On Sat, Oct 03, 2026 at 04:27:52PM +0800, Pei Xiao wrote:
> tpm_nsc_remove() is used as the release callback of the hand-created
> platform device and dereferences the chip drvdata unconditionally.
> If init fails before tpmm_chip_alloc() (e.g. request_region() cannot
> claim the ports), the error path drops the last device reference and
> the release callback runs with chip == NULL, crashing module init.
> 
> Return early when the chip has not been created yet.
> 
> Fixes: afb5abc262e9 ("tpm: two-phase chip management functions")
> Assisted-by: GLM-5.3
> Signed-off-by: Pei Xiao <[email protected]>
> ---
>  drivers/char/tpm/tpm_nsc.c | 7 ++++++-
>  1 file changed, 6 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/char/tpm/tpm_nsc.c b/drivers/char/tpm/tpm_nsc.c
> index 879ac88f5783..46a52dc99b14 100644
> --- a/drivers/char/tpm/tpm_nsc.c
> +++ b/drivers/char/tpm/tpm_nsc.c
> @@ -259,7 +259,12 @@ static struct platform_device *pdev = NULL;
>  static void tpm_nsc_remove(struct device *dev)
>  {
>       struct tpm_chip *chip = dev_get_drvdata(dev);
> -     struct tpm_nsc_priv *priv = dev_get_drvdata(&chip->dev);
> +     struct tpm_nsc_priv *priv;
> +
> +     if (!chip)
> +             return;
> +
> +     priv = dev_get_drvdata(&chip->dev);
>  
>       tpm_chip_unregister(chip);
>       release_region(priv->base, 2);
> -- 
> 2.25.1
> 

I can apply this, thanks.

Reviewed-by: Jarkko Sakkinen <[email protected]>

Br, Jarkko

Reply via email to