* [PATCH] soc: microchip: mpfs: Fix flash leak in mpfs_sys_controller_probe()
@ 2026-09-17 15:35 Wentao Liang
2026-10-02 17:48 ` Conor Dooley
0 siblings, 1 reply; 3+ messages in thread
From: Wentao Liang @ 2026-09-17 15:35 UTC (permalink / raw)
To: conor.dooley
Cc: daire.mcnamara, linux-kernel, linux-riscv, Wentao Liang, stable
of_get_mtd_device_by_node() returns an MTD device reference that the
caller has to drop with put_mtd_device(). The probe error paths return
without releasing it, and the reference stored in sys_controller->flash
is never dropped when the controller is destroyed either.
Release the flash on the probe error paths and in
mpfs_sys_controller_delete(), so the reference is always put.
Fixes: 742aa6c563d2 ("soc: microchip: mpfs: enable access to the system controller's flash")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/soc/microchip/mpfs-sys-controller.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/soc/microchip/mpfs-sys-controller.c b/drivers/soc/microchip/mpfs-sys-controller.c
index 92d1142a59e6..ad57b09e5807 100644
--- a/drivers/soc/microchip/mpfs-sys-controller.c
+++ b/drivers/soc/microchip/mpfs-sys-controller.c
@@ -98,6 +98,8 @@ static void mpfs_sys_controller_delete(struct kref *kref)
struct mpfs_sys_controller *sys_controller =
container_of(kref, struct mpfs_sys_controller, consumers);
+ if (sys_controller->flash)
+ put_mtd_device(sys_controller->flash);
mbox_free_channel(sys_controller->chan);
kfree(sys_controller);
}
@@ -159,7 +161,8 @@ static int mpfs_sys_controller_probe(struct platform_device *pdev)
of_data = (struct mpfs_syscon_config *) device_get_match_data(dev);
if (!of_data) {
dev_err(dev, "Error getting match data\n");
- return -EINVAL;
+ ret = -EINVAL;
+ goto out_free;
}
for (i = 0; i < of_data->nb_subdevs; i++) {
@@ -174,6 +177,10 @@ static int mpfs_sys_controller_probe(struct platform_device *pdev)
return 0;
out_free:
+ if (!IS_ERR_OR_NULL(sys_controller->flash))
+ put_mtd_device(sys_controller->flash);
+ if (!IS_ERR_OR_NULL(sys_controller->chan))
+ mbox_free_channel(sys_controller->chan);
kfree(sys_controller);
return ret;
}
--
2.34.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] soc: microchip: mpfs: Fix flash leak in mpfs_sys_controller_probe()
2026-09-17 15:35 [PATCH] soc: microchip: mpfs: Fix flash leak in mpfs_sys_controller_probe() Wentao Liang
@ 2026-10-02 17:48 ` Conor Dooley
2026-10-08 13:18 ` Conor Dooley
0 siblings, 1 reply; 3+ messages in thread
From: Conor Dooley @ 2026-10-02 17:48 UTC (permalink / raw)
To: Wentao Liang
Cc: conor.dooley, daire.mcnamara, linux-kernel, linux-riscv, stable
[-- Attachment #1: Type: text/plain, Size: 2769 bytes --]
On Thu, Sep 17, 2026 at 03:35:50PM +0000, Wentao Liang wrote:
> of_get_mtd_device_by_node() returns an MTD device reference that the
> caller has to drop with put_mtd_device(). The probe error paths return
> without releasing it, and the reference stored in sys_controller->flash
> is never dropped when the controller is destroyed either.
>
> Release the flash on the probe error paths and in
> mpfs_sys_controller_delete(), so the reference is always put.
Is this diff sufficient?
If probe passes, shouldn't the driver also call this during removal?
Removal here just decrements the refcount, so the delete function is
where the call would have to go. Another patch for this driver pointed
out that the teardown code should actually call mpfs_sys_controller_put()
https://patchwork.kernel.org/project/lei-conor/patch/20260924110054.1553880-1-lgs201920130244@gmail.com/
so the right thing to do here is probably a mix of what you've got here
and what was done in that patch?
I note that the other user of this function, u-boot-env.c, doesn't call
this either.
Cheers,
Conor.
>
> Fixes: 742aa6c563d2 ("soc: microchip: mpfs: enable access to the system controller's flash")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
> ---
> drivers/soc/microchip/mpfs-sys-controller.c | 9 ++++++++-
> 1 file changed, 8 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/soc/microchip/mpfs-sys-controller.c b/drivers/soc/microchip/mpfs-sys-controller.c
> index 92d1142a59e6..ad57b09e5807 100644
> --- a/drivers/soc/microchip/mpfs-sys-controller.c
> +++ b/drivers/soc/microchip/mpfs-sys-controller.c
> @@ -98,6 +98,8 @@ static void mpfs_sys_controller_delete(struct kref *kref)
> struct mpfs_sys_controller *sys_controller =
> container_of(kref, struct mpfs_sys_controller, consumers);
>
> + if (sys_controller->flash)
> + put_mtd_device(sys_controller->flash);
> mbox_free_channel(sys_controller->chan);
> kfree(sys_controller);
> }
> @@ -159,7 +161,8 @@ static int mpfs_sys_controller_probe(struct platform_device *pdev)
> of_data = (struct mpfs_syscon_config *) device_get_match_data(dev);
> if (!of_data) {
> dev_err(dev, "Error getting match data\n");
> - return -EINVAL;
> + ret = -EINVAL;
> + goto out_free;
> }
>
> for (i = 0; i < of_data->nb_subdevs; i++) {
> @@ -174,6 +177,10 @@ static int mpfs_sys_controller_probe(struct platform_device *pdev)
> return 0;
>
> out_free:
> + if (!IS_ERR_OR_NULL(sys_controller->flash))
> + put_mtd_device(sys_controller->flash);
> + if (!IS_ERR_OR_NULL(sys_controller->chan))
> + mbox_free_channel(sys_controller->chan);
> kfree(sys_controller);
> return ret;
> }
> --
> 2.34.1
>
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] soc: microchip: mpfs: Fix flash leak in mpfs_sys_controller_probe()
2026-10-02 17:48 ` Conor Dooley
@ 2026-10-08 13:18 ` Conor Dooley
0 siblings, 0 replies; 3+ messages in thread
From: Conor Dooley @ 2026-10-08 13:18 UTC (permalink / raw)
To: Wentao Liang
Cc: conor.dooley, daire.mcnamara, linux-kernel, linux-riscv, stable
[-- Attachment #1: Type: text/plain, Size: 3203 bytes --]
On Fri, Oct 02, 2026 at 06:48:28PM +0100, Conor Dooley wrote:
> On Thu, Sep 17, 2026 at 03:35:50PM +0000, Wentao Liang wrote:
> > of_get_mtd_device_by_node() returns an MTD device reference that the
> > caller has to drop with put_mtd_device(). The probe error paths return
> > without releasing it, and the reference stored in sys_controller->flash
> > is never dropped when the controller is destroyed either.
> >
> > Release the flash on the probe error paths and in
> > mpfs_sys_controller_delete(), so the reference is always put.
>
> Is this diff sufficient?
> If probe passes, shouldn't the driver also call this during removal?
>
> Removal here just decrements the refcount, so the delete function is
> where the call would have to go. Another patch for this driver pointed
> out that the teardown code should actually call mpfs_sys_controller_put()
> https://patchwork.kernel.org/project/lei-conor/patch/20260924110054.1553880-1-lgs201920130244@gmail.com/
> so the right thing to do here is probably a mix of what you've got here
> and what was done in that patch?
>
> I note that the other user of this function, u-boot-env.c, doesn't call
> this either.
I've applied a v2 of that patch I mentioned, so I'll expect a new
iteration here on top of that:
https://patchwork.kernel.org/project/lei-conor/patch/20261007121743.192486-1-lgs201920130244@gmail.com/
Cheers,
Conor.
>
> Cheers,
> Conor.
>
> >
> > Fixes: 742aa6c563d2 ("soc: microchip: mpfs: enable access to the system controller's flash")
> > Cc: stable@vger.kernel.org
> > Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
> > ---
> > drivers/soc/microchip/mpfs-sys-controller.c | 9 ++++++++-
> > 1 file changed, 8 insertions(+), 1 deletion(-)
> >
> > diff --git a/drivers/soc/microchip/mpfs-sys-controller.c b/drivers/soc/microchip/mpfs-sys-controller.c
> > index 92d1142a59e6..ad57b09e5807 100644
> > --- a/drivers/soc/microchip/mpfs-sys-controller.c
> > +++ b/drivers/soc/microchip/mpfs-sys-controller.c
> > @@ -98,6 +98,8 @@ static void mpfs_sys_controller_delete(struct kref *kref)
> > struct mpfs_sys_controller *sys_controller =
> > container_of(kref, struct mpfs_sys_controller, consumers);
> >
> > + if (sys_controller->flash)
> > + put_mtd_device(sys_controller->flash);
> > mbox_free_channel(sys_controller->chan);
> > kfree(sys_controller);
> > }
> > @@ -159,7 +161,8 @@ static int mpfs_sys_controller_probe(struct platform_device *pdev)
> > of_data = (struct mpfs_syscon_config *) device_get_match_data(dev);
> > if (!of_data) {
> > dev_err(dev, "Error getting match data\n");
> > - return -EINVAL;
> > + ret = -EINVAL;
> > + goto out_free;
> > }
> >
> > for (i = 0; i < of_data->nb_subdevs; i++) {
> > @@ -174,6 +177,10 @@ static int mpfs_sys_controller_probe(struct platform_device *pdev)
> > return 0;
> >
> > out_free:
> > + if (!IS_ERR_OR_NULL(sys_controller->flash))
> > + put_mtd_device(sys_controller->flash);
> > + if (!IS_ERR_OR_NULL(sys_controller->chan))
> > + mbox_free_channel(sys_controller->chan);
> > kfree(sys_controller);
> > return ret;
> > }
> > --
> > 2.34.1
> >
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-08 13:18 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 15:35 [PATCH] soc: microchip: mpfs: Fix flash leak in mpfs_sys_controller_probe() Wentao Liang
2026-10-02 17:48 ` Conor Dooley
2026-10-08 13:18 ` Conor Dooley
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®