Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp3479971imu; Sun, 11 Nov 2018 16:03:48 -0800 (PST) X-Google-Smtp-Source: AJdET5ePcCG9Eq4Hc1UNO5+yfSjkQRcEzUDTPMmHB77Bo6sLFyPqthQDi/eiVlR7aRJcjVUX/gZf X-Received: by 2002:a63:6f0d:: with SMTP id k13mr5231490pgc.42.1541981027978; Sun, 11 Nov 2018 16:03:47 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1541981027; cv=none; d=google.com; s=arc-20160816; b=T2FCN/6BmhxefccJGWzJe7anALhEoHmaqAjxPtlYP0lXx+xC8ildQg1uLQrvB7nDa8 ghEpXvyFgTfE5roc92WUNvpEFXyECmpusMsyzVXjupFmadvtI3HrMYqd/YyLU9rW9lS8 rmk8RHa6D+vF/fnCPamyWmW3hcPwpTMo/ohKLK+S9/2axWsxjdzzElUdtlQ+6t5JwLp3 yz+BFvM2Meklz8rs8jRcf1zI5SxfuNaBOwAWS+JZVez4Pi/o9y9BFNRYJt0CWeLIpSFo 4/whu1p9c3WTpqCAZbuWy4i6F/Hs1Adxvk4u1v+U1IRsAqbi8tGUE5/vh+CMuBRfEC4K KmEg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=7huLf75dFtKDlx1KvXxBSV5QEPMx2/UERw7hI7orSRs=; b=fXFg3e7Qavr+vWrUk2ZZ/7Qh4cjFJuTEMSmcSRt8DtpYndjiUvngkp5IYUXA4PDa4h IMSkVsrBGvo1oSNb7jBwyFIwm2lRpBiPtl15Io2XZv2V/C5EqYw0/ok+Tl7HJEQPaYwe dIsPyZ0ViybA4KNHW7yck1+c8SIVwYY5sOjHQCA9lKmi0FkhoWxTX3cN12jVddKmWoqf PnbhUTGqBW8ty14YOGV0tkL5YZcZmpn/EfmacZFBDg6Fq7nlOORidcyxtwp3rc2awkRc Pd40JMCe/2I7iUM1glWr1GihAB3LpaYaen/MHaPPEXCo5FjOq7o3TWw7wVY62tyqj24g t2gQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=ZjC3Gl6G; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id m63-v6si16205982pld.161.2018.11.11.16.03.32; Sun, 11 Nov 2018 16:03:47 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=ZjC3Gl6G; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732576AbeKLJxa (ORCPT + 99 others); Mon, 12 Nov 2018 04:53:30 -0500 Received: from mail.kernel.org ([198.145.29.99]:34412 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1732127AbeKLIRw (ORCPT ); Mon, 12 Nov 2018 03:17:52 -0500 Received: from localhost (unknown [206.108.79.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 422AE2154B; Sun, 11 Nov 2018 22:27:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1541975276; bh=N3HqR7bTz75v+OdvrPAsmKVQxyyPQn07p17lQ/4JefQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=ZjC3Gl6GKq/0qOpff1u50PgcGLwkQqlsW3k+rafhbuHvE86ThEFWpXVOVupF7+5zN XrEskQX+UtytpVICiXKqlT7GnxLn0a0DQKfSUTNDeyqzPxp7bjmj2P0TWugFxQKNzu 5k+yQX1OEDvK72W6+ZNFrqHafE+jZX/GeyuCT10c= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Alexandre Belloni , Lee Jones , Sasha Levin Subject: [PATCH 4.19 187/361] mfd: menelaus: Fix possible race condition and leak Date: Sun, 11 Nov 2018 14:18:54 -0800 Message-Id: <20181111221646.583892531@linuxfoundation.org> X-Mailer: git-send-email 2.19.1 In-Reply-To: <20181111221619.915519183@linuxfoundation.org> References: <20181111221619.915519183@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.19-stable review patch. If anyone has any objections, please let me know. ------------------ From: Alexandre Belloni [ Upstream commit 9612f8f503804d2fd2f63aa6ba1e58bba4612d96 ] The IRQ work is added before the struct rtc is allocated and registered, but this struct is used in the IRQ handler. This may lead to a NULL pointer dereference. Switch to devm_rtc_allocate_device/rtc_register_device to allocate the rtc before calling menelaus_add_irq_work. Also, this solves a possible leak as the RTC is never released. Signed-off-by: Alexandre Belloni Signed-off-by: Lee Jones Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- drivers/mfd/menelaus.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) --- a/drivers/mfd/menelaus.c +++ b/drivers/mfd/menelaus.c @@ -1094,6 +1094,7 @@ static void menelaus_rtc_alarm_work(stru static inline void menelaus_rtc_init(struct menelaus_chip *m) { int alarm = (m->client->irq > 0); + int err; /* assume 32KDETEN pin is pulled high */ if (!(menelaus_read_reg(MENELAUS_OSC_CTRL) & 0x80)) { @@ -1101,6 +1102,12 @@ static inline void menelaus_rtc_init(str return; } + m->rtc = devm_rtc_allocate_device(&m->client->dev); + if (IS_ERR(m->rtc)) + return; + + m->rtc->ops = &menelaus_rtc_ops; + /* support RTC alarm; it can issue wakeups */ if (alarm) { if (menelaus_add_irq_work(MENELAUS_RTCALM_IRQ, @@ -1125,10 +1132,8 @@ static inline void menelaus_rtc_init(str menelaus_write_reg(MENELAUS_RTC_CTRL, m->rtc_control); } - m->rtc = rtc_device_register(DRIVER_NAME, - &m->client->dev, - &menelaus_rtc_ops, THIS_MODULE); - if (IS_ERR(m->rtc)) { + err = rtc_register_device(m->rtc); + if (err) { if (alarm) { menelaus_remove_irq_work(MENELAUS_RTCALM_IRQ); device_init_wakeup(&m->client->dev, 0);