| From 9cc69de41ca86caa0de04e3f22df43174c2e511a Mon Sep 17 00:00:00 2001 |
| From: Qiushi Wu <wu000273@umn.edu> |
| Date: Sat, 13 Jun 2020 14:05:33 -0500 |
| Subject: [PATCH] firmware: Fix a reference count leak. |
| |
| commit fe3c60684377d5ad9b0569b87ed3e26e12c8173b upstream. |
| |
| kobject_init_and_add() takes reference even when it fails. |
| If this function returns an error, kobject_put() must be called to |
| properly clean up the memory associated with the object. |
| Callback function fw_cfg_sysfs_release_entry() in kobject_put() |
| can handle the pointer "entry" properly. |
| |
| Signed-off-by: Qiushi Wu <wu000273@umn.edu> |
| Link: https://lore.kernel.org/r/20200613190533.15712-1-wu000273@umn.edu |
| Signed-off-by: Michael S. Tsirkin <mst@redhat.com> |
| Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com> |
| |
| diff --git a/drivers/firmware/qemu_fw_cfg.c b/drivers/firmware/qemu_fw_cfg.c |
| index 039e0f91dba8..6945c3c96637 100644 |
| --- a/drivers/firmware/qemu_fw_cfg.c |
| +++ b/drivers/firmware/qemu_fw_cfg.c |
| @@ -605,8 +605,10 @@ static int fw_cfg_register_file(const struct fw_cfg_file *f) |
| /* register entry under "/sys/firmware/qemu_fw_cfg/by_key/" */ |
| err = kobject_init_and_add(&entry->kobj, &fw_cfg_sysfs_entry_ktype, |
| fw_cfg_sel_ko, "%d", entry->select); |
| - if (err) |
| - goto err_register; |
| + if (err) { |
| + kobject_put(&entry->kobj); |
| + return err; |
| + } |
| |
| /* add raw binary content access */ |
| err = sysfs_create_bin_file(&entry->kobj, &fw_cfg_sysfs_attr_raw); |
| @@ -622,7 +624,6 @@ static int fw_cfg_register_file(const struct fw_cfg_file *f) |
| |
| err_add_raw: |
| kobject_del(&entry->kobj); |
| -err_register: |
| kfree(entry); |
| return err; |
| } |
| -- |
| 2.27.0 |
| |