From: Myeonghun Pak <hidden> Date: 2026-09-13 20:41:17
setup_shmem_window() acquires a PCMCIA memory window using
pcmcia_request_window(). If pcmcia_map_mem_page() or the subsequent
ioremap() fails, the function returns without releasing the requested
window.
pcnet_config() treats shared-memory setup failure as non-fatal and falls
back to setup_dma_config(). Probe can therefore continue while socket
window 3 and its reserved iomem range remain unnecessarily held for the
rest of the bound lifetime of the device. pcmcia_disable_device()
eventually releases the window during teardown.
Route error paths after a successful request through a new release label
that calls pcmcia_release_window(). Fold the existing buffer-verification
cleanup into the same path, keeping iounmap() before the window release
when a mapping exists. Leave the request failure path unchanged.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Assisted-by: OpenAI:GPT-5.6
Co-developed-by: Ijae Kim <redacted>
Signed-off-by: Ijae Kim <redacted>
Signed-off-by: Myeonghun Pak <redacted>
Reviewed-by: Simon Horman <horms@kernel.org>
---
Changes in v3:
- Drop Fixes and stable Cc as suggested by Simon Horman.
- Add Simon Horman's Reviewed-by tag.
Link: https://lore.kernel.org/netdev/20260910231400.31919-1-mhun512@gmail.com/
Changes in v2:
- Clarify that the window remains reserved only until device teardown.
- Make the DMA fallback and continued probe description conditional.
- Avoid claiming that every request failure leaves no resource held.
- Restore the surrounding indentation for the new goto statements.
Link: https://lore.kernel.org/netdev/20260731161740.44955-1-mhun512@gmail.com/
---
drivers/net/ethernet/8390/pcnet_cs.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
@@ -1434,14 +1434,14 @@ static int setup_shmem_window(struct pcmcia_device *link, int start_pg,offset-=offset%window_size;ret=pcmcia_map_mem_page(link,link->resource[3],offset);if(ret)-gotofailed;+gotorelease;/* Try scribbling on the buffer */info->base=ioremap(link->resource[3]->start,resource_size(link->resource[3]));if(unlikely(!info->base)){ret=-ENOMEM;-gotofailed;+gotorelease;}for(i=0;i<(TX_PAGES<<8);i+=2)
@@ -1452,9 +1452,8 @@ static int setup_shmem_window(struct pcmcia_device *link, int start_pg,pcnet_reset_8390(dev);if(i!=(TX_PAGES<<8)){iounmap(info->base);-pcmcia_release_window(link,link->resource[3]);info->base=NULL;-gotofailed;+gotorelease;}ei_status.mem=info->base+offset;
@@ -1475,6 +1474,8 @@ static int setup_shmem_window(struct pcmcia_device *link, int start_pg,info->flags|=USE_SHMEM;return0;+release:+pcmcia_release_window(link,link->resource[3]);failed:return1;}
From: Jacob Keller <jacob.e.keller@intel.com> Date: 2026-09-15 23:45:28
On 9/13/2026 1:41 PM, Myeonghun Pak wrote:
setup_shmem_window() acquires a PCMCIA memory window using
pcmcia_request_window(). If pcmcia_map_mem_page() or the subsequent
ioremap() fails, the function returns without releasing the requested
window.
pcnet_config() treats shared-memory setup failure as non-fatal and falls
back to setup_dma_config(). Probe can therefore continue while socket
window 3 and its reserved iomem range remain unnecessarily held for the
rest of the bound lifetime of the device. pcmcia_disable_device()
eventually releases the window during teardown.
Route error paths after a successful request through a new release label
that calls pcmcia_release_window(). Fold the existing buffer-verification
cleanup into the same path, keeping iounmap() before the window release
when a mapping exists. Leave the request failure path unchanged.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Assisted-by: OpenAI:GPT-5.6
Co-developed-by: Ijae Kim <redacted>
Signed-off-by: Ijae Kim <redacted>
Signed-off-by: Myeonghun Pak <redacted>
Reviewed-by: Simon Horman <horms@kernel.org>
---
Changes in v3:
- Drop Fixes and stable Cc as suggested by Simon Horman.
- Add Simon Horman's Reviewed-by tag.
Link: https://lore.kernel.org/netdev/20260910231400.31919-1-mhun512@gmail.com/
Changes in v2:
- Clarify that the window remains reserved only until device teardown.
- Make the DMA fallback and continued probe description conditional.
- Avoid claiming that every request failure leaves no resource held.
- Restore the surrounding indentation for the new goto statements.
Link: https://lore.kernel.org/netdev/20260731161740.44955-1-mhun512@gmail.com/
---
Seems reasonable to me. No reason to hold that memory indefinitely.
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
@@ -1434,14 +1434,14 @@ static int setup_shmem_window(struct pcmcia_device *link, int start_pg,offset-=offset%window_size;ret=pcmcia_map_mem_page(link,link->resource[3],offset);if(ret)-gotofailed;+gotorelease;/* Try scribbling on the buffer */info->base=ioremap(link->resource[3]->start,resource_size(link->resource[3]));if(unlikely(!info->base)){ret=-ENOMEM;-gotofailed;+gotorelease;}for(i=0;i<(TX_PAGES<<8);i+=2)
@@ -1452,9 +1452,8 @@ static int setup_shmem_window(struct pcmcia_device *link, int start_pg,pcnet_reset_8390(dev);if(i!=(TX_PAGES<<8)){iounmap(info->base);-pcmcia_release_window(link,link->resource[3]);info->base=NULL;-gotofailed;+gotorelease;}ei_status.mem=info->base+offset;
@@ -1475,6 +1474,8 @@ static int setup_shmem_window(struct pcmcia_device *link, int start_pg,info->flags|=USE_SHMEM;return0;+release:+pcmcia_release_window(link,link->resource[3]);failed:return1;}
Hello:
This patch was applied to netdev/net-next.git (main)
by Jakub Kicinski [off-list ref]:
On Sun, 13 Sep 2026 16:41:04 -0400 you wrote:
setup_shmem_window() acquires a PCMCIA memory window using
pcmcia_request_window(). If pcmcia_map_mem_page() or the subsequent
ioremap() fails, the function returns without releasing the requested
window.
pcnet_config() treats shared-memory setup failure as non-fatal and falls
back to setup_dma_config(). Probe can therefore continue while socket
window 3 and its reserved iomem range remain unnecessarily held for the
rest of the bound lifetime of the device. pcmcia_disable_device()
eventually releases the window during teardown.
[...]