mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file
@ 2024-07-02 10:33 Aleksandr Mishin
  2024-07-02 10:50 ` Przemek Kitszel
  2024-07-03 17:26 ` Ido Schimmel
  0 siblings, 2 replies; 3+ messages in thread
From: Aleksandr Mishin @ 2024-07-02 10:33 UTC (permalink / raw)
  To: Jiri Pirko
  Cc: Aleksandr Mishin, Ido Schimmel, Petr Machata, David S. Miller,
	Eric Dumazet, Jakub Kicinski, Paolo Abeni, netdev, linux-kernel,
	lvc-project

In case of invalid INI file mlxsw_linecard_types_init() deallocates memory
but doesn't reset pointer to NULL and returns 0. In case of any error
occured after mlxsw_linecard_types_init() call, mlxsw_linecards_init()
calls mlxsw_linecard_types_fini() which perform memory deallocation again.

Add pointer reset to NULL.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: b217127e5e4e ("mlxsw: core_linecards: Add line card objects and implement provisioning")
Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>
---
 drivers/net/ethernet/mellanox/mlxsw/core_linecards.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c b/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
index 025e0db983fe..b032d5a4b3b8 100644
--- a/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
+++ b/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
@@ -1484,6 +1484,7 @@ static int mlxsw_linecard_types_init(struct mlxsw_core *mlxsw_core,
 	vfree(types_info->data);
 err_data_alloc:
 	kfree(types_info);
+	linecards->types_info = NULL;
 	return err;
 }
 
-- 
2.30.2


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file
  2024-07-02 10:33 [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file Aleksandr Mishin
@ 2024-07-02 10:50 ` Przemek Kitszel
  2024-07-03 17:26 ` Ido Schimmel
  1 sibling, 0 replies; 3+ messages in thread
From: Przemek Kitszel @ 2024-07-02 10:50 UTC (permalink / raw)
  To: Aleksandr Mishin, Jiri Pirko
  Cc: Ido Schimmel, Petr Machata, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, netdev, linux-kernel, lvc-project

On 7/2/24 12:33, Aleksandr Mishin wrote:
> In case of invalid INI file mlxsw_linecard_types_init() deallocates memory

IMO there should be some comment in the code indicating that invalid
file is not a critical error. I find it weird anyway that you ignore
invalid-file-error, but propagate ENOMEM.

> but doesn't reset pointer to NULL and returns 0. In case of any error
> occured after mlxsw_linecard_types_init() call, mlxsw_linecards_init()

typo: occurred

> calls mlxsw_linecard_types_fini() which perform memory deallocation again.
> 
> Add pointer reset to NULL.
> 
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
> 
> Fixes: b217127e5e4e ("mlxsw: core_linecards: Add line card objects and implement provisioning")

this indeed avoids double free,
Reviewed-by: Przemek Kitszel <przemyslaw.kitszel@intel.com>

> Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>
> ---
>   drivers/net/ethernet/mellanox/mlxsw/core_linecards.c | 1 +
>   1 file changed, 1 insertion(+)
> 
> diff --git a/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c b/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
> index 025e0db983fe..b032d5a4b3b8 100644
> --- a/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
> +++ b/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
> @@ -1484,6 +1484,7 @@ static int mlxsw_linecard_types_init(struct mlxsw_core *mlxsw_core,
>   	vfree(types_info->data);
>   err_data_alloc:
>   	kfree(types_info);
> +	linecards->types_info = NULL;
>   	return err;
>   }
>   

BTW:
mlxsw_linecard_types_file_validate() don't need @types_info param

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file
  2024-07-02 10:33 [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file Aleksandr Mishin
  2024-07-02 10:50 ` Przemek Kitszel
@ 2024-07-03 17:26 ` Ido Schimmel
  1 sibling, 0 replies; 3+ messages in thread
From: Ido Schimmel @ 2024-07-03 17:26 UTC (permalink / raw)
  To: Aleksandr Mishin
  Cc: Jiri Pirko, Petr Machata, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, netdev, linux-kernel, lvc-project

On Tue, Jul 02, 2024 at 01:33:52PM +0300, Aleksandr Mishin wrote:
> In case of invalid INI file mlxsw_linecard_types_init() deallocates memory
> but doesn't reset pointer to NULL and returns 0. In case of any error
> occured after mlxsw_linecard_types_init() call, mlxsw_linecards_init()
> calls mlxsw_linecard_types_fini() which perform memory deallocation again.

s/perform/performs/

> 
> Add pointer reset to NULL.
> 
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
> 
> Fixes: b217127e5e4e ("mlxsw: core_linecards: Add line card objects and implement provisioning")
> Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>

Reviewed-by: Ido Schimmel <idosch@nvidia.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2024-07-03 17:27 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-07-02 10:33 [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file Aleksandr Mishin
2024-07-02 10:50 ` Przemek Kitszel
2024-07-03 17:26 ` Ido Schimmel

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®