public inbox for netdev@vger.kernel.org 
 help / color / mirror / Atom feed
From: Pavel Skripkin <paskripkin@gmail•com>
To: Dongliang Mu <mudongliangabcd@gmail•com>
Cc: "Dongliang Mu" <dzm91@hust•edu.cn>,
	"Wolfgang Grandegger" <wg@grandegger•com>,
	"Marc Kleine-Budde" <mkl@pengutronix•de>,
	"David S. Miller" <davem@davemloft•net>,
	"Jakub Kicinski" <kuba@kernel•org>,
	"Stephane Grosjean" <s.grosjean@peak-system•com>,
	"Stefan Mätje" <stefan.maetje@esd•eu>,
	"Vincent Mailhol" <mailhol.vincent@wanadoo•fr>,
	linux-can@vger•kernel.org,
	"open list:NETWORKING [GENERAL]" <netdev@vger•kernel.org>,
	linux-kernel <linux-kernel@vger•kernel.org>
Subject: Re: [PATCH] drivers: net: remove a dangling pointer in peak_usb_create_dev
Date: Fri, 21 Jan 2022 22:36:45 +0300	[thread overview]
Message-ID: <8d4b0822-4e94-d124-e191-bec3effaf97c@gmail.com> (raw)
In-Reply-To: <CAD-N9QUZ95zqboe=58gybue6ssSO-M-raijd3XnGXkXnp3wiqQ@mail.gmail.com>

Hi Dongliang,

On 1/21/22 08:58, Dongliang Mu wrote:
[...]>> BTW, as you mentioned, dev->next_siblings is used in struct
>> peak_usb_adapter::dev_free() (i.e., pcan_usb_fd_free or
>> pcan_usb_pro_free), how about the following path?
>>
>> peak_usb_probe
>> -> peak_usb_create_dev (goto adap_dev_free;)
>>    -> dev->adapter->dev_free()
>>       -> pcan_usb_fd_free or pcan_usb_pro_free (This function uses
>> next_siblings as condition elements)
>>
>> static void pcan_usb_fd_free(struct peak_usb_device *dev)
>> {
>>         /* last device: can free shared objects now */
>>         if (!dev->prev_siblings && !dev->next_siblings) {
>>                 struct pcan_usb_fd_device *pdev =
>>                         container_of(dev, struct pcan_usb_fd_device, dev);
>>
>>                 /* free commands buffer */
>>                 kfree(pdev->cmd_buffer_addr);
>>
>>                 /* free usb interface object */
>>                 kfree(pdev->usb_if);
>>         }
>> }
>>
>> If next_siblings is not NULL, will it lead to the missing free of
>> cmd_buffer_addr and usb_if?
> 
> The answer is No. Forget my silly thought.
> 

Yeah, it seems like (at least based on code), that this dangling pointer 
is not dangerous, since nothing accesses it. And next_siblings 
_guaranteed_ to be NULL, since dev->next_siblings is set NULL in 
disconnect()




With regards,
Pavel Skripkin

  reply	other threads:[~2022-01-21 19:37 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-01-20 13:05 [PATCH] drivers: net: remove a dangling pointer in peak_usb_create_dev Dongliang Mu
2022-01-20 14:27 ` Pavel Skripkin
2022-01-21  0:09   ` Dongliang Mu
2022-01-21  3:36     ` Dongliang Mu
2022-01-21  5:58       ` Dongliang Mu
2022-01-21 19:36         ` Pavel Skripkin [this message]
2022-01-22  6:45           ` Dongliang Mu
2022-01-23 13:48             ` Pavel Skripkin
2022-01-24  6:04               ` Dongliang Mu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8d4b0822-4e94-d124-e191-bec3effaf97c@gmail.com \
    --to=paskripkin@gmail$(echo .)com \
    --cc=davem@davemloft$(echo .)net \
    --cc=dzm91@hust$(echo .)edu.cn \
    --cc=kuba@kernel$(echo .)org \
    --cc=linux-can@vger$(echo .)kernel.org \
    --cc=linux-kernel@vger$(echo .)kernel.org \
    --cc=mailhol.vincent@wanadoo$(echo .)fr \
    --cc=mkl@pengutronix$(echo .)de \
    --cc=mudongliangabcd@gmail$(echo .)com \
    --cc=netdev@vger$(echo .)kernel.org \
    --cc=s.grosjean@peak-system$(echo .)com \
    --cc=stefan.maetje@esd$(echo .)eu \
    --cc=wg@grandegger$(echo .)com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox