[PATCHv2] mtd: rawnand: fsl_ifc: allocate shared ctrl with devm_kzalloc

Miquel Raynal miquel.raynal at bootlin.com
Tue Sep 8 02:37:11 PDT 2026


On 07/09/2026 at 23:01:11 -07, Rosen Penev <rosenp at gmail.com> wrote:

> Allocate the shared fsl_ifc_nand_ctrl structure against the controller
> device, which outlives all NAND child devices, so it is freed
> automatically.  This drops the manual kfree() and the broken chip
> counter that was decremented in remove() but never incremented
> anywhere, leaking the structure and leaving the freed pointer in
> ctrl->nand on re-probe.
>
> Assisted-by: opencode:big-pickle
> Signed-off-by: Rosen Penev <rosenp at gmail.com>
> ---
>  v2: rebase.
>  drivers/mtd/nand/raw/fsl_ifc_nand.c | 15 ++-------------
>  1 file changed, 2 insertions(+), 13 deletions(-)
>
> diff --git a/drivers/mtd/nand/raw/fsl_ifc_nand.c b/drivers/mtd/nand/raw/fsl_ifc_nand.c
> index a88ac2cfaccd..4c2d95461c2e 100644
> --- a/drivers/mtd/nand/raw/fsl_ifc_nand.c
> +++ b/drivers/mtd/nand/raw/fsl_ifc_nand.c
> @@ -50,7 +50,6 @@ struct fsl_ifc_nand_ctrl {
>  	unsigned int index;	/* Pointer to next byte to 'read'	*/
>  	unsigned int oob;	/* Non zero if operating on OOB data	*/
>  	unsigned int eccread;	/* Non zero for a full-page ECC read	*/
> -	unsigned int counter;	/* counter for the initializations	*/
>  	unsigned int max_bitflips;  /* Saved during READ0 cmd		*/
>  };
>  
> @@ -1033,15 +1032,13 @@ static int fsl_ifc_nand_probe(struct platform_device *dev)
>  
>  	mutex_lock(&fsl_ifc_nand_mutex);
>  	if (!fsl_ifc_ctrl_dev->nand) {
> -		ifc_nand_ctrl = kzalloc_obj(*ifc_nand_ctrl);
> +		ifc_nand_ctrl = devm_kzalloc(fsl_ifc_ctrl_dev->dev, sizeof(*ifc_nand_ctrl),
> +					     GFP_KERNEL);

This is a global object. I don't get why it's global. But it seems not
relevant to tie with ctrl_dev->dev (see Sashiko report). Can you please
go one step further in this cleanup?

Thanks,
Miquèl



More information about the linux-mtd mailing list