From: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
To: Takashi Iwai <tiwai@suse.de>
Cc: linux-kernel@vger.kernel.org
Subject: Re: Is devm_* broken ?
Date: Wed, 15 Jul 2015 19:27:42 +0300 [thread overview]
Message-ID: <12287299.f8AJmpnxZx@avalon> (raw)
In-Reply-To: <s5hmvyxl7f1.wl-tiwai@suse.de>
On Wednesday 15 July 2015 18:20:02 Takashi Iwai wrote:
> On Wed, 15 Jul 2015 18:08:34 +0200, Laurent Pinchart wrote:
> > On Wednesday 15 July 2015 17:51:28 Takashi Iwai wrote:
> > > On Wed, 15 Jul 2015 00:34:53 +0200, Laurent Pinchart wrote:
> > > > Hello,
> > > >
> > > > I came to realize not too long ago that the following sequence of
> > > > events will lead to a crash with any platform driver that uses devm_*
> > > > and creates device nodes.
> > > >
> > > > 1. Get a platform device bound it its driver
> > > > 2. Open the corresponding device node in userspace and keep it open
> > > > 3. Unbind the platform device from its driver through sysfs
> > > >
> > > > echo <device-name> > /sys/bus/platform/drivers/<driver-name>/unbind
> > > >
> > > > (or for hotpluggable devices just unplug the device)
> > > >
> > > > 4. Close the device node
> > > > 5. Enjoy the fireworks
> > > >
> > > > While having a device node open prevents modules from being unloaded,
> > > > it doesn't prevent devices from being unbound from drivers. If the
> > > > driver uses devm_* helpers to allocate memory the memory will be freed
> > > > when the device is unbound from the driver, but that memory will still
> > > > be used by any operation touching an open device node.
> > > >
> > > > Is devm_* inherently broken ? It's so widely used, tell me I'm missing
> > > > something obvious.
> > >
> > > I don't think this is specific to devm_*() but it's about the resource
> > > management in general. After bus or driver's remove callback, all
> > > device resources that have been assigned by the driver are supposed to
> > > be freed, or ready to be freed.
> >
> > The remove callback notifies drivers that the device has been removed and
> > that it's time to clean up. However, drivers have no control over
> > userspace, so they can't force applications to close all open file
> > handles, unmap memory and otherwise free all device-related resources
> > immediately and synchronously. The best a driver can do is prevent any
> > new reference to a resource from being taken by userspace (returning an
> > error from open() for instance) and wait until all existing references
> > get released before finally freeing resources. This is where devm_* hurts
> > as a driver can't delay freeing resources until after all references held
> > by userspace are released.
>
> Right, and this is what ALSA drivers does in general.
Does that mean that an ALSA driver that uses devm_* will crash if the device
is unbound from the driver (possibly because it gets disconnected) while
userspace uses the ALSA device ? Isn't that considered as an issue ?
> > If I were to switch the uvcvideo driver from kzalloc to devm_kzalloc it
> > would crash if the webcam gets disconnected while userspace has the V4L2
> > device node open.
>
> The disconnection is a bit different story, but I see your concern.
>From a resources release point of view disconnection and unbind are similar.
--
Regards,
Laurent Pinchart
next prev parent reply other threads:[~2015-07-15 16:27 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-07-14 22:34 Is devm_* broken ? Laurent Pinchart
2015-07-15 15:51 ` Takashi Iwai
2015-07-15 16:08 ` Laurent Pinchart
2015-07-15 16:20 ` Takashi Iwai
2015-07-15 16:27 ` Laurent Pinchart [this message]
2015-07-15 16:34 ` Takashi Iwai
2015-07-28 14:10 ` Laurent Pinchart
2015-07-15 17:00 ` Dan Williams
2015-07-15 18:03 ` Tejun Heo
2015-07-28 14:16 ` Laurent Pinchart
2015-07-28 15:22 ` Tejun Heo
2015-07-28 17:05 ` Laurent Pinchart
2015-08-04 19:56 ` Pavel Machek
2015-08-04 21:26 ` Dmitry Torokhov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=12287299.f8AJmpnxZx@avalon \
--to=laurent.pinchart@ideasonboard.com \
--cc=linux-kernel@vger.kernel.org \
--cc=tiwai@suse.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.