* [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
@ 2026-08-24 9:05 liupeng
2026-09-17 22:10 ` lyude
0 siblings, 1 reply; 10+ messages in thread
From: liupeng @ 2026-08-24 9:05 UTC (permalink / raw)
To: Lyude Paul, Danilo Krummrich, Maarten Lankhorst, Maxime Ripard,
Thomas Zimmermann, David Airlie, Simona Vetter, Guenter Roeck,
open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS,
open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS, open list,
open list:HARDWARE
MONITORING:Keyword:(devm_)?hwmon_device_(un)?register(|_with_groups|_with_info)
Cc: liupeng
In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
allocated drm->debugfs is leaked because the function returns the
error code directly.
In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
the allocated hwmon structure is leaked because the function returns
the error code directly.
Fix both by freeing the allocated memory and clearing the pointer on
the error paths.
Signed-off-by: liupeng <liupeng01@kylinos.cn>
---
drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++---
drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++
2 files changed, 14 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
index 47d5579c568d..88223931f382 100644
--- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
+++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
@@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor *minor)
int
nouveau_debugfs_init(struct nouveau_drm *drm)
{
+ int ret;
+
drm->debugfs = kzalloc_obj(*drm->debugfs);
if (!drm->debugfs)
return -ENOMEM;
- return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
- NVIF_CLASS_CONTROL, NULL, 0,
- &drm->debugfs->ctrl);
+ ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
+ NVIF_CLASS_CONTROL, NULL, 0,
+ &drm->debugfs->ctrl);
+ if (ret) {
+ kfree(drm->debugfs);
+ drm->debugfs = NULL;
+ return ret;
+ }
+
+ return 0;
}
void
diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
index 726397ab035d..ffbe7f542ab0 100644
--- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
+++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
@@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
if (IS_ERR(hwmon_dev)) {
ret = PTR_ERR(hwmon_dev);
NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret);
+ drm->hwmon = NULL;
+ kfree(hwmon);
return ret;
}
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
2026-08-24 9:05 [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths liupeng
@ 2026-09-17 22:10 ` lyude
2026-09-22 4:40 ` [PATCH v2] " liupeng
0 siblings, 1 reply; 10+ messages in thread
From: lyude @ 2026-09-17 22:10 UTC (permalink / raw)
To: liupeng, Danilo Krummrich, Maarten Lankhorst, Maxime Ripard,
Thomas Zimmermann, David Airlie, Simona Vetter, Guenter Roeck,
open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS,
open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS, open list,
open list:HARDWARE
MONITORING:Keyword:(devm_)?hwmon_device_(un)?register(|_with_groups|_with_info)
Mind adding the proper Fixes: tags and Cc: tags here?
On Mon, 2026-08-24 at 17:05 +0800, liupeng wrote:
> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
> previously
> allocated drm->debugfs is leaked because the function returns the
> error code directly.
>
> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
> the allocated hwmon structure is leaked because the function returns
> the error code directly.
>
> Fix both by freeing the allocated memory and clearing the pointer on
> the error paths.
>
> Signed-off-by: liupeng <liupeng01@kylinos.cn>
> ---
> drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++---
> drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++
> 2 files changed, 14 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> index 47d5579c568d..88223931f382 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> @@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor
> *minor)
> int
> nouveau_debugfs_init(struct nouveau_drm *drm)
> {
> + int ret;
> +
> drm->debugfs = kzalloc_obj(*drm->debugfs);
> if (!drm->debugfs)
> return -ENOMEM;
>
> - return nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> - NVIF_CLASS_CONTROL, NULL, 0,
> - &drm->debugfs->ctrl);
> + ret = nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> + NVIF_CLASS_CONTROL, NULL, 0,
> + &drm->debugfs->ctrl);
> + if (ret) {
> + kfree(drm->debugfs);
> + drm->debugfs = NULL;
> + return ret;
> + }
> +
> + return 0;
> }
>
> void
> diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> index 726397ab035d..ffbe7f542ab0 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
> if (IS_ERR(hwmon_dev)) {
> ret = PTR_ERR(hwmon_dev);
> NV_ERROR(drm, "Unable to register hwmon device:
> %d\n", ret);
> + drm->hwmon = NULL;
> + kfree(hwmon);
> return ret;
> }
>
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH v2] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
2026-09-17 22:10 ` lyude
@ 2026-09-22 4:40 ` liupeng
2026-10-08 21:45 ` lyude
0 siblings, 1 reply; 10+ messages in thread
From: liupeng @ 2026-09-22 4:40 UTC (permalink / raw)
To: lyude, dakr
Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon,
stable, liupeng
In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
allocated drm->debugfs is leaked because the function returns the
error code directly.
In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
the allocated hwmon structure is leaked because the function returns
the error code directly.
Fix both by freeing the allocated memory and clearing the pointer on
the error paths.
Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs")
Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM")
Cc: stable@vger.kernel.org
Signed-off-by: liupeng <liupeng01@kylinos.cn>
---
Changes in v2:
- Add Fixes: tags for the commits that introduced the leaks
- Add Cc: stable@vger.kernel.org for stable backporting
drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++---
drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++
2 files changed, 14 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
index 47d5579c568d..88223931f382 100644
--- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
+++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
@@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor *minor)
int
nouveau_debugfs_init(struct nouveau_drm *drm)
{
+ int ret;
+
drm->debugfs = kzalloc_obj(*drm->debugfs);
if (!drm->debugfs)
return -ENOMEM;
- return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
- NVIF_CLASS_CONTROL, NULL, 0,
- &drm->debugfs->ctrl);
+ ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
+ NVIF_CLASS_CONTROL, NULL, 0,
+ &drm->debugfs->ctrl);
+ if (ret) {
+ kfree(drm->debugfs);
+ drm->debugfs = NULL;
+ return ret;
+ }
+
+ return 0;
}
void
diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
index 726397ab035d..ffbe7f542ab0 100644
--- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
+++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
@@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
if (IS_ERR(hwmon_dev)) {
ret = PTR_ERR(hwmon_dev);
NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret);
+ drm->hwmon = NULL;
+ kfree(hwmon);
return ret;
}
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v2] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
2026-09-22 4:40 ` [PATCH v2] " liupeng
@ 2026-10-08 21:45 ` lyude
2026-10-09 11:51 ` [PATCH v3] " liupeng
0 siblings, 1 reply; 10+ messages in thread
From: lyude @ 2026-10-08 21:45 UTC (permalink / raw)
To: liupeng, dakr
Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon,
stable
One nit-pick below:
On Tue, 2026-09-22 at 12:40 +0800, liupeng wrote:
> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
> previously
> allocated drm->debugfs is leaked because the function returns the
> error code directly.
>
> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
> the allocated hwmon structure is leaked because the function returns
> the error code directly.
>
> Fix both by freeing the allocated memory and clearing the pointer on
> the error paths.
>
> Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for
> debugfs")
> Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except
> the hwmon interfaces to THERM")
> Cc: stable@vger.kernel.org
> Signed-off-by: liupeng <liupeng01@kylinos.cn>
> ---
> Changes in v2:
> - Add Fixes: tags for the commits that introduced the leaks
> - Add Cc: stable@vger.kernel.org for stable backporting
>
> drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++---
> drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++
> 2 files changed, 14 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> index 47d5579c568d..88223931f382 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> @@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor
> *minor)
> int
> nouveau_debugfs_init(struct nouveau_drm *drm)
> {
> + int ret;
> +
> drm->debugfs = kzalloc_obj(*drm->debugfs);
> if (!drm->debugfs)
> return -ENOMEM;
>
> - return nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> - NVIF_CLASS_CONTROL, NULL, 0,
> - &drm->debugfs->ctrl);
> + ret = nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> + NVIF_CLASS_CONTROL, NULL, 0,
> + &drm->debugfs->ctrl);
> + if (ret) {
> + kfree(drm->debugfs);
> + drm->debugfs = NULL;
> + return ret;
^ We could get rid of this extra return…
> + }
> +
> + return 0;
…and just return ret here
With that fixed:
Reviewed-by: Lyude Paul <lyude@redhat.com>
> }
>
> void
> diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> index 726397ab035d..ffbe7f542ab0 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
> if (IS_ERR(hwmon_dev)) {
> ret = PTR_ERR(hwmon_dev);
> NV_ERROR(drm, "Unable to register hwmon device:
> %d\n", ret);
> + drm->hwmon = NULL;
> + kfree(hwmon);
> return ret;
> }
>
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
2026-10-08 21:45 ` lyude
@ 2026-10-09 11:51 ` liupeng
2026-10-09 21:35 ` lyude
0 siblings, 1 reply; 10+ messages in thread
From: liupeng @ 2026-10-09 11:51 UTC (permalink / raw)
To: lyude, dakr
Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon,
stable, liupeng
In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
allocated drm->debugfs is leaked because the function returns the
error code directly.
In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
the allocated hwmon structure is leaked because the function returns
the error code directly.
Fix both by freeing the allocated memory and clearing the pointer on
the error paths.
Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs")
Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM")
Cc: stable@vger.kernel.org
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: liupeng <liupeng01@kylinos.cn>
---
Changes in v3:
- Drop the extra return in nouveau_debugfs_init() as suggested by Lyude.
- Add Reviewed-by tag.
drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++
2 files changed, 13 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
index 47d5579c568d..338421e52f69 100644
--- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
+++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
@@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor *minor)
int
nouveau_debugfs_init(struct nouveau_drm *drm)
{
+ int ret;
+
drm->debugfs = kzalloc_obj(*drm->debugfs);
if (!drm->debugfs)
return -ENOMEM;
- return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
- NVIF_CLASS_CONTROL, NULL, 0,
- &drm->debugfs->ctrl);
+ ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
+ NVIF_CLASS_CONTROL, NULL, 0,
+ &drm->debugfs->ctrl);
+ if (ret) {
+ kfree(drm->debugfs);
+ drm->debugfs = NULL;
+ }
+
+ return ret;
}
void
diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
index 726397ab035d..ffbe7f542ab0 100644
--- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
+++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
@@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
if (IS_ERR(hwmon_dev)) {
ret = PTR_ERR(hwmon_dev);
NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret);
+ drm->hwmon = NULL;
+ kfree(hwmon);
return ret;
}
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
2026-10-09 11:51 ` [PATCH v3] " liupeng
@ 2026-10-09 21:35 ` lyude
2026-10-09 21:40 ` Danilo Krummrich
0 siblings, 1 reply; 10+ messages in thread
From: lyude @ 2026-10-09 21:35 UTC (permalink / raw)
To: liupeng, dakr
Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon,
stable
Reviewed-by: Lyude Paul <lyude@redhat.com>
Will push to drm-misc-fixes in a moment
On Fri, 2026-10-09 at 19:51 +0800, liupeng wrote:
> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
> previously
> allocated drm->debugfs is leaked because the function returns the
> error code directly.
>
> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
> the allocated hwmon structure is leaked because the function returns
> the error code directly.
>
> Fix both by freeing the allocated memory and clearing the pointer on
> the error paths.
>
> Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for
> debugfs")
> Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except
> the hwmon interfaces to THERM")
> Cc: stable@vger.kernel.org
> Reviewed-by: Lyude Paul <lyude@redhat.com>
> Signed-off-by: liupeng <liupeng01@kylinos.cn>
> ---
> Changes in v3:
> - Drop the extra return in nouveau_debugfs_init() as suggested by
> Lyude.
> - Add Reviewed-by tag.
>
> drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
> drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++
> 2 files changed, 13 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> index 47d5579c568d..338421e52f69 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor
> *minor)
> int
> nouveau_debugfs_init(struct nouveau_drm *drm)
> {
> + int ret;
> +
> drm->debugfs = kzalloc_obj(*drm->debugfs);
> if (!drm->debugfs)
> return -ENOMEM;
>
> - return nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> - NVIF_CLASS_CONTROL, NULL, 0,
> - &drm->debugfs->ctrl);
> + ret = nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> + NVIF_CLASS_CONTROL, NULL, 0,
> + &drm->debugfs->ctrl);
> + if (ret) {
> + kfree(drm->debugfs);
> + drm->debugfs = NULL;
> + }
> +
> + return ret;
> }
>
> void
> diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> index 726397ab035d..ffbe7f542ab0 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
> if (IS_ERR(hwmon_dev)) {
> ret = PTR_ERR(hwmon_dev);
> NV_ERROR(drm, "Unable to register hwmon device:
> %d\n", ret);
> + drm->hwmon = NULL;
> + kfree(hwmon);
> return ret;
> }
>
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
2026-10-09 21:35 ` lyude
@ 2026-10-09 21:40 ` Danilo Krummrich
2026-10-09 21:43 ` lyude
0 siblings, 1 reply; 10+ messages in thread
From: Danilo Krummrich @ 2026-10-09 21:40 UTC (permalink / raw)
To: lyude
Cc: liupeng, maarten.lankhorst, mripard, tzimmermann, airlied,
simona, linux, nouveau, bskeggs, dri-devel, nouveau,
linux-kernel, linux-hwmon, stable
On Fri Oct 9, 2026 at 11:35 PM CEST, lyude wrote:
> Reviewed-by: Lyude Paul <lyude@redhat.com>
>
> Will push to drm-misc-fixes in a moment
Please wait, those are two unrelated fixes with two different Fixes: tags, so
those should be two separate patches.
I'm also not sure this is -fixes material. A memory leak in an unwind path for
-rc7 feels wrong.
Thanks,
Danilo
> On Fri, 2026-10-09 at 19:51 +0800, liupeng wrote:
>> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
>> previously
>> allocated drm->debugfs is leaked because the function returns the
>> error code directly.
>>
>> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
>> the allocated hwmon structure is leaked because the function returns
>> the error code directly.
>>
>> Fix both by freeing the allocated memory and clearing the pointer on
>> the error paths.
>>
>> Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for
>> debugfs")
>> Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except
>> the hwmon interfaces to THERM")
>> Cc: stable@vger.kernel.org
>> Reviewed-by: Lyude Paul <lyude@redhat.com>
>> Signed-off-by: liupeng <liupeng01@kylinos.cn>
>> ---
>> Changes in v3:
>> - Drop the extra return in nouveau_debugfs_init() as suggested by
>> Lyude.
>> - Add Reviewed-by tag.
>>
>> drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
>> drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++
>> 2 files changed, 13 insertions(+), 3 deletions(-)
>>
>> diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
>> b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
>> index 47d5579c568d..338421e52f69 100644
>> --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
>> +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
>> @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor
>> *minor)
>> int
>> nouveau_debugfs_init(struct nouveau_drm *drm)
>> {
>> + int ret;
>> +
>> drm->debugfs = kzalloc_obj(*drm->debugfs);
>> if (!drm->debugfs)
>> return -ENOMEM;
>>
>> - return nvif_object_ctor(&drm->client.device.object,
>> "debugfsCtrl", 0,
>> - NVIF_CLASS_CONTROL, NULL, 0,
>> - &drm->debugfs->ctrl);
>> + ret = nvif_object_ctor(&drm->client.device.object,
>> "debugfsCtrl", 0,
>> + NVIF_CLASS_CONTROL, NULL, 0,
>> + &drm->debugfs->ctrl);
>> + if (ret) {
>> + kfree(drm->debugfs);
>> + drm->debugfs = NULL;
>> + }
>> +
>> + return ret;
>> }
>>
>> void
>> diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
>> b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
>> index 726397ab035d..ffbe7f542ab0 100644
>> --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
>> +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
>> @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
>> if (IS_ERR(hwmon_dev)) {
>> ret = PTR_ERR(hwmon_dev);
>> NV_ERROR(drm, "Unable to register hwmon device:
>> %d\n", ret);
>> + drm->hwmon = NULL;
>> + kfree(hwmon);
>> return ret;
>> }
>>
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
2026-10-09 21:40 ` Danilo Krummrich
@ 2026-10-09 21:43 ` lyude
2026-10-10 2:20 ` [PATCH v4 1/2] drm/nouveau: Fix memory leak in debugfs init error path liupeng
0 siblings, 1 reply; 10+ messages in thread
From: lyude @ 2026-10-09 21:43 UTC (permalink / raw)
To: Danilo Krummrich
Cc: liupeng, maarten.lankhorst, mripard, tzimmermann, airlied,
simona, linux, nouveau, bskeggs, dri-devel, nouveau,
linux-kernel, linux-hwmon, stable
On Fri, 2026-10-09 at 23:40 +0200, Danilo Krummrich wrote:
> On Fri Oct 9, 2026 at 11:35 PM CEST, lyude wrote:
> > Reviewed-by: Lyude Paul <lyude@redhat.com>
> >
> > Will push to drm-misc-fixes in a moment
>
> Please wait, those are two unrelated fixes with two different Fixes:
> tags, so
> those should be two separate patches.
Thanks, I think my brain just glossed over the tags while looking at
this.
liupeng, could you split these patches up?
>
> I'm also not sure this is -fixes material. A memory leak in an unwind
> path for
> -rc7 feels wrong.
>
> Thanks,
> Danilo
>
> > On Fri, 2026-10-09 at 19:51 +0800, liupeng wrote:
> > > In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
> > > previously
> > > allocated drm->debugfs is leaked because the function returns the
> > > error code directly.
> > >
> > > In nouveau_hwmon_init(), if hwmon_device_register_with_info()
> > > fails,
> > > the allocated hwmon structure is leaked because the function
> > > returns
> > > the error code directly.
> > >
> > > Fix both by freeing the allocated memory and clearing the pointer
> > > on
> > > the error paths.
> > >
> > > Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object
> > > for
> > > debugfs")
> > > Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything
> > > except
> > > the hwmon interfaces to THERM")
> > > Cc: stable@vger.kernel.org
> > > Reviewed-by: Lyude Paul <lyude@redhat.com>
> > > Signed-off-by: liupeng <liupeng01@kylinos.cn>
> > > ---
> > > Changes in v3:
> > > - Drop the extra return in nouveau_debugfs_init() as suggested by
> > > Lyude.
> > > - Add Reviewed-by tag.
> > >
> > > drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
> > > drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++
> > > 2 files changed, 13 insertions(+), 3 deletions(-)
> > >
> > > diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> > > b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> > > index 47d5579c568d..338421e52f69 100644
> > > --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> > > +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> > > @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor
> > > *minor)
> > > int
> > > nouveau_debugfs_init(struct nouveau_drm *drm)
> > > {
> > > + int ret;
> > > +
> > > drm->debugfs = kzalloc_obj(*drm->debugfs);
> > > if (!drm->debugfs)
> > > return -ENOMEM;
> > >
> > > - return nvif_object_ctor(&drm->client.device.object,
> > > "debugfsCtrl", 0,
> > > - NVIF_CLASS_CONTROL, NULL, 0,
> > > - &drm->debugfs->ctrl);
> > > + ret = nvif_object_ctor(&drm->client.device.object,
> > > "debugfsCtrl", 0,
> > > + NVIF_CLASS_CONTROL, NULL, 0,
> > > + &drm->debugfs->ctrl);
> > > + if (ret) {
> > > + kfree(drm->debugfs);
> > > + drm->debugfs = NULL;
> > > + }
> > > +
> > > + return ret;
> > > }
> > >
> > > void
> > > diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> > > b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> > > index 726397ab035d..ffbe7f542ab0 100644
> > > --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> > > +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> > > @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
> > > if (IS_ERR(hwmon_dev)) {
> > > ret = PTR_ERR(hwmon_dev);
> > > NV_ERROR(drm, "Unable to register hwmon device:
> > > %d\n", ret);
> > > + drm->hwmon = NULL;
> > > + kfree(hwmon);
> > > return ret;
> > > }
> > >
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH v4 1/2] drm/nouveau: Fix memory leak in debugfs init error path
2026-10-09 21:43 ` lyude
@ 2026-10-10 2:20 ` liupeng
2026-10-10 2:20 ` [PATCH v4 2/2] drm/nouveau: Fix memory leak in hwmon " liupeng
0 siblings, 1 reply; 10+ messages in thread
From: liupeng @ 2026-10-10 2:20 UTC (permalink / raw)
To: lyude, dakr
Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
nouveau, dri-devel, nouveau, linux-kernel, linux-hwmon, stable,
liupeng
In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
allocated drm->debugfs is leaked because the function returns the
error code directly.
Fix this by freeing the allocated memory and clearing the pointer on
the error path.
Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs")
Cc: stable@vger.kernel.org
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: liupeng <liupeng01@kylinos.cn>
---
Changes in v4:
- Split the debugfs and hwmon fixes into two separate patches as
requested by Danilo, since they are unrelated fixes with different
Fixes: tags. No functional change to this fix.
drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
index 47d5579c568d..338421e52f69 100644
--- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
+++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
@@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor *minor)
int
nouveau_debugfs_init(struct nouveau_drm *drm)
{
+ int ret;
+
drm->debugfs = kzalloc_obj(*drm->debugfs);
if (!drm->debugfs)
return -ENOMEM;
- return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
- NVIF_CLASS_CONTROL, NULL, 0,
- &drm->debugfs->ctrl);
+ ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
+ NVIF_CLASS_CONTROL, NULL, 0,
+ &drm->debugfs->ctrl);
+ if (ret) {
+ kfree(drm->debugfs);
+ drm->debugfs = NULL;
+ }
+
+ return ret;
}
void
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH v4 2/2] drm/nouveau: Fix memory leak in hwmon init error path
2026-10-10 2:20 ` [PATCH v4 1/2] drm/nouveau: Fix memory leak in debugfs init error path liupeng
@ 2026-10-10 2:20 ` liupeng
0 siblings, 0 replies; 10+ messages in thread
From: liupeng @ 2026-10-10 2:20 UTC (permalink / raw)
To: lyude, dakr
Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
nouveau, dri-devel, nouveau, linux-kernel, linux-hwmon, stable,
liupeng
In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
the allocated hwmon structure is leaked because the function returns
the error code directly.
Fix this by freeing the allocated memory and clearing the pointer on
the error path.
Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM")
Cc: stable@vger.kernel.org
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: liupeng <liupeng01@kylinos.cn>
---
Changes in v4:
- Split the debugfs and hwmon fixes into two separate patches as
requested by Danilo, since they are unrelated fixes with different
Fixes: tags. No functional change to this fix.
drivers/gpu/drm/nouveau/nouveau_hwmon.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
index 726397ab035d..ffbe7f542ab0 100644
--- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
+++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
@@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
if (IS_ERR(hwmon_dev)) {
ret = PTR_ERR(hwmon_dev);
NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret);
+ drm->hwmon = NULL;
+ kfree(hwmon);
return ret;
}
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2026-10-10 2:20 UTC | newest]
Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-24 9:05 [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths liupeng
2026-09-17 22:10 ` lyude
2026-09-22 4:40 ` [PATCH v2] " liupeng
2026-10-08 21:45 ` lyude
2026-10-09 11:51 ` [PATCH v3] " liupeng
2026-10-09 21:35 ` lyude
2026-10-09 21:40 ` Danilo Krummrich
2026-10-09 21:43 ` lyude
2026-10-10 2:20 ` [PATCH v4 1/2] drm/nouveau: Fix memory leak in debugfs init error path liupeng
2026-10-10 2:20 ` [PATCH v4 2/2] drm/nouveau: Fix memory leak in hwmon " liupeng
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®