mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record()
@ 2026-01-06  9:13 Zilin Guan
  2026-01-06  9:13 ` [PATCH v3 2/2] platform/x86/amd: Use scope-based cleanup for wbrf_record() Zilin Guan
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Zilin Guan @ 2026-01-06  9:13 UTC (permalink / raw)
  To: hansg
  Cc: ilpo.jarvinen, platform-driver-x86, linux-kernel, Zilin Guan, Jianhao Xu

The tmp buffer is allocated using kcalloc() but is not freed if
acpi_evaluate_dsm() fails. This causes a memory leak in the error path.

Fix this by explicitly freeing the tmp buffer in the error handling
path of acpi_evaluate_dsm().

Fixes: 58e82a62669d ("platform/x86/amd: Add support for AMD ACPI based Wifi band RFI mitigation feature")
Suggested-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Co-developed-by: Jianhao Xu <jianhao.xu@seu.edu.cn>
Signed-off-by: Jianhao Xu <jianhao.xu@seu.edu.cn>
Signed-off-by: Zilin Guan <zilin@seu.edu.cn>
---
Changes in v3:
- Split from v2 to separate the fix from the cleanup.

Changes in v2:
- Use scope-based cleanup helper __free() for automatic resource cleanup.

 drivers/platform/x86/amd/wbrf.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/platform/x86/amd/wbrf.c b/drivers/platform/x86/amd/wbrf.c
index dd197b3aebe0..0f58d252b620 100644
--- a/drivers/platform/x86/amd/wbrf.c
+++ b/drivers/platform/x86/amd/wbrf.c
@@ -104,8 +104,10 @@ static int wbrf_record(struct acpi_device *adev, uint8_t action, struct wbrf_ran
 	obj = acpi_evaluate_dsm(adev->handle, &wifi_acpi_dsm_guid,
 				WBRF_REVISION, WBRF_RECORD, &argv4);
 
-	if (!obj)
+	if (!obj) {
+		kfree(tmp);
 		return -EINVAL;
+	}
 
 	if (obj->type != ACPI_TYPE_INTEGER) {
 		ret = -EINVAL;
-- 
2.34.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v3 2/2] platform/x86/amd: Use scope-based cleanup for wbrf_record()
  2026-01-06  9:13 [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record() Zilin Guan
@ 2026-01-06  9:13 ` Zilin Guan
  2026-01-06 11:00 ` [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record() Markus Elfring
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 5+ messages in thread
From: Zilin Guan @ 2026-01-06  9:13 UTC (permalink / raw)
  To: hansg
  Cc: ilpo.jarvinen, platform-driver-x86, linux-kernel, Zilin Guan,
	Markus Elfring, Jianhao Xu

Simplify resource management in wbrf_record() by using the scope-based
cleanup helper __free(). This ensures that the tmp and obj are
automatically freed when they go out of scope, eliminating the need for
explicit error handling labels and manual freeing.

Suggested-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Suggested-by: Markus Elfring <Markus.Elfring@web.de>
Co-developed-by: Jianhao Xu <jianhao.xu@seu.edu.cn>
Signed-off-by: Jianhao Xu <jianhao.xu@seu.edu.cn>
Signed-off-by: Zilin Guan <zilin@seu.edu.cn>
---
Changes in v3:
- Split from v2.
- Use __free(kfree) for 'obj' instead of adding a new DEFINE_FREE() macro.

Changes in v2:
- Use scope-based cleanup helper __free() for automatic resource cleanup.

 drivers/platform/x86/amd/wbrf.c | 25 ++++++++-----------------
 1 file changed, 8 insertions(+), 17 deletions(-)

diff --git a/drivers/platform/x86/amd/wbrf.c b/drivers/platform/x86/amd/wbrf.c
index 0f58d252b620..dc10d12bc80d 100644
--- a/drivers/platform/x86/amd/wbrf.c
+++ b/drivers/platform/x86/amd/wbrf.c
@@ -42,8 +42,6 @@ static BLOCKING_NOTIFIER_HEAD(wbrf_chain_head);
 static int wbrf_record(struct acpi_device *adev, uint8_t action, struct wbrf_ranges_in_out *in)
 {
 	union acpi_object argv4;
-	union acpi_object *tmp;
-	union acpi_object *obj;
 	u32 num_of_ranges = 0;
 	u32 num_of_elements;
 	u32 arg_idx = 0;
@@ -74,7 +72,7 @@ static int wbrf_record(struct acpi_device *adev, uint8_t action, struct wbrf_ran
 	 */
 	num_of_elements = 2 * num_of_ranges + 2;
 
-	tmp = kcalloc(num_of_elements, sizeof(*tmp), GFP_KERNEL);
+	union acpi_object *tmp __free(kfree) = kcalloc(num_of_elements, sizeof(*tmp), GFP_KERNEL);
 	if (!tmp)
 		return -ENOMEM;
 
@@ -101,26 +99,19 @@ static int wbrf_record(struct acpi_device *adev, uint8_t action, struct wbrf_ran
 		tmp[arg_idx++].integer.value = in->band_list[i].end;
 	}
 
-	obj = acpi_evaluate_dsm(adev->handle, &wifi_acpi_dsm_guid,
-				WBRF_REVISION, WBRF_RECORD, &argv4);
+	union acpi_object *obj __free(kfree) =
+		acpi_evaluate_dsm(adev->handle, &wifi_acpi_dsm_guid,
+				  WBRF_REVISION, WBRF_RECORD, &argv4);
 
-	if (!obj) {
-		kfree(tmp);
+	if (!obj)
 		return -EINVAL;
-	}
 
-	if (obj->type != ACPI_TYPE_INTEGER) {
-		ret = -EINVAL;
-		goto out;
-	}
+	if (obj->type != ACPI_TYPE_INTEGER)
+		return -EINVAL;
 
 	ret = obj->integer.value;
 	if (ret)
-		ret = -EINVAL;
-
-out:
-	ACPI_FREE(obj);
-	kfree(tmp);
+		return -EINVAL;
 
 	return ret;
 }
-- 
2.34.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record()
  2026-01-06  9:13 [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record() Zilin Guan
  2026-01-06  9:13 ` [PATCH v3 2/2] platform/x86/amd: Use scope-based cleanup for wbrf_record() Zilin Guan
@ 2026-01-06 11:00 ` Markus Elfring
  2026-01-15 14:27 ` Ilpo Järvinen
  2026-01-26 14:30 ` Ilpo Järvinen
  3 siblings, 0 replies; 5+ messages in thread
From: Markus Elfring @ 2026-01-06 11:00 UTC (permalink / raw)
  To: Jianhao Xu, Zilin Guan, platform-driver-x86, Hans de Goede,
	Ilpo Järvinen
  Cc: LKML

…
> ---
> Changes in v3:
> - Split from v2 to separate the fix from the cleanup.
…

Would a cover letter be helpful also for such a small patch series?

Regards,
Markus

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record()
  2026-01-06  9:13 [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record() Zilin Guan
  2026-01-06  9:13 ` [PATCH v3 2/2] platform/x86/amd: Use scope-based cleanup for wbrf_record() Zilin Guan
  2026-01-06 11:00 ` [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record() Markus Elfring
@ 2026-01-15 14:27 ` Ilpo Järvinen
  2026-01-26 14:30 ` Ilpo Järvinen
  3 siblings, 0 replies; 5+ messages in thread
From: Ilpo Järvinen @ 2026-01-15 14:27 UTC (permalink / raw)
  To: hansg, Zilin Guan; +Cc: platform-driver-x86, linux-kernel, Jianhao Xu

On Tue, 06 Jan 2026 09:13:17 +0000, Zilin Guan wrote:

> The tmp buffer is allocated using kcalloc() but is not freed if
> acpi_evaluate_dsm() fails. This causes a memory leak in the error path.
> 
> Fix this by explicitly freeing the tmp buffer in the error handling
> path of acpi_evaluate_dsm().
> 
> 
> [...]


Thank you for your contribution, it has been applied to my local
review-ilpo-fixes branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-fixes branch only once I've pushed my
local branch there, which might take a while.

The list of commits applied:
[1/2] platform/x86/amd: Fix memory leak in wbrf_record()
      commit: 2bf1877b7094c684e1d652cac6912cfbc507ad3e
[2/2] platform/x86/amd: Use scope-based cleanup for wbrf_record()
      (no commit info)

--
 i.


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record()
  2026-01-06  9:13 [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record() Zilin Guan
                   ` (2 preceding siblings ...)
  2026-01-15 14:27 ` Ilpo Järvinen
@ 2026-01-26 14:30 ` Ilpo Järvinen
  3 siblings, 0 replies; 5+ messages in thread
From: Ilpo Järvinen @ 2026-01-26 14:30 UTC (permalink / raw)
  To: hansg, Zilin Guan; +Cc: platform-driver-x86, linux-kernel, Jianhao Xu

On Tue, 06 Jan 2026 09:13:17 +0000, Zilin Guan wrote:

> The tmp buffer is allocated using kcalloc() but is not freed if
> acpi_evaluate_dsm() fails. This causes a memory leak in the error path.
> 
> Fix this by explicitly freeing the tmp buffer in the error handling
> path of acpi_evaluate_dsm().
> 
> 
> [...]


Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.

The list of commits applied:
[1/2] platform/x86/amd: Fix memory leak in wbrf_record()
      (no commit info)
[2/2] platform/x86/amd: Use scope-based cleanup for wbrf_record()
      commit: 2ee832305a25657d7cfb577bc30d8c1d43bfb951

--
 i.


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-01-26 14:30 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-01-06  9:13 [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record() Zilin Guan
2026-01-06  9:13 ` [PATCH v3 2/2] platform/x86/amd: Use scope-based cleanup for wbrf_record() Zilin Guan
2026-01-06 11:00 ` [PATCH v3 1/2] platform/x86/amd: Fix memory leak in wbrf_record() Markus Elfring
2026-01-15 14:27 ` Ilpo Järvinen
2026-01-26 14:30 ` Ilpo Järvinen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®