add missing of_node_put |
| Message-ID | <qwEjw-5Tc-27@gated-at.bofh.it> |
| In reply to | #1270039 |
On 16.11.2015 12:33, Julia Lawall wrote:
> for_each_available_child_of_node performs an of_node_get on each iteration,
> so a return from the middle of the loop requires an of_node_put.
>
> A simplified version of the semantic patch that finds this problem is as
> follows (http://coccinelle.lip6.fr):
>
> // <smpl>
> @@
> expression root,e;
> local idexpression child;
> @@
>
> for_each_available_child_of_node(root, child) {
> ... when != of_node_put(child)
> when != e = child
> (
> return child;
> |
> * return ...;
> )
> ...
> }
> // </smpl>
>
> Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
Acked-by: Sebastian Hesselbarth <sebastian.hesselbarth@gmail.com>
Thanks!
> ---
> drivers/phy/phy-berlin-sata.c | 20 ++++++++++++++------
> 1 file changed, 14 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/phy/phy-berlin-sata.c b/drivers/phy/phy-berlin-sata.c
> index 77a2e05..f84a33a 100644
> --- a/drivers/phy/phy-berlin-sata.c
> +++ b/drivers/phy/phy-berlin-sata.c
> @@ -195,7 +195,7 @@ static int phy_berlin_sata_probe(struct platform_device *pdev)
> struct phy_provider *phy_provider;
> struct phy_berlin_priv *priv;
> struct resource *res;
> - int i = 0;
> + int ret, i = 0;
> u32 phy_id;
>
> priv = devm_kzalloc(dev, sizeof(*priv), GFP_KERNEL);
> @@ -237,22 +237,27 @@ static int phy_berlin_sata_probe(struct platform_device *pdev)
> if (of_property_read_u32(child, "reg", &phy_id)) {
> dev_err(dev, "missing reg property in node %s\n",
> child->name);
> - return -EINVAL;
> + ret = -EINVAL;
> + goto put_child;
> }
>
> if (phy_id >= ARRAY_SIZE(phy_berlin_power_down_bits)) {
> dev_err(dev, "invalid reg in node %s\n", child->name);
> - return -EINVAL;
> + ret = -EINVAL;
> + goto put_child;
> }
>
> phy_desc = devm_kzalloc(dev, sizeof(*phy_desc), GFP_KERNEL);
> - if (!phy_desc)
> - return -ENOMEM;
> + if (!phy_desc) {
> + ret = -ENOMEM;
> + goto put_child;
> + }
>
> phy = devm_phy_create(dev, NULL, &phy_berlin_sata_ops);
> if (IS_ERR(phy)) {
> dev_err(dev, "failed to create PHY %d\n", phy_id);
> - return PTR_ERR(phy);
> + ret = PTR_ERR(phy);
> + goto put_child;
> }
>
> phy_desc->phy = phy;
> @@ -269,6 +274,9 @@ static int phy_berlin_sata_probe(struct platform_device *pdev)
> phy_provider =
> devm_of_phy_provider_register(dev, phy_berlin_sata_phy_xlate);
> return PTR_ERR_OR_ZERO(phy_provider);
> +put_child:
> + of_node_put(child);
> + return ret;
> }
>
> static const struct of_device_id phy_berlin_sata_of_match[] = {
>
> --
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at http://www.tux.org/lkml/
>
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Julia Lawall <Julia.Lawall@lip6.fr> |
|---|---|
| Date | 2015-11-16 12:50 +0100 |
| Subject | [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put |
| Message-ID | <qvqsi-6MZ-41@gated-at.bofh.it> |
| In reply to | #1270037 |
for_each_available_child_of_node performs an of_node_get on each iteration,
so a return from the middle of the loop requires an of_node_put.
A simplified version of the semantic patch that finds this problem is as
follows (http://coccinelle.lip6.fr):
// <smpl>
@@
expression root,e;
local idexpression child;
@@
for_each_available_child_of_node(root, child) {
... when != of_node_put(child)
when != e = child
(
return child;
|
* return ...;
)
...
}
// </smpl>
Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
---
drivers/phy/phy-brcmstb-sata.c | 17 ++++++++++++-----
1 file changed, 12 insertions(+), 5 deletions(-)
diff --git a/drivers/phy/phy-brcmstb-sata.c b/drivers/phy/phy-brcmstb-sata.c
index 8a2cb16..cd9dba8 100644
--- a/drivers/phy/phy-brcmstb-sata.c
+++ b/drivers/phy/phy-brcmstb-sata.c
@@ -140,7 +140,7 @@ static int brcm_sata_phy_probe(struct platform_device *pdev)
struct brcm_sata_phy *priv;
struct resource *res;
struct phy_provider *provider;
- int count = 0;
+ int ret, count = 0;
if (of_get_child_count(dn) == 0)
return -ENODEV;
@@ -163,16 +163,19 @@ static int brcm_sata_phy_probe(struct platform_device *pdev)
if (of_property_read_u32(child, "reg", &id)) {
dev_err(dev, "missing reg property in node %s\n",
child->name);
- return -EINVAL;
+ ret = -EINVAL;
+ goto put_child;
}
if (id >= MAX_PORTS) {
dev_err(dev, "invalid reg: %u\n", id);
- return -EINVAL;
+ ret = -EINVAL;
+ goto put_child;
}
if (priv->phys[id].phy) {
dev_err(dev, "already registered port %u\n", id);
- return -EINVAL;
+ ret = -EINVAL;
+ goto put_child;
}
port = &priv->phys[id];
@@ -182,7 +185,8 @@ static int brcm_sata_phy_probe(struct platform_device *pdev)
port->ssc_en = of_property_read_bool(child, "brcm,enable-ssc");
if (IS_ERR(port->phy)) {
dev_err(dev, "failed to create PHY\n");
- return PTR_ERR(port->phy);
+ ret = PTR_ERR(port->phy);
+ goto put_child;
}
phy_set_drvdata(port->phy, port);
@@ -198,6 +202,9 @@ static int brcm_sata_phy_probe(struct platform_device *pdev)
dev_info(dev, "registered %d port(s)\n", count);
return 0;
+put_child:
+ of_node_put(child);
+ return ret;
}
static struct platform_driver brcm_sata_phy_driver = {
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Brian Norris <computersforpeace@gmail.com> |
|---|---|
| Date | 2015-11-17 02:40 +0100 |
| Subject | Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put |
| Message-ID | <qvDpv-6FC-5@gated-at.bofh.it> |
| In reply to | #1270045 |
On Mon, Nov 16, 2015 at 12:33:14PM +0100, Julia Lawall wrote:
> for_each_available_child_of_node performs an of_node_get on each iteration,
> so a return from the middle of the loop requires an of_node_put.
>
> A simplified version of the semantic patch that finds this problem is as
> follows (http://coccinelle.lip6.fr):
>
> // <smpl>
> @@
> expression root,e;
> local idexpression child;
> @@
>
> for_each_available_child_of_node(root, child) {
> ... when != of_node_put(child)
> when != e = child
> (
> return child;
> |
> * return ...;
> )
> ...
> }
> // </smpl>
>
> Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
>
> ---
For this patch:
Acked-by: Brian Norris <computersforpeace@gmail.com>
> drivers/phy/phy-brcmstb-sata.c | 17 ++++++++++++-----
> 1 file changed, 12 insertions(+), 5 deletions(-)
[snip patch, which fixes of_node_put() handling for
for_each_available_child_of_node() loop, which creates PHY devices with
devm_phy_create()]
This reminds me of a potential problem I'm looking at in other
subsystems: from code reading (I haven't seen any issues in practice,
probably because I don't use OF_DYNAMIC) it looks like device-creating
infrastructure like the PHY subsystem should be acquiring a reference to
the device_node when they stash it away. But drivers/phy/phy-core.c does
not do this, AFAICT.
See phy_create(), which does
phy->dev.of_node = node ?: dev->of_node;
and later might reuse this of_node pointer, even though it never called
of_node_get() on this node.
Potential patch to fix this (not tested).
Signed-off-by: Brian Norris <computersforpeace@gmail.com>
diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c
index fc48fac003a6..8df29caeeef9 100644
--- a/drivers/phy/phy-core.c
+++ b/drivers/phy/phy-core.c
@@ -697,6 +697,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
phy->dev.class = phy_class;
phy->dev.parent = dev;
phy->dev.of_node = node ?: dev->of_node;
+ of_node_get(phy->dev.of_node);
phy->id = id;
phy->ops = ops;
@@ -726,6 +727,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
return phy;
put_dev:
+ of_node_put(phy->dev.of_node);
put_device(&phy->dev); /* calls phy_release() which frees resources */
return ERR_PTR(ret);
@@ -775,6 +777,7 @@ EXPORT_SYMBOL_GPL(devm_phy_create);
*/
void phy_destroy(struct phy *phy)
{
+ of_node_put(phy->dev.of_node);
pm_runtime_disable(&phy->dev);
device_unregister(&phy->dev);
}
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Julia Lawall <julia.lawall@lip6.fr> |
|---|---|
| Date | 2015-11-17 07:20 +0100 |
| Subject | Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put |
| Message-ID | <qvHMu-1gI-17@gated-at.bofh.it> |
| In reply to | #1270750 |
On Mon, 16 Nov 2015, Brian Norris wrote:
> On Mon, Nov 16, 2015 at 12:33:14PM +0100, Julia Lawall wrote:
> > for_each_available_child_of_node performs an of_node_get on each iteration,
> > so a return from the middle of the loop requires an of_node_put.
> >
> > A simplified version of the semantic patch that finds this problem is as
> > follows (http://coccinelle.lip6.fr):
> >
> > // <smpl>
> > @@
> > expression root,e;
> > local idexpression child;
> > @@
> >
> > for_each_available_child_of_node(root, child) {
> > ... when != of_node_put(child)
> > when != e = child
> > (
> > return child;
> > |
> > * return ...;
> > )
> > ...
> > }
> > // </smpl>
> >
> > Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
> >
> > ---
>
> For this patch:
>
> Acked-by: Brian Norris <computersforpeace@gmail.com>
>
> > drivers/phy/phy-brcmstb-sata.c | 17 ++++++++++++-----
> > 1 file changed, 12 insertions(+), 5 deletions(-)
>
> [snip patch, which fixes of_node_put() handling for
> for_each_available_child_of_node() loop, which creates PHY devices with
> devm_phy_create()]
>
> This reminds me of a potential problem I'm looking at in other
> subsystems: from code reading (I haven't seen any issues in practice,
> probably because I don't use OF_DYNAMIC) it looks like device-creating
> infrastructure like the PHY subsystem should be acquiring a reference to
> the device_node when they stash it away. But drivers/phy/phy-core.c does
> not do this, AFAICT.
>
> See phy_create(), which does
>
> phy->dev.of_node = node ?: dev->of_node;
>
> and later might reuse this of_node pointer, even though it never called
> of_node_get() on this node.
>
> Potential patch to fix this (not tested).
>
> Signed-off-by: Brian Norris <computersforpeace@gmail.com>
>
> diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c
> index fc48fac003a6..8df29caeeef9 100644
> --- a/drivers/phy/phy-core.c
> +++ b/drivers/phy/phy-core.c
> @@ -697,6 +697,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
> phy->dev.class = phy_class;
> phy->dev.parent = dev;
> phy->dev.of_node = node ?: dev->of_node;
> + of_node_get(phy->dev.of_node);
Why not put of_node_get around dev->of_node?
julia
> phy->id = id;
> phy->ops = ops;
>
> @@ -726,6 +727,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
> return phy;
>
> put_dev:
> + of_node_put(phy->dev.of_node);
> put_device(&phy->dev); /* calls phy_release() which frees resources */
> return ERR_PTR(ret);
>
> @@ -775,6 +777,7 @@ EXPORT_SYMBOL_GPL(devm_phy_create);
> */
> void phy_destroy(struct phy *phy)
> {
> + of_node_put(phy->dev.of_node);
> pm_runtime_disable(&phy->dev);
> device_unregister(&phy->dev);
> }
> --
> To unsubscribe from this list: send the line "unsubscribe kernel-janitors" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
>
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Julia Lawall <julia.lawall@lip6.fr> |
|---|---|
| Date | 2015-11-17 18:50 +0100 |
| Subject | Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put |
| Message-ID | <qvSye-8a9-9@gated-at.bofh.it> |
| In reply to | #1270896 |
On Tue, 17 Nov 2015, Brian Norris wrote:
> On Tue, Nov 17, 2015 at 07:12:22AM +0100, Julia Lawall wrote:
> > On Mon, 16 Nov 2015, Brian Norris wrote:
> > >
> > > This reminds me of a potential problem I'm looking at in other
> > > subsystems: from code reading (I haven't seen any issues in practice,
> > > probably because I don't use OF_DYNAMIC) it looks like device-creating
> > > infrastructure like the PHY subsystem should be acquiring a reference to
> > > the device_node when they stash it away. But drivers/phy/phy-core.c does
> > > not do this, AFAICT.
> > >
> > > See phy_create(), which does
> > >
> > > phy->dev.of_node = node ?: dev->of_node;
> > >
> > > and later might reuse this of_node pointer, even though it never called
> > > of_node_get() on this node.
> > >
> > > Potential patch to fix this (not tested).
> > >
> > > Signed-off-by: Brian Norris <computersforpeace@gmail.com>
> > >
> > > diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c
> > > index fc48fac003a6..8df29caeeef9 100644
> > > --- a/drivers/phy/phy-core.c
> > > +++ b/drivers/phy/phy-core.c
> > > @@ -697,6 +697,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
> > > phy->dev.class = phy_class;
> > > phy->dev.parent = dev;
> > > phy->dev.of_node = node ?: dev->of_node;
> > > + of_node_get(phy->dev.of_node);
> >
> > Why not put of_node_get around dev->of_node?
>
> Like this?
>
> phy->dev.of_node = node ?: of_node_get(dev->of_node);
>
> Or this?
>
> phy->dev.of_node = of_node_get(node ?: dev->of_node);
>
> The former wouldn't do what I proposed; if this PHY device is created
> with a sub-node of 'dev' rather than dev->of_node, then the caller will
> pass it in as the 2nd argument to phy_create (i.e., 'node'), and then I
> expect it's the PHY core's responsibility to refcount it.
>
> I'd be fine with the latter. Looks a little better, I suppose.
I proposed it because I was worried that the of_node field could end up
containing something that had been freed. But probably this is not
possible? If it is not possible, then the ?: in the function argument is
probably a bit ugly...
Is this something that should be checked for elsewhere?
julia
> If my understanding is correct, I'll send a proper patch to do the
> latter.
>
> Regards,
> Brian
>
> > julia
> >
> > > phy->id = id;
> > > phy->ops = ops;
> > >
> > > @@ -726,6 +727,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
> > > return phy;
> > >
> > > put_dev:
> > > + of_node_put(phy->dev.of_node);
> > > put_device(&phy->dev); /* calls phy_release() which frees resources */
> > > return ERR_PTR(ret);
> > >
> > > @@ -775,6 +777,7 @@ EXPORT_SYMBOL_GPL(devm_phy_create);
> > > */
> > > void phy_destroy(struct phy *phy)
> > > {
> > > + of_node_put(phy->dev.of_node);
> > > pm_runtime_disable(&phy->dev);
> > > device_unregister(&phy->dev);
> > > }
> > > --
> > > To unsubscribe from this list: send the line "unsubscribe kernel-janitors" in
> > > the body of a message to majordomo@vger.kernel.org
> > > More majordomo info at http://vger.kernel.org/majordomo-info.html
> > >
>
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Brian Norris <computersforpeace@gmail.com> |
|---|---|
| Date | 2015-11-17 19:40 +0100 |
| Subject | Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put |
| Message-ID | <qvTkC-f2-17@gated-at.bofh.it> |
| In reply to | #1271488 |
On Tue, Nov 17, 2015 at 06:48:39PM +0100, Julia Lawall wrote: > On Tue, 17 Nov 2015, Brian Norris wrote: > > On Tue, Nov 17, 2015 at 07:12:22AM +0100, Julia Lawall wrote: > > > On Mon, 16 Nov 2015, Brian Norris wrote: > > > > diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c > > > > index fc48fac003a6..8df29caeeef9 100644 > > > > --- a/drivers/phy/phy-core.c > > > > +++ b/drivers/phy/phy-core.c > > > > @@ -697,6 +697,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node, > > > > phy->dev.class = phy_class; > > > > phy->dev.parent = dev; > > > > phy->dev.of_node = node ?: dev->of_node; > > > > + of_node_get(phy->dev.of_node); > > > > > > Why not put of_node_get around dev->of_node? > > > > Like this? > > > > phy->dev.of_node = node ?: of_node_get(dev->of_node); > > > > Or this? > > > > phy->dev.of_node = of_node_get(node ?: dev->of_node); > > > > The former wouldn't do what I proposed; if this PHY device is created > > with a sub-node of 'dev' rather than dev->of_node, then the caller will > > pass it in as the 2nd argument to phy_create (i.e., 'node'), and then I > > expect it's the PHY core's responsibility to refcount it. > > > > I'd be fine with the latter. Looks a little better, I suppose. > > I proposed it because I was worried that the of_node field could end up > containing something that had been freed. But probably this is not > possible? AIUI, the caller of phy_create() should already have a refcount on both 'dev->of_node' and 'node' (if applicable), so nobody should be freeing it from underneath us right here. But *after* phy_create() returns, there's no guarantee the caller will hold a reference for us. So even if it's ever possible, I'd consider it a bug in the caller, not in phy_create(). > If it is not possible, then the ?: in the function argument is > probably a bit ugly... OK, then I'll go with my first proposal. > Is this something that should be checked for elsewhere? I expect the same sort of problem shows up plenty of other places. I don't think many people use CONFIG_OF_DYNAMIC, so the effects of these failures probably aren't felt by many. Brian -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Brian Norris <computersforpeace@gmail.com> |
|---|---|
| Date | 2015-11-17 19:40 +0100 |
| Subject | Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put |
| Message-ID | <qvTkE-f2-59@gated-at.bofh.it> |
| In reply to | #1271527 |
On Tue, Nov 17, 2015 at 10:30:36AM -0800, Brian Norris wrote: > I expect the same sort of problem shows up plenty of other places. I > don't think many people use CONFIG_OF_DYNAMIC, so the effects of these > failures probably aren't felt by many. Also, there's a quite-relevant todo item in Documentation/devicetree/todo.txt: === CONFIG_OF_DYNAMIC === ... - Document node lifecycle for CONFIG_OF_DYNAMIC :) Brian -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Julia Lawall <julia.lawall@lip6.fr> |
|---|---|
| Date | 2015-11-17 23:40 +0100 |
| Subject | Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put |
| Message-ID | <qvX4R-2FN-3@gated-at.bofh.it> |
| In reply to | #1271527 |
On Tue, 17 Nov 2015, Brian Norris wrote: > On Tue, Nov 17, 2015 at 06:48:39PM +0100, Julia Lawall wrote: > > On Tue, 17 Nov 2015, Brian Norris wrote: > > > On Tue, Nov 17, 2015 at 07:12:22AM +0100, Julia Lawall wrote: > > > > On Mon, 16 Nov 2015, Brian Norris wrote: > > > > > diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c > > > > > index fc48fac003a6..8df29caeeef9 100644 > > > > > --- a/drivers/phy/phy-core.c > > > > > +++ b/drivers/phy/phy-core.c > > > > > @@ -697,6 +697,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node, > > > > > phy->dev.class = phy_class; > > > > > phy->dev.parent = dev; > > > > > phy->dev.of_node = node ?: dev->of_node; > > > > > + of_node_get(phy->dev.of_node); > > > > > > > > Why not put of_node_get around dev->of_node? > > > > > > Like this? > > > > > > phy->dev.of_node = node ?: of_node_get(dev->of_node); > > > > > > Or this? > > > > > > phy->dev.of_node = of_node_get(node ?: dev->of_node); > > > > > > The former wouldn't do what I proposed; if this PHY device is created > > > with a sub-node of 'dev' rather than dev->of_node, then the caller will > > > pass it in as the 2nd argument to phy_create (i.e., 'node'), and then I > > > expect it's the PHY core's responsibility to refcount it. > > > > > > I'd be fine with the latter. Looks a little better, I suppose. > > > > I proposed it because I was worried that the of_node field could end up > > containing something that had been freed. But probably this is not > > possible? > > AIUI, the caller of phy_create() should already have a refcount on both > 'dev->of_node' and 'node' (if applicable), so nobody should be freeing > it from underneath us right here. But *after* phy_create() returns, > there's no guarantee the caller will hold a reference for us. > > So even if it's ever possible, I'd consider it a bug in the caller, not > in phy_create(). > > > If it is not possible, then the ?: in the function argument is > > probably a bit ugly... > > OK, then I'll go with my first proposal. > > > Is this something that should be checked for elsewhere? > > I expect the same sort of problem shows up plenty of other places. I > don't think many people use CONFIG_OF_DYNAMIC, so the effects of these > failures probably aren't felt by many. I tried the following semantic patch: @@ struct device_node *e; expression e1; identifier fld; @@ ... when != of_node_get(...) *(<+...e1->fld...+>) = e ... when != of_node_get(...) return e1; basically, this says that a structure field is initilized to a device node value, the structure is returned by the containing function, and the containing function contains no of_node_get at all. Certainly this is quite constrained, but it does produce a number of examples. I looked at a few of them: drivers/clk/ingenic/cgu.c, ingenic_cgu_new clk/pistachio/clk.c, pistachio_clk_alloc_provider drivers/mfd/syscon.c, of_syscon_register drivers/of/pdt.c, function of_pdt_create_node Any idea whether these need of_node_get? In all cases the device node value comes in as a parameter. thanks, julia -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Brian Norris <computersforpeace@gmail.com> |
|---|---|
| Date | 2015-11-18 20:10 +0100 |
| Subject | device_node lifetime (was: Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put) |
| Message-ID | <qwghc-77w-17@gated-at.bofh.it> |
| In reply to | #1271706 |
(changing subject, add devicetree@vger.kernel.org) On Tue, Nov 17, 2015 at 11:33:25PM +0100, Julia Lawall wrote: > On Tue, 17 Nov 2015, Brian Norris wrote: > > On Tue, Nov 17, 2015 at 06:48:39PM +0100, Julia Lawall wrote: > > > Is this something that should be checked for elsewhere? > > > > I expect the same sort of problem shows up plenty of other places. I > > don't think many people use CONFIG_OF_DYNAMIC, so the effects of these > > failures probably aren't felt by many. > > I tried the following semantic patch: > > @@ > struct device_node *e; > expression e1; > identifier fld; > @@ > > ... when != of_node_get(...) > *(<+...e1->fld...+>) = e > ... when != of_node_get(...) > return e1; > > basically, this says that a structure field is initilized to a device node > value, the structure is returned by the containing function, and the > containing function contains no of_node_get at all. Certainly this is > quite constrained, but it does produce a number of examples. > > I looked at a few of them: > > drivers/clk/ingenic/cgu.c, ingenic_cgu_new > clk/pistachio/clk.c, pistachio_clk_alloc_provider It looks like the clock core (drivers/clk/clk.c) initially grabs the clk provider node in of_clk_init(), then drops it after it's initialized, but most of these providers use of_clk_add_provider(), which seems to manage the device_node lifetime for the user. So I think these are OK. > drivers/mfd/syscon.c, of_syscon_register This one looks potentially suspect. Syscon nodes aren't usually directly managed by a single driver, and the device_node pointer is used for lookups later...so I think it should keep a kref, and it doesn't. > drivers/of/pdt.c, function of_pdt_create_node Not real sure about this one. > Any idea whether these need of_node_get? In all cases the device node > value comes in as a parameter. I'm really not an expert on this stuff. I just saw a potential problem that I happen to be looking at in other subsystems, and I wanted to know what others thought. I think this discussion should include the DT folks and the subsystems in question. For one, I'm as interested as anyone in getting this todo clarified: Documentation/devicetree/todo.txt - Document node lifecycle for CONFIG_OF_DYNAMIC Regards, Brian -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Julia Lawall <julia.lawall@lip6.fr> |
|---|---|
| Date | 2015-11-18 21:50 +0100 |
| Subject | Re: device_node lifetime (was: Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put) |
| Message-ID | <qwhPY-84P-17@gated-at.bofh.it> |
| In reply to | #1272484 |
On Wed, 18 Nov 2015, Brian Norris wrote: > (changing subject, add devicetree@vger.kernel.org) > > On Tue, Nov 17, 2015 at 11:33:25PM +0100, Julia Lawall wrote: > > On Tue, 17 Nov 2015, Brian Norris wrote: > > > On Tue, Nov 17, 2015 at 06:48:39PM +0100, Julia Lawall wrote: > > > > Is this something that should be checked for elsewhere? > > > > > > I expect the same sort of problem shows up plenty of other places. I > > > don't think many people use CONFIG_OF_DYNAMIC, so the effects of these > > > failures probably aren't felt by many. > > > > I tried the following semantic patch: > > > > @@ > > struct device_node *e; > > expression e1; > > identifier fld; > > @@ > > > > ... when != of_node_get(...) > > *(<+...e1->fld...+>) = e > > ... when != of_node_get(...) > > return e1; > > > > basically, this says that a structure field is initilized to a device node > > value, the structure is returned by the containing function, and the > > containing function contains no of_node_get at all. Certainly this is > > quite constrained, but it does produce a number of examples. > > > > I looked at a few of them: > > > > drivers/clk/ingenic/cgu.c, ingenic_cgu_new > > clk/pistachio/clk.c, pistachio_clk_alloc_provider > > It looks like the clock core (drivers/clk/clk.c) initially grabs the clk > provider node in of_clk_init(), then drops it after it's initialized, > but most of these providers use of_clk_add_provider(), which seems to > manage the device_node lifetime for the user. So I think these are OK. > > > drivers/mfd/syscon.c, of_syscon_register > > This one looks potentially suspect. Syscon nodes aren't usually directly > managed by a single driver, and the device_node pointer is used for > lookups later...so I think it should keep a kref, and it doesn't. > > > drivers/of/pdt.c, function of_pdt_create_node > > Not real sure about this one. > > > Any idea whether these need of_node_get? In all cases the device node > > value comes in as a parameter. > > I'm really not an expert on this stuff. I just saw a potential problem > that I happen to be looking at in other subsystems, and I wanted to know > what others thought. Thanks for the analysis. I will look into them a bit more. Hopefully at least the maintainer of each file will know what should be done. julia > I think this discussion should include the DT folks > and the subsystems in question. For one, I'm as interested as anyone in > getting this todo clarified: > > Documentation/devicetree/todo.txt > - Document node lifecycle for CONFIG_OF_DYNAMIC > > Regards, > Brian > -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Rob Herring <robh@kernel.org> |
|---|---|
| Date | 2015-11-19 19:50 +0100 |
| Subject | Re: device_node lifetime (was: Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put) |
| Message-ID | <qwCro-4G9-21@gated-at.bofh.it> |
| In reply to | #1272484 |
On Wed, Nov 18, 2015 at 1:05 PM, Brian Norris <computersforpeace@gmail.com> wrote: > (changing subject, add devicetree@vger.kernel.org) > > On Tue, Nov 17, 2015 at 11:33:25PM +0100, Julia Lawall wrote: >> On Tue, 17 Nov 2015, Brian Norris wrote: >> > On Tue, Nov 17, 2015 at 06:48:39PM +0100, Julia Lawall wrote: >> > > Is this something that should be checked for elsewhere? >> > >> > I expect the same sort of problem shows up plenty of other places. I >> > don't think many people use CONFIG_OF_DYNAMIC, so the effects of these >> > failures probably aren't felt by many. The "problem" is non-existent because either CONFIG_OF_DYNAMIC is off or where it is used is limited (memory and cpus on PSeries) and now overlays. Overlays have the potential to be problematic, but we should manage ref counting for overlays in a completely different way. What that looks like, I don't know. I'll leave that to the person that cares about removing overlays. >> basically, this says that a structure field is initilized to a device node >> value, the structure is returned by the containing function, and the >> containing function contains no of_node_get at all. Certainly this is >> quite constrained, but it does produce a number of examples. I've got no idea if this is right or not. >> drivers/of/pdt.c, function of_pdt_create_node > > Not real sure about this one. SPARC. Stay away. > >> Any idea whether these need of_node_get? In all cases the device node >> value comes in as a parameter. > > I'm really not an expert on this stuff. I just saw a potential problem > that I happen to be looking at in other subsystems, and I wanted to know > what others thought. I think this discussion should include the DT folks > and the subsystems in question. For one, I'm as interested as anyone in > getting this todo clarified: > > Documentation/devicetree/todo.txt > - Document node lifecycle for CONFIG_OF_DYNAMIC Step 2 after figuring out it can't be documented is "define a new way to handle dynamic DT refcounting aka how to get rid of of_node_get/put." Rob -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Russell King - ARM Linux <linux@arm.linux.org.uk> |
|---|---|
| Date | 2015-11-19 20:20 +0100 |
| Subject | Re: device_node lifetime (was: Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put) |
| Message-ID | <qwCUq-57G-21@gated-at.bofh.it> |
| In reply to | #1273375 |
On Thu, Nov 19, 2015 at 12:44:11PM -0600, Rob Herring wrote: > On Wed, Nov 18, 2015 at 1:05 PM, Brian Norris > <computersforpeace@gmail.com> wrote: > > (changing subject, add devicetree@vger.kernel.org) > > > > On Tue, Nov 17, 2015 at 11:33:25PM +0100, Julia Lawall wrote: > >> On Tue, 17 Nov 2015, Brian Norris wrote: > >> > On Tue, Nov 17, 2015 at 06:48:39PM +0100, Julia Lawall wrote: > >> > > Is this something that should be checked for elsewhere? > >> > > >> > I expect the same sort of problem shows up plenty of other places. I > >> > don't think many people use CONFIG_OF_DYNAMIC, so the effects of these > >> > failures probably aren't felt by many. > > The "problem" is non-existent because either CONFIG_OF_DYNAMIC is off > or where it is used is limited (memory and cpus on PSeries) and now > overlays. Overlays have the potential to be problematic, but we should > manage ref counting for overlays in a completely different way. What > that looks like, I don't know. I'll leave that to the person that > cares about removing overlays. So are you saying we should just forget about of_node_put and delete all of_node_put/of_node_get references in code outside drivers/of ? That seems pretty obtuse given that we do have the overlay code merged, and sounds to me like a very bad idea. Expecting those who want to use overlays to run around checking that the refcounting is correct in drivers is a really silly idea IMHO - the existing API is refcounted, so either people really ought to be using it correctly as it's already been designed (in other words, with correct refcounting, and we shouldn't be shovelling this problem onto other people) or the refcounting should be completely killed. The existing half-way house of "we have refcounting, but we don't care about it" is really insane. Either we have refcounting, and it's used properly, or we don't have refcounting. No middle ground IMHO. -- FTTC broadband for 0.8mile line: currently at 9.6Mbps down 400kbps up according to speedtest.net. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Brian Norris <computersforpeace@gmail.com> |
|---|---|
| Date | 2015-11-17 18:50 +0100 |
| Subject | Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put |
| Message-ID | <qvSye-8a9-11@gated-at.bofh.it> |
| In reply to | #1270896 |
On Tue, Nov 17, 2015 at 07:12:22AM +0100, Julia Lawall wrote:
> On Mon, 16 Nov 2015, Brian Norris wrote:
> >
> > This reminds me of a potential problem I'm looking at in other
> > subsystems: from code reading (I haven't seen any issues in practice,
> > probably because I don't use OF_DYNAMIC) it looks like device-creating
> > infrastructure like the PHY subsystem should be acquiring a reference to
> > the device_node when they stash it away. But drivers/phy/phy-core.c does
> > not do this, AFAICT.
> >
> > See phy_create(), which does
> >
> > phy->dev.of_node = node ?: dev->of_node;
> >
> > and later might reuse this of_node pointer, even though it never called
> > of_node_get() on this node.
> >
> > Potential patch to fix this (not tested).
> >
> > Signed-off-by: Brian Norris <computersforpeace@gmail.com>
> >
> > diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c
> > index fc48fac003a6..8df29caeeef9 100644
> > --- a/drivers/phy/phy-core.c
> > +++ b/drivers/phy/phy-core.c
> > @@ -697,6 +697,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
> > phy->dev.class = phy_class;
> > phy->dev.parent = dev;
> > phy->dev.of_node = node ?: dev->of_node;
> > + of_node_get(phy->dev.of_node);
>
> Why not put of_node_get around dev->of_node?
Like this?
phy->dev.of_node = node ?: of_node_get(dev->of_node);
Or this?
phy->dev.of_node = of_node_get(node ?: dev->of_node);
The former wouldn't do what I proposed; if this PHY device is created
with a sub-node of 'dev' rather than dev->of_node, then the caller will
pass it in as the 2nd argument to phy_create (i.e., 'node'), and then I
expect it's the PHY core's responsibility to refcount it.
I'd be fine with the latter. Looks a little better, I suppose.
If my understanding is correct, I'll send a proper patch to do the
latter.
Regards,
Brian
> julia
>
> > phy->id = id;
> > phy->ops = ops;
> >
> > @@ -726,6 +727,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
> > return phy;
> >
> > put_dev:
> > + of_node_put(phy->dev.of_node);
> > put_device(&phy->dev); /* calls phy_release() which frees resources */
> > return ERR_PTR(ret);
> >
> > @@ -775,6 +777,7 @@ EXPORT_SYMBOL_GPL(devm_phy_create);
> > */
> > void phy_destroy(struct phy *phy)
> > {
> > + of_node_put(phy->dev.of_node);
> > pm_runtime_disable(&phy->dev);
> > device_unregister(&phy->dev);
> > }
> > --
> > To unsubscribe from this list: send the line "unsubscribe kernel-janitors" in
> > the body of a message to majordomo@vger.kernel.org
> > More majordomo info at http://vger.kernel.org/majordomo-info.html
> >
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Kishon Vijay Abraham I <kishon@ti.com> |
|---|---|
| Date | 2015-11-27 15:20 +0100 |
| Subject | Re: [PATCH 1/7] phy: brcmstb-sata: add missing of_node_put |
| Message-ID | <qzs2t-3Zb-5@gated-at.bofh.it> |
| In reply to | #1270750 |
+Grant
Hi,
On Tuesday 17 November 2015 07:08 AM, Brian Norris wrote:
> On Mon, Nov 16, 2015 at 12:33:14PM +0100, Julia Lawall wrote:
>> for_each_available_child_of_node performs an of_node_get on each iteration,
>> so a return from the middle of the loop requires an of_node_put.
>>
>> A simplified version of the semantic patch that finds this problem is as
>> follows (http://coccinelle.lip6.fr):
>>
>> // <smpl>
>> @@
>> expression root,e;
>> local idexpression child;
>> @@
>>
>> for_each_available_child_of_node(root, child) {
>> ... when != of_node_put(child)
>> when != e = child
>> (
>> return child;
>> |
>> * return ...;
>> )
>> ...
>> }
>> // </smpl>
>>
>> Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
>>
>> ---
>
> For this patch:
>
> Acked-by: Brian Norris <computersforpeace@gmail.com>
>
>> drivers/phy/phy-brcmstb-sata.c | 17 ++++++++++++-----
>> 1 file changed, 12 insertions(+), 5 deletions(-)
>
> [snip patch, which fixes of_node_put() handling for
> for_each_available_child_of_node() loop, which creates PHY devices with
> devm_phy_create()]
>
> This reminds me of a potential problem I'm looking at in other
> subsystems: from code reading (I haven't seen any issues in practice,
> probably because I don't use OF_DYNAMIC) it looks like device-creating
> infrastructure like the PHY subsystem should be acquiring a reference to
> the device_node when they stash it away. But drivers/phy/phy-core.c does
> not do this, AFAICT.
>
> See phy_create(), which does
>
> phy->dev.of_node = node ?: dev->of_node;
>
> and later might reuse this of_node pointer, even though it never called
> of_node_get() on this node.
>
> Potential patch to fix this (not tested).
>
> Signed-off-by: Brian Norris <computersforpeace@gmail.com>
>
> diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c
> index fc48fac003a6..8df29caeeef9 100644
> --- a/drivers/phy/phy-core.c
> +++ b/drivers/phy/phy-core.c
> @@ -697,6 +697,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
> phy->dev.class = phy_class;
> phy->dev.parent = dev;
> phy->dev.of_node = node ?: dev->of_node;
> + of_node_get(phy->dev.of_node);
> phy->id = id;
> phy->ops = ops;
>
> @@ -726,6 +727,7 @@ struct phy *phy_create(struct device *dev, struct device_node *node,
> return phy;
>
> put_dev:
> + of_node_put(phy->dev.of_node);
> put_device(&phy->dev); /* calls phy_release() which frees resources */
> return ERR_PTR(ret);
>
> @@ -775,6 +777,7 @@ EXPORT_SYMBOL_GPL(devm_phy_create);
> */
> void phy_destroy(struct phy *phy)
> {
> + of_node_put(phy->dev.of_node);
I think it's better to have this patch in phy-core though OF_DYNAMIC is not
enabled?
Grant,
Is it safe to assume of_node_get() will prevent "anyone else" from deleting the
node?
Here phy core uses the node pointer (passed to it by phy providers) and we
would like to avoid "anyone" from removing this node pointer resulting in phy
core having an invalid node pointer. Using of_node_get() in phy core should be
sufficient for this?
We are also interested in this todo tasklist for Devicetree..
"Document node lifecycle for CONFIG_OF_DYNAMIC"
Please find the complete thread of this mail chain here [1]
[1] -> http://www.gossamer-threads.com/lists/linux/kernel/2304857
Thanks
Kishon
> pm_runtime_disable(&phy->dev);
> device_unregister(&phy->dev);
> }
>
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Julia Lawall <Julia.Lawall@lip6.fr> |
|---|---|
| Date | 2015-11-16 12:50 +0100 |
| Subject | [PATCH 7/7] phy: cygnus: pcie: add missing of_node_put |
| Message-ID | <qvqsj-6MZ-45@gated-at.bofh.it> |
| In reply to | #1270037 |
for_each_available_child_of_node performs an of_node_get on each iteration,
so a return from the middle of the loop requires an of_node_put.
A simplified version of the semantic patch that finds this problem is as
follows (http://coccinelle.lip6.fr):
// <smpl>
@@
expression root,e;
local idexpression child;
@@
for_each_available_child_of_node(root, child) {
... when != of_node_put(child)
when != e = child
(
return child;
|
* return ...;
)
...
}
// </smpl>
Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
---
drivers/phy/phy-bcm-cygnus-pcie.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
diff --git a/drivers/phy/phy-bcm-cygnus-pcie.c b/drivers/phy/phy-bcm-cygnus-pcie.c
index 7ad72b7..082c03f 100644
--- a/drivers/phy/phy-bcm-cygnus-pcie.c
+++ b/drivers/phy/phy-bcm-cygnus-pcie.c
@@ -128,6 +128,7 @@ static int cygnus_pcie_phy_probe(struct platform_device *pdev)
struct phy_provider *provider;
struct resource *res;
unsigned cnt = 0;
+ int ret;
if (of_get_child_count(node) == 0) {
dev_err(dev, "PHY no child node\n");
@@ -154,24 +155,28 @@ static int cygnus_pcie_phy_probe(struct platform_device *pdev)
if (of_property_read_u32(child, "reg", &id)) {
dev_err(dev, "missing reg property for %s\n",
child->name);
- return -EINVAL;
+ ret = -EINVAL;
+ goto put_child;
}
if (id >= MAX_NUM_PHYS) {
dev_err(dev, "invalid PHY id: %u\n", id);
- return -EINVAL;
+ ret = -EINVAL;
+ goto put_child;
}
if (core->phys[id].phy) {
dev_err(dev, "duplicated PHY id: %u\n", id);
- return -EINVAL;
+ ret = -EINVAL;
+ goto put_child;
}
p = &core->phys[id];
p->phy = devm_phy_create(dev, child, &cygnus_pcie_phy_ops);
if (IS_ERR(p->phy)) {
dev_err(dev, "failed to create PHY\n");
- return PTR_ERR(p->phy);
+ ret = PTR_ERR(p->phy);
+ goto put_child;
}
p->core = core;
@@ -191,6 +196,9 @@ static int cygnus_pcie_phy_probe(struct platform_device *pdev)
dev_dbg(dev, "registered %u PCIe PHY(s)\n", cnt);
return 0;
+put_child:
+ of_node_put(child);
+ return ret;
}
static const struct of_device_id cygnus_pcie_phy_match_table[] = {
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Ray Jui <rjui@broadcom.com> |
|---|---|
| Date | 2015-11-16 18:20 +0100 |
| Subject | Re: [PATCH 7/7] phy: cygnus: pcie: add missing of_node_put |
| Message-ID | <qvvBD-1Ii-7@gated-at.bofh.it> |
| In reply to | #1270046 |
Hi Julia,
On 11/16/2015 3:33 AM, Julia Lawall wrote:
> for_each_available_child_of_node performs an of_node_get on each iteration,
> so a return from the middle of the loop requires an of_node_put.
>
> A simplified version of the semantic patch that finds this problem is as
> follows (http://coccinelle.lip6.fr):
>
> // <smpl>
> @@
> expression root,e;
> local idexpression child;
> @@
>
> for_each_available_child_of_node(root, child) {
> ... when != of_node_put(child)
> when != e = child
> (
> return child;
> |
> * return ...;
> )
> ...
> }
> // </smpl>
>
> Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
>
> ---
> drivers/phy/phy-bcm-cygnus-pcie.c | 16 ++++++++++++----
> 1 file changed, 12 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/phy/phy-bcm-cygnus-pcie.c b/drivers/phy/phy-bcm-cygnus-pcie.c
> index 7ad72b7..082c03f 100644
> --- a/drivers/phy/phy-bcm-cygnus-pcie.c
> +++ b/drivers/phy/phy-bcm-cygnus-pcie.c
> @@ -128,6 +128,7 @@ static int cygnus_pcie_phy_probe(struct platform_device *pdev)
> struct phy_provider *provider;
> struct resource *res;
> unsigned cnt = 0;
> + int ret;
>
> if (of_get_child_count(node) == 0) {
> dev_err(dev, "PHY no child node\n");
> @@ -154,24 +155,28 @@ static int cygnus_pcie_phy_probe(struct platform_device *pdev)
> if (of_property_read_u32(child, "reg", &id)) {
> dev_err(dev, "missing reg property for %s\n",
> child->name);
> - return -EINVAL;
> + ret = -EINVAL;
> + goto put_child;
> }
>
> if (id >= MAX_NUM_PHYS) {
> dev_err(dev, "invalid PHY id: %u\n", id);
> - return -EINVAL;
> + ret = -EINVAL;
> + goto put_child;
> }
>
> if (core->phys[id].phy) {
> dev_err(dev, "duplicated PHY id: %u\n", id);
> - return -EINVAL;
> + ret = -EINVAL;
> + goto put_child;
> }
>
> p = &core->phys[id];
> p->phy = devm_phy_create(dev, child, &cygnus_pcie_phy_ops);
> if (IS_ERR(p->phy)) {
> dev_err(dev, "failed to create PHY\n");
> - return PTR_ERR(p->phy);
> + ret = PTR_ERR(p->phy);
> + goto put_child;
> }
>
> p->core = core;
> @@ -191,6 +196,9 @@ static int cygnus_pcie_phy_probe(struct platform_device *pdev)
> dev_dbg(dev, "registered %u PCIe PHY(s)\n", cnt);
>
> return 0;
> +put_child:
> + of_node_put(child);
> + return ret;
> }
>
> static const struct of_device_id cygnus_pcie_phy_match_table[] = {
>
This fix looks good to me. Thanks!
Reviewed-by: Ray Jui <rjui@broadcom.com>
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web