mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] mtd: rawnand: ndfc: fix I/O mapping leak on remove
@ 2026-09-15 16:42 Guangshuo Li
  2026-09-25 13:33 ` Miquel Raynal
  0 siblings, 1 reply; 2+ messages in thread
From: Guangshuo Li @ 2026-09-15 16:42 UTC (permalink / raw)
  To: Miquel Raynal, Richard Weinberger, Vignesh Raghavendra,
	Rosen Penev, Guangshuo Li, Thomas Gleixner, Sean MacLennan,
	David Woodhouse, linux-mtd, linux-kernel
  Cc: stable

ndfc_probe() maps the controller registers with of_iomap(), but the
remove path does not call the matching iounmap() before the driver is
removed.

If ndfc_chip_init() fails, the probe error path correctly unmaps
ndfc->ndfcbase. However, after a successful probe, the mapping remains
active for the lifetime of the device and ndfc_remove() never releases
it, leaking the I/O mapping on driver unbind.

Call iounmap() in ndfc_remove() after the NAND device cleanup to release
the controller register mapping.

This issue was found by manual code inspection.

Fixes: a808ad3b0d28 ("[MTD] [NAND] ndfc driver")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
---
 drivers/mtd/nand/raw/ndfc.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/mtd/nand/raw/ndfc.c b/drivers/mtd/nand/raw/ndfc.c
index a48274297d3b..0091b335b651 100644
--- a/drivers/mtd/nand/raw/ndfc.c
+++ b/drivers/mtd/nand/raw/ndfc.c
@@ -252,6 +252,7 @@ static void ndfc_remove(struct platform_device *ofdev)
 	WARN_ON(ret);
 	nand_cleanup(chip);
 	kfree(mtd->name);
+	iounmap(ndfc->ndfcbase);
 }
 
 static const struct of_device_id ndfc_match[] = {
-- 
2.43.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] mtd: rawnand: ndfc: fix I/O mapping leak on remove
  2026-09-15 16:42 [PATCH] mtd: rawnand: ndfc: fix I/O mapping leak on remove Guangshuo Li
@ 2026-09-25 13:33 ` Miquel Raynal
  0 siblings, 0 replies; 2+ messages in thread
From: Miquel Raynal @ 2026-09-25 13:33 UTC (permalink / raw)
  To: Guangshuo Li
  Cc: Richard Weinberger, Vignesh Raghavendra, Rosen Penev,
	Thomas Gleixner, Sean MacLennan, David Woodhouse, linux-mtd,
	linux-kernel, stable

On 16/09/2026 at 00:42:04 +08, Guangshuo Li <lgs201920130244@gmail.com> wrote:

> ndfc_probe() maps the controller registers with of_iomap(), but the
> remove path does not call the matching iounmap() before the driver is
> removed.
>
> If ndfc_chip_init() fails, the probe error path correctly unmaps
> ndfc->ndfcbase. However, after a successful probe, the mapping remains
> active for the lifetime of the device and ndfc_remove() never releases
> it, leaking the I/O mapping on driver unbind.
>
> Call iounmap() in ndfc_remove() after the NAND device cleanup to release
> the controller register mapping.
>
> This issue was found by manual code inspection.
>
> Fixes: a808ad3b0d28 ("[MTD] [NAND] ndfc driver")
> Cc: stable@vger.kernel.org
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>

No longer applies after Rosen Penev's patch, can you please rebase on top?

Thanks,
Miquèl

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-25 13:33 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-15 16:42 [PATCH] mtd: rawnand: ndfc: fix I/O mapping leak on remove Guangshuo Li
2026-09-25 13:33 ` Miquel Raynal

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®