diff mbox series

net: farsync: Fix kmemleak when rmmods farsync

Message ID 20221208120540.3758720-1-lizetao1@huawei.com (mailing list archive)
State Accepted
Commit 2f623aaf9f31de968dea6169849706a2f9be444c
Delegated to: Netdev Maintainers
Headers show
Series net: farsync: Fix kmemleak when rmmods farsync | expand

Checks

Context Check Description
netdev/tree_selection success Guessed tree name to be net-next
netdev/fixes_present success Fixes tag not required for -next series
netdev/subject_prefix warning Target tree name not specified in the subject
netdev/cover_letter success Single patches do not need cover letters
netdev/patch_count success Link
netdev/header_inline success No static functions without inline keyword in header files
netdev/build_32bit success Errors and warnings before: 0 this patch: 0
netdev/cc_maintainers success CCed 6 of 6 maintainers
netdev/build_clang success Errors and warnings before: 0 this patch: 0
netdev/module_param success Was 0 now: 0
netdev/verify_signedoff success Signed-off-by tag matches author and committer
netdev/check_selftest success No net selftest shell script
netdev/verify_fixes success Fixes tag looks correct
netdev/build_allmodconfig_warn success Errors and warnings before: 0 this patch: 0
netdev/checkpatch success total: 0 errors, 0 warnings, 0 checks, 14 lines checked
netdev/kdoc success Errors and warnings before: 0 this patch: 0
netdev/source_inline success Was 0 now: 0

Commit Message

lizetao Dec. 8, 2022, 12:05 p.m. UTC
There are two memory leaks reported by kmemleak:

  unreferenced object 0xffff888114b20200 (size 128):
    comm "modprobe", pid 4846, jiffies 4295146524 (age 401.345s)
    hex dump (first 32 bytes):
      e0 62 57 09 81 88 ff ff e0 62 57 09 81 88 ff ff  .bW......bW.....
      01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    backtrace:
      [<ffffffff815bcd82>] kmalloc_trace+0x22/0x60
      [<ffffffff83d35c78>] __hw_addr_add_ex+0x198/0x6c0
      [<ffffffff83d3989d>] dev_addr_init+0x13d/0x230
      [<ffffffff83d1063d>] alloc_netdev_mqs+0x10d/0xe50
      [<ffffffff82b4a06e>] alloc_hdlcdev+0x2e/0x80
      [<ffffffffa016a741>] fst_add_one+0x601/0x10e0 [farsync]
      ...

  unreferenced object 0xffff88810b85b000 (size 1024):
    comm "modprobe", pid 4846, jiffies 4295146523 (age 401.346s)
    hex dump (first 32 bytes):
      00 00 b0 02 00 c9 ff ff 00 70 0a 00 00 c9 ff ff  .........p......
      00 00 00 f2 00 00 00 f3 0a 00 00 00 02 00 00 00  ................
    backtrace:
      [<ffffffff815bcd82>] kmalloc_trace+0x22/0x60
      [<ffffffffa016a294>] fst_add_one+0x154/0x10e0 [farsync]
      [<ffffffff82060e83>] local_pci_probe+0xd3/0x170
      ...

The root cause is traced to the netdev and fst_card_info are not freed
when removes one fst in fst_remove_one(), which may trigger oom if
repeated insmod and rmmod module.

Fix it by adding free_netdev() and kfree() in fst_remove_one(), just as
the operations on the error handling path in fst_add_one().

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Li Zetao <lizetao1@huawei.com>
---
 drivers/net/wan/farsync.c | 2 ++
 1 file changed, 2 insertions(+)

Comments

Jiri Pirko Dec. 8, 2022, 12:44 p.m. UTC | #1
Thu, Dec 08, 2022 at 01:05:40PM CET, lizetao1@huawei.com wrote:
>There are two memory leaks reported by kmemleak:
>
>  unreferenced object 0xffff888114b20200 (size 128):
>    comm "modprobe", pid 4846, jiffies 4295146524 (age 401.345s)
>    hex dump (first 32 bytes):
>      e0 62 57 09 81 88 ff ff e0 62 57 09 81 88 ff ff  .bW......bW.....
>      01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
>    backtrace:
>      [<ffffffff815bcd82>] kmalloc_trace+0x22/0x60
>      [<ffffffff83d35c78>] __hw_addr_add_ex+0x198/0x6c0
>      [<ffffffff83d3989d>] dev_addr_init+0x13d/0x230
>      [<ffffffff83d1063d>] alloc_netdev_mqs+0x10d/0xe50
>      [<ffffffff82b4a06e>] alloc_hdlcdev+0x2e/0x80
>      [<ffffffffa016a741>] fst_add_one+0x601/0x10e0 [farsync]
>      ...
>
>  unreferenced object 0xffff88810b85b000 (size 1024):
>    comm "modprobe", pid 4846, jiffies 4295146523 (age 401.346s)
>    hex dump (first 32 bytes):
>      00 00 b0 02 00 c9 ff ff 00 70 0a 00 00 c9 ff ff  .........p......
>      00 00 00 f2 00 00 00 f3 0a 00 00 00 02 00 00 00  ................
>    backtrace:
>      [<ffffffff815bcd82>] kmalloc_trace+0x22/0x60
>      [<ffffffffa016a294>] fst_add_one+0x154/0x10e0 [farsync]
>      [<ffffffff82060e83>] local_pci_probe+0xd3/0x170
>      ...
>
>The root cause is traced to the netdev and fst_card_info are not freed
>when removes one fst in fst_remove_one(), which may trigger oom if
>repeated insmod and rmmod module.
>
>Fix it by adding free_netdev() and kfree() in fst_remove_one(), just as
>the operations on the error handling path in fst_add_one().
>
>Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
>Signed-off-by: Li Zetao <lizetao1@huawei.com>

Reviewed-by: Jiri Pirko <jiri@nvidia.com>

On top, may be worth ordering the cleanup in fst_remove_one() to be
aligned with the order in fst_add_one() error path.
patchwork-bot+netdevbpf@kernel.org Dec. 12, 2022, 9:50 a.m. UTC | #2
Hello:

This patch was applied to netdev/net.git (master)
by David S. Miller <davem@davemloft.net>:

On Thu, 8 Dec 2022 20:05:40 +0800 you wrote:
> There are two memory leaks reported by kmemleak:
> 
>   unreferenced object 0xffff888114b20200 (size 128):
>     comm "modprobe", pid 4846, jiffies 4295146524 (age 401.345s)
>     hex dump (first 32 bytes):
>       e0 62 57 09 81 88 ff ff e0 62 57 09 81 88 ff ff  .bW......bW.....
>       01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
>     backtrace:
>       [<ffffffff815bcd82>] kmalloc_trace+0x22/0x60
>       [<ffffffff83d35c78>] __hw_addr_add_ex+0x198/0x6c0
>       [<ffffffff83d3989d>] dev_addr_init+0x13d/0x230
>       [<ffffffff83d1063d>] alloc_netdev_mqs+0x10d/0xe50
>       [<ffffffff82b4a06e>] alloc_hdlcdev+0x2e/0x80
>       [<ffffffffa016a741>] fst_add_one+0x601/0x10e0 [farsync]
>       ...
> 
> [...]

Here is the summary with links:
  - net: farsync: Fix kmemleak when rmmods farsync
    https://git.kernel.org/netdev/net/c/2f623aaf9f31

You are awesome, thank you!
diff mbox series

Patch

diff --git a/drivers/net/wan/farsync.c b/drivers/net/wan/farsync.c
index 6a212c085435..5b01642ca44e 100644
--- a/drivers/net/wan/farsync.c
+++ b/drivers/net/wan/farsync.c
@@ -2545,6 +2545,7 @@  fst_remove_one(struct pci_dev *pdev)
 		struct net_device *dev = port_to_dev(&card->ports[i]);
 
 		unregister_hdlc_device(dev);
+		free_netdev(dev);
 	}
 
 	fst_disable_intr(card);
@@ -2564,6 +2565,7 @@  fst_remove_one(struct pci_dev *pdev)
 				  card->tx_dma_handle_card);
 	}
 	fst_card_array[card->card_no] = NULL;
+	kfree(card);
 }
 
 static struct pci_driver fst_driver = {