mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH RESEND] [SCSI] raid class: Fix error handling in raid_component_add
@ 2024-12-24  7:43 Ma Ke
  2025-01-10 21:44 ` Martin K. Petersen
  0 siblings, 1 reply; 2+ messages in thread
From: Ma Ke @ 2024-12-24  7:43 UTC (permalink / raw)
  To: jejb, martin.petersen, jeff, James.Bottomley
  Cc: linux-scsi, linux-kernel, Ma Ke, stable

The reference count of the device incremented in device_initialize() is
not decremented when device_add() fails. Add a put_device() call before
returning from the function to decrement reference count for cleanup.
Or it could cause memory leak.

As comment of device_add() says, if device_add() succeeds, you should
call device_del() when you want to get rid of it. If device_add() has
not succeeded, use only put_device() to drop the reference count.

Found by code review.

Cc: stable@vger.kernel.org
Fixes: ed542bed126c ("[SCSI] raid class: handle component-add errors")
Signed-off-by: Ma Ke <make_ruc2021@163.com>
---
 drivers/scsi/raid_class.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/scsi/raid_class.c b/drivers/scsi/raid_class.c
index 898a0bdf8df6..2cb2949a78c6 100644
--- a/drivers/scsi/raid_class.c
+++ b/drivers/scsi/raid_class.c
@@ -251,6 +251,7 @@ int raid_component_add(struct raid_template *r,struct device *raid_dev,
 	list_del(&rc->node);
 	rd->component_count--;
 	put_device(component_dev);
+	put_device(&rc->dev);
 	kfree(rc);
 	return err;
 }
-- 
2.25.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH RESEND] [SCSI] raid class: Fix error handling in raid_component_add
  2024-12-24  7:43 [PATCH RESEND] [SCSI] raid class: Fix error handling in raid_component_add Ma Ke
@ 2025-01-10 21:44 ` Martin K. Petersen
  0 siblings, 0 replies; 2+ messages in thread
From: Martin K. Petersen @ 2025-01-10 21:44 UTC (permalink / raw)
  To: Ma Ke
  Cc: jejb, martin.petersen, jeff, James.Bottomley, linux-scsi,
	linux-kernel, stable


> The reference count of the device incremented in device_initialize()
> is not decremented when device_add() fails. Add a put_device() call
> before returning from the function to decrement reference count for
> cleanup. Or it could cause memory leak.

60c5fd2e8f3c ("scsi: core: raid_class: Remove raid_component_add()")

-- 
Martin K. Petersen	Oracle Linux Engineering

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2025-01-10 21:44 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-12-24  7:43 [PATCH RESEND] [SCSI] raid class: Fix error handling in raid_component_add Ma Ke
2025-01-10 21:44 ` Martin K. Petersen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®