* [PATCH] platform/x86/amd/pmf: Fix power_supply refcount leak in amd_pmf_get_battery_prop()
@ 2026-09-02 21:02 Jack Boykin
2026-10-05 17:44 ` Ilpo Järvinen
0 siblings, 1 reply; 2+ messages in thread
From: Jack Boykin @ 2026-09-02 21:02 UTC (permalink / raw)
To: Shyam Sundar S K, Hans de Goede, Ilpo Järvinen
Cc: Jack Boykin, stable, platform-driver-x86, linux-kernel
power_supply_get_by_name() takes a reference that is only dropped on
the error path. On success it leaks, five times per policy evaluation.
Unregistering the battery later trips the use_cnt WARN_ON in
power_supply_unregister() and never frees it.
While here, return -ENODEV instead of an uninitialised 'value' when
no battery matches, and stop at the first supply found rather than
letting the last one in the table win.
Found by reading the code. Fix and changelog drafted with Claude Code
(Fable 5.1) and reviewed by hand. Compile-tested only (allmodconfig,
W=1, sparse); not run on Smart PC hardware.
Fixes: f4627dfd0e19 ("platform/x86/amd/pmf: Add support to get inputs from other subsystems")
Cc: stable@vger.kernel.org
Assisted-by: LLM sparse
Signed-off-by: Jack Boykin <jtboykin.jb@gmail.com>
---
drivers/platform/x86/amd/pmf/spc.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/platform/x86/amd/pmf/spc.c b/drivers/platform/x86/amd/pmf/spc.c
index 94355b435..ba852397c 100644
--- a/drivers/platform/x86/amd/pmf/spc.c
+++ b/drivers/platform/x86/amd/pmf/spc.c
@@ -199,13 +199,11 @@ static int amd_pmf_get_battery_prop(enum power_supply_property prop)
continue;
ret = power_supply_get_property(psy, prop, &value);
- if (ret) {
- power_supply_put(psy);
- return ret;
- }
+ power_supply_put(psy);
+ return ret ? ret : value.intval;
}
- return value.intval;
+ return -ENODEV;
}
static int amd_pmf_get_battery_info(struct amd_pmf_dev *dev, struct ta_pmf_enact_table *in)
--
2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] platform/x86/amd/pmf: Fix power_supply refcount leak in amd_pmf_get_battery_prop()
2026-09-02 21:02 [PATCH] platform/x86/amd/pmf: Fix power_supply refcount leak in amd_pmf_get_battery_prop() Jack Boykin
@ 2026-10-05 17:44 ` Ilpo Järvinen
0 siblings, 0 replies; 2+ messages in thread
From: Ilpo Järvinen @ 2026-10-05 17:44 UTC (permalink / raw)
To: Shyam Sundar S K, Hans de Goede, Jack Boykin
Cc: stable, platform-driver-x86, linux-kernel
On Wed, 02 Sep 2026 16:02:12 -0500, Jack Boykin wrote:
> power_supply_get_by_name() takes a reference that is only dropped on
> the error path. On success it leaks, five times per policy evaluation.
> Unregistering the battery later trips the use_cnt WARN_ON in
> power_supply_unregister() and never frees it.
>
> While here, return -ENODEV instead of an uninitialised 'value' when
> no battery matches, and stop at the first supply found rather than
> letting the last one in the table win.
>
> [...]
Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.
FYI [if applicable to your patch], as per Linus' policy change, also
fixes are mostly routed through for-next unless the fix is for a
commit introduced in the most recent cycle or is clearly a regression
fix.
The list of commits applied:
[1/1] platform/x86/amd/pmf: Fix power_supply refcount leak in amd_pmf_get_battery_prop()
commit: 6676654ebfc858cfc416b44d7687ccc6bfe0b021
--
i.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-05 17:44 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-02 21:02 [PATCH] platform/x86/amd/pmf: Fix power_supply refcount leak in amd_pmf_get_battery_prop() Jack Boykin
2026-10-05 17:44 ` Ilpo Järvinen
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®