[PATCH 10/11] test: boot: imagemap: detach UBI when the test is done

Simon Glass sjg at chromium.org
Thu Oct 1 09:02:35 PDT 2026


Hi Daniel,

On 2026-09-29T00:04:16, Daniel Golle <daniel at makrotopia.org> wrote:
> test: boot: imagemap: detach UBI when the test is done
>
> The UBI test attaches UBI to the sandbox NAND and leaves it attached, so
> UBI still holds a reference to the MTD device when the test ends. Running
> the suite a second time crashes in mtd_partitions_used(): the test calls
> mtd_probe_devices(), which rebuilds the partition list of a master whose
> partitions UBI is still using, and the walk then follows a freed entry.

Just to check: mtd_del_parts() checks mtd_partitions_used() precisely
so that it does not delete partitions still in use. If the walk
follows a freed entry, something has already freed a partition while
UBI held it. That looks like an MTD bug which 'ubi part nand2'
followed by anything that reprobes could also hit. Please can you
explain what frees the entry? If it is a real core bug, I suspect it
should be fixed there, with this patch only tidying up the test.

>
> Detach UBI at the end of the test, and again at the start so a device
> left behind by anything else is released before the partitions are
> rebuilt.
>
> Fixes: 05c1fbbfa79f ("test: boot: add imagemap unit tests")
> Signed-off-by: Daniel Golle <daniel at makrotopia.org>
>
> test/boot/imagemap.c | 8 ++++++++
>  1 file changed, 8 insertions(+)

> diff --git a/test/boot/imagemap.c b/test/boot/imagemap.c
> @@ -592,6 +592,13 @@ static int imagemap_test_ubiblock(struct unit_test_state *uts)
> +     /*
> +      * Release any device a previous run attached: UBI keeps a reference to
> +      * the MTD device, and mtd_probe_devices() would then rebuild the
> +      * partition list behind its back.
> +      */
> +     ubi_detach();

This only helps if the device was left behind by an earlier run of
this same test. Linker-list order puts imagemap_test_mtd_blk before
this one, and it also calls mtd_probe_devices(), so if this test fails
part-way, the next pass crashes in mtd_blk before this detach is
reached.

After the next patch it also acts on freed memory (see my comment on
patch 3), and the 'ubi' global is left holding an MTD whose udevice
has gone.

> diff --git a/test/boot/imagemap.c b/test/boot/imagemap.c
> @@ -638,6 +645,7 @@ static int imagemap_test_ubiblock(struct unit_test_state *uts)
>
>       imagemap_cleanup(imdev);
>       free(wbuf);
> +     ubi_detach();
>
>       return 0;
>  }

This is skipped whenever a ut_assert...() between ubi_part() and here
fails, which is exactly the case the start-of-test detach is meant to
cover, and wbuf leaks too. Please can you move the body into a helper
and have the test function always detach afterwards, something like:

    static int imagemap_test_ubiblock(struct unit_test_state *uts)
    {
        int ret;

        ret = do_ubiblock_test(uts);
        ubi_detach();

        return ret;
    }

That keeps the teardown on every exit path, so you can drop the detach
at the start. What do you think?

Regards,
Simon



More information about the openwrt-devel mailing list