Re: [PATCH] coresight: syscfg: Fix null pointer dereference when configfs init fails
From: Mike Leach
Date: Tue Sep 29 2026 - 08:30:51 EST
Reviewed-by: Mike Leach <mike.leach@xxxxxxx>
On 9/28/26 13:35, Yingchao Deng wrote:
If cscfg_configfs_init() fails, cscfg_init() takes the exit_err path:
cscfg_init() -> cscfg_clear_device() -> cscfg_configfs_release()
-> configfs_unregister_subsystem()
which tears down a configfs subsystem that was never registered.
configfs_unregister_subsystem() begins with:
struct dentry *dentry = dget(group->cg_item.ci_dentry);
struct dentry *root = dentry->d_sb->s_root;
ci_dentry is assigned in configfs_create_dir() only once the subsystem
directory has been created, which never happened here. cscfg_mgr
comes from kzalloc_obj(), so ci_dentry is still NULL, and dget()
hands a NULL dentry back unchanged - the next line dereferences it.
Handle the failure in cscfg_init() directly: unregister the device and
return the error, releasing the devres-allocated config item type and
cscfg_mgr without touching the subsystem.
Fixes: a13d5a246aca ("coresight: syscfg: Add initial configfs support")
Suggested-by: Leo Yan <leo.yan@xxxxxxx>
Link: https://lore.kernel.org/all/20260924162404.GN200420@xxxxxxxxxxxxxxx/
Signed-off-by: Yingchao Deng <dengyingchao@xxxxxxxxxxxxxxx>
---
drivers/hwtracing/coresight/coresight-syscfg.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/hwtracing/coresight/coresight-syscfg.c b/drivers/hwtracing/coresight/coresight-syscfg.c
index 2bfdd7b45e49..00b29d1656c0 100644
--- a/drivers/hwtracing/coresight/coresight-syscfg.c
+++ b/drivers/hwtracing/coresight/coresight-syscfg.c
@@ -1299,8 +1299,10 @@ int __init cscfg_init(void)
/* initialise configfs subsystem */
err = cscfg_configfs_init(cscfg_mgr);
- if (err)
- goto exit_err;
+ if (err) {
+ device_unregister(cscfg_device());
+ return err;
+ }
/* preload built-in configurations */
err = cscfg_preload(THIS_MODULE);