mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling
@ 2026-09-28 17:40 Priyank Rathod
  2026-09-28 17:40 ` [PATCH v5 1/3] PCI/AER: Fix memory leak in aer_recover_queue() on kfifo buffer overflow Priyank Rathod
                   ` (4 more replies)
  0 siblings, 5 replies; 6+ messages in thread
From: Priyank Rathod @ 2026-09-28 17:40 UTC (permalink / raw)
  To: Mahesh J Salgaonkar, Oliver O'Halloran, Bjorn Helgaas
  Cc: Lukas Wunner, Kuppuswamy Sathyanarayanan, Jonathan Cameron,
	Ilpo Järvinen, Dave Jiang, Shiju Jose, Rafael J. Wysocki,
	linuxppc-dev, linux-pci, linux-kernel, Priyank Rathod, stable

When firmware reports PCIe Advanced Error Reporting (AER) events via ACPI
APEI GHES (ghes_handle_aer()), it allocates a snapshot buffer from
ghes_estatus_pool to store the aer_capability_regs registers before
enqueuing the error record into aer_recover_ring.

aer_recover_queue() returns void, so ghes_handle_aer() cannot release that
buffer itself; ownership is handed to the AER code, which until now freed
it only on the fully successful path. If the record cannot be enqueued, or
if a dequeued record cannot be mapped to a pci_dev, the allocation is
silently leaked. Under a sustained error storm this exhausts
ghes_estatus_pool, which then breaks GHES hardware error reporting
system-wide.

This series fixes both leak paths and documents the ownership rule:

Patch 1: aer_recover_queue() when kfifo_in_spinlocked() fails because
         aer_recover_ring (capacity 16) is full. The rejected entry is
         freed immediately via ghes_estatus_pool_region_free().

Patch 2: aer_recover_work_func() when a dequeued entry cannot be mapped to
         an active PCI device (pdev is NULL). The loop is restructured so
         ghes_estatus_pool_region_free() runs unconditionally for every
         dequeued item.

Patch 3: Add a kernel-doc comment stating that aer_recover_queue() takes
         ownership of @aer_regs, which must be allocated from
         ghes_estatus_pool. This is documentation only, so unlike
         patches 1 and 2 it has no Fixes: or Cc: stable tag.

Signed-off-by: Priyank Rathod <rathodpriyank@google.com>
---
Changes in v5:
- Add patch 3, a kernel-doc comment on aer_recover_queue() stating that
  it takes ownership of @aer_regs, which must come from ghes_estatus_pool
  (suggested by Kuppuswamy Sathyanarayanan). It is a separate patch so
  that the two fixes stay minimal for stable backports, and because the
  comment is only accurate once patch 2 is applied.
- Add Kuppuswamy's Reviewed-by to patches 1 and 2. Their code is
  unchanged from v4.
- Still applies cleanly to pci/next (94e8d4e94266), before or after
  Lukas' "Error reporting for AER-incapable devices" series:
  https://lore.kernel.org/r/cover.1790531238.git.lukas@wunner.de
- Cc Kuppuswamy Sathyanarayanan, Jonathan Cameron, Ilpo Järvinen and
  Dave Jiang, plus Shiju Jose and Rafael J. Wysocki as the author and
  committer of the commit in Fixes:.
- Link to v4: https://lore.kernel.org/r/20260918-b4-fix-aer-memleaks-v4-0-f0a2c21ed1d1@google.com

Changes in v4:
- Rebased onto v7.3-rc3+ (f259f446f519); applies cleanly to pci/next as
  well. No conflicts with the Advisory Non-Fatal Error support that landed
  in the meantime.
- Added missing Fixes: e2abc47a5a1a ("ACPI: APEI: Fix AER info corruption
  when error status data has multiple sections") and Cc: stable to both
  patches; that commit (v6.7-rc1) introduced the ghes_estatus_pool
  allocation whose ownership these paths drop.
- Patch 1: use braces on both arms of the if/else and fix the continuation
  alignment (checkpatch --strict).
- Both patches now build warning-free with W=1 and CONFIG_ACPI_APEI_PCIEAER=y
  (earlier revisions were only build-tested with APEI disabled, which
  compiles neither of the modified functions).
- Explained in both commit messages why the caller cannot free the buffer,
  and when the missing-pci_dev path is reachable.
- Cc: Lukas Wunner, who has been active in this code.
- Link to v3: https://lore.kernel.org/r/20260803-b4-fix-aer-memleaks-v3-1-e87159611933@google.com

Changes in v3:
- Resent to fix threading of the series.
- Link to v2: https://lore.kernel.org/r/20260803-b4-fix-aer-memleaks-v2-1-fd199b0171fd@google.com

Changes in v2:
- Refactored aer_recover_work_func() to ensure ghes_estatus_pool_region_free()
  is called unconditionally for every dequeued record.
- Added Patch 1 to fix related memory leak in aer_recover_queue() on kfifo
  buffer overflow.
- Link to v1: https://lore.kernel.org/r/20260803183853.432459-2-rathodpriyank@google.com

---
Priyank Rathod (3):
      PCI/AER: Fix memory leak in aer_recover_queue() on kfifo buffer overflow
      PCI/AER: Fix memory leak in aer_recover_work_func() when pci_dev is missing
      PCI/AER: Document that aer_recover_queue() takes ownership of aer_regs

 drivers/pci/pcie/aer.c | 48 +++++++++++++++++++++++++++++++++++-------------
 1 file changed, 35 insertions(+), 13 deletions(-)
---
base-commit: f259f446f5198d98e13756d2cd531812a0ad3064
change-id: 20260803-b4-fix-aer-memleaks-524a1bd5e888

Best regards,
-- 
Priyank Rathod <rathodpriyank@google.com>


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH v5 1/3] PCI/AER: Fix memory leak in aer_recover_queue() on kfifo buffer overflow
  2026-09-28 17:40 [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling Priyank Rathod
@ 2026-09-28 17:40 ` Priyank Rathod
  2026-09-28 17:40 ` [PATCH v5 2/3] PCI/AER: Fix memory leak in aer_recover_work_func() when pci_dev is missing Priyank Rathod
                   ` (3 subsequent siblings)
  4 siblings, 0 replies; 6+ messages in thread
From: Priyank Rathod @ 2026-09-28 17:40 UTC (permalink / raw)
  To: Mahesh J Salgaonkar, Oliver O'Halloran, Bjorn Helgaas
  Cc: Lukas Wunner, Kuppuswamy Sathyanarayanan, Jonathan Cameron,
	Ilpo Järvinen, Dave Jiang, Shiju Jose, Rafael J. Wysocki,
	linuxppc-dev, linux-pci, linux-kernel, Priyank Rathod, stable

When ACPI APEI/GHES processes PCIe AER error records, it allocates memory
for aer_capability_regs (aer_regs) from ghes_estatus_pool and passes it
to aer_recover_queue() to be enqueued into aer_recover_ring.

If kfifo_in_spinlocked() fails due to a buffer overflow,
aer_recover_queue() logged an error message but returned without freeing
aer_regs. Because the entry was rejected and never inserted into the
queue, aer_recover_work_func() could never dequeue or free it, leaking
the allocated ghes_estatus_pool memory.

aer_recover_queue() returns void, so the caller ghes_handle_aer() cannot
free the buffer itself: ownership is transferred to the AER code, which
until now only released it on the success path.

Free aer_regs via ghes_estatus_pool_region_free() when
kfifo_in_spinlocked() fails on buffer overflow.

Fixes: e2abc47a5a1a ("ACPI: APEI: Fix AER info corruption when error status data has multiple sections")
Cc: stable@vger.kernel.org
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Signed-off-by: Priyank Rathod <rathodpriyank@google.com>
---
 drivers/pci/pcie/aer.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/drivers/pci/pcie/aer.c b/drivers/pci/pcie/aer.c
index d8dcd238fda1..b013b853b555 100644
--- a/drivers/pci/pcie/aer.c
+++ b/drivers/pci/pcie/aer.c
@@ -1415,11 +1415,14 @@ void aer_recover_queue(int domain, unsigned int bus, unsigned int devfn,
 	};
 
 	if (kfifo_in_spinlocked(&aer_recover_ring, &entry, 1,
-				 &aer_recover_ring_lock))
+				 &aer_recover_ring_lock)) {
 		schedule_work(&aer_recover_work);
-	else
+	} else {
 		pr_err("buffer overflow in recovery for %04x:%02x:%02x.%x\n",
 		       domain, bus, PCI_SLOT(devfn), PCI_FUNC(devfn));
+		ghes_estatus_pool_region_free((unsigned long)aer_regs,
+					      sizeof(struct aer_capability_regs));
+	}
 }
 EXPORT_SYMBOL_GPL(aer_recover_queue);
 #endif

-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH v5 2/3] PCI/AER: Fix memory leak in aer_recover_work_func() when pci_dev is missing
  2026-09-28 17:40 [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling Priyank Rathod
  2026-09-28 17:40 ` [PATCH v5 1/3] PCI/AER: Fix memory leak in aer_recover_queue() on kfifo buffer overflow Priyank Rathod
@ 2026-09-28 17:40 ` Priyank Rathod
  2026-09-28 17:40 ` [PATCH v5 3/3] PCI/AER: Document that aer_recover_queue() takes ownership of aer_regs Priyank Rathod
                   ` (2 subsequent siblings)
  4 siblings, 0 replies; 6+ messages in thread
From: Priyank Rathod @ 2026-09-28 17:40 UTC (permalink / raw)
  To: Mahesh J Salgaonkar, Oliver O'Halloran, Bjorn Helgaas
  Cc: Lukas Wunner, Kuppuswamy Sathyanarayanan, Jonathan Cameron,
	Ilpo Järvinen, Dave Jiang, Shiju Jose, Rafael J. Wysocki,
	linuxppc-dev, linux-pci, linux-kernel, Priyank Rathod, stable

When ACPI APEI/GHES processes PCIe AER error records, it allocates memory
for aer_capability_regs (entry.regs) from ghes_estatus_pool and queues
the entry into aer_recover_ring.

In aer_recover_work_func(), items are popped from aer_recover_ring via
kfifo_get(). If pci_get_domain_bus_and_slot() fails to find a matching
pci_dev, the code previously executed 'continue', bypassing the call to
ghes_estatus_pool_region_free(). As a result, the memory allocated for
entry.regs from ghes_estatus_pool was leaked.

This is reachable whenever the device reported by firmware is not (or is
no longer) present in the PCI device tree, e.g. after hot-removal or when
firmware reports an error for a device the kernel never enumerated.

Refactor aer_recover_work_func() to ensure ghes_estatus_pool_region_free()
is called unconditionally for every dequeued entry, releasing the pool
memory even when pci_dev is missing.

Fixes: e2abc47a5a1a ("ACPI: APEI: Fix AER info corruption when error status data has multiple sections")
Cc: stable@vger.kernel.org
Reviewed-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Signed-off-by: Priyank Rathod <rathodpriyank@google.com>
---
 drivers/pci/pcie/aer.c | 23 ++++++++++++-----------
 1 file changed, 12 insertions(+), 11 deletions(-)

diff --git a/drivers/pci/pcie/aer.c b/drivers/pci/pcie/aer.c
index b013b853b555..a6600801af6e 100644
--- a/drivers/pci/pcie/aer.c
+++ b/drivers/pci/pcie/aer.c
@@ -1366,14 +1366,13 @@ static void aer_recover_work_func(struct work_struct *work)
 	while (kfifo_get(&aer_recover_ring, &entry)) {
 		pdev = pci_get_domain_bus_and_slot(entry.domain, entry.bus,
 						   entry.devfn);
-		if (!pdev) {
+		if (!pdev)
 			pr_err_ratelimited("%04x:%02x:%02x.%x: no pci_dev found\n",
 					   entry.domain, entry.bus,
 					   PCI_SLOT(entry.devfn),
 					   PCI_FUNC(entry.devfn));
-			continue;
-		}
-		pci_print_aer(pdev, entry.severity, entry.regs);
+		else
+			pci_print_aer(pdev, entry.severity, entry.regs);
 
 		/*
 		 * Memory for aer_capability_regs(entry.regs) is being
@@ -1385,13 +1384,15 @@ static void aer_recover_work_func(struct work_struct *work)
 		ghes_estatus_pool_region_free((unsigned long)entry.regs,
 					    sizeof(struct aer_capability_regs));
 
-		if (entry.severity == AER_NONFATAL)
-			pcie_do_recovery(pdev, pci_channel_io_normal,
-					 aer_root_reset);
-		else if (entry.severity == AER_FATAL)
-			pcie_do_recovery(pdev, pci_channel_io_frozen,
-					 aer_root_reset);
-		pci_dev_put(pdev);
+		if (pdev) {
+			if (entry.severity == AER_NONFATAL)
+				pcie_do_recovery(pdev, pci_channel_io_normal,
+						 aer_root_reset);
+			else if (entry.severity == AER_FATAL)
+				pcie_do_recovery(pdev, pci_channel_io_frozen,
+						 aer_root_reset);
+			pci_dev_put(pdev);
+		}
 	}
 }
 

-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH v5 3/3] PCI/AER: Document that aer_recover_queue() takes ownership of aer_regs
  2026-09-28 17:40 [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling Priyank Rathod
  2026-09-28 17:40 ` [PATCH v5 1/3] PCI/AER: Fix memory leak in aer_recover_queue() on kfifo buffer overflow Priyank Rathod
  2026-09-28 17:40 ` [PATCH v5 2/3] PCI/AER: Fix memory leak in aer_recover_work_func() when pci_dev is missing Priyank Rathod
@ 2026-09-28 17:40 ` Priyank Rathod
  2026-10-05 15:45 ` [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling Priyank Rathod
  2026-10-05 23:27 ` Bjorn Helgaas
  4 siblings, 0 replies; 6+ messages in thread
From: Priyank Rathod @ 2026-09-28 17:40 UTC (permalink / raw)
  To: Mahesh J Salgaonkar, Oliver O'Halloran, Bjorn Helgaas
  Cc: Lukas Wunner, Kuppuswamy Sathyanarayanan, Jonathan Cameron,
	Ilpo Järvinen, Dave Jiang, Shiju Jose, Rafael J. Wysocki,
	linuxppc-dev, linux-pci, linux-kernel, Priyank Rathod

ghes_handle_aer() allocates the AER register snapshot that it passes to
aer_recover_queue() from ghes_estatus_pool.  aer_recover_queue() returns
void, so the caller cannot tell whether the record was queued, and the
AER code owns the buffer from then on and must free it on every path.

None of this is documented at the definition of this exported function.
With GHES enabled, a new caller that passed a buffer from any other
allocator would hit the BUG() in gen_pool_free_owner() when the AER code
returns the buffer to ghes_estatus_pool, and a caller that freed the
buffer itself would cause a double free.

Add a kernel-doc comment that describes the parameters and states that
aer_recover_queue() takes ownership of @aer_regs, which must have been
allocated from ghes_estatus_pool.

No functional change.

Suggested-by: Kuppuswamy Sathyanarayanan <sathyanarayanan.kuppuswamy@linux.intel.com>
Link: https://lore.kernel.org/r/4513e7d4-4e2f-42d8-8f0c-2f0e03815dee@linux.intel.com
Signed-off-by: Priyank Rathod <rathodpriyank@google.com>
---
 drivers/pci/pcie/aer.c | 18 ++++++++++++++++++
 1 file changed, 18 insertions(+)

diff --git a/drivers/pci/pcie/aer.c b/drivers/pci/pcie/aer.c
index a6600801af6e..a58244e00bc4 100644
--- a/drivers/pci/pcie/aer.c
+++ b/drivers/pci/pcie/aer.c
@@ -1404,6 +1404,24 @@ static void aer_recover_work_func(struct work_struct *work)
 static DEFINE_SPINLOCK(aer_recover_ring_lock);
 static DECLARE_WORK(aer_recover_work, aer_recover_work_func);
 
+/**
+ * aer_recover_queue - queue an AER error record reported by firmware
+ * @domain: PCI domain (segment) of the device that reported the error
+ * @bus: bus number of the device that reported the error
+ * @devfn: encoded device and function number, as returned by PCI_DEVFN()
+ * @severity: AER_CORRECTABLE, AER_NONFATAL or AER_FATAL
+ * @aer_regs: snapshot of the device's AER Capability registers
+ *
+ * Queue an error record received from firmware through APEI GHES.  The
+ * record is processed later from a workqueue, which logs the error and,
+ * for uncorrectable errors, attempts recovery of the device.
+ *
+ * Takes ownership of @aer_regs, which must have been allocated from
+ * ghes_estatus_pool with a size of sizeof(struct aer_capability_regs).
+ * The buffer is freed with ghes_estatus_pool_region_free() by the work
+ * item that processes the record, or immediately if the queue is full.
+ * The caller must not access or free @aer_regs after this call.
+ */
 void aer_recover_queue(int domain, unsigned int bus, unsigned int devfn,
 		       int severity, struct aer_capability_regs *aer_regs)
 {

-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling
  2026-09-28 17:40 [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling Priyank Rathod
                   ` (2 preceding siblings ...)
  2026-09-28 17:40 ` [PATCH v5 3/3] PCI/AER: Document that aer_recover_queue() takes ownership of aer_regs Priyank Rathod
@ 2026-10-05 15:45 ` Priyank Rathod
  2026-10-05 23:27 ` Bjorn Helgaas
  4 siblings, 0 replies; 6+ messages in thread
From: Priyank Rathod @ 2026-10-05 15:45 UTC (permalink / raw)
  To: Bjorn Helgaas
  Cc: Mahesh J Salgaonkar, Oliver O'Halloran, Lukas Wunner,
	Kuppuswamy Sathyanarayanan, Jonathan Cameron, Ilpo Järvinen,
	Dave Jiang, Shiju Jose, Rafael J. Wysocki, linuxppc-dev,
	linux-pci, linux-kernel

Hi Bjorn,

Gentle ping on this series. Patches 1 and 2 carry Kuppuswamy's
Reviewed-by, and patch 3 is the kernel-doc comment he suggested. All
three still apply cleanly to current pci/next.

Is there anything you would like changed before it can be considered
for v7.4? I am happy to respin.

Kuppuswamy, if patch 3 matches what you had in mind, a Reviewed-by on
it would be appreciated.

Thanks,
Priyank

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling
  2026-09-28 17:40 [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling Priyank Rathod
                   ` (3 preceding siblings ...)
  2026-10-05 15:45 ` [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling Priyank Rathod
@ 2026-10-05 23:27 ` Bjorn Helgaas
  4 siblings, 0 replies; 6+ messages in thread
From: Bjorn Helgaas @ 2026-10-05 23:27 UTC (permalink / raw)
  To: Priyank Rathod
  Cc: Mahesh J Salgaonkar, Oliver O'Halloran, Bjorn Helgaas,
	Lukas Wunner, Kuppuswamy Sathyanarayanan, Jonathan Cameron,
	Ilpo Järvinen, Dave Jiang, Shiju Jose, Rafael J. Wysocki,
	linuxppc-dev, linux-pci, linux-kernel, stable

On Mon, Sep 28, 2026 at 05:40:11PM +0000, Priyank Rathod wrote:
> When firmware reports PCIe Advanced Error Reporting (AER) events via ACPI
> APEI GHES (ghes_handle_aer()), it allocates a snapshot buffer from
> ghes_estatus_pool to store the aer_capability_regs registers before
> enqueuing the error record into aer_recover_ring.
> 
> aer_recover_queue() returns void, so ghes_handle_aer() cannot release that
> buffer itself; ownership is handed to the AER code, which until now freed
> it only on the fully successful path. If the record cannot be enqueued, or
> if a dequeued record cannot be mapped to a pci_dev, the allocation is
> silently leaked. Under a sustained error storm this exhausts
> ghes_estatus_pool, which then breaks GHES hardware error reporting
> system-wide.
> 
> This series fixes both leak paths and documents the ownership rule:
> 
> Patch 1: aer_recover_queue() when kfifo_in_spinlocked() fails because
>          aer_recover_ring (capacity 16) is full. The rejected entry is
>          freed immediately via ghes_estatus_pool_region_free().
> 
> Patch 2: aer_recover_work_func() when a dequeued entry cannot be mapped to
>          an active PCI device (pdev is NULL). The loop is restructured so
>          ghes_estatus_pool_region_free() runs unconditionally for every
>          dequeued item.
> 
> Patch 3: Add a kernel-doc comment stating that aer_recover_queue() takes
>          ownership of @aer_regs, which must be allocated from
>          ghes_estatus_pool. This is documentation only, so unlike
>          patches 1 and 2 it has no Fixes: or Cc: stable tag.
> 
> Signed-off-by: Priyank Rathod <rathodpriyank@google.com>

Applied to pci/aer for v7.4, thanks!

> ---
> Changes in v5:
> - Add patch 3, a kernel-doc comment on aer_recover_queue() stating that
>   it takes ownership of @aer_regs, which must come from ghes_estatus_pool
>   (suggested by Kuppuswamy Sathyanarayanan). It is a separate patch so
>   that the two fixes stay minimal for stable backports, and because the
>   comment is only accurate once patch 2 is applied.
> - Add Kuppuswamy's Reviewed-by to patches 1 and 2. Their code is
>   unchanged from v4.
> - Still applies cleanly to pci/next (94e8d4e94266), before or after
>   Lukas' "Error reporting for AER-incapable devices" series:
>   https://lore.kernel.org/r/cover.1790531238.git.lukas@wunner.de
> - Cc Kuppuswamy Sathyanarayanan, Jonathan Cameron, Ilpo Järvinen and
>   Dave Jiang, plus Shiju Jose and Rafael J. Wysocki as the author and
>   committer of the commit in Fixes:.
> - Link to v4: https://lore.kernel.org/r/20260918-b4-fix-aer-memleaks-v4-0-f0a2c21ed1d1@google.com
> 
> Changes in v4:
> - Rebased onto v7.3-rc3+ (f259f446f519); applies cleanly to pci/next as
>   well. No conflicts with the Advisory Non-Fatal Error support that landed
>   in the meantime.
> - Added missing Fixes: e2abc47a5a1a ("ACPI: APEI: Fix AER info corruption
>   when error status data has multiple sections") and Cc: stable to both
>   patches; that commit (v6.7-rc1) introduced the ghes_estatus_pool
>   allocation whose ownership these paths drop.
> - Patch 1: use braces on both arms of the if/else and fix the continuation
>   alignment (checkpatch --strict).
> - Both patches now build warning-free with W=1 and CONFIG_ACPI_APEI_PCIEAER=y
>   (earlier revisions were only build-tested with APEI disabled, which
>   compiles neither of the modified functions).
> - Explained in both commit messages why the caller cannot free the buffer,
>   and when the missing-pci_dev path is reachable.
> - Cc: Lukas Wunner, who has been active in this code.
> - Link to v3: https://lore.kernel.org/r/20260803-b4-fix-aer-memleaks-v3-1-e87159611933@google.com
> 
> Changes in v3:
> - Resent to fix threading of the series.
> - Link to v2: https://lore.kernel.org/r/20260803-b4-fix-aer-memleaks-v2-1-fd199b0171fd@google.com
> 
> Changes in v2:
> - Refactored aer_recover_work_func() to ensure ghes_estatus_pool_region_free()
>   is called unconditionally for every dequeued record.
> - Added Patch 1 to fix related memory leak in aer_recover_queue() on kfifo
>   buffer overflow.
> - Link to v1: https://lore.kernel.org/r/20260803183853.432459-2-rathodpriyank@google.com
> 
> ---
> Priyank Rathod (3):
>       PCI/AER: Fix memory leak in aer_recover_queue() on kfifo buffer overflow
>       PCI/AER: Fix memory leak in aer_recover_work_func() when pci_dev is missing
>       PCI/AER: Document that aer_recover_queue() takes ownership of aer_regs
> 
>  drivers/pci/pcie/aer.c | 48 +++++++++++++++++++++++++++++++++++-------------
>  1 file changed, 35 insertions(+), 13 deletions(-)
> ---
> base-commit: f259f446f5198d98e13756d2cd531812a0ad3064
> change-id: 20260803-b4-fix-aer-memleaks-524a1bd5e888
> 
> Best regards,
> -- 
> Priyank Rathod <rathodpriyank@google.com>
> 

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-05 23:27 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 17:40 [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling Priyank Rathod
2026-09-28 17:40 ` [PATCH v5 1/3] PCI/AER: Fix memory leak in aer_recover_queue() on kfifo buffer overflow Priyank Rathod
2026-09-28 17:40 ` [PATCH v5 2/3] PCI/AER: Fix memory leak in aer_recover_work_func() when pci_dev is missing Priyank Rathod
2026-09-28 17:40 ` [PATCH v5 3/3] PCI/AER: Document that aer_recover_queue() takes ownership of aer_regs Priyank Rathod
2026-10-05 15:45 ` [PATCH v5 0/3] PCI/AER: Fix ghes_estatus_pool memory leaks in error handling Priyank Rathod
2026-10-05 23:27 ` Bjorn Helgaas

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®