On Wed, Sep 16, 2026 at 11:36:25AM +0200, Ulf Hansson wrote:
> On Wed, Sep 16, 2026 at 9:43 AM Johan Hovold <johan(a)kernel.org> wrote:
> >
> > On Tue, Sep 15, 2026 at 03:20:46PM +0200, Ulf Hansson wrote:
> > > From: Ulf Hansson <ulfh(a)kernel.org>
> > >
> > > As there are no longer any users of these functions, let's make them
> > > internal to the mmc core.
> >
> > Why would you want to do that? The devres helpers should just be simple
> > wrappers around these and sometimes devres just isn't a good fit.
>
> At the moment there seems to be no need for them. I would rather keep
> API/interfaces as simple as possible, so I prefer to remove them at
> this point.
>
> If we see a need for them, we can always add them back.
Devres generally only works when all resources are device managed.
Therefore you should always provide the underlying non-devres manages
interface as well so that you don't force devres on drivers where it
could cause trouble.
> > Especially with the work cancellations present in mmc_free_host() (which
> > I have pointed out elsewhere should not be there), a driver may need to
> > free the host before tearing down other non-devres managed resources
> > during unbind.
>
> Can you please point me to such an example so I can try to understand better?
We just discussed the renesas driver which can schedule rescan work
before registering the host controller. [1]
If such a driver also has non-devres managed resources that are freed
before the work is cancelled you have a use-after-free.
> > This may even be needed for greybus which currently destroys the
> > connection before freeing the host.
>
> I looked closer at gb_sdio_remove() (the greybus sdio driver's
> ->remove() callback) and I think the problem isn't about freeing the
> host.
>
> Instead it seems like the call to mmc_remove_host() is done too late.
> To me it looks like when the mmc core tries to power off the card
> gracefully, through mmc_remove_host() the driver has already moved
> into a state where it no longer accepts any requests.
Yes, that looks wrong, but that's a separate issue.
I only pointed at greybus as an example of a driver which has non-devres
managed resources. If there is (rescan) work still scheduled after
probe() or remove() returns, there's a potential use-after-free.
Johan
[1] https://lore.kernel.org/lkml/ap7CaVj82BJZgjf6@hovoldconsulting.com/
From: Ulf Hansson <ulfh(a)kernel.org>
The only remaining user of mmc_alloc|free_host() is the greybus sdio driver.
Let's convert it into using the resource managed variant so we can drop the
export of mmc_alloc|free_host().
Ulf Hansson (2):
staging: greybus: sdio: Convert to devm_mmc_alloc_host()
mmc: core: Turn mmc_alloc|free_host() into static functions
drivers/mmc/core/host.c | 35 +++++++++-------------------------
drivers/staging/greybus/sdio.c | 11 +++--------
include/linux/mmc/host.h | 2 --
3 files changed, 12 insertions(+), 36 deletions(-)
--
2.43.0
The usermode helper declarations were previously provided by linux/kmod.h
but commit c1f3fa2a4fde ("kmod: split off umh headers into its own file")
moved them to linux/umh.h in 2017. Add explicit includes of linux/umh.h to
files that use usermode helpers and remove linux/kmod.h where it is no
longer needed.
Also add a missing include of linux/sysctl.h to kernel/time/jiffies.c.
Finally, clean up linux/kmod.h so that it includes only the headers that it
actually requires, importantly removing the compat linux/umh.h include.
This cleanup is motivated by trying to reduce the preprocessed size of
linux/module.h, which includes linux/kmod.h. linux/module.h appears in
roughly 15k #include directives across the kernel. This makes it a "hot"
header, so it should avoid pulling in unnecessary definitions. Note that
this series doesn't immediately improve the situation, since most of the
files included by linux/kmod.h are, for now, also included by
linux/module.h through other paths.
Apologies for the wide distribution. Acked-bys are appreciated.
---
Changes in v3:
- Rebase on top of v7.3-rc2.
- Clean up commit descriptions.
- Link to v2: https://patch.msgid.link/20260721131207.803760-1-petr.pavlu@suse.com
Changes in v2:
- Remove the linux/kmod.h include from kernel/cgroup/cgroup-v1.c.
- Add a missing include of linux/sysctl.h to kernel/time/jiffies.c.
- Link to v1: https://patch.msgid.link/20260708154510.6794-1-petr.pavlu@suse.com
---
Petr Pavlu (3):
umh, treewide: Explicitly include linux/umh.h where needed
time/jiffies: Include linux/sysctl.h for proc_int_u2k_conv_uop(), ...
module: Bring includes in linux/kmod.h up to date
arch/x86/kernel/cpu/mce/dev-mcelog.c | 2 +-
drivers/block/drbd/drbd_nl.c | 1 +
drivers/greybus/svc_watchdog.c | 1 +
drivers/macintosh/windfarm_core.c | 1 +
drivers/pnp/pnpbios/core.c | 2 +-
drivers/video/fbdev/uvesafb.c | 1 +
fs/coredump.c | 2 +-
fs/nfs/cache_lib.c | 2 +-
fs/nfsd/nfs4layouts.c | 2 +-
fs/nfsd/nfs4recover.c | 1 +
fs/ocfs2/stackglue.c | 1 +
include/linux/kmod.h | 12 ++----------
kernel/cgroup/cgroup-v1.c | 2 +-
kernel/module/kmod.c | 1 +
kernel/power/process.c | 2 +-
kernel/reboot.c | 2 +-
kernel/time/jiffies.c | 1 +
kernel/umh.c | 2 +-
lib/kobject_uevent.c | 2 +-
net/bridge/br_stp_if.c | 2 +-
security/keys/request_key.c | 2 +-
security/tomoyo/common.h | 2 +-
22 files changed, 23 insertions(+), 23 deletions(-)
---
base-commit: df2908090cda368b01ff43709f51890076c56157
change-id: 20260816-module-include-kmod-14d1a0e19462
gb_hid_set_report() sizes its request payload as sizeof(*request) + len -
1, but report[] in struct gb_hid_set_report_request is a flexible array
member that sizeof() already excludes. The buffer is therefore one byte too
small, so memcpy(request->report, buf, len) writes one byte past its end,
which KASAN reports as a slab-out-of-bounds write. Drop the stray - 1 so
the allocation covers the whole report.
Closes: https://lore.kernel.org/all/CA+0ovCgLrz4WhPKP5LGW5HZa8VOodgeo6pWuyQGgHE7UY5…
Signed-off-by: Farhad Alemi <farhad.alemi(a)berkeley.edu>
---
The device was emulated.
--- a/drivers/staging/greybus/hid.c
+++ b/drivers/staging/greybus/hid.c
@@ -97,7 +97,8 @@ static int gb_hid_set_report(struct gb_hid *ghid, u8
report_type, u8 report_id,
{
struct gb_hid_set_report_request *request;
struct gb_operation *operation;
- int ret, size = sizeof(*request) + len - 1;
+ /* report[] is a flexible array, so sizeof() already excludes it. */
+ int ret, size = sizeof(*request) + len;
ret = gb_pm_runtime_get_sync(ghid->bundle);
if (ret)
The debugfs buffers in gb_camera (data[PAGE_SIZE], length) are written
with sprintf without any bounds checking. The four places in
gb_camera_debugfs_capabilities, gb_camera_debugfs_configure_streams and
gb_camera_debugfs_flush do:
buffer->length += sprintf(buffer->data + buffer->length, ...);
buffer->length = sprintf(buffer->data, ...);
If the formatted data ever grows (e.g., more streams, larger hex dump)
or if length is already close to PAGE_SIZE, this will overrun the
PAGE_SIZE buffer and corrupt memory. The driver is debugfs-only so
the impact is limited, but it is still a real bug and the pattern is
repeated in multiple places.
Fix it by using scnprintf with the remaining size:
scnprintf(buffer->data + buffer->length, PAGE_SIZE - buffer->length, ...)
scnprintf(buffer->data, PAGE_SIZE, ...)
This is the standard way to write to a fixed-size buffer in the
kernel. It guarantees we never write past PAGE_SIZE and will truncate
instead of overrunning, which is safe for debugfs output. The return
value still accumulates in length, which matches the existing use with
simple_read_from_buffer (it will just show truncated output rather
than corrupting).
I checked that this exact conversion has not been proposed before:
the recent greybus conversions to sysfs_emit (light.c, gbphy.c) and
fbtft/vme_tsi148 scnprintf patches do not touch camera.c at all,
and a search of lore for "gb_camera_debugfs" shows no prior patch
for these four sprintf sites.
No functional change for normal sizes, just makes the code safe if
the buffer ever fills up.
Signed-off-by: Vaibhav Agarwal <contectforbusiness(a)proton.me>
---
drivers/staging/greybus/camera.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/drivers/staging/greybus/camera.c b/drivers/staging/greybus/camera.c
index 62b55bb28..efc83ceff 100644
--- a/drivers/staging/greybus/camera.c
+++ b/drivers/staging/greybus/camera.c
@@ -890,7 +890,8 @@ static ssize_t gb_camera_debugfs_capabilities(struct gb_camera *gcam,
for (i = 0; i < size; i += 16) {
unsigned int nbytes = min_t(unsigned int, size - i, 16);
- buffer->length += sprintf(buffer->data + buffer->length,
+ buffer->length += scnprintf(buffer->data + buffer->length,
+ PAGE_SIZE - buffer->length,
"%*ph\n", nbytes, caps + i);
}
@@ -973,12 +974,13 @@ static ssize_t gb_camera_debugfs_configure_streams(struct gb_camera *gcam,
if (ret < 0)
goto done;
- buffer->length = sprintf(buffer->data, "%u;%u;", nstreams, flags);
+ buffer->length = scnprintf(buffer->data, PAGE_SIZE, "%u;%u;", nstreams, flags);
for (i = 0; i < nstreams; ++i) {
struct gb_camera_stream_config *stream = &streams[i];
- buffer->length += sprintf(buffer->data + buffer->length,
+ buffer->length += scnprintf(buffer->data + buffer->length,
+ PAGE_SIZE - buffer->length,
"%u;%u;%u;%u;%u;%u;%u;",
stream->width, stream->height,
stream->format, stream->vc,
@@ -1046,7 +1048,7 @@ static ssize_t gb_camera_debugfs_flush(struct gb_camera *gcam,
if (ret < 0)
return ret;
- buffer->length = sprintf(buffer->data, "%u", req_id);
+ buffer->length = scnprintf(buffer->data, PAGE_SIZE, "%u", req_id);
return len;
}
Adhere to Linux kernel coding style. Reported by checkpatch:
CHECK: Alignment should match open parenthesis
Signed-off-by: S Tarun Kumar Lywait <tarun.k.lywait(a)gmail.com>
---
drivers/staging/greybus/camera.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/staging/greybus/camera.c b/drivers/staging/greybus/camera.c
index 62b55bb28408..9853bd60ff27 100644
--- a/drivers/staging/greybus/camera.c
+++ b/drivers/staging/greybus/camera.c
@@ -263,9 +263,10 @@ static int gb_camera_get_max_pkt_size(struct gb_camera *gcam,
* Validate the stream configuration response verifying padding is correctly
* set and the returned number of streams is supported
*/
-static const int gb_camera_configure_streams_validate_response(struct gb_camera *gcam,
- struct gb_camera_configure_streams_response *resp,
- unsigned int nstreams)
+static const int gb_camera_configure_streams_validate_response
+ (struct gb_camera *gcam,
+ struct gb_camera_configure_streams_response *resp,
+ unsigned int nstreams)
{
unsigned int i;
--
2.47.3