diff options
| author | Yaxiong Tian <tianyaxiong@kylinos.cn> | 2026-04-01 11:30:46 +0800 |
|---|---|---|
| committer | Chanwoo Choi <cw00.choi@samsung.com> | 2026-08-22 19:27:10 +0900 |
| commit | eb6eaeb5d28df03aa7a21555398f83554f587eca (patch) | |
| tree | 43a00ef7a47bb683acac7b8c35be9634da4afe9e | |
| parent | 8d3ae59288f1e7d58d76558a6ee96d533bc5019f (diff) | |
| download | linux-next-eb6eaeb5d28df03aa7a21555398f83554f587eca.tar.gz linux-next-eb6eaeb5d28df03aa7a21555398f83554f587eca.zip | |
PM / devfreq: Fix possible null pointer issue in devfreq_add_governor()
When a user removes a governor using devfreq_remove_governor(), if
the current device is using this governor, devfreq->governor will
be set to NULL. When the user registers any governor
using devfreq_add_governor(), since devfreq->governor is NULL, a
null pointer error occurs in strncmp().
For example: A user loads the userspace gov through a module, then
a device selects userspace. When unloading the userspace module and
then loading it again, the null pointer error occurs:
Unable to handle kernel NULL pointer dereference at virtual address
0000000000000010
Mem abort info:
ESR = 0x0000000096000004
EC = 0x25: DABT (current EL), IL = 32 bits
*******************skip *********************
Call trace:
__pi_strncmp+0x20/0x1b8
devfreq_userspace_init+0x1c/0xff8 [governor_userspace]
do_one_initcall+0x4c/0x278
do_init_module+0x5c/0x218
load_module+0x1f1c/0x1fc8
init_module_from_file+0x8c/0xd0
__arm64_sys_finit_module+0x220/0x3d8
invoke_syscall+0x48/0x110
el0_svc_common.constprop.0+0xbc/0xe8
do_el0_svc+0x20/0x30
el0_svc+0x24/0xb8
el0t_64_sync_handler+0xb8/0xc0
el0t_64_sync+0x14c/0x150
To fix this issue, remove the list_for_each_entry() logic, as
find_devfreq_governor() has already checked for the existence of
governor with the same name. This makes it impossible to find a
duplicate governor in the list, so the subsequent logic is
unreachable and can be removed.
Fixes: 1b5c1be2c88e ("PM / devfreq: map devfreq drivers to governor using name")
Signed-off-by: Yaxiong Tian <tianyaxiong@kylinos.cn>
Co-developed-by: Jie Zhan <zhanjie9@hisilicon.com>
Signed-off-by: Jie Zhan <zhanjie9@hisilicon.com>
Signed-off-by: Chanwoo Choi <cw00.choi@samsung.com>
Link: https://patchwork.kernel.org/project/linux-pm/patch/20260401033046.67482-1-tianyaxiong@kylinos.cn/
| -rw-r--r-- | drivers/devfreq/devfreq.c | 33 |
1 files changed, 0 insertions, 33 deletions
diff --git a/drivers/devfreq/devfreq.c b/drivers/devfreq/devfreq.c index 82dd9a43dc62..994984f7b6e1 100644 --- a/drivers/devfreq/devfreq.c +++ b/drivers/devfreq/devfreq.c @@ -1261,7 +1261,6 @@ void devfreq_resume(void) int devfreq_add_governor(struct devfreq_governor *governor) { struct devfreq_governor *g; - struct devfreq *devfreq; int err = 0; if (!governor) { @@ -1280,38 +1279,6 @@ int devfreq_add_governor(struct devfreq_governor *governor) list_add(&governor->node, &devfreq_governor_list); - list_for_each_entry(devfreq, &devfreq_list, node) { - int ret = 0; - struct device *dev = devfreq->dev.parent; - - if (!strncmp(devfreq->governor->name, governor->name, - DEVFREQ_NAME_LEN)) { - /* The following should never occur */ - if (devfreq->governor) { - dev_warn(dev, - "%s: Governor %s already present\n", - __func__, devfreq->governor->name); - ret = devfreq->governor->event_handler(devfreq, - DEVFREQ_GOV_STOP, NULL); - if (ret) { - dev_warn(dev, - "%s: Governor %s stop = %d\n", - __func__, - devfreq->governor->name, ret); - } - /* Fall through */ - } - devfreq->governor = governor; - ret = devfreq->governor->event_handler(devfreq, - DEVFREQ_GOV_START, NULL); - if (ret) { - dev_warn(dev, "%s: Governor %s start=%d\n", - __func__, devfreq->governor->name, - ret); - } - } - } - err_out: mutex_unlock(&devfreq_list_lock); |
