Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1513220 > unrolled thread

[PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks

Started byJohan Hovold <johan@kernel.org>
First post2016-11-01 12:10 +0100
Last post2016-11-01 18:10 +0100
Articles 5 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks Johan Hovold <johan@kernel.org> - 2016-11-01 12:10 +0100
    Re: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and  of_node leaks David Miller <davem@davemloft.net> - 2016-11-01 17:30 +0100
      Re: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node  leaks Johan Hovold <johan@kernel.org> - 2016-11-01 17:50 +0100
        Re: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and  of_node leaks David Miller <davem@davemloft.net> - 2016-11-01 18:00 +0100
          Re: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node  leaks Johan Hovold <johan@kernel.org> - 2016-11-01 18:10 +0100

#1513220 — [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks

FromJohan Hovold <johan@kernel.org>
Date2016-11-01 12:10 +0100
Subject[PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks
Message-ID<syF73-7U4-21@gated-at.bofh.it>
Make sure to drop the references taken by of_get_child_by_name() and
bus_find_device() before returning from cpsw_phy_sel().

Note that there is no guarantee that the devres-managed struct
cpsw_phy_sel_priv will continue to be valid until this function returns
regardless of this change.

Fixes: 5892cd135e16 ("drivers: net: cpsw-phy-sel: Add new driver...")
Signed-off-by: Johan Hovold <johan@kernel.org>
---
 drivers/net/ethernet/ti/cpsw-phy-sel.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/net/ethernet/ti/cpsw-phy-sel.c b/drivers/net/ethernet/ti/cpsw-phy-sel.c
index 054a8dd23dae..589beb843f56 100644
--- a/drivers/net/ethernet/ti/cpsw-phy-sel.c
+++ b/drivers/net/ethernet/ti/cpsw-phy-sel.c
@@ -176,8 +176,11 @@ void cpsw_phy_sel(struct device *dev, phy_interface_t phy_mode, int slave)
 	}
 
 	dev = bus_find_device(&platform_bus_type, NULL, node, match);
+	of_node_put(node);
 	priv = dev_get_drvdata(dev);
 
+	put_device(dev);
+
 	priv->cpsw_phy_sel(priv, phy_mode, slave);
 }
 EXPORT_SYMBOL_GPL(cpsw_phy_sel);
-- 
2.7.3

[toc] | [next] | [standalone]


#1513353 — Re: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks

FromDavid Miller <davem@davemloft.net>
Date2016-11-01 17:30 +0100
SubjectRe: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks
Message-ID<syK6K-2Be-37@gated-at.bofh.it>
In reply to#1513220
From: Johan Hovold <johan@kernel.org>
Date: Tue,  1 Nov 2016 12:03:35 +0100

> diff --git a/drivers/net/ethernet/ti/cpsw-phy-sel.c b/drivers/net/ethernet/ti/cpsw-phy-sel.c
> index 054a8dd23dae..589beb843f56 100644
> --- a/drivers/net/ethernet/ti/cpsw-phy-sel.c
> +++ b/drivers/net/ethernet/ti/cpsw-phy-sel.c
> @@ -176,8 +176,11 @@ void cpsw_phy_sel(struct device *dev, phy_interface_t phy_mode, int slave)
>  	}
>  
>  	dev = bus_find_device(&platform_bus_type, NULL, node, match);
> +	of_node_put(node);
>  	priv = dev_get_drvdata(dev);
>  
> +	put_device(dev);
> +
>  	priv->cpsw_phy_sel(priv, phy_mode, slave);
>  }
>  EXPORT_SYMBOL_GPL(cpsw_phy_sel);

The only reference you have to 'dev' is the one obtained from the
bus_find_device() call, therefore you must at least hold onto
'dev' until after the priv->cpsw_phy_sel(priv, phy_mode, slave); call.

[toc] | [prev] | [next] | [standalone]


#1513366 — Re: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks

FromJohan Hovold <johan@kernel.org>
Date2016-11-01 17:50 +0100
SubjectRe: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks
Message-ID<syKq5-2Hy-13@gated-at.bofh.it>
In reply to#1513353
On Tue, Nov 01, 2016 at 12:27:11PM -0400, David Miller wrote:
> From: Johan Hovold <johan@kernel.org>
> Date: Tue,  1 Nov 2016 12:03:35 +0100
> 
> > diff --git a/drivers/net/ethernet/ti/cpsw-phy-sel.c b/drivers/net/ethernet/ti/cpsw-phy-sel.c
> > index 054a8dd23dae..589beb843f56 100644
> > --- a/drivers/net/ethernet/ti/cpsw-phy-sel.c
> > +++ b/drivers/net/ethernet/ti/cpsw-phy-sel.c
> > @@ -176,8 +176,11 @@ void cpsw_phy_sel(struct device *dev, phy_interface_t phy_mode, int slave)
> >  	}
> >  
> >  	dev = bus_find_device(&platform_bus_type, NULL, node, match);
> > +	of_node_put(node);
> >  	priv = dev_get_drvdata(dev);
> >  
> > +	put_device(dev);
> > +
> >  	priv->cpsw_phy_sel(priv, phy_mode, slave);
> >  }
> >  EXPORT_SYMBOL_GPL(cpsw_phy_sel);
> 
> The only reference you have to 'dev' is the one obtained from the
> bus_find_device() call, therefore you must at least hold onto
> 'dev' until after the priv->cpsw_phy_sel(priv, phy_mode, slave); call.

As I mentioned in the commit message "...there is no guarantee that the
devres-managed struct cpsw_phy_sel_priv will continue to be valid until
this function returns regardless of this change".

Specifically, holding a reference to dev does not prevent the
cpsw_phy_sel driver from being unbound and priv from being freed.

Thanks,
Johan

[toc] | [prev] | [next] | [standalone]


#1513372 — Re: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks

FromDavid Miller <davem@davemloft.net>
Date2016-11-01 18:00 +0100
SubjectRe: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks
Message-ID<syKzL-2KG-21@gated-at.bofh.it>
In reply to#1513366
From: Johan Hovold <johan@kernel.org>
Date: Tue, 1 Nov 2016 17:42:25 +0100

> On Tue, Nov 01, 2016 at 12:27:11PM -0400, David Miller wrote:
>> From: Johan Hovold <johan@kernel.org>
>> Date: Tue,  1 Nov 2016 12:03:35 +0100
>> 
>> > diff --git a/drivers/net/ethernet/ti/cpsw-phy-sel.c b/drivers/net/ethernet/ti/cpsw-phy-sel.c
>> > index 054a8dd23dae..589beb843f56 100644
>> > --- a/drivers/net/ethernet/ti/cpsw-phy-sel.c
>> > +++ b/drivers/net/ethernet/ti/cpsw-phy-sel.c
>> > @@ -176,8 +176,11 @@ void cpsw_phy_sel(struct device *dev, phy_interface_t phy_mode, int slave)
>> >  	}
>> >  
>> >  	dev = bus_find_device(&platform_bus_type, NULL, node, match);
>> > +	of_node_put(node);
>> >  	priv = dev_get_drvdata(dev);
>> >  
>> > +	put_device(dev);
>> > +
>> >  	priv->cpsw_phy_sel(priv, phy_mode, slave);
>> >  }
>> >  EXPORT_SYMBOL_GPL(cpsw_phy_sel);
>> 
>> The only reference you have to 'dev' is the one obtained from the
>> bus_find_device() call, therefore you must at least hold onto
>> 'dev' until after the priv->cpsw_phy_sel(priv, phy_mode, slave); call.
> 
> As I mentioned in the commit message "...there is no guarantee that the
> devres-managed struct cpsw_phy_sel_priv will continue to be valid until
> this function returns regardless of this change".
> 
> Specifically, holding a reference to dev does not prevent the
> cpsw_phy_sel driver from being unbound and priv from being freed.

But you should at least hold onto the object while you call a function
pointer embedded in a data structure referred by it.

[toc] | [prev] | [next] | [standalone]


#1513379 — Re: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks

FromJohan Hovold <johan@kernel.org>
Date2016-11-01 18:10 +0100
SubjectRe: [PATCH net 2/4] net: ethernet: ti: cpsw: fix device and of_node leaks
Message-ID<syKJr-33k-9@gated-at.bofh.it>
In reply to#1513372
On Tue, Nov 01, 2016 at 12:48:48PM -0400, David Miller wrote:
> From: Johan Hovold <johan@kernel.org>
> Date: Tue, 1 Nov 2016 17:42:25 +0100
> 
> > On Tue, Nov 01, 2016 at 12:27:11PM -0400, David Miller wrote:
> >> From: Johan Hovold <johan@kernel.org>
> >> Date: Tue,  1 Nov 2016 12:03:35 +0100
> >> 
> >> > diff --git a/drivers/net/ethernet/ti/cpsw-phy-sel.c b/drivers/net/ethernet/ti/cpsw-phy-sel.c
> >> > index 054a8dd23dae..589beb843f56 100644
> >> > --- a/drivers/net/ethernet/ti/cpsw-phy-sel.c
> >> > +++ b/drivers/net/ethernet/ti/cpsw-phy-sel.c
> >> > @@ -176,8 +176,11 @@ void cpsw_phy_sel(struct device *dev, phy_interface_t phy_mode, int slave)
> >> >  	}
> >> >  
> >> >  	dev = bus_find_device(&platform_bus_type, NULL, node, match);
> >> > +	of_node_put(node);
> >> >  	priv = dev_get_drvdata(dev);
> >> >  
> >> > +	put_device(dev);
> >> > +
> >> >  	priv->cpsw_phy_sel(priv, phy_mode, slave);
> >> >  }
> >> >  EXPORT_SYMBOL_GPL(cpsw_phy_sel);
> >> 
> >> The only reference you have to 'dev' is the one obtained from the
> >> bus_find_device() call, therefore you must at least hold onto
> >> 'dev' until after the priv->cpsw_phy_sel(priv, phy_mode, slave); call.
> > 
> > As I mentioned in the commit message "...there is no guarantee that the
> > devres-managed struct cpsw_phy_sel_priv will continue to be valid until
> > this function returns regardless of this change".
> > 
> > Specifically, holding a reference to dev does not prevent the
> > cpsw_phy_sel driver from being unbound and priv from being freed.
> 
> But you should at least hold onto the object while you call a function
> pointer embedded in a data structure referred by it.

But there is no such reference to be held (currently). While priv is
valid (i.e. dev has a driver bound), driver core will hold a reference
to dev. If someone unbinds the driver, priv will be gone long before dev
and all bets are off anyway.

So I released the reference to dev before dereferencing priv on purpose
to avoid having someone make false assumptions about the lifetime of priv.

Johan

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web