* [PATCH] dca: fix provider device memory leak on domain allocation failure
@ 2026-09-19 17:59 Guangshuo Li
2026-09-21 11:30 ` Markus Elfring
2026-09-21 15:12 ` krzk
0 siblings, 2 replies; 4+ messages in thread
From: Guangshuo Li @ 2026-09-19 17:59 UTC (permalink / raw)
To: Kees Cook, Guangshuo Li, Dan Williams, Maciej Sosnowski, linux-kernel
Cc: stable
register_dca_provider() calls dca_sysfs_add_provider() before looking up
or allocating the DCA domain. A successful dca_sysfs_add_provider()
allocates an IDR entry and creates the dca%d class device.
If no domain exists and dca_allocate_domain() fails, the function
returns -ENODEV without calling dca_sysfs_remove_provider(). The class
device therefore remains registered and the IDR entry remains
allocated. The caller may subsequently free the dca_provider, leaving
the IDR entry pointing to freed memory.
Since the class device is never unregistered, its device reference is
not dropped and device_create_release() is never reached, leaking the
struct device allocation.
Call dca_sysfs_remove_provider() before returning when domain allocation
fails. This unregisters the class device and removes the corresponding
IDR entry.
The issue was identified by a static analysis tool I developed and
confirmed by manual review.
Fixes: 1a5aeeecd550 ("dca: registering requesters in multiple dca domains")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
---
drivers/dca/dca-core.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/dca/dca-core.c b/drivers/dca/dca-core.c
index 583510850fad..57e41fa87cca 100644
--- a/drivers/dca/dca-core.c
+++ b/drivers/dca/dca-core.c
@@ -368,8 +368,11 @@ int register_dca_provider(struct dca_provider *dca, struct device *dev)
raw_spin_unlock_irqrestore(&dca_lock, flags);
rc = dca_pci_rc_from_dev(dev);
newdomain = dca_allocate_domain(rc);
- if (!newdomain)
+ if (!newdomain) {
+ dca_sysfs_remove_provider(dca);
return -ENODEV;
+ }
+
raw_spin_lock_irqsave(&dca_lock, flags);
/* Recheck, we might have raced after dropping the lock */
domain = dca_get_domain(dev);
--
2.43.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] dca: fix provider device memory leak on domain allocation failure
2026-09-19 17:59 [PATCH] dca: fix provider device memory leak on domain allocation failure Guangshuo Li
@ 2026-09-21 11:30 ` Markus Elfring
2026-09-21 15:12 ` krzk
1 sibling, 0 replies; 4+ messages in thread
From: Markus Elfring @ 2026-09-21 11:30 UTC (permalink / raw)
To: Guangshuo Li, kernel-janitors, Dan Williams, Kees Cook, Maciej Sosnowski
Cc: stable, LKML
…
> +++ b/drivers/dca/dca-core.c
> @@ -368,8 +368,11 @@ int register_dca_provider(struct dca_provider *dca, struct device *dev)
> raw_spin_unlock_irqrestore(&dca_lock, flags);
> rc = dca_pci_rc_from_dev(dev);
> newdomain = dca_allocate_domain(rc);
> - if (!newdomain)
> + if (!newdomain) {
> + dca_sysfs_remove_provider(dca);
> return -ENODEV;
> + }
> +
> raw_spin_lock_irqsave(&dca_lock, flags);
…
Please avoid a bit of duplicate source code in this function implementation
by using another goto chain.
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/process/coding-style.rst?h=v7.3-rc4#n572
https://elixir.bootlin.com/linux/v7.3-rc3/source/drivers/dca/dca-core.c#L335-L389
Regards,
Markus
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] dca: fix provider device memory leak on domain allocation failure
2026-09-19 17:59 [PATCH] dca: fix provider device memory leak on domain allocation failure Guangshuo Li
2026-09-21 11:30 ` Markus Elfring
@ 2026-09-21 15:12 ` krzk
2026-09-22 2:48 ` Guangshuo Li
1 sibling, 1 reply; 4+ messages in thread
From: krzk @ 2026-09-21 15:12 UTC (permalink / raw)
To: Guangshuo Li
Cc: stable, Maciej Sosnowski, Dan Williams, Kees Cook, linux-kernel
On Sun, 20 Sep 2026 01:59:24 +0800, Guangshuo Li wrote:
> register_dca_provider() calls dca_sysfs_add_provider() before looking up
> or allocating the DCA domain. A successful dca_sysfs_add_provider()
> allocates an IDR entry and creates the dca%d class device.
>
> If no domain exists and dca_allocate_domain() fails, the function
> returns -ENODEV without calling dca_sysfs_remove_provider(). The class
> device therefore remains registered and the IDR entry remains
> allocated. The caller may subsequently free the dca_provider, leaving
> the IDR entry pointing to freed memory.
>
> Since the class device is never unregistered, its device reference is
> not dropped and device_create_release() is never reached, leaking the
> struct device allocation.
>
> Call dca_sysfs_remove_provider() before returning when domain allocation
> fails. This unregisters the class device and removes the corresponding
> IDR entry.
>
> The issue was identified by a static analysis tool I developed and
> confirmed by manual review.
>
> Fixes: 1a5aeeecd550 ("dca: registering requesters in multiple dca domains")
> Cc: stable@vger.kernel.org
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
> drivers/dca/dca-core.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.
More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.
This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down. Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.
Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem, how to document usage of LLM and how what you should not
do if this was posted in a good faith.
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] dca: fix provider device memory leak on domain allocation failure
2026-09-21 15:12 ` krzk
@ 2026-09-22 2:48 ` Guangshuo Li
0 siblings, 0 replies; 4+ messages in thread
From: Guangshuo Li @ 2026-09-22 2:48 UTC (permalink / raw)
To: krzk; +Cc: stable, Maciej Sosnowski, Dan Williams, Kees Cook, linux-kernel
Hi Krzysztof,
Thank you for your feedback.
On Mon, 21 Sept 2026 at 23:13, <krzk@kernel.org> wrote:
>
>
> On Sun, 20 Sep 2026 01:59:24 +0800, Guangshuo Li wrote:
> > register_dca_provider() calls dca_sysfs_add_provider() before looking up
> > or allocating the DCA domain. A successful dca_sysfs_add_provider()
> > allocates an IDR entry and creates the dca%d class device.
> >
> > If no domain exists and dca_allocate_domain() fails, the function
> > returns -ENODEV without calling dca_sysfs_remove_provider(). The class
> > device therefore remains registered and the IDR entry remains
> > allocated. The caller may subsequently free the dca_provider, leaving
> > the IDR entry pointing to freed memory.
> >
> > Since the class device is never unregistered, its device reference is
> > not dropped and device_create_release() is never reached, leaking the
> > struct device allocation.
> >
> > Call dca_sysfs_remove_provider() before returning when domain allocation
> > fails. This unregisters the class device and removes the corresponding
> > IDR entry.
> >
> > The issue was identified by a static analysis tool I developed and
> > confirmed by manual review.
> >
> > Fixes: 1a5aeeecd550 ("dca: registering requesters in multiple dca domains")
> > Cc: stable@vger.kernel.org
> > Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> > ---
> > drivers/dca/dca-core.c | 5 ++++-
> > 1 file changed, 4 insertions(+), 1 deletion(-)
> >
>
>
> You sent multiple independent patches, to multiple independent
> subsystems. The amount of these patches clearly suggest this was
> AI generated and most likely not tested.
>
> More importantly, you sent all this work without properly organizing
> relevant patches into patchsets. This makes reviewing difficult
> and might cause multiple reviewers to address the same issue.
> Replying to the entire set is impossible and requires handling each
> patch independently, instead of applying or discarding the set.
> Maintainers also won't see the bigger picture of your work. Quite
> worrying.
>
> This is on the verge of hostile patch: bomb us with so many
> contributions, we won't be able to handle them in efficient manner,
> like responding ONCE to ask you to slow down. Considering all this
> is untested and LLM generated, I have even more doubts whether this
> should be considered for review.
>
> Please read kernel documentation BEFORE posting more work. It will
> explain you how to identify subsystems, how to organize your work per
> subsystem, how to document usage of LLM and how what you should not
> do if this was posted in a good faith.
>
> Best regards,
> Krzysztof
>
>
>
I would like to clarify that these patches were manually reviewed and
audited by us; they were not simply generated and submitted by an LLM.
However, I understand why the recent submission pattern may have given
that impression. We sent too many patches in a short period of time,
and we also failed to respond to some discussions in a timely manner,
which made the situation look worse.
Many of the recent patches, especially the v2 revisions, are
corrections and improvements based on previous review feedback rather
than completely new untested changes. That said, we recognize that the
way we submitted them increased the burden on maintainers and
reviewers.
We apologize for the pressure this caused to the community. We will be
more careful about organizing patches by subsystem, preparing proper
patchsets, and following the kernel contribution guidelines before
sending future work.
Thank you again for pointing this out.
Best regards,
Guangshuo
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-22 2:48 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-19 17:59 [PATCH] dca: fix provider device memory leak on domain allocation failure Guangshuo Li
2026-09-21 11:30 ` Markus Elfring
2026-09-21 15:12 ` krzk
2026-09-22 2:48 ` Guangshuo Li
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®