Reviewed-by: Mike Leach mike.leach@arm.com
On 9/28/26 13:35, Yingchao Deng wrote:
If cscfg_configfs_init() fails, cscfg_init() takes the exit_err path:
cscfg_init() -> cscfg_clear_device() -> cscfg_configfs_release() -> configfs_unregister_subsystem()
which tears down a configfs subsystem that was never registered. configfs_unregister_subsystem() begins with:
struct dentry *dentry = dget(group->cg_item.ci_dentry); struct dentry *root = dentry->d_sb->s_root;
ci_dentry is assigned in configfs_create_dir() only once the subsystem directory has been created, which never happened here. cscfg_mgr comes from kzalloc_obj(), so ci_dentry is still NULL, and dget() hands a NULL dentry back unchanged - the next line dereferences it.
Handle the failure in cscfg_init() directly: unregister the device and return the error, releasing the devres-allocated config item type and cscfg_mgr without touching the subsystem.
Fixes: a13d5a246aca ("coresight: syscfg: Add initial configfs support") Suggested-by: Leo Yan leo.yan@arm.com Link: https://lore.kernel.org/all/20260924162404.GN200420@e132581.arm.com/ Signed-off-by: Yingchao Deng dengyingchao@kylinsec.com.cn
drivers/hwtracing/coresight/coresight-syscfg.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/hwtracing/coresight/coresight-syscfg.c b/drivers/hwtracing/coresight/coresight-syscfg.c index 2bfdd7b45e49..00b29d1656c0 100644 --- a/drivers/hwtracing/coresight/coresight-syscfg.c +++ b/drivers/hwtracing/coresight/coresight-syscfg.c @@ -1299,8 +1299,10 @@ int __init cscfg_init(void) /* initialise configfs subsystem */ err = cscfg_configfs_init(cscfg_mgr);
- if (err)
goto exit_err;
- if (err) {
device_unregister(cscfg_device());return err;- }
/* preload built-in configurations */ err = cscfg_preload(THIS_MODULE);