* Re: [2/2] ASoC: samsung: odroid: fix a double-free issue for cpu_dai
[not found] <201907150949139435825@zte.com.cn>
@ 2019-07-15 6:40 ` Markus Elfring
0 siblings, 0 replies; 2+ messages in thread
From: Markus Elfring @ 2019-07-15 6:40 UTC (permalink / raw)
To: Wen Yang, alsa-devel, kernel-janitors
Cc: linux-kernel, Cheng Shengyu, Jaroslav Kysela,
Krzysztof Kozlowski, Liam Girdwood, Mark Brown, Sangbeom Kim,
Sylwester Nawrocki, Takashi Iwai, Xue Zhihong, Yi Wang
> These two updates fix two different bugs.
I can follow this view to some degree.
> and the other is the double-free issue
This programming error affects also the use of data structures which became invalid.
https://cwe.mitre.org/data/definitions/415.html#oc_415_Notes
> So we sent two patches to fix them separately.
You would like to fix something according to two variables (of the data type “device_node *”)
in the same function implementation.
Please combine these corrections in an update step under a topic like
“ASoC: samsung: odroid: Fix handling of device node references in odroid_audio_probe()”.
(The previous update step would contain still a known programming mistake otherwise,
wouldn't it?)
Regards,
Markus
^ permalink raw reply [flat|nested] 2+ messages in thread
* [PATCH 2/2] ASoC: samsung: odroid: fix a double-free issue for cpu_dai
@ 2019-07-13 3:46 Wen Yang
2019-07-14 12:47 ` [2/2] " Markus Elfring
0 siblings, 1 reply; 2+ messages in thread
From: Wen Yang @ 2019-07-13 3:46 UTC (permalink / raw)
To: krzk
Cc: sbkim73, s.nawrocki, lgirdwood, broonie, perex, tiwai,
alsa-devel, linux-kernel, xue.zhihong, wang.yi59, cheng.shengyu,
Wen Yang
The cpu_dai variable is still being used after the of_node_put() call,
which may result in double-free:
of_node_put(cpu_dai); ---> released here
ret = devm_snd_soc_register_card(dev, card);
if (ret < 0) {
...
goto err_put_clk_i2s; --> jump to err_put_clk_i2s
...
err_put_clk_i2s:
clk_put(priv->clk_i2s_bus);
err_put_sclk:
clk_put(priv->sclk_i2s);
err_put_cpu_dai:
of_node_put(cpu_dai); --> double-free here
Fixes: d832d2b246c5 ("ASoC: samsung: odroid: Fix of_node refcount unbalance")
Signed-off-by: Wen Yang <wen.yang99@zte.com.cn>
Cc: Krzysztof Kozlowski <krzk@kernel.org>
Cc: Sangbeom Kim <sbkim73@samsung.com>
Cc: Sylwester Nawrocki <s.nawrocki@samsung.com>
Cc: Liam Girdwood <lgirdwood@gmail.com>
Cc: Mark Brown <broonie@kernel.org>
Cc: Jaroslav Kysela <perex@perex.cz>
Cc: Takashi Iwai <tiwai@suse.com>
Cc: alsa-devel@alsa-project.org
Cc: linux-kernel@vger.kernel.org
---
sound/soc/samsung/odroid.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/soc/samsung/odroid.c b/sound/soc/samsung/odroid.c
index 64ebe89..f0f5fa9 100644
--- a/sound/soc/samsung/odroid.c
+++ b/sound/soc/samsung/odroid.c
@@ -308,7 +308,6 @@ static int odroid_audio_probe(struct platform_device *pdev)
ret = PTR_ERR(priv->clk_i2s_bus);
goto err_put_sclk;
}
- of_node_put(cpu_dai);
ret = devm_snd_soc_register_card(dev, card);
if (ret < 0) {
@@ -316,6 +315,7 @@ static int odroid_audio_probe(struct platform_device *pdev)
goto err_put_clk_i2s;
}
+ of_node_put(cpu_dai);
of_node_put(codec);
return 0;
--
2.9.5
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [2/2] ASoC: samsung: odroid: fix a double-free issue for cpu_dai
2019-07-13 3:46 [PATCH 2/2] " Wen Yang
@ 2019-07-14 12:47 ` Markus Elfring
0 siblings, 0 replies; 2+ messages in thread
From: Markus Elfring @ 2019-07-14 12:47 UTC (permalink / raw)
To: Wen Yang, alsa-devel
Cc: kernel-janitors, LKML, Cheng Shengyu, Jaroslav Kysela,
Krzysztof Kozlowski, Liam Girdwood, Mark Brown, Sangbeom Kim,
Sylwester Nawrocki, Takashi Iwai, Xue Zhihong, Yi Wang
> The cpu_dai variable is still being used after the of_node_put() call,
Such an implementation detail is questionable.
https://wiki.sei.cmu.edu/confluence/display/c/MEM30-C.+Do+not+access+freed+memory
> which may result in double-free:
This consequence is also undesirable.
https://cwe.mitre.org/data/definitions/415.html
Now I wonder if two update steps are really appropriate as a fix
instead of using a single update step for the desired correction
in this software module.
Should a commit (including previous ones) usually be correct by itself?
Regards,
Markus
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2019-07-15 6:41 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <201907150949139435825@zte.com.cn>
2019-07-15 6:40 ` [2/2] ASoC: samsung: odroid: fix a double-free issue for cpu_dai Markus Elfring
2019-07-13 3:46 [PATCH 2/2] " Wen Yang
2019-07-14 12:47 ` [2/2] " Markus Elfring
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®