[merged mm-nonmm-stable] rapidio-clear-mport-net-when-rio_add_net-fails.patch removed from -mm tree

Andrew Morton <[email protected]> Mon, 03 Aug 2026 21:05:21 -0700
Newsgroups org.kernel.vger.mm-commits
Message-ID <[email protected]>
The quilt patch titled
     Subject: rapidio: clear mport->net when rio_add_net() fails
has been removed from the -mm tree.  Its filename was
     rapidio-clear-mport-net-when-rio_add_net-fails.patch

This patch was dropped because it was merged into the mm-nonmm-stable branch
of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm

------------------------------------------------------
From: Guangshuo Li <[email protected]>
Subject: rapidio: clear mport->net when rio_add_net() fails
Date: Wed, 8 Jul 2026 15:06:28 +0800

rio_alloc_net() stores the newly allocated rio_net in mport->net before
rio_scan_alloc_net() registers the device.

If rio_add_net() fails, rio_scan_alloc_net() drops the device reference
with put_device(), which releases the rio_net through the device release
callback.  However, mport->net is left pointing at the freed object.

A later mport unregister path can then dereference the dangling mport->net
pointer and may try to free the same rio_net again.

Clear mport->net in the rio_add_net() failure path, matching the cleanup
done for the destID table allocation failure path.

Link: https://lore.kernel.org/[email protected]
Fixes: e842f9a1edf3 ("rapidio: add check for rio_add_net() in rio_scan_alloc_net()")
Signed-off-by: Guangshuo Li <[email protected]>
Cc: Alexandre Bounine <[email protected]>
Cc: Matt Porter <[email protected]>
Cc: Yang yingliang <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
---

 drivers/rapidio/rio-scan.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/rapidio/rio-scan.c~rapidio-clear-mport-net-when-rio_add_net-fails
+++ a/drivers/rapidio/rio-scan.c
@@ -874,6 +874,7 @@ static struct rio_net *rio_scan_alloc_ne
 		net->dev.release = rio_scan_release_dev;
 		if (rio_add_net(net)) {
 			put_device(&net->dev);
+			mport->net = NULL;
 			net = NULL;
 		}
 	}
_

Patches currently in -mm which might be from [email protected] are