From: Danilo Krummrich <dakr@kernel.org>
To: "Russell King" <linux@armlinux.org.uk>,
"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
"Rafael J. Wysocki" <rafael@kernel.org>,
"Ioana Ciornei" <ioana.ciornei@nxp.com>,
"Nipun Gupta" <nipun.gupta@amd.com>,
"Nikhil Agarwal" <nikhil.agarwal@amd.com>,
"K. Y. Srinivasan" <kys@microsoft.com>,
"Haiyang Zhang" <haiyangz@microsoft.com>,
"Wei Liu" <wei.liu@kernel.org>,
"Dexuan Cui" <decui@microsoft.com>,
"Long Li" <longli@microsoft.com>,
"Bjorn Helgaas" <bhelgaas@google.com>,
"Armin Wolf" <W_Armin@gmx.de>,
"Bjorn Andersson" <andersson@kernel.org>,
"Mathieu Poirier" <mathieu.poirier@linaro.org>,
"Vineeth Vijayan" <vneethv@linux.ibm.com>,
"Peter Oberparleiter" <oberpar@linux.ibm.com>,
"Heiko Carstens" <hca@linux.ibm.com>,
"Vasily Gorbik" <gor@linux.ibm.com>,
"Alexander Gordeev" <agordeev@linux.ibm.com>,
"Christian Borntraeger" <borntraeger@linux.ibm.com>,
"Sven Schnelle" <svens@linux.ibm.com>,
"Harald Freudenberger" <freude@linux.ibm.com>,
"Holger Dengler" <dengler@linux.ibm.com>,
"Mark Brown" <broonie@kernel.org>,
"Michael S. Tsirkin" <mst@redhat.com>,
"Jason Wang" <jasowang@redhat.com>,
"Xuan Zhuo" <xuanzhuo@linux.alibaba.com>,
"Eugenio Pérez" <eperezma@redhat.com>,
"Alex Williamson" <alex@shazbot.org>,
"Juergen Gross" <jgross@suse.com>,
"Stefano Stabellini" <sstabellini@kernel.org>,
"Oleksandr Tyshchenko" <oleksandr_tyshchenko@epam.com>,
"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>
Cc: linux-kernel@vger.kernel.org, driver-core@lists.linux.dev,
linuxppc-dev@lists.ozlabs.org, linux-hyperv@vger.kernel.org,
linux-pci@vger.kernel.org, platform-driver-x86@vger.kernel.org,
linux-arm-msm@vger.kernel.org, linux-remoteproc@vger.kernel.org,
linux-s390@vger.kernel.org, linux-spi@vger.kernel.org,
virtualization@lists.linux.dev, kvm@vger.kernel.org,
xen-devel@lists.xenproject.org,
linux-arm-kernel@lists.infradead.org,
Danilo Krummrich <dakr@kernel.org>,
Gui-Dong Han <hanguidong02@gmail.com>
Subject: [PATCH 09/12] s390/cio: use generic driver_override infrastructure
Date: Tue, 24 Mar 2026 01:59:13 +0100 [thread overview]
Message-ID: <20260324005919.2408620-10-dakr@kernel.org> (raw)
In-Reply-To: <20260324005919.2408620-1-dakr@kernel.org>
When a driver is probed through __driver_attach(), the bus' match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.
Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.
Note that calling match() from __driver_attach() without the device lock
held is intentional. [1]
Link: https://lore.kernel.org/driver-core/DGRGTIRHA62X.3RY09D9SOK77P@kernel.org/ [1]
Reported-by: Gui-Dong Han <hanguidong02@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=220789
Fixes: ebc3d1791503 ("s390/cio: introduce driver_override on the css bus")
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
---
drivers/s390/cio/cio.h | 5 -----
drivers/s390/cio/css.c | 34 ++++------------------------------
2 files changed, 4 insertions(+), 35 deletions(-)
diff --git a/drivers/s390/cio/cio.h b/drivers/s390/cio/cio.h
index 08a5e9380e75..bad142c536e1 100644
--- a/drivers/s390/cio/cio.h
+++ b/drivers/s390/cio/cio.h
@@ -103,11 +103,6 @@ struct subchannel {
struct work_struct todo_work;
struct schib_config config;
u64 dma_mask;
- /*
- * Driver name to force a match. Do not set directly, because core
- * frees it. Use driver_set_override() to set or clear it.
- */
- const char *driver_override;
} __attribute__ ((aligned(8)));
DECLARE_PER_CPU_ALIGNED(struct irb, cio_irb);
diff --git a/drivers/s390/cio/css.c b/drivers/s390/cio/css.c
index 5ab239f38588..e5a0ec6b4e3e 100644
--- a/drivers/s390/cio/css.c
+++ b/drivers/s390/cio/css.c
@@ -159,7 +159,6 @@ static void css_subchannel_release(struct device *dev)
sch->config.intparm = 0;
cio_commit_config(sch);
- kfree(sch->driver_override);
kfree(sch);
}
@@ -323,37 +322,9 @@ static ssize_t modalias_show(struct device *dev, struct device_attribute *attr,
static DEVICE_ATTR_RO(modalias);
-static ssize_t driver_override_store(struct device *dev,
- struct device_attribute *attr,
- const char *buf, size_t count)
-{
- struct subchannel *sch = to_subchannel(dev);
- int ret;
-
- ret = driver_set_override(dev, &sch->driver_override, buf, count);
- if (ret)
- return ret;
-
- return count;
-}
-
-static ssize_t driver_override_show(struct device *dev,
- struct device_attribute *attr, char *buf)
-{
- struct subchannel *sch = to_subchannel(dev);
- ssize_t len;
-
- device_lock(dev);
- len = sysfs_emit(buf, "%s\n", sch->driver_override);
- device_unlock(dev);
- return len;
-}
-static DEVICE_ATTR_RW(driver_override);
-
static struct attribute *subch_attrs[] = {
&dev_attr_type.attr,
&dev_attr_modalias.attr,
- &dev_attr_driver_override.attr,
NULL,
};
@@ -1356,9 +1327,11 @@ static int css_bus_match(struct device *dev, const struct device_driver *drv)
struct subchannel *sch = to_subchannel(dev);
const struct css_driver *driver = to_cssdriver(drv);
struct css_device_id *id;
+ int ret;
/* When driver_override is set, only bind to the matching driver */
- if (sch->driver_override && strcmp(sch->driver_override, drv->name))
+ ret = device_match_driver_override(dev, drv);
+ if (ret == 0)
return 0;
for (id = driver->subchannel_type; id->match_flags; id++) {
@@ -1415,6 +1388,7 @@ static int css_uevent(const struct device *dev, struct kobj_uevent_env *env)
static const struct bus_type css_bus_type = {
.name = "css",
+ .driver_override = true,
.match = css_bus_match,
.probe = css_probe,
.remove = css_remove,
--
2.53.0
next prev parent reply other threads:[~2026-03-24 1:00 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-24 0:59 [PATCH 00/12] treewide: Convert buses to use generic driver_override Danilo Krummrich
2026-03-24 0:59 ` [PATCH 01/12] amba: use generic driver_override infrastructure Danilo Krummrich
2026-03-24 0:59 ` [PATCH 02/12] bus: fsl-mc: " Danilo Krummrich
2026-03-25 12:01 ` Ioana Ciornei
2026-03-28 12:10 ` Christophe Leroy (CS GROUP)
2026-04-04 16:56 ` Christophe Leroy (CS GROUP)
2026-03-24 0:59 ` [PATCH 03/12] cdx: " Danilo Krummrich
2026-03-24 0:59 ` [PATCH 04/12] hv: vmbus: " Danilo Krummrich
2026-03-25 17:28 ` Michael Kelley
2026-04-04 15:01 ` [PATCH v2] Drivers: " Danilo Krummrich
2026-03-24 0:59 ` [PATCH 05/12] PCI: " Danilo Krummrich
2026-03-25 3:08 ` Gui-Dong Han
2026-03-26 18:08 ` Bjorn Helgaas
2026-03-30 16:28 ` Danilo Krummrich
2026-03-30 17:38 ` Danilo Krummrich
2026-03-30 20:10 ` Alex Williamson
2026-03-31 8:06 ` Danilo Krummrich
2026-03-31 8:22 ` Danilo Krummrich
2026-03-31 19:18 ` Alex Williamson
2026-03-24 0:59 ` [PATCH 06/12] platform/wmi: " Danilo Krummrich
2026-03-24 19:41 ` Armin Wolf
2026-03-31 15:02 ` Ilpo Järvinen
2026-03-31 15:43 ` Danilo Krummrich
2026-03-31 15:50 ` Ilpo Järvinen
2026-03-24 0:59 ` [PATCH 07/12] rpmsg: " Danilo Krummrich
2026-03-25 15:49 ` Mathieu Poirier
2026-03-24 0:59 ` [PATCH 08/12] vdpa: " Danilo Krummrich
2026-03-25 10:17 ` Eugenio Perez Martin
2026-03-24 0:59 ` Danilo Krummrich [this message]
2026-03-26 9:43 ` [PATCH 09/12] s390/cio: " Vineeth Vijayan
2026-03-24 0:59 ` [PATCH 10/12] s390/ap: " Danilo Krummrich
2026-03-24 12:41 ` Harald Freudenberger
2026-03-24 12:58 ` Holger Dengler
2026-03-24 0:59 ` [PATCH 11/12] spi: " Danilo Krummrich
2026-03-24 0:59 ` [PATCH 12/12] driver core: remove driver_set_override() Danilo Krummrich
2026-03-24 8:09 ` Greg Kroah-Hartman
2026-03-24 15:00 ` (subset) [PATCH 00/12] treewide: Convert buses to use generic driver_override Mark Brown
2026-03-25 9:29 ` Michael S. Tsirkin
2026-03-26 17:38 ` Danilo Krummrich
2026-04-04 15:07 ` (subset) " Danilo Krummrich
2026-04-04 16:58 ` Christophe Leroy (CS GROUP)
2026-04-04 17:04 ` Danilo Krummrich
2026-04-04 17:09 ` Christophe Leroy (CS GROUP)
2026-04-04 19:20 ` Danilo Krummrich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260324005919.2408620-10-dakr@kernel.org \
--to=dakr@kernel.org \
--cc=W_Armin@gmx.de \
--cc=agordeev@linux.ibm.com \
--cc=alex@shazbot.org \
--cc=andersson@kernel.org \
--cc=bhelgaas@google.com \
--cc=borntraeger@linux.ibm.com \
--cc=broonie@kernel.org \
--cc=chleroy@kernel.org \
--cc=decui@microsoft.com \
--cc=dengler@linux.ibm.com \
--cc=driver-core@lists.linux.dev \
--cc=eperezma@redhat.com \
--cc=freude@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=gregkh@linuxfoundation.org \
--cc=haiyangz@microsoft.com \
--cc=hanguidong02@gmail.com \
--cc=hca@linux.ibm.com \
--cc=ioana.ciornei@nxp.com \
--cc=jasowang@redhat.com \
--cc=jgross@suse.com \
--cc=kvm@vger.kernel.org \
--cc=kys@microsoft.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-hyperv@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux-remoteproc@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=linux-spi@vger.kernel.org \
--cc=linux@armlinux.org.uk \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=longli@microsoft.com \
--cc=mathieu.poirier@linaro.org \
--cc=mst@redhat.com \
--cc=nikhil.agarwal@amd.com \
--cc=nipun.gupta@amd.com \
--cc=oberpar@linux.ibm.com \
--cc=oleksandr_tyshchenko@epam.com \
--cc=platform-driver-x86@vger.kernel.org \
--cc=rafael@kernel.org \
--cc=sstabellini@kernel.org \
--cc=svens@linux.ibm.com \
--cc=virtualization@lists.linux.dev \
--cc=vneethv@linux.ibm.com \
--cc=wei.liu@kernel.org \
--cc=xen-devel@lists.xenproject.org \
--cc=xuanzhuo@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.