mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] mtd: rawnand: tegra: fix OF node leak in tegra_nand_chips_init()
@ 2026-10-08 18:24 Haotian Zhang
  2026-10-08 18:34 ` sashiko-bot
  2026-10-09  6:10 ` Krzysztof Kozlowski
  0 siblings, 2 replies; 3+ messages in thread
From: Haotian Zhang @ 2026-10-08 18:24 UTC (permalink / raw)
  To: Stefan Agner, Lucas Stach, Miquel Raynal, Richard Weinberger,
	Vignesh Raghavendra, Thierry Reding, Jonathan Hunter,
	Boris Brezillon, Dmitry Osipenko
  Cc: linux-mtd, linux-tegra, linux-kernel

tegra_nand_chips_init() takes an extra reference on the child NAND node
with of_get_next_child() and passes it to nand_set_flash_node(), which
only stores the pointer in mtd->dev.of_node. None of the return paths,
including the successful one, drop that reference, so the device node is
leaked. The get/put pair performed by the MTD core in add_mtd_device()
and mtd_release() is balanced and cannot compensate for it.

Release the reference with of_node_put() right after the node has been
stored, and route the earlier error paths through an err_put_node label
so that they release it as well.

Fixes: d7d9f8ec77fe ("mtd: rawnand: add NVIDIA Tegra NAND Flash controller driver")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
---
 drivers/mtd/nand/raw/tegra_nand.c | 19 ++++++++++++++-----
 1 file changed, 14 insertions(+), 5 deletions(-)

diff --git a/drivers/mtd/nand/raw/tegra_nand.c b/drivers/mtd/nand/raw/tegra_nand.c
index 7f9eb5f042a7..752ec3768b73 100644
--- a/drivers/mtd/nand/raw/tegra_nand.c
+++ b/drivers/mtd/nand/raw/tegra_nand.c
@@ -1086,19 +1086,22 @@ static int tegra_nand_chips_init(struct device *dev,
 	nsels = of_property_count_elems_of_size(np_nand, "reg", sizeof(u32));
 	if (nsels != 1) {
 		dev_err(dev, "Missing/invalid reg property\n");
-		return -EINVAL;
+		ret = -EINVAL;
+		goto err_put_node;
 	}
 
 	/* Retrieve CS id, currently only single die NAND supported */
 	ret = of_property_read_u32(np_nand, "reg", &cs);
 	if (ret) {
 		dev_err(dev, "could not retrieve reg property: %d\n", ret);
-		return ret;
+		goto err_put_node;
 	}
 
 	nand = devm_kzalloc(dev, sizeof(*nand), GFP_KERNEL);
-	if (!nand)
-		return -ENOMEM;
+	if (!nand) {
+		ret = -ENOMEM;
+		goto err_put_node;
+	}
 
 	nand->cs[0] = cs;
 
@@ -1107,7 +1110,7 @@ static int tegra_nand_chips_init(struct device *dev,
 	if (IS_ERR(nand->wp_gpio)) {
 		ret = PTR_ERR(nand->wp_gpio);
 		dev_err(dev, "Failed to request WP GPIO: %d\n", ret);
-		return ret;
+		goto err_put_node;
 	}
 
 	chip = &nand->chip;
@@ -1119,6 +1122,7 @@ static int tegra_nand_chips_init(struct device *dev,
 	mtd->owner = THIS_MODULE;
 
 	nand_set_flash_node(chip, np_nand);
+	of_node_put(np_nand);
 
 	if (!mtd->name)
 		mtd->name = "tegra_nand";
@@ -1141,6 +1145,11 @@ static int tegra_nand_chips_init(struct device *dev,
 	ctrl->chip = chip;
 
 	return 0;
+
+err_put_node:
+	of_node_put(np_nand);
+
+	return ret;
 }
 
 static int tegra_nand_probe(struct platform_device *pdev)
-- 
2.25.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] mtd: rawnand: tegra: fix OF node leak in tegra_nand_chips_init()
  2026-10-08 18:24 [PATCH] mtd: rawnand: tegra: fix OF node leak in tegra_nand_chips_init() Haotian Zhang
@ 2026-10-08 18:34 ` sashiko-bot
  2026-10-09  6:10 ` Krzysztof Kozlowski
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-10-08 18:34 UTC (permalink / raw)
  To: Thierry Reding, Vignesh Raghavendra, Haotian Zhang,
	Richard Weinberger, Stefan Agner, Miquel Raynal, Lucas Stach,
	Jonathan Hunter, Dmitry Osipenko, Boris Brezillon
  Cc: linux-tegra, linux-mtd, linux-kernel

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] mtd: rawnand: tegra: UAF due to premature of_node_put() before registration
--

commit 1cf3654f6b317262348cbad1bbf461282840058e
Author: Haotian Zhang <vulab@iscas.ac.cn>

mtd: rawnand: tegra: fix OF node leak in tegra_nand_chips_init()

This commit attempts to fix a device node leak by releasing np_nand right
after calling nand_set_flash_node().

> diff --git a/drivers/mtd/nand/raw/tegra_nand.c b/drivers/mtd/nand/raw/tegra_nand.c
> --- a/drivers/mtd/nand/raw/tegra_nand.c
> +++ b/drivers/mtd/nand/raw/tegra_nand.c
[ ... ]
> @@ -1119,6 +1122,7 @@ static int tegra_nand_chips_init(struct device *dev,
>  	mtd->owner = THIS_MODULE;
>  
>  	nand_set_flash_node(chip, np_nand);
> +	of_node_put(np_nand);

[Severity: High]
Does this introduce a use-after-free risk for the device node?

The nand_set_flash_node() helper stores the pointer in mtd->dev.of_node
but does not increment its reference count. By dropping the reference here,
could the node be freed before subsequent accesses?

Later in this function, nand_scan() dereferences this flash node to read 
properties:

drivers/mtd/nand/raw/nand_base.c:of_get_nand_bus_width() {
    struct device_node *dn = nand_get_flash_node(chip);
    ...
    ret = of_property_read_u32(dn, "nand-bus-width", &val);
    ...
}

Furthermore, mtd_device_register() will also access the node to increment
its refcount:

drivers/mtd/mtdcore.c:add_mtd_device() {
    ...
    mtd_check_of_node(mtd);
    of_node_get(mtd_get_of_node(mtd));
    ...
}

If dynamic DT unloading drops the final reference before
mtd_device_register() completes, it appears these later calls might access
freed memory.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261008182442.2770036-1-vulab@iscas.ac.cn?part=1

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] mtd: rawnand: tegra: fix OF node leak in tegra_nand_chips_init()
  2026-10-08 18:24 [PATCH] mtd: rawnand: tegra: fix OF node leak in tegra_nand_chips_init() Haotian Zhang
  2026-10-08 18:34 ` sashiko-bot
@ 2026-10-09  6:10 ` Krzysztof Kozlowski
  1 sibling, 0 replies; 3+ messages in thread
From: Krzysztof Kozlowski @ 2026-10-09  6:10 UTC (permalink / raw)
  To: Haotian Zhang
  Cc: Vignesh Raghavendra, Richard Weinberger, linux-mtd, linux-kernel,
	Miquel Raynal, Jonathan Hunter, linux-tegra, Boris Brezillon,
	Dmitry Osipenko, Lucas Stach, Thierry Reding, Stefan Agner


On Fri, 09 Oct 2026 02:24:42 +0800, Haotian Zhang wrote:
> tegra_nand_chips_init() takes an extra reference on the child NAND node
> with of_get_next_child() and passes it to nand_set_flash_node(), which
> only stores the pointer in mtd->dev.of_node. None of the return paths,
> including the successful one, drop that reference, so the device node is
> leaked. The get/put pair performed by the MTD core in add_mtd_device()
> and mtd_release() is balanced and cannot compensate for it.
> 
> Release the reference with of_node_put() right after the node has been
> stored, and route the earlier error paths through an err_put_node label
> so that they release it as well.
> 
> Fixes: d7d9f8ec77fe ("mtd: rawnand: add NVIDIA Tegra NAND Flash controller driver")
> Assisted-by: DeepSeek-V4.1-Flash
> Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
> ---
>  drivers/mtd/nand/raw/tegra_nand.c | 19 ++++++++++++++-----
>  1 file changed, 14 insertions(+), 5 deletions(-)
> 



Multiple things here:
1. Your team ignored completely previous feedback.

2. You use multiple identities with this email, thus I actually doubt we speak
   with actual person.

3. Finally, same feedback:
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.

More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.

This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down.  Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.

Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem (so a patchset grouping multiple patches with a short cover
letter), how to document usage of LLM and how what you should not do
if this was posted in a good faith.

Best regards,
Krzysztof





^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-09  6:10 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 18:24 [PATCH] mtd: rawnand: tegra: fix OF node leak in tegra_nand_chips_init() Haotian Zhang
2026-10-08 18:34 ` sashiko-bot
2026-10-09  6:10 ` Krzysztof Kozlowski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®