mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Peng Fan (OSS)" <peng.fan@oss.nxp.com>
To: Mark Brown <broonie@kernel.org>,
	 Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	 "Rafael J. Wysocki" <rafael@kernel.org>,
	Danilo Krummrich <dakr@kernel.org>
Cc: linux-kernel@vger.kernel.org, driver-core@lists.linux.dev,
	 Peng Fan <peng.fan@nxp.com>
Subject: [PATCH 5/7] regmap: use devm_kmemdup() for bus copies and remove free_on_exit
Date: Wed, 30 Sep 2026 17:46:59 +0800	[thread overview]
Message-ID: <20260930-regmap-lock-2nd-v1-5-33a8a482f9ae@nxp.com> (raw)
In-Reply-To: <20260930-regmap-lock-2nd-v1-0-33a8a482f9ae@nxp.com>

From: Peng Fan <peng.fan@nxp.com>

regmap_get_i2c_bus() and regmap_get_spi_bus() duplicate the static bus
struct when the transfer size needs clamping. They use kmemdup()
and set the free_on_exit flag so regmap_exit() will kfree the copy.

Replace kmemdup() with devm_kmemdup() tied to the parent device, which
lets devres handle the lifetime automatically.  This is safe because
devres cleanup is LIFO: the bus copy (allocated first) is freed after
the regmap devres action calls regmap_exit(), so the bus is guaranteed
alive while the regmap references it. For the non-devm regmap_init
path the driver calls regmap_exit() in its remove() callback, and
devres runs after remove() returns, so the ordering holds there as
well.

With no remaining producers of free_on_exit, remove the flag from
struct regmap_bus and drop the corresponding kfree() calls in
__regmap_init() and regmap_exit().

Assisted-by: LLM
Signed-off-by: Peng Fan <peng.fan@nxp.com>
---
 drivers/base/regmap/regmap-i2c.c | 3 +--
 drivers/base/regmap/regmap-spi.c | 3 +--
 drivers/base/regmap/regmap.c     | 4 ----
 include/linux/regmap.h           | 2 --
 4 files changed, 2 insertions(+), 10 deletions(-)

diff --git a/drivers/base/regmap/regmap-i2c.c b/drivers/base/regmap/regmap-i2c.c
index 51a04961faf7..813e8b407a0f 100644
--- a/drivers/base/regmap/regmap-i2c.c
+++ b/drivers/base/regmap/regmap-i2c.c
@@ -403,10 +403,9 @@ static const struct regmap_bus *regmap_get_i2c_bus(struct i2c_client *i2c,
 				(config->reg_bits + config->pad_bits) / BITS_PER_BYTE;
 
 		if (max_read || max_write) {
-			ret_bus = kmemdup(bus, sizeof(*bus), GFP_KERNEL);
+			ret_bus = devm_kmemdup(&i2c->dev, bus, sizeof(*bus), GFP_KERNEL);
 			if (!ret_bus)
 				return ERR_PTR(-ENOMEM);
-			ret_bus->free_on_exit = true;
 			ret_bus->max_raw_read = max_read;
 			ret_bus->max_raw_write = max_write;
 			bus = ret_bus;
diff --git a/drivers/base/regmap/regmap-spi.c b/drivers/base/regmap/regmap-spi.c
index b9fec387997e..8b5a3fbcb18d 100644
--- a/drivers/base/regmap/regmap-spi.c
+++ b/drivers/base/regmap/regmap-spi.c
@@ -117,7 +117,7 @@ static const struct regmap_bus *regmap_get_spi_bus(struct spi_device *spi,
 	struct regmap_bus *bus;
 
 	if (max_size != SIZE_MAX) {
-		bus = kmemdup(&regmap_spi, sizeof(*bus), GFP_KERNEL);
+		bus = devm_kmemdup(&spi->dev, &regmap_spi, sizeof(*bus), GFP_KERNEL);
 		if (!bus)
 			return ERR_PTR(-ENOMEM);
 
@@ -126,7 +126,6 @@ static const struct regmap_bus *regmap_get_spi_bus(struct spi_device *spi,
 		if (max_size + reg_reserve_size > max_msg_size)
 			max_size -= reg_reserve_size;
 
-		bus->free_on_exit = true;
 		bus->max_raw_read = max_size;
 		bus->max_raw_write = max_size;
 
diff --git a/drivers/base/regmap/regmap.c b/drivers/base/regmap/regmap.c
index b9830afa6d8e..bb5553ce58d1 100644
--- a/drivers/base/regmap/regmap.c
+++ b/drivers/base/regmap/regmap.c
@@ -1175,8 +1175,6 @@ struct regmap *__regmap_init(struct device *dev,
 err_map:
 	kfree(map);
 err:
-	if (bus && bus->free_on_exit)
-		kfree(bus);
 	return ERR_PTR(ret);
 }
 EXPORT_SYMBOL_GPL(__regmap_init);
@@ -1479,8 +1477,6 @@ void regmap_exit(struct regmap *map)
 		mutex_destroy(&map->mutex);
 	kfree_const(map->name);
 	kfree(map->patch);
-	if (map->bus && map->bus->free_on_exit)
-		kfree(map->bus);
 	kfree(map);
 }
 EXPORT_SYMBOL_GPL(regmap_exit);
diff --git a/include/linux/regmap.h b/include/linux/regmap.h
index c8aebd148e08..f8334a37bd0e 100644
--- a/include/linux/regmap.h
+++ b/include/linux/regmap.h
@@ -579,7 +579,6 @@ typedef void (*regmap_hw_free_context)(void *context);
  *	     to perform locking. This field is ignored if custom lock/unlock
  *	     functions are used (see fields lock/unlock of
  *	     struct regmap_config).
- * @free_on_exit: kfree this on exit of regmap
  * @write: Write operation.
  * @gather_write: Write operation with split register/value, return -ENOTSUPP
  *                if not implemented  on a given device.
@@ -613,7 +612,6 @@ typedef void (*regmap_hw_free_context)(void *context);
  */
 struct regmap_bus {
 	bool fast_io;
-	bool free_on_exit;
 	regmap_hw_write write;
 	regmap_hw_gather_write gather_write;
 	regmap_hw_async_write async_write;

-- 
2.51.0


  parent reply	other threads:[~2026-09-30  9:50 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30  9:46 [PATCH 0/7] regmap: cleanups for regcache and regmap init paths Peng Fan (OSS)
2026-09-30  9:46 ` [PATCH 1/7] regcache: extract locked helpers to replace open-coded lock/unlock pairs Peng Fan (OSS)
2026-09-30  9:46 ` [PATCH 2/7] regcache: extract __regcache_sync() to deduplicate sync dispatch Peng Fan (OSS)
2026-09-30  9:46 ` [PATCH 3/7] regcache: simplify control flow and reduce nesting Peng Fan (OSS)
2026-09-30  9:46 ` [PATCH 4/7] regmap: use krealloc_array() in regmap_register_patch() Peng Fan (OSS)
2026-09-30  9:46 ` Peng Fan (OSS) [this message]
2026-09-30  9:47 ` [PATCH 6/7] regmap: return errors directly before map allocation in __regmap_init() Peng Fan (OSS)
2026-09-30  9:47 ` [PATCH 7/7] regmap: fix potential double-free of map->reg_defaults on cache reinit Peng Fan (OSS)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930-regmap-lock-2nd-v1-5-33a8a482f9ae@nxp.com \
    --to=peng.fan@oss.nxp.com \
    --cc=broonie@kernel.org \
    --cc=dakr@kernel.org \
    --cc=driver-core@lists.linux.dev \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=peng.fan@nxp.com \
    --cc=rafael@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®