From: Alex Williamson <alex.williamson@redhat.com>
To: Eric Auger <eric.auger@redhat.com>
Cc: eric.auger.pro@gmail.com, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] vfio: fix noiommu vfio_iommu_group_get reference count
Date: Thu, 10 Aug 2017 13:47:25 -0600 [thread overview]
Message-ID: <20170810134725.13fc5648@w520.home> (raw)
In-Reply-To: <1502225068-9699-1-git-send-email-eric.auger@redhat.com>
On Tue, 8 Aug 2017 22:44:28 +0200
Eric Auger <eric.auger@redhat.com> wrote:
> In vfio_iommu_group_get() we want to increase the reference
> count of the iommu group.
>
> In noiommu case, the group does not exist and is allocated.
> iommu_group_add_device() increases the group ref count. However we
> then call iommu_group_put() which decrements it.
>
> This leads to a "refcount_t: underflow WARN_ON".
Yep, the group is created with an initial reference count of 1, we then
add the device, which increments the reference count. Normally the
instantiator of the group would then release the reference, so that
only the device reference holds the group. However here we want a
reference in addition to the device reference, so we should never have
released the initial reference. Seems right, except...
> Signed-off-by: Eric Auger <eric.auger@redhat.com>
> ---
> drivers/vfio/vfio.c | 1 -
> 1 file changed, 1 deletion(-)
>
> diff --git a/drivers/vfio/vfio.c b/drivers/vfio/vfio.c
> index 330d505..fd8d691 100644
> --- a/drivers/vfio/vfio.c
> +++ b/drivers/vfio/vfio.c
> @@ -138,7 +138,6 @@ struct iommu_group *vfio_iommu_group_get(struct device *dev)
> iommu_group_set_name(group, "vfio-noiommu");
> iommu_group_set_iommudata(group, &noiommu, NULL);
> ret = iommu_group_add_device(group, dev);
> - iommu_group_put(group);
> if (ret)
> return NULL;
We leak the group in the error case here. Perhaps the 'put' is
correct, it was just typo'd outside of the error case. Thanks,
Alex
prev parent reply other threads:[~2017-08-10 19:47 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-08-08 20:44 Eric Auger
2017-08-10 19:47 ` Alex Williamson [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170810134725.13fc5648@w520.home \
--to=alex.williamson@redhat.com \
--cc=eric.auger.pro@gmail.com \
--cc=eric.auger@redhat.com \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®