From: Sam Asadi <asadi.samuel@gmail.com>
To: gregkh@linuxfoundation.org
Cc: devel@driverdev.osuosl.org, linux-kernel@vger.kernel.org,
Krzysztof Kozlowski <k.kozlowski@samsung.com>,
<stable@vger.kernel.org>, Mike Turquette <mturquette@linaro.org>,
sam-the-6 <asadi.samuel@gmail.com>
Subject: [PATCH 14/94] clk: s2mps11: Fix double free corruption during driver unbind
Date: Tue, 15 Jul 2014 20:00:29 +0300 [thread overview]
Message-ID: <1405443709-15288-14-git-send-email-asadi.samuel@gmail.com> (raw)
In-Reply-To: <1405443709-15288-1-git-send-email-asadi.samuel@gmail.com>
From: Krzysztof Kozlowski <k.kozlowski@samsung.com>
After unbinding the driver memory was corrupted by double free of
clk_lookup structure. This lead to OOPS when re-binding the driver
again.
The driver allocated memory for 'clk_lookup' with devm_kzalloc. During
driver removal this memory was freed twice: once by clkdev_drop() and
second by devm code.
Kernel panic log:
[ 30.839284] Unable to handle kernel paging request at virtual address 5f343173
[ 30.846476] pgd = dee14000
[ 30.849165] [5f343173] *pgd=00000000
[ 30.852703] Internal error: Oops: 805 [#1] PREEMPT SMP ARM
[ 30.858166] Modules linked in:
[ 30.861208] CPU: 0 PID: 1 Comm: bash Not tainted 3.16.0-rc2-00239-g94bdf617b07e-dirty #40
[ 30.869364] task: df478000 ti: df480000 task.ti: df480000
[ 30.874752] PC is at clkdev_add+0x2c/0x38
[ 30.878738] LR is at clkdev_add+0x18/0x38
[ 30.882732] pc : [<c0350908>] lr : [<c03508f4>] psr: 60000013
[ 30.882732] sp : df481e78 ip : 00000001 fp : c0700ed8
[ 30.894187] r10: 0000000c r9 : 00000000 r8 : c07b0e3c
[ 30.899396] r7 : 00000002 r6 : df45f9d0 r5 : df421390 r4 : c0700d6c
[ 30.905906] r3 : 5f343173 r2 : c0700d84 r1 : 60000013 r0 : c0700d6c
[ 30.912417] Flags: nZCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment user
[ 30.919534] Control: 10c53c7d Table: 5ee1406a DAC: 00000015
[ 30.925262] Process bash (pid: 1, stack limit = 0xdf480240)
[ 30.930817] Stack: (0xdf481e78 to 0xdf482000)
[ 30.935159] 1e60: 00001000 df6de610
[ 30.943321] 1e80: df7f4558 c0355650 c05ec6ec c0700eb0 df6de600 df7f4510 dec9d69c 00000014
[ 30.951480] 1ea0: 00167b48 df6de610 c0700e30 c0713518 00000000 c0700e30 dec9d69c 00000006
[ 30.959639] 1ec0: 00167b48 c02c1b7c c02c1b64 df6de610 c07aff48 c02c0420 c06fb150 c047cc20
[ 30.967798] 1ee0: df6de610 df6de610 c0700e30 df6de644 c06fb150 0000000c dec9d690 c02bef90
[ 30.975957] 1f00: dec9c6c0 dece4c00 df481f80 dece4c00 0000000c c02be73c 0000000c c016ca8c
[ 30.984116] 1f20: c016ca48 00000000 00000000 c016c1f4 00000000 00000000 b6f18000 df481f80
[ 30.992276] 1f40: df7f66c0 0000000c df480000 df480000 b6f18000 c011094c df47839c 60000013
[ 31.000435] 1f60: 00000000 00000000 df7f66c0 df7f66c0 0000000c df480000 b6f18000 c0110dd4
[ 31.008594] 1f80: 00000000 00000000 0000000c b6ec05d8 0000000c b6f18000 00000004 c000f2a8
[ 31.016753] 1fa0: 00001000 c000f0e0 b6ec05d8 0000000c 00000001 b6f18000 0000000c 00000000
[ 31.024912] 1fc0: b6ec05d8 0000000c b6f18000 00000004 0000000c 00000001 00000000 00167b48
[ 31.033071] 1fe0: 00000000 bed83a80 b6e004f0 b6e5122c 60000010 00000001 ffffffff ffffffff
[ 31.041248] [<c0350908>] (clkdev_add) from [<c0355650>] (s2mps11_clk_probe+0x2b4/0x3b4)
[ 31.049223] [<c0355650>] (s2mps11_clk_probe) from [<c02c1b7c>] (platform_drv_probe+0x18/0x48)
[ 31.057728] [<c02c1b7c>] (platform_drv_probe) from [<c02c0420>] (driver_probe_device+0x13c/0x384)
[ 31.066579] [<c02c0420>] (driver_probe_device) from [<c02bef90>] (bind_store+0x88/0xd8)
[ 31.074564] [<c02bef90>] (bind_store) from [<c02be73c>] (drv_attr_store+0x20/0x2c)
[ 31.082118] [<c02be73c>] (drv_attr_store) from [<c016ca8c>] (sysfs_kf_write+0x44/0x48)
[ 31.090016] [<c016ca8c>] (sysfs_kf_write) from [<c016c1f4>] (kernfs_fop_write+0xc0/0x17c)
[ 31.098176] [<c016c1f4>] (kernfs_fop_write) from [<c011094c>] (vfs_write+0xa0/0x1c4)
[ 31.105899] [<c011094c>] (vfs_write) from [<c0110dd4>] (SyS_write+0x40/0x8c)
[ 31.112931] [<c0110dd4>] (SyS_write) from [<c000f0e0>] (ret_fast_syscall+0x0/0x3c)
[ 31.120481] Code: e2842018 e584501c e1a00004 e885000c (e5835000)
[ 31.126596] ---[ end trace efad45bfa3a61b05 ]---
[ 31.131181] Kernel panic - not syncing: Fatal exception
[ 31.136368] CPU1: stopping
[ 31.139054] CPU: 1 PID: 0 Comm: swapper/1 Tainted: G D 3.16.0-rc2-00239-g94bdf617b07e-dirty #40
[ 31.148697] [<c0016480>] (unwind_backtrace) from [<c0012950>] (show_stack+0x10/0x14)
[ 31.156419] [<c0012950>] (show_stack) from [<c0480db8>] (dump_stack+0x80/0xcc)
[ 31.163622] [<c0480db8>] (dump_stack) from [<c001499c>] (handle_IPI+0x130/0x15c)
[ 31.170998] [<c001499c>] (handle_IPI) from [<c000862c>] (gic_handle_irq+0x60/0x68)
[ 31.178549] [<c000862c>] (gic_handle_irq) from [<c0013480>] (__irq_svc+0x40/0x70)
[ 31.186009] Exception stack(0xdf4bdf88 to 0xdf4bdfd0)
[ 31.191046] df80: ffffffed 00000000 00000000 00000000 df4bc000 c06d042c
[ 31.199207] dfa0: 00000000 ffffffed c06d03c0 00000000 c070c288 00000000 00000000 df4bdfd0
[ 31.207363] dfc0: c0010324 c0010328 60000013 ffffffff
[ 31.212402] [<c0013480>] (__irq_svc) from [<c0010328>] (arch_cpu_idle+0x28/0x30)
[ 31.219783] [<c0010328>] (arch_cpu_idle) from [<c005f150>] (cpu_startup_entry+0x2c4/0x3f0)
[ 31.228027] [<c005f150>] (cpu_startup_entry) from [<400086c4>] (0x400086c4)
[ 31.234968] ---[ end Kernel panic - not syncing: Fatal exception
Fixes: 7cc560dea415 ("clk: s2mps11: Add support for s2mps11")
Cc: <stable@vger.kernel.org>
Signed-off-by: Krzysztof Kozlowski <k.kozlowski@samsung.com>
Reviewed-by: Yadwinder Singh Brar <yadi.brar@samsung.com>
Signed-off-by: Mike Turquette <mturquette@linaro.org>
Signed-off-by: sam-the-6 <asadi.samuel@gmail.com>
---
drivers/clk/clk-s2mps11.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/drivers/clk/clk-s2mps11.c b/drivers/clk/clk-s2mps11.c
index 9b7b585..3757e9e 100644
--- a/drivers/clk/clk-s2mps11.c
+++ b/drivers/clk/clk-s2mps11.c
@@ -230,16 +230,13 @@ static int s2mps11_clk_probe(struct platform_device *pdev)
goto err_reg;
}
- s2mps11_clk->lookup = devm_kzalloc(&pdev->dev,
- sizeof(struct clk_lookup), GFP_KERNEL);
+ s2mps11_clk->lookup = clkdev_alloc(s2mps11_clk->clk,
+ s2mps11_name(s2mps11_clk), NULL);
if (!s2mps11_clk->lookup) {
ret = -ENOMEM;
goto err_lup;
}
- s2mps11_clk->lookup->con_id = s2mps11_name(s2mps11_clk);
- s2mps11_clk->lookup->clk = s2mps11_clk->clk;
-
clkdev_add(s2mps11_clk->lookup);
}
--
1.7.10.4
next prev parent reply other threads:[~2014-07-15 17:21 UTC|newest]
Thread overview: 99+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-07-15 17:00 [PATCH 01/94] ARM: shmobile: Add DT and defconfigs to MAINTAINERS Sam Asadi
2014-07-15 17:00 ` [PATCH 02/94] clk: ti: apll: not allocating enough data Sam Asadi
2014-07-15 17:00 ` [PATCH 03/94] clk: ti: dra7: return error code in failure case Sam Asadi
2014-07-15 17:00 ` [PATCH 04/94] clk: ti: am43x: Fix boot with CONFIG_SOC_AM33XX disabled Sam Asadi
2014-07-15 17:00 ` [PATCH 05/94] clk: ti: set CLK_SET_RATE_NO_REPARENT for ti,mux-clock Sam Asadi
2014-07-15 17:00 ` [PATCH 06/94] clk: samsung: fix several typos to fix boot on s3c2410 Sam Asadi
2014-07-15 17:00 ` [PATCH 07/94] clk: samsung: add more aliases for s3c24xx Sam Asadi
2014-07-15 17:00 ` [PATCH 08/94] clk: samsung: exynos4: Remove SRC_MASK_ISP gates Sam Asadi
2014-07-15 17:00 ` [PATCH 09/94] clk: s3c64xx: Hookup SPI clocks correctly Sam Asadi
2014-07-15 17:00 ` [PATCH 10/94] clk/exynos5250: fix bit number for tv sysmmu clock Sam Asadi
2014-07-15 17:00 ` [PATCH 11/94] clk: exynos5420: Remove aclk66_peric from the clock tree description Sam Asadi
2014-07-15 17:00 ` [PATCH 12/94] dma: cppi41: handle 0-length packets Sam Asadi
2014-07-15 17:00 ` [PATCH 13/94] Update imx-sdma cyclic handling to report residue Sam Asadi
2014-07-15 17:00 ` Sam Asadi [this message]
2014-07-15 17:00 ` [PATCH 15/94] clk: sunxi: fix devm_ioremap_resource error detection code Sam Asadi
2014-07-15 17:00 ` [PATCH 16/94] ARM: kprobes: Prevent known test failures stopping other tests running Sam Asadi
2014-07-15 17:00 ` [PATCH 17/94] ARM: kprobes: Disallow instructions with PC and register specified shift Sam Asadi
2014-07-15 17:00 ` [PATCH 18/94] ARM: kprobes: Fix test code compilation errors for ARMv4 targets Sam Asadi
2014-07-15 17:00 ` [PATCH 19/94] clk: qcom: HDMI source sel is 3 not 2 Sam Asadi
2014-07-15 17:00 ` [PATCH 20/94] ARM: dts: dra7xx-clocks: Fix the l3 and l4 clock rates Sam Asadi
2014-07-15 17:00 ` [PATCH 21/94] ARM: EXYNOS: Fix the check for non-smp configuration Sam Asadi
2014-07-15 17:00 ` [PATCH 22/94] ARM: dts: fix pwm-cells in pwm node for exynos4 Sam Asadi
2014-07-15 17:00 ` [PATCH 23/94] clocksource: exynos_mct: Fix ftrace Sam Asadi
2014-07-15 17:00 ` [PATCH 24/94] clocksource: exynos_mct: Register the timer for stable udelay Sam Asadi
2014-07-15 17:00 ` [PATCH 25/94] iio: hid-sensor-press: Fix return values Sam Asadi
2014-07-15 17:00 ` [PATCH 26/94] iio: hid-sensor-accel-3d: " Sam Asadi
2014-07-15 17:00 ` [PATCH 27/94] iio: hid-sensor-magn-3d: " Sam Asadi
2014-07-15 17:00 ` [PATCH 28/94] iio: hid-sensor-als: " Sam Asadi
2014-07-15 17:00 ` [PATCH 29/94] iio: hid-sensor-gyro-3d: " Sam Asadi
2014-07-15 17:00 ` [PATCH 30/94] iio: hid-sensor-prox: " Sam Asadi
2014-07-15 17:00 ` [PATCH 31/94] ext4: fix unjournalled bg descriptor while initializing inode bitmap Sam Asadi
2014-07-15 17:00 ` [PATCH 32/94] ext4: clarify error count warning messages Sam Asadi
2014-07-15 17:00 ` [PATCH 33/94] ext4: clarify ext4_error message in ext4_mb_generate_buddy_error() Sam Asadi
2014-07-15 17:00 ` [PATCH 34/94] ext4: disable synchronous transaction batching if max_batch_time==0 Sam Asadi
2014-07-15 17:00 ` [PATCH 35/94] ARM: OMAP3: PRM/CM: Add back macros used by TI DSP/Bridge driver Sam Asadi
2014-07-15 17:00 ` [PATCH 36/94] ARM: DRA7: hwmod: Fixup SATA hwmod Sam Asadi
2014-07-15 17:00 ` [PATCH 37/94] ARM: DRA7: hwmod: Add SYSCONFIG for usb_otg_ss Sam Asadi
2014-07-15 17:00 ` [PATCH 38/94] ARM: OMAP2+: clock/dpll: fix _dpll_test_fint arithmetics overflow Sam Asadi
2014-07-15 17:00 ` [PATCH 39/94] iio:tcs3472: Check for buffer enabled and locking Sam Asadi
2014-07-15 17:00 ` [PATCH 40/94] USB: cp210x: add support for Corsair usb dongle Sam Asadi
2014-07-15 17:00 ` [PATCH 41/94] usb: option: Add ID for Telewell TW-LTE 4G v2 Sam Asadi
2014-07-15 17:00 ` [PATCH 42/94] ARM: DRA7/AM43XX: fix header definition for omap44xx_restart Sam Asadi
2014-07-15 17:00 ` [PATCH 43/94] ARM: dts: dra7-evm: Make VDDA_1V8_PHY supply always on Sam Asadi
2014-07-15 17:00 ` [PATCH 44/94] ARM: OMAP2+: create dsp device only on OMAP3 SoCs Sam Asadi
2014-07-15 17:01 ` [PATCH 45/94] ARM: OMAP2+: Make GPMC skip disabled devices Sam Asadi
2014-07-15 17:01 ` [PATCH 46/94] ARM: dts: am335x-evm: Enable the McASP FIFO for audio Sam Asadi
2014-07-16 5:40 ` Peter Ujfalusi
2014-07-15 17:01 ` [PATCH 47/94] ARM: dts: am335x-evmsk: " Sam Asadi
2014-07-15 17:01 ` [PATCH 48/94] ARM: dts: Fix TI CPSW Phy mode selection on IGEP COM AQUILA Sam Asadi
2014-07-15 17:01 ` [PATCH 49/94] ARM: l2c: fix revision checking Sam Asadi
2014-07-15 17:01 ` [PATCH 50/94] ARM: EXYNOS: Update secondary boot addr for secure mode Sam Asadi
2014-07-15 17:01 ` [PATCH 51/94] ARM: dts: Update the parent for Audss clocks in Exynos5420 Sam Asadi
2014-07-15 17:01 ` [PATCH 52/94] ARM: imx: fix shared gate clock Sam Asadi
2014-07-15 17:01 ` [PATCH 53/94] ARM: OMAP2+: Remove non working OMAP HDMI audio initialization Sam Asadi
2014-07-15 17:01 ` [PATCH 54/94] iio: ti_am335x_adc: Fix: Use same step id at FIFOs both ends Sam Asadi
2014-07-15 17:01 ` [PATCH 55/94] Drivers: hv: vmbus: Fix a bug in the channel callback dispatch code Sam Asadi
2014-07-15 17:01 ` [PATCH 56/94] Drivers: hv: util: Fix a bug in the KVP code Sam Asadi
2014-07-15 17:01 ` [PATCH 57/94] USB: ftdi_sio: Add extra PID Sam Asadi
2014-07-15 17:01 ` [PATCH 58/94] i8k: Fix non-SMP operation Sam Asadi
2014-08-18 23:19 ` i8k: Don't revert affinity in i8k_smm Con Kolivas
2014-08-19 2:32 ` Guenter Roeck
2014-08-19 12:34 ` Con Kolivas
2014-07-15 17:01 ` [PATCH 59/94] m68k: Fix boot regression on machines with RAM at non-zero Sam Asadi
2014-07-15 17:01 ` [PATCH 60/94] ARM: EXYNOS: Add support for clock handling in power domain Sam Asadi
2014-07-15 17:01 ` [PATCH 61/94] clk: exynos5420: Add IDs for clocks used in PD mfc Sam Asadi
2014-07-15 17:01 ` [PATCH 62/94] ARM: dts: Add clock property for mfc_pd in exynos5420 Sam Asadi
2014-07-15 17:01 ` [PATCH 63/94] ARM: EXYNOS: Register cpuidle device only on exynos4210 and 5250 Sam Asadi
2014-07-15 17:01 ` [PATCH 64/94] serial: Test for no tx data on tx restart Sam Asadi
2014-07-15 17:01 ` [PATCH 65/94] serial: arc_uart: Use uart_circ_empty() for open-coded comparison Sam Asadi
2014-07-15 17:01 ` [PATCH 66/94] m68k: Export mach_random_get_entropy to modules Sam Asadi
2014-07-15 17:01 ` [PATCH 67/94] ext4: revert commit which was causing fs corruption after journal replays Sam Asadi
2014-07-15 17:01 ` [PATCH 68/94] serial: imx: Fix build breakage Sam Asadi
2014-07-15 17:01 ` [PATCH 69/94] serial: sh-sci: Add device tree support for r8a7{778,740,3a4} and sh73a0 Sam Asadi
2014-07-15 17:01 ` [PATCH 70/94] USB: serial: ftdi_sio: Add Infineon Triboard Sam Asadi
2014-07-15 17:01 ` [PATCH 71/94] phy: sun4i: depend on RESET_CONTROLLER Sam Asadi
2014-07-15 17:01 ` [PATCH 72/94] phy: omap-usb2: fix devm_ioremap_resource error detection code Sam Asadi
2014-07-15 17:01 ` [PATCH 73/94] drivers: phy: phy-samsung-usb2.c: Add missing MODULE_DEVICE_TABLE Sam Asadi
2014-07-15 17:01 ` [PATCH 74/94] phy: core: Fix error path in phy_create() Sam Asadi
2014-07-15 17:01 ` [PATCH 75/94] phy: omap-usb2: Balance pm_runtime_enable() on probe failure and remove Sam Asadi
2014-07-15 17:01 ` [PATCH 76/94] ARM: at91: at91sam9x5: add clocks for usb device Sam Asadi
2014-07-15 17:01 ` [PATCH 77/94] Documentation/Changes: clean up mcelog paragraph Sam Asadi
2014-07-15 17:01 ` [PATCH 78/94] scripts/kernel-doc: handle object-like macros Sam Asadi
2014-07-15 17:01 ` [PATCH 79/94] DocBook: fix mtdnand typos Sam Asadi
2014-07-15 17:01 ` [PATCH 80/94] DocBook: fix various typos Sam Asadi
2014-07-15 17:01 ` [PATCH 81/94] Documenation/laptops: rename and update hpfall.c Sam Asadi
2014-07-15 17:01 ` [PATCH 82/94] ext4: fix a potential deadlock in __ext4_es_shrink() Sam Asadi
2014-07-15 17:01 ` [PATCH 83/94] ext4: fix potential null pointer dereference in ext4_free_inode Sam Asadi
2014-07-15 17:01 ` [PATCH 84/94] parisc: add serial ports of C8000/1GHz machine to hardware database Sam Asadi
2014-07-15 17:01 ` [PATCH 85/94] parisc: fix fanotify_mark() syscall on 32bit compat kernel Sam Asadi
2014-07-15 17:01 ` [PATCH 86/94] parisc: drop unused defines and header includes Sam Asadi
2014-07-15 17:01 ` [PATCH 87/94] clk: spear3xx: Use proper control register offset Sam Asadi
2014-07-15 17:01 ` [PATCH 88/94] clk: spear3xx: Set proper clock parent of uart1/2 Sam Asadi
2014-07-15 17:01 ` [PATCH 89/94] Linux 3.16-rc5 Sam Asadi
2014-07-15 17:37 ` Valdis.Kletnieks
2014-07-15 17:01 ` [PATCH 90/94] Staging: comedi: 8253.h fixed by removing 'return' from generic func Sam Asadi
2014-07-15 17:01 ` [PATCH 91/94] Staging: comedi: 8255: fixed by adding an empthy line Sam Asadi
2014-07-15 17:01 ` [PATCH 92/94] Staging: comedi: adl_pci9118: fixed style issues Sam Asadi
2014-07-15 17:01 ` [PATCH 93/94] Staging: comedi: 3 files revised " Sam Asadi
2014-07-15 17:01 ` [PATCH 94/94] Staging: commedi: 8253.h: style issue fixed Sam Asadi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1405443709-15288-14-git-send-email-asadi.samuel@gmail.com \
--to=asadi.samuel@gmail.com \
--cc=devel@driverdev.osuosl.org \
--cc=gregkh@linuxfoundation.org \
--cc=k.kozlowski@samsung.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mturquette@linaro.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®