Received: by 2002:a05:6a10:2726:0:0:0:0 with SMTP id ib38csp1213379pxb; Tue, 29 Mar 2022 20:46:11 -0700 (PDT) X-Google-Smtp-Source: ABdhPJw9mKVpoGrYL9pHdNmLNmadApA1g9X4Gu0byWI8P6vQCCDA4X+yxzuRivdGy77yJ7XaefCm X-Received: by 2002:a05:6402:350d:b0:419:547f:134a with SMTP id b13-20020a056402350d00b00419547f134amr8477203edd.405.1648611971053; Tue, 29 Mar 2022 20:46:11 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1648611971; cv=none; d=google.com; s=arc-20160816; b=TeMODWs48J3GywkCtlIPsyjUUxCogXOYkCeqOuYySH7tlTzKYYeh/09CKmb1DFE7an 82R88E6TQzql3+aUIW/4osVQAj0i/piDJ8VoyTLc8hSjgD5aAw1Om+tx3p6G1p02AxN4 A/3Qu2Qcxzn20M+hb3xXeA33N4pQ6A+K9bmhgJnfm3vtXDilodThRy24BBjQyBnYyLoO 2i4H0/RRCv3/sfUIW+5JdyUjqdNAwCZj2l5exkF9GWEny7CGfBMJNXsqpvZs1XW/0Z38 iiFXl4/u4R/TiGKETW464iI1otLnEDBOi1sxCh/5eOwx9Ow8e4iLPT7AFP0RpfNE7aDW P05w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=GtysjXm9RkwZpLhMftUmhj8qUdHYgmqOkGeujUmUcCQ=; b=rdQgyx+5QZZ7gTqUKB7SlWxyJsXjQgDJJ1Yfcv+wCKH3uf+pls3H1lcNTuct+uoUYZ X5N71N9q8kjqmbVNw/AMLLTekHIXMeoJww/ED/UZa3nqe3IK5+g7ezAEdfZswA8OtLBp whBH7t/fw9++VE10oLMXUTcYlZx3gTeWX0FQLtw48ouFOfPsxsJ1OvjTsADRFD+MNZRG CxTwgFe7Z1z5Vfk8tmfeuwUgbYIz7BrhYV6N690Abm/nXJS1zarsZtb54fEiHLdhoPpO oOtmjEo+tEw5S+m5kKzFQd+RXln/I0VBbOsUeDY2Ozodw0epMIA79B6ulWG1NOTNOuck Ro1A== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=c65yvGVA; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id c23-20020aa7df17000000b00419d1d0307asi12587748edy.19.2022.03.29.20.45.44; Tue, 29 Mar 2022 20:46:11 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=c65yvGVA; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S238997AbiC2Pvm (ORCPT + 99 others); Tue, 29 Mar 2022 11:51:42 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:58520 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S238537AbiC2Pvk (ORCPT ); Tue, 29 Mar 2022 11:51:40 -0400 Received: from mail-ed1-x535.google.com (mail-ed1-x535.google.com [IPv6:2a00:1450:4864:20::535]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 2877C85640; Tue, 29 Mar 2022 08:49:57 -0700 (PDT) Received: by mail-ed1-x535.google.com with SMTP id h4so13425128edr.3; Tue, 29 Mar 2022 08:49:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=GtysjXm9RkwZpLhMftUmhj8qUdHYgmqOkGeujUmUcCQ=; b=c65yvGVAqe02PNddxlppLIXo90yHqcUOThMOCPShodfhCEdKPp1ASyA2zFPQxCo7Gc xYS3PpmdKEVSGGkEV0acnesxhwOGPHKwA9K9fS7IB/VuIY3IkCpBdfto04SIb4MACjjL Ej/5fBSTtXvZW3VMRzJKTWuTGoqNSYygQ82htTlC515s6r/Gf5OWaWHikCp1TKfBsgq8 wsRsqioLiE70+Zhw5yu8qyCSyxn3uKPNC3/pnM6ReVzggOoLI7sm9WxzmV9m+vCA/0eQ P+ItTJNpKnn0OBTOKdn+v9BLA0Noogv75YOZoGWNSzEf71WYpgRgTgkwLFqxZgvgpC94 u51A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=GtysjXm9RkwZpLhMftUmhj8qUdHYgmqOkGeujUmUcCQ=; b=eQjjmzl6u35wsDZFyqBXWuIcjFgBujs8vJQxtfARUF+ooYyCUFd4a5aMipq9m74yZl Cdsi7kKeMica1m6olKyJ23pXSyjwHf2BEHtiEfHT4uzli+6SW4ewiWBJQ2qTJnn1kOy2 yZ/ssXDToIFmFcQP7LlLwSO1LSfyxdyz/UWZEH0QeWfjXfoOpxhIMd1OXLdi2hUT2SAW xqCTZ9vfoOtOU6+Ymh0HxOOAayBvYS0asJjna3d6qunRWbArQMLh+oszR6WF96Bilet4 LYBtcBSwFmN+v0/hmAUrtMlmn1ckVyRUbNDVMn96+PVFkfzA4FxAOanO8JWLWPKHT0Nd RaEg== X-Gm-Message-State: AOAM531yYIqQqa04vnJYMsP05TVzyDy7uVC5/i2CogMTnSqyVRPvUJOV 0ReYFFyMh84Ai3QO0hWh5LKwETF5EA0= X-Received: by 2002:a50:bf0f:0:b0:410:c512:cb6f with SMTP id f15-20020a50bf0f000000b00410c512cb6fmr5415364edk.262.1648568992434; Tue, 29 Mar 2022 08:49:52 -0700 (PDT) Received: from localhost.localdomain (host-95-249-145-232.retail.telecomitalia.it. [95.249.145.232]) by smtp.gmail.com with ESMTPSA id s20-20020a056402015400b00418f9574a36sm8696843edu.73.2022.03.29.08.49.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 29 Mar 2022 08:49:51 -0700 (PDT) From: "Fabio M. De Francesco" To: axboe@kernel.dk, linux-block@vger.kernel.org, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com, "James E.J. Bottomley" , "Martin K. Petersen" , linux-scsi@vger.kernel.org, Dan Carpenter Cc: "Fabio M. De Francesco" , syzbot+f08c77040fa163a75a46@syzkaller.appspotmail.com Subject: [PATCH] scsi: sd: call device_del() if device_add_disk() fails Date: Tue, 29 Mar 2022 17:49:48 +0200 Message-Id: <20220329154948.10350-1-fmdefrancesco@gmail.com> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM, RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org In sd_probe(), if device_add_disk() fails it simply calls put_device() and jumps to the "out" label but the device is never deleted from system. This leads to a memory leak as reported by Syzbot.[1] Fix this bug by calling device_del() soon before put_device() when device_add_disk() fails. [1] [syzbot] memory leak in blk_mq_init_tags https://lore.kernel.org/lkml/000000000000c341cc05db38c1b0@google.com/ Reported-by: syzbot+f08c77040fa163a75a46@syzkaller.appspotmail.com Suggested-by: Dan Carpenter Fixes: 2a7a891f4c40 ("scsi: sd: Add error handling support for add_disk()") Signed-off-by: Fabio M. De Francesco --- This patch replace the previous attempt to fix the bug reported by Syzbot. Therefore, the previous wrong patch at https://lore.kernel.org/lkml/20220328084452.11479-1-fmdefrancesco@gmail.com/ must be discarded. Many thanks to Dan Carpenter. drivers/scsi/sd.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c index a390679cf458..13d96d0f9dde 100644 --- a/drivers/scsi/sd.c +++ b/drivers/scsi/sd.c @@ -3474,6 +3474,7 @@ static int sd_probe(struct device *dev) error = device_add_disk(dev, gd, NULL); if (error) { + device_del(&sdkp->disk_dev); put_device(&sdkp->disk_dev); goto out; } -- 2.34.1