* [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file
@ 2024-07-02 10:33 Aleksandr Mishin
2024-07-02 10:50 ` Przemek Kitszel
2024-07-03 17:26 ` Ido Schimmel
0 siblings, 2 replies; 3+ messages in thread
From: Aleksandr Mishin @ 2024-07-02 10:33 UTC (permalink / raw)
To: Jiri Pirko
Cc: Aleksandr Mishin, Ido Schimmel, Petr Machata, David S. Miller,
Eric Dumazet, Jakub Kicinski, Paolo Abeni, netdev, linux-kernel,
lvc-project
In case of invalid INI file mlxsw_linecard_types_init() deallocates memory
but doesn't reset pointer to NULL and returns 0. In case of any error
occured after mlxsw_linecard_types_init() call, mlxsw_linecards_init()
calls mlxsw_linecard_types_fini() which perform memory deallocation again.
Add pointer reset to NULL.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: b217127e5e4e ("mlxsw: core_linecards: Add line card objects and implement provisioning")
Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>
---
drivers/net/ethernet/mellanox/mlxsw/core_linecards.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c b/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
index 025e0db983fe..b032d5a4b3b8 100644
--- a/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
+++ b/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
@@ -1484,6 +1484,7 @@ static int mlxsw_linecard_types_init(struct mlxsw_core *mlxsw_core,
vfree(types_info->data);
err_data_alloc:
kfree(types_info);
+ linecards->types_info = NULL;
return err;
}
--
2.30.2
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file
2024-07-02 10:33 [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file Aleksandr Mishin
@ 2024-07-02 10:50 ` Przemek Kitszel
2024-07-03 17:26 ` Ido Schimmel
1 sibling, 0 replies; 3+ messages in thread
From: Przemek Kitszel @ 2024-07-02 10:50 UTC (permalink / raw)
To: Aleksandr Mishin, Jiri Pirko
Cc: Ido Schimmel, Petr Machata, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, netdev, linux-kernel, lvc-project
On 7/2/24 12:33, Aleksandr Mishin wrote:
> In case of invalid INI file mlxsw_linecard_types_init() deallocates memory
IMO there should be some comment in the code indicating that invalid
file is not a critical error. I find it weird anyway that you ignore
invalid-file-error, but propagate ENOMEM.
> but doesn't reset pointer to NULL and returns 0. In case of any error
> occured after mlxsw_linecard_types_init() call, mlxsw_linecards_init()
typo: occurred
> calls mlxsw_linecard_types_fini() which perform memory deallocation again.
>
> Add pointer reset to NULL.
>
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
>
> Fixes: b217127e5e4e ("mlxsw: core_linecards: Add line card objects and implement provisioning")
this indeed avoids double free,
Reviewed-by: Przemek Kitszel <przemyslaw.kitszel@intel.com>
> Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>
> ---
> drivers/net/ethernet/mellanox/mlxsw/core_linecards.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c b/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
> index 025e0db983fe..b032d5a4b3b8 100644
> --- a/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
> +++ b/drivers/net/ethernet/mellanox/mlxsw/core_linecards.c
> @@ -1484,6 +1484,7 @@ static int mlxsw_linecard_types_init(struct mlxsw_core *mlxsw_core,
> vfree(types_info->data);
> err_data_alloc:
> kfree(types_info);
> + linecards->types_info = NULL;
> return err;
> }
>
BTW:
mlxsw_linecard_types_file_validate() don't need @types_info param
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file
2024-07-02 10:33 [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file Aleksandr Mishin
2024-07-02 10:50 ` Przemek Kitszel
@ 2024-07-03 17:26 ` Ido Schimmel
1 sibling, 0 replies; 3+ messages in thread
From: Ido Schimmel @ 2024-07-03 17:26 UTC (permalink / raw)
To: Aleksandr Mishin
Cc: Jiri Pirko, Petr Machata, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, netdev, linux-kernel, lvc-project
On Tue, Jul 02, 2024 at 01:33:52PM +0300, Aleksandr Mishin wrote:
> In case of invalid INI file mlxsw_linecard_types_init() deallocates memory
> but doesn't reset pointer to NULL and returns 0. In case of any error
> occured after mlxsw_linecard_types_init() call, mlxsw_linecards_init()
> calls mlxsw_linecard_types_fini() which perform memory deallocation again.
s/perform/performs/
>
> Add pointer reset to NULL.
>
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
>
> Fixes: b217127e5e4e ("mlxsw: core_linecards: Add line card objects and implement provisioning")
> Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2024-07-03 17:27 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-07-02 10:33 [PATCH net] mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file Aleksandr Mishin
2024-07-02 10:50 ` Przemek Kitszel
2024-07-03 17:26 ` Ido Schimmel
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®