[PATCH v2 01/15] efi/libstub: Fix error unwind freeing fdt in allocate_new_fdt_and_exit_boot()
Jason Gunthorpe
jgg at nvidia.com
Fri Oct 2 16:31:38 PDT 2026
Sashiko says fdt_addr can point to either an allocated fdt or the fdt from
get_fdt() which is memory owned by FW.
Only the allocated fdt should be freed on the error unwind path. Use a
dedicated variable for the allocation's size so that the free does not get
confused.
Fixes: 4fc8e738ff3e ("efi: libstub: remove DT dependency from generic stub")
Reviewed-by: Jonathan Cameron <jonathan.cameron at oss.qualcomm.com>
Signed-off-by: Jason Gunthorpe <jgg at nvidia.com>
---
drivers/firmware/efi/libstub/fdt.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/firmware/efi/libstub/fdt.c b/drivers/firmware/efi/libstub/fdt.c
index 23b3543d3041b0..f01450b4997546 100644
--- a/drivers/firmware/efi/libstub/fdt.c
+++ b/drivers/firmware/efi/libstub/fdt.c
@@ -229,6 +229,7 @@ efi_status_t allocate_new_fdt_and_exit_boot(void *handle,
u32 desc_ver;
efi_status_t status;
struct exit_boot_struct priv;
+ unsigned long fdt_size_allocated = 0;
unsigned long fdt_addr = 0;
unsigned long fdt_size = 0;
@@ -251,12 +252,13 @@ efi_status_t allocate_new_fdt_and_exit_boot(void *handle,
if (strstr(cmdline_ptr, "dtb="))
efi_err("Ignoring DTB from command line.\n");
} else {
- status = efi_load_dtb(image, &fdt_addr, &fdt_size);
+ status = efi_load_dtb(image, &fdt_addr, &fdt_size_allocated);
if (status != EFI_SUCCESS && status != EFI_NOT_READY) {
efi_err("Failed to load device tree!\n");
goto fail;
}
+ fdt_size = fdt_size_allocated;
}
if (fdt_addr) {
@@ -334,7 +336,7 @@ efi_status_t allocate_new_fdt_and_exit_boot(void *handle,
efi_free(MAX_FDT_SIZE, *new_fdt_addr);
fail:
- efi_free(fdt_size, fdt_addr);
+ efi_free(fdt_size_allocated, fdt_addr);
if (!efi_novamap)
efi_bs_call(free_pool, priv.runtime_map);
--
2.43.0
More information about the linux-riscv
mailing list