[PATCH net] net/smc: remove device from smcd_dev_list after failed device_add()

Subsystems: networking [general], shared memory communications (smc) sockets, the rest

STALE1905d

2 messages, 2 authors, 2021-05-17 · open the first message on its own page

[PATCH net] net/smc: remove device from smcd_dev_list after failed device_add()

From: Karsten Graul <hidden>
Date: 2021-05-17 08:47:26

From: Julian Wiedmann <redacted>

If the device_add() for a smcd_dev fails, there's no cleanup step that
rolls back the earlier list_add(). The device subsequently gets freed,
and we end up with a corrupted list.

Add some error handling that removes the device from the list.

Fixes: c6ba7c9ba43d ("net/smc: add base infrastructure for SMC-D and ISM")
Signed-off-by: Julian Wiedmann <redacted>
Signed-off-by: Karsten Graul <redacted>
---
 net/smc/smc_ism.c | 11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/net/smc/smc_ism.c b/net/smc/smc_ism.c
index 9c6e95882553..d24b96ea0eb5 100644
--- a/net/smc/smc_ism.c
+++ b/net/smc/smc_ism.c
@@ -428,6 +428,8 @@ EXPORT_SYMBOL_GPL(smcd_alloc_dev);
 
 int smcd_register_dev(struct smcd_dev *smcd)
 {
+	int rc;
+
 	mutex_lock(&smcd_dev_list.mutex);
 	if (list_empty(&smcd_dev_list.list)) {
 		u8 *system_eid = NULL;
@@ -447,7 +449,14 @@ int smcd_register_dev(struct smcd_dev *smcd)
 			    dev_name(&smcd->dev), smcd->pnetid,
 			    smcd->pnetid_by_user ? " (user defined)" : "");
 
-	return device_add(&smcd->dev);
+	rc = device_add(&smcd->dev);
+	if (rc) {
+		mutex_lock(&smcd_dev_list.mutex);
+		list_del(&smcd->list);
+		mutex_unlock(&smcd_dev_list.mutex);
+	}
+
+	return rc;
 }
 EXPORT_SYMBOL_GPL(smcd_register_dev);
 
-- 
2.25.1

Re: [PATCH net] net/smc: remove device from smcd_dev_list after failed device_add()

From: patchwork-bot+netdevbpf@kernel.org
Date: 2021-05-17 22:30:13

Hello:

This patch was applied to netdev/net.git (refs/heads/master):

On Mon, 17 May 2021 10:47:06 +0200 you wrote:
From: Julian Wiedmann <redacted>

If the device_add() for a smcd_dev fails, there's no cleanup step that
rolls back the earlier list_add(). The device subsequently gets freed,
and we end up with a corrupted list.

Add some error handling that removes the device from the list.

[...]
Here is the summary with links:
  - [net] net/smc: remove device from smcd_dev_list after failed device_add()
    https://git.kernel.org/netdev/net/c/444d7be9532d

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help