mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Alexey Charkov <alchark@flipper.net>
To: "Liam Girdwood" <lgirdwood@gmail.com>,
	"Mark Brown" <broonie@kernel.org>,
	"Corentin Labbe" <clabbe@baylibre.com>,
	"Manivannan Sadhasivam" <mani@kernel.org>,
	"Bartosz Golaszewski" <brgl@kernel.org>,
	"Bjorn Helgaas" <bhelgaas@google.com>,
	"Krzysztof Wilczyński" <kwilczynski@kernel.org>
Cc: linux-kernel@vger.kernel.org,
	 Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>,
	 Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>,
	 linux-pci@vger.kernel.org, linux-pm@vger.kernel.org,
	 Alexey Charkov <alchark@flipper.net>,
	stable@vger.kernel.org,  Sashiko <sashiko-bot@kernel.org>
Subject: [PATCH 1/4] regulator: of: fill in supply names in of_regulator_bulk_get_all()
Date: Tue, 29 Sep 2026 14:05:46 +0400	[thread overview]
Message-ID: <20260929-regulator-get-all-v1-1-e887c66a47f1@flipper.net> (raw)
In-Reply-To: <20260929-regulator-get-all-v1-0-e887c66a47f1@flipper.net>

of_regulator_bulk_get_all() returns an array it allocated itself, and
fills in only the consumer of each entry. Every other way of getting a
bulk array has the supply name set, because the caller provides it, and
the core expects it to be there: regulator_bulk_enable() prints it when
a supply fails to enable, so a caller that hands such an array to it
dereferences uninitialised memory on that path.

Copy each name into the array's own allocation, right behind the
entries, so that it shares the array's lifetime and callers still have
nothing extra to free. That also retires the fixed 64 byte stack buffer
the names were assembled in, which is_supply_name() never bounded the
copy against.

Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260928-b4-rk3576-reboot-mode-v1-0-65486b03bd41@flipper.net?part=3
Fixes: 27b9ecc7a9ba ("regulator: Add of_regulator_bulk_get_all")
Signed-off-by: Alexey Charkov <alchark@flipper.net>
---
 drivers/regulator/of_regulator.c | 24 +++++++++++++++++-------
 1 file changed, 17 insertions(+), 7 deletions(-)

diff --git a/drivers/regulator/of_regulator.c b/drivers/regulator/of_regulator.c
index c0cc6cc0afd8..785b7a11dfc6 100644
--- a/drivers/regulator/of_regulator.c
+++ b/drivers/regulator/of_regulator.c
@@ -935,15 +935,15 @@ static int is_supply_name(const char *name)
 int of_regulator_bulk_get_all(struct device *dev, struct device_node *np,
 			      struct regulator_bulk_data **consumers)
 {
-	int num_consumers = 0;
+	int num_consumers = 0, names_len = 0;
 	struct regulator *tmp;
 	struct regulator_bulk_data *_consumers = NULL;
 	struct property *prop;
+	char *names;
 	int i, n = 0, ret;
-	char name[64];
 
 	/*
-	 * first pass: get numbers of xxx-supply
+	 * first pass: get numbers of xxx-supply and the room their names take
 	 * second pass: fill consumers
 	 */
 restart:
@@ -953,16 +953,19 @@ int of_regulator_bulk_get_all(struct device *dev, struct device_node *np,
 			continue;
 		if (!_consumers) {
 			num_consumers++;
+			names_len += i + 1;
 			continue;
 		} else {
-			memcpy(name, prop->name, i);
-			name[i] = '\0';
-			tmp = regulator_get(dev, name);
+			memcpy(names, prop->name, i);
+			names[i] = '\0';
+			tmp = regulator_get(dev, names);
 			if (IS_ERR(tmp)) {
 				ret = PTR_ERR(tmp);
 				goto error;
 			}
+			_consumers[n].supply = names;
 			_consumers[n].consumer = tmp;
+			names += i + 1;
 			n++;
 			continue;
 		}
@@ -973,9 +976,16 @@ int of_regulator_bulk_get_all(struct device *dev, struct device_node *np,
 	}
 	if (num_consumers == 0)
 		return 0;
-	_consumers = kmalloc_objs(struct regulator_bulk_data, num_consumers);
+	/*
+	 * The supply names are kept in the same allocation as the array, so
+	 * that they share its lifetime and the caller has nothing extra to
+	 * free.
+	 */
+	_consumers = kzalloc(size_add(size_mul(num_consumers, sizeof(*_consumers)),
+				      names_len), GFP_KERNEL);
 	if (!_consumers)
 		return -ENOMEM;
+	names = (char *)(_consumers + num_consumers);
 	goto restart;
 
 error:

-- 
2.55.0


  reply	other threads:[~2026-09-29 10:06 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29 10:05 [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Alexey Charkov
2026-09-29 10:05 ` Alexey Charkov [this message]
2026-09-29 10:05 ` [PATCH 2/4] regulator: of: state who owns the array from of_regulator_bulk_get_all() Alexey Charkov
2026-09-29 10:05 ` [PATCH 3/4] power: sequencing: pcie-m2: Fix leaking " Alexey Charkov
2026-09-29 10:05 ` [PATCH 4/4] PCI/pwrctrl: generic: " Alexey Charkov
2026-10-01  7:52   ` Bartosz Golaszewski
2026-10-01 16:46   ` Bjorn Helgaas
2026-10-01 16:51     ` Bjorn Helgaas
2026-09-29 15:31 ` [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Mark Brown

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929-regulator-get-all-v1-1-e887c66a47f1@flipper.net \
    --to=alchark@flipper.net \
    --cc=bartosz.golaszewski@oss.qualcomm.com \
    --cc=bhelgaas@google.com \
    --cc=brgl@kernel.org \
    --cc=broonie@kernel.org \
    --cc=clabbe@baylibre.com \
    --cc=kwilczynski@kernel.org \
    --cc=lgirdwood@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=linux-pm@vger.kernel.org \
    --cc=mani@kernel.org \
    --cc=manivannan.sadhasivam@oss.qualcomm.com \
    --cc=sashiko-bot@kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®