* [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all()
@ 2026-09-29 10:05 Alexey Charkov
2026-09-29 10:05 ` [PATCH 1/4] regulator: of: fill in supply names in of_regulator_bulk_get_all() Alexey Charkov
` (4 more replies)
0 siblings, 5 replies; 9+ messages in thread
From: Alexey Charkov @ 2026-09-29 10:05 UTC (permalink / raw)
To: Liam Girdwood, Mark Brown, Corentin Labbe, Manivannan Sadhasivam,
Bartosz Golaszewski, Bjorn Helgaas, Krzysztof Wilczyński
Cc: linux-kernel, Manivannan Sadhasivam, Bartosz Golaszewski,
linux-pci, linux-pm, Alexey Charkov, stable, Sashiko
of_regulator_bulk_get_all() only fills in the .consumer part of the
struct regulator_bulk_data for the regulators it gets, leaving .supply as
garbage, while the rest of the regulator core expects a meaningful name
there (e.g. for error prints), causing uninitialized memory access in any
failure paths in the core.
It also allocates the supplies array and hands it to callers, but never
says the callers need to free it (which they don't), causing leaks.
Fix both (the latter in two instances).
Signed-off-by: Alexey Charkov <alchark@flipper.net>
---
Alexey Charkov (4):
regulator: of: fill in supply names in of_regulator_bulk_get_all()
regulator: of: state who owns the array from of_regulator_bulk_get_all()
power: sequencing: pcie-m2: Fix leaking array from of_regulator_bulk_get_all()
PCI/pwrctrl: generic: Fix leaking array from of_regulator_bulk_get_all()
drivers/pci/pwrctrl/generic.c | 1 +
drivers/power/sequencing/pwrseq-pcie-m2.c | 2 ++
drivers/regulator/of_regulator.c | 29 ++++++++++++++++++++++-------
3 files changed, 25 insertions(+), 7 deletions(-)
---
base-commit: 6375e61c01e93e35ee7acd336a689ac1fae4b509
change-id: 20260929-regulator-get-all-a553e73ff1ce
Best regards,
--
Alexey Charkov <alchark@flipper.net>
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 1/4] regulator: of: fill in supply names in of_regulator_bulk_get_all()
2026-09-29 10:05 [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Alexey Charkov
@ 2026-09-29 10:05 ` Alexey Charkov
2026-09-29 10:05 ` [PATCH 2/4] regulator: of: state who owns the array from of_regulator_bulk_get_all() Alexey Charkov
` (3 subsequent siblings)
4 siblings, 0 replies; 9+ messages in thread
From: Alexey Charkov @ 2026-09-29 10:05 UTC (permalink / raw)
To: Liam Girdwood, Mark Brown, Corentin Labbe, Manivannan Sadhasivam,
Bartosz Golaszewski, Bjorn Helgaas, Krzysztof Wilczyński
Cc: linux-kernel, Manivannan Sadhasivam, Bartosz Golaszewski,
linux-pci, linux-pm, Alexey Charkov, stable, Sashiko
of_regulator_bulk_get_all() returns an array it allocated itself, and
fills in only the consumer of each entry. Every other way of getting a
bulk array has the supply name set, because the caller provides it, and
the core expects it to be there: regulator_bulk_enable() prints it when
a supply fails to enable, so a caller that hands such an array to it
dereferences uninitialised memory on that path.
Copy each name into the array's own allocation, right behind the
entries, so that it shares the array's lifetime and callers still have
nothing extra to free. That also retires the fixed 64 byte stack buffer
the names were assembled in, which is_supply_name() never bounded the
copy against.
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260928-b4-rk3576-reboot-mode-v1-0-65486b03bd41@flipper.net?part=3
Fixes: 27b9ecc7a9ba ("regulator: Add of_regulator_bulk_get_all")
Signed-off-by: Alexey Charkov <alchark@flipper.net>
---
drivers/regulator/of_regulator.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
diff --git a/drivers/regulator/of_regulator.c b/drivers/regulator/of_regulator.c
index c0cc6cc0afd8..785b7a11dfc6 100644
--- a/drivers/regulator/of_regulator.c
+++ b/drivers/regulator/of_regulator.c
@@ -935,15 +935,15 @@ static int is_supply_name(const char *name)
int of_regulator_bulk_get_all(struct device *dev, struct device_node *np,
struct regulator_bulk_data **consumers)
{
- int num_consumers = 0;
+ int num_consumers = 0, names_len = 0;
struct regulator *tmp;
struct regulator_bulk_data *_consumers = NULL;
struct property *prop;
+ char *names;
int i, n = 0, ret;
- char name[64];
/*
- * first pass: get numbers of xxx-supply
+ * first pass: get numbers of xxx-supply and the room their names take
* second pass: fill consumers
*/
restart:
@@ -953,16 +953,19 @@ int of_regulator_bulk_get_all(struct device *dev, struct device_node *np,
continue;
if (!_consumers) {
num_consumers++;
+ names_len += i + 1;
continue;
} else {
- memcpy(name, prop->name, i);
- name[i] = '\0';
- tmp = regulator_get(dev, name);
+ memcpy(names, prop->name, i);
+ names[i] = '\0';
+ tmp = regulator_get(dev, names);
if (IS_ERR(tmp)) {
ret = PTR_ERR(tmp);
goto error;
}
+ _consumers[n].supply = names;
_consumers[n].consumer = tmp;
+ names += i + 1;
n++;
continue;
}
@@ -973,9 +976,16 @@ int of_regulator_bulk_get_all(struct device *dev, struct device_node *np,
}
if (num_consumers == 0)
return 0;
- _consumers = kmalloc_objs(struct regulator_bulk_data, num_consumers);
+ /*
+ * The supply names are kept in the same allocation as the array, so
+ * that they share its lifetime and the caller has nothing extra to
+ * free.
+ */
+ _consumers = kzalloc(size_add(size_mul(num_consumers, sizeof(*_consumers)),
+ names_len), GFP_KERNEL);
if (!_consumers)
return -ENOMEM;
+ names = (char *)(_consumers + num_consumers);
goto restart;
error:
--
2.55.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 2/4] regulator: of: state who owns the array from of_regulator_bulk_get_all()
2026-09-29 10:05 [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Alexey Charkov
2026-09-29 10:05 ` [PATCH 1/4] regulator: of: fill in supply names in of_regulator_bulk_get_all() Alexey Charkov
@ 2026-09-29 10:05 ` Alexey Charkov
2026-09-29 10:05 ` [PATCH 3/4] power: sequencing: pcie-m2: Fix leaking " Alexey Charkov
` (2 subsequent siblings)
4 siblings, 0 replies; 9+ messages in thread
From: Alexey Charkov @ 2026-09-29 10:05 UTC (permalink / raw)
To: Liam Girdwood, Mark Brown, Corentin Labbe, Manivannan Sadhasivam,
Bartosz Golaszewski, Bjorn Helgaas, Krzysztof Wilczyński
Cc: linux-kernel, Manivannan Sadhasivam, Bartosz Golaszewski,
linux-pci, linux-pm, Alexey Charkov
of_regulator_bulk_get_all() allocates the consumer array and hands it to
the caller, but never said so. Its own error path frees the array, while
regulator_bulk_free() only puts the regulators, so both callers release
the regulators and leak the array.
Spell the contract out in the kerneldoc.
Signed-off-by: Alexey Charkov <alchark@flipper.net>
---
drivers/regulator/of_regulator.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/regulator/of_regulator.c b/drivers/regulator/of_regulator.c
index 785b7a11dfc6..09e26febfc83 100644
--- a/drivers/regulator/of_regulator.c
+++ b/drivers/regulator/of_regulator.c
@@ -929,6 +929,11 @@ static int is_supply_name(const char *name)
* before returning to the caller, and @consumers will not be
* changed.
*
+ * On success the array is allocated here and handed to the caller, which
+ * owns it from then on: release the regulators with regulator_bulk_free()
+ * and free the array itself with kfree(). The supply names live in the
+ * same allocation, so they are gone once the array is freed.
+ *
* Return: Number of regulators on success, or a negative error number
* on failure.
*/
--
2.55.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 3/4] power: sequencing: pcie-m2: Fix leaking array from of_regulator_bulk_get_all()
2026-09-29 10:05 [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Alexey Charkov
2026-09-29 10:05 ` [PATCH 1/4] regulator: of: fill in supply names in of_regulator_bulk_get_all() Alexey Charkov
2026-09-29 10:05 ` [PATCH 2/4] regulator: of: state who owns the array from of_regulator_bulk_get_all() Alexey Charkov
@ 2026-09-29 10:05 ` Alexey Charkov
2026-09-29 10:05 ` [PATCH 4/4] PCI/pwrctrl: generic: " Alexey Charkov
2026-09-29 15:31 ` [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Mark Brown
4 siblings, 0 replies; 9+ messages in thread
From: Alexey Charkov @ 2026-09-29 10:05 UTC (permalink / raw)
To: Liam Girdwood, Mark Brown, Corentin Labbe, Manivannan Sadhasivam,
Bartosz Golaszewski, Bjorn Helgaas, Krzysztof Wilczyński
Cc: linux-kernel, Manivannan Sadhasivam, Bartosz Golaszewski,
linux-pci, linux-pm, Alexey Charkov, stable
of_regulator_bulk_get_all() allocates the consumers array and hands it to
the caller, who is expected to free it at an appropriate time.
pwrseq-pcie-m2.c never did, leading to a memory leak.
Add an explicit kfree() for the consumers array.
Cc: stable@vger.kernel.org
Fixes: 52e7b5bd62ba ("power: sequencing: Add the Power Sequencing driver for the PCIe M.2 connectors")
Signed-off-by: Alexey Charkov <alchark@flipper.net>
---
drivers/power/sequencing/pwrseq-pcie-m2.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/power/sequencing/pwrseq-pcie-m2.c b/drivers/power/sequencing/pwrseq-pcie-m2.c
index 91916768e922..0febe4b3d980 100644
--- a/drivers/power/sequencing/pwrseq-pcie-m2.c
+++ b/drivers/power/sequencing/pwrseq-pcie-m2.c
@@ -613,6 +613,7 @@ static int pwrseq_pcie_m2_probe(struct platform_device *pdev)
mutex_destroy(&ctx->list_lock);
err_free_regulators:
regulator_bulk_free(ctx->num_vregs, ctx->regs);
+ kfree(ctx->regs);
return ret;
}
@@ -626,6 +627,7 @@ static void pwrseq_pcie_m2_remove(struct platform_device *pdev)
mutex_destroy(&ctx->list_lock);
regulator_bulk_free(ctx->num_vregs, ctx->regs);
+ kfree(ctx->regs);
}
static const struct of_device_id pwrseq_pcie_m2_of_match[] = {
--
2.55.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 4/4] PCI/pwrctrl: generic: Fix leaking array from of_regulator_bulk_get_all()
2026-09-29 10:05 [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Alexey Charkov
` (2 preceding siblings ...)
2026-09-29 10:05 ` [PATCH 3/4] power: sequencing: pcie-m2: Fix leaking " Alexey Charkov
@ 2026-09-29 10:05 ` Alexey Charkov
2026-10-01 7:52 ` Bartosz Golaszewski
2026-10-01 16:46 ` Bjorn Helgaas
2026-09-29 15:31 ` [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Mark Brown
4 siblings, 2 replies; 9+ messages in thread
From: Alexey Charkov @ 2026-09-29 10:05 UTC (permalink / raw)
To: Liam Girdwood, Mark Brown, Corentin Labbe, Manivannan Sadhasivam,
Bartosz Golaszewski, Bjorn Helgaas, Krzysztof Wilczyński
Cc: linux-kernel, Manivannan Sadhasivam, Bartosz Golaszewski,
linux-pci, linux-pm, Alexey Charkov, stable
of_regulator_bulk_get_all() allocates the consumers array and hands it to
the caller, who is expected to free it at an appropriate time.
PCI pwrctrl never did, leading to a memory leak.
Add an explicit kfree() for the consumers array.
Cc: stable@vger.kernel.org
Fixes: 75996c92f4de ("PCI/pwrctrl: Add pwrctrl driver for PCI slots")
Signed-off-by: Alexey Charkov <alchark@flipper.net>
---
drivers/pci/pwrctrl/generic.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/pci/pwrctrl/generic.c b/drivers/pci/pwrctrl/generic.c
index d56171e0ee24..4b6cbbb52248 100644
--- a/drivers/pci/pwrctrl/generic.c
+++ b/drivers/pci/pwrctrl/generic.c
@@ -63,6 +63,7 @@ static void devm_slot_pwrctrl_release(void *data)
struct slot_pwrctrl *slot = data;
regulator_bulk_free(slot->num_supplies, slot->supplies);
+ kfree(slot->supplies);
}
static int slot_pwrctrl_probe(struct platform_device *pdev)
--
2.55.0
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all()
2026-09-29 10:05 [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Alexey Charkov
` (3 preceding siblings ...)
2026-09-29 10:05 ` [PATCH 4/4] PCI/pwrctrl: generic: " Alexey Charkov
@ 2026-09-29 15:31 ` Mark Brown
4 siblings, 0 replies; 9+ messages in thread
From: Mark Brown @ 2026-09-29 15:31 UTC (permalink / raw)
To: Alexey Charkov
Cc: Liam Girdwood, Corentin Labbe, Manivannan Sadhasivam,
Bartosz Golaszewski, Bjorn Helgaas, Krzysztof Wilczyński,
linux-kernel, Manivannan Sadhasivam, Bartosz Golaszewski,
linux-pci, linux-pm, stable, Sashiko
[-- Attachment #1: Type: text/plain, Size: 611 bytes --]
On Tue, Sep 29, 2026 at 02:05:45PM +0400, Alexey Charkov wrote:
> regulator: of: fill in supply names in of_regulator_bulk_get_all()
> regulator: of: state who owns the array from of_regulator_bulk_get_all()
> power: sequencing: pcie-m2: Fix leaking array from of_regulator_bulk_get_all()
> PCI/pwrctrl: generic: Fix leaking array from of_regulator_bulk_get_all()
Please don't combine tangentially related patches for multiple
subsystems into a single series, it just causes problems getting things
applied. If there's no actual dependencies send things separately to
each subsystem.
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 4/4] PCI/pwrctrl: generic: Fix leaking array from of_regulator_bulk_get_all()
2026-09-29 10:05 ` [PATCH 4/4] PCI/pwrctrl: generic: " Alexey Charkov
@ 2026-10-01 7:52 ` Bartosz Golaszewski
2026-10-01 16:46 ` Bjorn Helgaas
1 sibling, 0 replies; 9+ messages in thread
From: Bartosz Golaszewski @ 2026-10-01 7:52 UTC (permalink / raw)
To: Alexey Charkov
Cc: Liam Girdwood, Mark Brown, Corentin Labbe, Manivannan Sadhasivam,
Bartosz Golaszewski, Bjorn Helgaas, Krzysztof Wilczyński,
linux-kernel, Manivannan Sadhasivam, Bartosz Golaszewski,
linux-pci, linux-pm, stable
On Tue, 29 Sep 2026 12:05:49 +0200, Alexey Charkov <alchark@flipper.net> said:
> of_regulator_bulk_get_all() allocates the consumers array and hands it to
> the caller, who is expected to free it at an appropriate time.
> PCI pwrctrl never did, leading to a memory leak.
>
> Add an explicit kfree() for the consumers array.
>
> Cc: stable@vger.kernel.org
> Fixes: 75996c92f4de ("PCI/pwrctrl: Add pwrctrl driver for PCI slots")
> Signed-off-by: Alexey Charkov <alchark@flipper.net>
> ---
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 4/4] PCI/pwrctrl: generic: Fix leaking array from of_regulator_bulk_get_all()
2026-09-29 10:05 ` [PATCH 4/4] PCI/pwrctrl: generic: " Alexey Charkov
2026-10-01 7:52 ` Bartosz Golaszewski
@ 2026-10-01 16:46 ` Bjorn Helgaas
2026-10-01 16:51 ` Bjorn Helgaas
1 sibling, 1 reply; 9+ messages in thread
From: Bjorn Helgaas @ 2026-10-01 16:46 UTC (permalink / raw)
To: Alexey Charkov
Cc: Liam Girdwood, Mark Brown, Corentin Labbe, Manivannan Sadhasivam,
Bartosz Golaszewski, Bjorn Helgaas, Krzysztof Wilczyński,
linux-kernel, Manivannan Sadhasivam, Bartosz Golaszewski,
linux-pci, linux-pm, stable
On Tue, Sep 29, 2026 at 02:05:49PM +0400, Alexey Charkov wrote:
> of_regulator_bulk_get_all() allocates the consumers array and hands it to
> the caller, who is expected to free it at an appropriate time.
> PCI pwrctrl never did, leading to a memory leak.
>
> Add an explicit kfree() for the consumers array.
>
> Cc: stable@vger.kernel.org
> Fixes: 75996c92f4de ("PCI/pwrctrl: Add pwrctrl driver for PCI slots")
> Signed-off-by: Alexey Charkov <alchark@flipper.net>
Acked-by: Bjorn Helgaas <bhelgaas@google.com>
I assume this will be merged via a non-PCI tree.
> ---
> drivers/pci/pwrctrl/generic.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/pci/pwrctrl/generic.c b/drivers/pci/pwrctrl/generic.c
> index d56171e0ee24..4b6cbbb52248 100644
> --- a/drivers/pci/pwrctrl/generic.c
> +++ b/drivers/pci/pwrctrl/generic.c
> @@ -63,6 +63,7 @@ static void devm_slot_pwrctrl_release(void *data)
> struct slot_pwrctrl *slot = data;
>
> regulator_bulk_free(slot->num_supplies, slot->supplies);
> + kfree(slot->supplies);
> }
>
> static int slot_pwrctrl_probe(struct platform_device *pdev)
>
> --
> 2.55.0
>
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 4/4] PCI/pwrctrl: generic: Fix leaking array from of_regulator_bulk_get_all()
2026-10-01 16:46 ` Bjorn Helgaas
@ 2026-10-01 16:51 ` Bjorn Helgaas
0 siblings, 0 replies; 9+ messages in thread
From: Bjorn Helgaas @ 2026-10-01 16:51 UTC (permalink / raw)
To: Alexey Charkov
Cc: Liam Girdwood, Mark Brown, Corentin Labbe, Manivannan Sadhasivam,
Bartosz Golaszewski, Bjorn Helgaas, Krzysztof Wilczyński,
linux-kernel, Manivannan Sadhasivam, Bartosz Golaszewski,
linux-pci, linux-pm, stable
On Thu, Oct 01, 2026 at 11:46:11AM -0500, Bjorn Helgaas wrote:
> On Tue, Sep 29, 2026 at 02:05:49PM +0400, Alexey Charkov wrote:
> > of_regulator_bulk_get_all() allocates the consumers array and hands it to
> > the caller, who is expected to free it at an appropriate time.
> > PCI pwrctrl never did, leading to a memory leak.
> >
> > Add an explicit kfree() for the consumers array.
> >
> > Cc: stable@vger.kernel.org
> > Fixes: 75996c92f4de ("PCI/pwrctrl: Add pwrctrl driver for PCI slots")
> > Signed-off-by: Alexey Charkov <alchark@flipper.net>
>
> Acked-by: Bjorn Helgaas <bhelgaas@google.com>
>
> I assume this will be merged via a non-PCI tree.
After reading farther through my email, I see this was posted
separately, so I applied that to pci/pwrctrl for v7.4.
> > ---
> > drivers/pci/pwrctrl/generic.c | 1 +
> > 1 file changed, 1 insertion(+)
> >
> > diff --git a/drivers/pci/pwrctrl/generic.c b/drivers/pci/pwrctrl/generic.c
> > index d56171e0ee24..4b6cbbb52248 100644
> > --- a/drivers/pci/pwrctrl/generic.c
> > +++ b/drivers/pci/pwrctrl/generic.c
> > @@ -63,6 +63,7 @@ static void devm_slot_pwrctrl_release(void *data)
> > struct slot_pwrctrl *slot = data;
> >
> > regulator_bulk_free(slot->num_supplies, slot->supplies);
> > + kfree(slot->supplies);
> > }
> >
> > static int slot_pwrctrl_probe(struct platform_device *pdev)
> >
> > --
> > 2.55.0
> >
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2026-10-01 16:51 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-29 10:05 [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Alexey Charkov
2026-09-29 10:05 ` [PATCH 1/4] regulator: of: fill in supply names in of_regulator_bulk_get_all() Alexey Charkov
2026-09-29 10:05 ` [PATCH 2/4] regulator: of: state who owns the array from of_regulator_bulk_get_all() Alexey Charkov
2026-09-29 10:05 ` [PATCH 3/4] power: sequencing: pcie-m2: Fix leaking " Alexey Charkov
2026-09-29 10:05 ` [PATCH 4/4] PCI/pwrctrl: generic: " Alexey Charkov
2026-10-01 7:52 ` Bartosz Golaszewski
2026-10-01 16:46 ` Bjorn Helgaas
2026-10-01 16:51 ` Bjorn Helgaas
2026-09-29 15:31 ` [PATCH 0/4] regulator: of: Fixes to of_regulator_bulk_get_all() Mark Brown
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®