Re: [PATCH v2] params: serialize lookup_or_create_module_kobject()
From: Petr Pavlu
Date: Thu Sep 24 2026 - 10:42:24 EST
On 9/18/26 12:07 PM, Jiakai Xu wrote:
> lookup_or_create_module_kobject() first looks up the module kobject with
> kset_find_obj() and, if not found, creates a new one with
> kobject_init_and_add(). The function is called at runtime from
> module_add_driver() since commit f95bbfe18512 ("drivers: base: handle
> module_kobject creation"), which means two concurrent driver
> registrations for the same built-in module name can both miss the
> lookup and race to create the same kobject.
>
> The loser of the race gets -EEXIST from kobject_init_and_add() and its
> kobject is removed from module_kset by kobject_add_internal() before
> the failure is reported. The error path then calls kobject_put(),
> which invokes module_kobj_release(), but that only completes
> ->kobj_completion and never frees the dynamically allocated
> module_kobject, leaking it (96 bytes) along with the object having been
> detached from the kset.
The patch fixes the module_kobject leak in this specific race condition,
but not in cases when kobject_init_and_add() (or sysfs_create_file())
fails for another reason. Do you plan to address that separately?
>
> This is triggerable by unprivileged users, e.g. by concurrently issuing
> the RAW_IOCTL_INIT ioctl of the raw-gadget driver, which registers the
> "raw_gadget" driver on the gadget bus:
Nit: The device registration is done by the USB_RAW_IOCTL_RUN ioctl +
I believe the raw-gadget device node should default to root-only (0600).
--
Thanks,
Petr