mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2] perf/dwc_pcie: Fix PCI device reference leak in probe
@ 2026-08-20 13:56 Ruoyu Wang
  2026-08-20 14:16 ` Markus Elfring
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Ruoyu Wang @ 2026-08-20 13:56 UTC (permalink / raw)
  To: Shuai Xue, Jing Zhang, Will Deacon, Mark Rutland, Yunhui Cui,
	Markus Elfring
  Cc: linux-arm-kernel, linux-perf-users, linux-kernel, Ruoyu Wang

pci_get_domain_bus_and_slot() returns a referenced PCI device. When the
subsequent RAS DES capability lookup fails, dwc_pcie_pmu_probe() returns
-ENODEV without releasing that reference. Repeated failed probes can
therefore keep the PCI device allocated after removal.

Declare the looked-up device with __free(pci_dev_put), so the temporary
reference is released on every return path. Keeping the reference scoped
to the whole probe also covers all later uses of the device during
initialization.

This issue was found by a static analysis checker and confirmed by manual
source review.

Fixes: 7f35b429802a ("perf/dwc_pcie: fix duplicate pci_dev devices")
Suggested-by: Markus Elfring <Markus.Elfring@web.de>
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
---
Changes in v2:
- Manage the lookup reference with __free(pci_dev_put).
- Keep the reference scoped through the complete probe.

Link: https://lore.kernel.org/r/20260814133925.1385687-1-ruoyuw560@gmail.com/
---
 drivers/perf/dwc_pcie_pmu.c | 11 +++++------
 1 file changed, 5 insertions(+), 6 deletions(-)

diff --git a/drivers/perf/dwc_pcie_pmu.c b/drivers/perf/dwc_pcie_pmu.c
index 5385401fa9cf6..0e69bd71c3e61 100644
--- a/drivers/perf/dwc_pcie_pmu.c
+++ b/drivers/perf/dwc_pcie_pmu.c
@@ -694,16 +694,16 @@ static struct notifier_block dwc_pcie_pmu_nb = {
 
 static int dwc_pcie_pmu_probe(struct platform_device *plat_dev)
 {
-	struct pci_dev *pdev;
+	u32 sbdf = plat_dev->id;
+	struct pci_dev *pdev __free(pci_dev_put) =
+		pci_get_domain_bus_and_slot(sbdf >> 16,
+					    PCI_BUS_NUM(sbdf & 0xffff),
+					    sbdf & 0xff);
 	struct dwc_pcie_pmu *pcie_pmu;
 	char *name;
-	u32 sbdf;
 	u16 vsec;
 	int ret;
 
-	sbdf = plat_dev->id;
-	pdev = pci_get_domain_bus_and_slot(sbdf >> 16, PCI_BUS_NUM(sbdf & 0xffff),
-					   sbdf & 0xff);
 	if (!pdev) {
 		pr_err("No pdev found for the sbdf 0x%x\n", sbdf);
 		return -ENODEV;
@@ -713,7 +713,6 @@ static int dwc_pcie_pmu_probe(struct platform_device *plat_dev)
 	if (!vsec)
 		return -ENODEV;
 
-	pci_dev_put(pdev);
 	name = devm_kasprintf(&plat_dev->dev, GFP_KERNEL, "dwc_rootport_%x", sbdf);
 	if (!name)
 		return -ENOMEM;
-- 
2.51.0


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH v2] perf/dwc_pcie: Fix PCI device reference leak in probe
  2026-08-20 13:56 [PATCH v2] perf/dwc_pcie: Fix PCI device reference leak in probe Ruoyu Wang
@ 2026-08-20 14:16 ` Markus Elfring
       [not found]   ` <CAK_7xqwRdXEe63YoMNE5KtLKA3+Nx=qVYj_mqfJmTVjb2-f-cQ@mail.gmail.com>
  2026-08-21  7:00 ` [PATCH v2] " Markus Elfring
  2026-10-04 22:09 ` Will Deacon
  2 siblings, 1 reply; 5+ messages in thread
From: Markus Elfring @ 2026-08-20 14:16 UTC (permalink / raw)
  To: Ruoyu Wang, linux-perf-users, linux-arm-kernel, Jing Zhang,
	Mark Rutland, Shuai Xue, Will Deacon, Yunhui Cui
  Cc: linux-kernel, kernel-janitors

…
> Declare the looked-up device with __free(pci_dev_put), so the temporary
> reference is released on every return path. Keeping the reference scoped
> to the whole probe also covers all later uses of the device during
> initialization.
…

Is there a need to reduce the scope for such a local variable further
by using a corresponding compound statement?

Regards,
Markus

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [v2] perf/dwc_pcie: Fix PCI device reference leak in probe
       [not found]   ` <CAK_7xqwRdXEe63YoMNE5KtLKA3+Nx=qVYj_mqfJmTVjb2-f-cQ@mail.gmail.com>
@ 2026-08-20 14:43     ` Markus Elfring
  0 siblings, 0 replies; 5+ messages in thread
From: Markus Elfring @ 2026-08-20 14:43 UTC (permalink / raw)
  To: Ruoyu Wang, linux-perf-users, linux-arm-kernel
  Cc: Jing Zhang, Mark Rutland, Shuai Xue, Will Deacon, Yunhui Cui,
	linux-kernel, kernel-janitors

> I think keeping the function scope is clearer here :)

I got an other impression because a pci_dev_put(pdev) call was applied
before a devm_kasprintf() call.
https://elixir.bootlin.com/linux/v7.2/source/drivers/perf/dwc_pcie_pmu.c#L695-L717

Regards,
Markus

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH v2] perf/dwc_pcie: Fix PCI device reference leak in probe
  2026-08-20 13:56 [PATCH v2] perf/dwc_pcie: Fix PCI device reference leak in probe Ruoyu Wang
  2026-08-20 14:16 ` Markus Elfring
@ 2026-08-21  7:00 ` Markus Elfring
  2026-10-04 22:09 ` Will Deacon
  2 siblings, 0 replies; 5+ messages in thread
From: Markus Elfring @ 2026-08-21  7:00 UTC (permalink / raw)
  To: Ruoyu Wang, linux-perf-users, linux-arm-kernel, Jing Zhang,
	Mark Rutland, Shuai Xue, Will Deacon, Yunhui Cui
  Cc: kernel-janitors, LKML

> This issue was found by a static analysis checker and confirmed by manual
> source review.

Can such a source code analysis approach point any related development concerns out
also according to a pci_dev_put(pdev) call in the “middle” of the discussed control flow?
https://elixir.bootlin.com/linux/v7.2/source/drivers/perf/dwc_pcie_pmu.c#L695-L770

Regards,
Markus

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH v2] perf/dwc_pcie: Fix PCI device reference leak in probe
  2026-08-20 13:56 [PATCH v2] perf/dwc_pcie: Fix PCI device reference leak in probe Ruoyu Wang
  2026-08-20 14:16 ` Markus Elfring
  2026-08-21  7:00 ` [PATCH v2] " Markus Elfring
@ 2026-10-04 22:09 ` Will Deacon
  2 siblings, 0 replies; 5+ messages in thread
From: Will Deacon @ 2026-10-04 22:09 UTC (permalink / raw)
  To: Shuai Xue, Jing Zhang, Mark Rutland, Yunhui Cui, Markus Elfring,
	Ruoyu Wang
  Cc: catalin.marinas, kernel-team, Will Deacon, linux-arm-kernel,
	linux-perf-users, linux-kernel

On Thu, 20 Aug 2026 21:56:11 +0800, Ruoyu Wang wrote:
> pci_get_domain_bus_and_slot() returns a referenced PCI device. When the
> subsequent RAS DES capability lookup fails, dwc_pcie_pmu_probe() returns
> -ENODEV without releasing that reference. Repeated failed probes can
> therefore keep the PCI device allocated after removal.
> 
> Declare the looked-up device with __free(pci_dev_put), so the temporary
> reference is released on every return path. Keeping the reference scoped
> to the whole probe also covers all later uses of the device during
> initialization.
> 
> [...]

Applied to arm64 (for-next/perf), thanks!

[1/1] perf/dwc_pcie: Fix PCI device reference leak in probe
      https://git.kernel.org/arm64/c/3a4067658363

Cheers,
-- 
Will

https://fixes.arm64.dev
https://next.arm64.dev
https://will.arm64.dev

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-10-04 22:09 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-20 13:56 [PATCH v2] perf/dwc_pcie: Fix PCI device reference leak in probe Ruoyu Wang
2026-08-20 14:16 ` Markus Elfring
     [not found]   ` <CAK_7xqwRdXEe63YoMNE5KtLKA3+Nx=qVYj_mqfJmTVjb2-f-cQ@mail.gmail.com>
2026-08-20 14:43     ` [v2] " Markus Elfring
2026-08-21  7:00 ` [PATCH v2] " Markus Elfring
2026-10-04 22:09 ` Will Deacon

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®