Re: [PATCH] ACPICA: Fix memory leak at acpi_ds_create_field()

"Rafael J. Wysocki (Intel)" <[email protected]> Thu, 13 Aug 2026 15:39:37 +0200
Newsgroups gmane.linux.acpi.devel,gmane.linux.kernel
Message-ID <CAJZ5v0isQYRN9aZCmWty-kZpjHvZWyJT2AnRXs9RDszy7b5TkA@mail.gmail.com>
On Thu, Aug 13, 2026 at 3:35 PM Breno Leitao <[email protected]> wrote:
>
> acpi_ds_create_field() allocates internal_pcc_buffer for operation
> regions in the PCC address space.
>
> The function runs once per field, so a second field on the
> same region overwrites the pointer and orphans the previous buffer.
>
> The matching ACPI_FREE() in acpi_ut_delete_internal_obj() only ever sees
> the last one.
>
> An arm64 platform whose SSDT declares regions with multiple fields each
> leaks two buffers at boot, as detected by kmemleak:
>
>   unreferenced object 0xffff000051e65400 (size 192):
>     comm "swapper/0", pid 1, jiffies 4294668436
>     backtrace (crc 0):
>       __kmalloc_noprof
>       acpi_ds_create_field
>       acpi_ds_load2_end_op
>       acpi_ds_exec_end_op
>       acpi_ps_parse_loop
>       acpi_ps_parse_aml
>       acpi_ns_load_table
>       acpi_load_tables
>       acpi_init
>
> Do not allocate a region if it was previously allocated before,
> preserving the current design, but, not leaking memory.
>
> Fixes: 0acf24ad7e10 ("ACPICA: Add support for PCC Opregion special context data")
> Signed-off-by: Breno Leitao <[email protected]>

As per Documentation/driver-api/acpi/linuxized-acpica.rst, please
submit a pull request with this change to the upstream ACPICA project
on GitHub.  The Linux patch will become applicable when there is a
corresponding commit upstream.

> ---
>  drivers/acpi/acpica/dsfield.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/acpi/acpica/dsfield.c b/drivers/acpi/acpica/dsfield.c
> index d7d56cc600d31..f7e503bf57c87 100644
> --- a/drivers/acpi/acpica/dsfield.c
> +++ b/drivers/acpi/acpica/dsfield.c
> @@ -522,7 +522,8 @@ acpi_ds_create_field(union acpi_parse_object *op,
>         }
>
>         if (info.region_node->object->region.space_id ==
> -           ACPI_ADR_SPACE_PLATFORM_COMM) {
> +           ACPI_ADR_SPACE_PLATFORM_COMM &&
> +           !region_node->object->field.internal_pcc_buffer) {
>                 region_node->object->field.internal_pcc_buffer =
>                     ACPI_ALLOCATE_ZEROED(info.region_node->object->region.
>                                          length);
>
> ---
> base-commit: 28d012efb4327f9c75d5e042a7c91e9a542efa98
> change-id: 20260813-acpica-pcc-field-leak-8f676f55179b
>
> Best regards,
> --
> Breno Leitao <[email protected]>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.