mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 20:54:03 +02:00
RISC-V: perf: fix resource cleanup on driver probe failure
Sashiko pointed out various UAF and memory leak issues around pmu_sbi_device_probe() error paths. If the probe fails, here are list of cleanups needed. a. Already registered pmu must be freed b. per cpu IRQ must be released c. pmu_ctr_list data structure must be freed d. cpu hotplug state must be cleaned up only if added. Fix the resource cleanup by reorganizing the code around probe failure. Reported-by: Sashiko AI <sashiko-bot@kernel.org> Reviewed-by: Charlie Jenkins <thecharlesjenkins@gmail.com> Signed-off-by: Atish Patra <atishp@meta.com> Link: https://patch.msgid.link/20260807-counter_delegation-v9-1-58658104e487@meta.com Signed-off-by: Paul Walmsley <pjw@kernel.org>
This commit is contained in:
parent
7e14e42edf
commit
e24a1418e9
|
|
@ -1219,22 +1219,29 @@ static int pmu_sbi_setup_irqs(struct riscv_pmu *pmu, struct platform_device *pde
|
|||
DOMAIN_BUS_ANY);
|
||||
if (!domain) {
|
||||
pr_err("Failed to find INTC IRQ root domain\n");
|
||||
return -ENODEV;
|
||||
ret = -ENODEV;
|
||||
goto err;
|
||||
}
|
||||
|
||||
riscv_pmu_irq = irq_create_mapping(domain, riscv_pmu_irq_num);
|
||||
if (!riscv_pmu_irq) {
|
||||
pr_err("Failed to map PMU interrupt for node\n");
|
||||
return -ENODEV;
|
||||
ret = -ENODEV;
|
||||
goto err;
|
||||
}
|
||||
|
||||
ret = request_percpu_irq(riscv_pmu_irq, pmu_sbi_ovf_handler, "riscv-pmu", hw_events);
|
||||
if (ret) {
|
||||
pr_err("registering percpu irq failed [%d]\n", ret);
|
||||
return ret;
|
||||
irq_dispose_mapping(riscv_pmu_irq);
|
||||
riscv_pmu_irq = 0;
|
||||
goto err;
|
||||
}
|
||||
|
||||
return 0;
|
||||
err:
|
||||
riscv_pmu_use_irq = false;
|
||||
return ret;
|
||||
}
|
||||
|
||||
#ifdef CONFIG_CPU_PM
|
||||
|
|
@ -1301,7 +1308,8 @@ static void riscv_pmu_destroy(struct riscv_pmu *pmu)
|
|||
}
|
||||
}
|
||||
riscv_pm_pmu_unregister(pmu);
|
||||
cpuhp_state_remove_instance(CPUHP_AP_PERF_RISCV_STARTING, &pmu->node);
|
||||
if (!hlist_unhashed(&pmu->node))
|
||||
cpuhp_state_remove_instance(CPUHP_AP_PERF_RISCV_STARTING, &pmu->node);
|
||||
}
|
||||
|
||||
static void pmu_sbi_event_init(struct perf_event *event)
|
||||
|
|
@ -1423,6 +1431,7 @@ static int pmu_sbi_device_probe(struct platform_device *pdev)
|
|||
struct riscv_pmu *pmu = NULL;
|
||||
int ret = -ENODEV;
|
||||
int num_counters;
|
||||
bool irq_requested = false;
|
||||
|
||||
pr_info("SBI PMU extension is available\n");
|
||||
pmu = riscv_pmu_alloc();
|
||||
|
|
@ -1451,6 +1460,7 @@ static int pmu_sbi_device_probe(struct platform_device *pdev)
|
|||
pmu->pmu.capabilities |= PERF_PMU_CAP_NO_INTERRUPT;
|
||||
pmu->pmu.capabilities |= PERF_PMU_CAP_NO_EXCLUDE;
|
||||
}
|
||||
irq_requested = (ret == 0);
|
||||
|
||||
pmu->pmu.attr_groups = riscv_pmu_attr_groups;
|
||||
pmu->pmu.parent = &pdev->dev;
|
||||
|
|
@ -1469,11 +1479,11 @@ static int pmu_sbi_device_probe(struct platform_device *pdev)
|
|||
|
||||
ret = riscv_pm_pmu_register(pmu);
|
||||
if (ret)
|
||||
goto out_unregister;
|
||||
goto out_destroy;
|
||||
|
||||
ret = perf_pmu_register(&pmu->pmu, "cpu", PERF_TYPE_RAW);
|
||||
if (ret)
|
||||
goto out_unregister;
|
||||
goto out_destroy;
|
||||
|
||||
/* SBI PMU Snapsphot is only available in SBI v2.0 */
|
||||
if (sbi_v2_available) {
|
||||
|
|
@ -1514,9 +1524,20 @@ static int pmu_sbi_device_probe(struct platform_device *pdev)
|
|||
return 0;
|
||||
|
||||
out_unregister:
|
||||
perf_pmu_unregister(&pmu->pmu);
|
||||
|
||||
out_destroy:
|
||||
riscv_pmu_destroy(pmu);
|
||||
if (irq_requested) {
|
||||
free_percpu_irq(riscv_pmu_irq, pmu->hw_events);
|
||||
irq_dispose_mapping(riscv_pmu_irq);
|
||||
riscv_pmu_irq = 0;
|
||||
}
|
||||
|
||||
out_free:
|
||||
free_percpu(pmu->hw_events);
|
||||
kfree(pmu_ctr_list);
|
||||
pmu_ctr_list = NULL;
|
||||
kfree(pmu);
|
||||
return ret;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user