From: Julia Lawall <hidden> Date: 2011-08-08 11:19:26
From: Julia Lawall <redacted>
At this point, ehv_pic has been allocated but not stored anywhere, so it
should be freed before leaving the function.
A simplified version of the semantic match that finds this problem is as
follows: (http://coccinelle.lip6.fr/)
// <smpl>
@exists@
local idexpression x;
statement S,S1;
expression E;
identifier fl;
expression *ptr != NULL;
@@
x = \(kmalloc\|kzalloc\|kcalloc\)(...);
...
if (x == NULL) S
<... when != x
when != if (...) { <+...kfree(x)...+> }
when any
when != true x == NULL
x->fl
...>
(
if (x == NULL) S1
|
if (...) { ... when != x
when forall
(
return \(0\|<+...x...+>\|ptr\);
|
* return ...;
)
}
)
// </smpl>
Signed-off-by: Julia Lawall <redacted>
---
arch/powerpc/sysdev/ehv_pic.c | 1 +
1 file changed, 1 insertion(+)
Although the fix is correct, I think there is another bug in this
function. 'np' is not released when the function finishes
successfully. I've looked at other functions that use
irq_alloc_host(), and most of them do the same thing: they don't call
of_node_put() on the device node pointer. The only exception I've
found is mpc5121_ads_cpld_pic_init().
Ben, Kumar: am I missing something? irq_alloc_host() calls of_node_get():
host->of_node =3D of_node_get(of_node);
so doesn't that mean that the caller of irq_alloc_host() should
release the device node pointer?
--=20
Timur Tabi
Linux kernel developer at Freescale=
From: Timur Tabi <hidden> Date: 2011-08-23 18:38:22
Julia Lawall wrote:
At this point, ehv_pic has been allocated but not stored anywhere, so it
should be freed before leaving the function.
Acked-by: Timur Tabi <redacted>
FYI, Ashish is no longer with Freescale, so I've taken over maintainership of
ehv_pic.
--
Timur Tabi
Linux kernel developer at Freescale
Although the fix is correct, I think there is another bug in this
function. 'np' is not released when the function finishes
successfully. I've looked at other functions that use
irq_alloc_host(), and most of them do the same thing: they don't call
of_node_put() on the device node pointer. The only exception I've
found is mpc5121_ads_cpld_pic_init().
Ben, Kumar: am I missing something? irq_alloc_host() calls of_node_get():
host->of_node = of_node_get(of_node);
so doesn't that mean that the caller of irq_alloc_host() should
release the device node pointer?
From: Kumar Gala <hidden> Date: 2011-11-24 07:19:19
On Aug 8, 2011, at 6:18 AM, Julia Lawall wrote:
From: Julia Lawall <redacted>
At this point, ehv_pic has been allocated but not stored anywhere, so it
should be freed before leaving the function.
A simplified version of the semantic match that finds this problem is as
follows: (http://coccinelle.lip6.fr/)
// <smpl>
@exists@
local idexpression x;
statement S,S1;
expression E;
identifier fl;
expression *ptr != NULL;
@@
x = \(kmalloc\|kzalloc\|kcalloc\)(...);
...
if (x == NULL) S
<... when != x
when != if (...) { <+...kfree(x)...+> }
when any
when != true x == NULL
x->fl
...>
(
if (x == NULL) S1
|
if (...) { ... when != x
when forall
(
return \(0\|<+...x...+>\|ptr\);
|
* return ...;
)
}
)
// </smpl>
Signed-off-by: Julia Lawall <redacted>
---
arch/powerpc/sysdev/ehv_pic.c | 1 +
1 file changed, 1 insertion(+)