From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp-relay-internal-1.canonical.com (smtp-relay-internal-1.canonical.com [185.125.188.123]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CEDBF3D952D for ; Thu, 30 Jul 2026 22:03:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=185.125.188.123 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785448986; cv=none; b=qHiMwswFeDkccYPGeyKpsmBI3JJ9m0YG/YAGjNywhetbnL6ivUTB9avmUbvwK83+0eeGXdkDlGWn8aKPcdizAFrxvP9kUzIstm/Pu9YGDova6P425XrSnAzMBvKHPjasKM8vWpJt+U7WFWLEPBFxtQSQSo5X6p2zIAFn3DfvZ3k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785448986; c=relaxed/simple; bh=D9dcnj5LECTV8a7RoNcBDar1wfZuvDpORRSo9O2acMA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=QQKWTrAjmk59JX3ToxTto8pvNlwKKKUsKv0Dum3KVB+nnhy6jiag9Nweqk28/QxTej8+3mPwMwaWKMODbnscaIbnINVMFEvatiW5pejjY2KiN0gX8+ILPBDLYRl70Qzssnh3kWGjMO2pW+P1JCbKnLtWyRc8D/D0lSy5Yj9aEsU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=canonical.com; spf=pass smtp.mailfrom=canonical.com; dkim=pass (4096-bit key) header.d=canonical.com header.i=@canonical.com header.b=iwEklnMJ; arc=none smtp.client-ip=185.125.188.123 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=canonical.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=canonical.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (4096-bit key) header.d=canonical.com header.i=@canonical.com header.b="iwEklnMJ" Received: from mail-wr1-f72.google.com (mail-wr1-f72.google.com [209.85.221.72]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-internal-1.canonical.com (Postfix) with ESMTPS id 160963F9A5 for ; Thu, 30 Jul 2026 22:03:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20251003; t=1785448981; bh=/U6NCYIqKYeny+V7yFbvYYYCTzc3996iTQiY0kja4rs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=iwEklnMJxi3ctpoL+9cv1inmFPr3WKWlB/IO5aHflQ9krboCv3SxaX+AuumJ0WUdO bJ3QSYktQYE7kZgFqOvF/KBSng1Yo/DEL3aMrDeKCrcM6ap8w/1C+KB8ZJl0qzfy9U RVklmTKOj1hAjc36xEVptj/aoHEnV1zSaRbDvbW6X2wvqI4jgF83XR/CCfe28g1nqB m8VQozsInuHZg03D+cwU83WNpDDtQAi1iUsALJoCtpJrYNjjhu2YaW5r46fAJIStJl Cx9ookYB3MuMG1aUBwqjCayYPKe8V0XLruG56W6GAGZH+/0BDB/q68NO4GnG6c2pcl Ljv8S/y97vzhCPp8IILwAcYnlt9H+qY9FNGzLSDcOgU9UO2HJqKwkFJZ0kj2comQAO fOUpPh4VqVa4a3hvZufo7/ChjalbGcouf+YcSA5/8r5wNJ7/MIxG7eCKMp7WIrYRY5 lQ6kFgdr2HdHHYv2Q6XKTvZ+HPd0YRWSQAdEr4VXblROnWW/8ZF1kqWkvNDlw3IwjA I5JWbHmRt+pi8gBrUOsULBvPXnC+PFYZhHTZoRlQ9uDHOYfruZ7Eh1jI/6hdy2h7hR fHKzPSDrQRIQi84g2BhWOqo2LmB6zgCkNZn8VgVjTI5aRJK6sAko+sGtufPK3WRAo+ CTpd265pa8G6stWoz93lmL9c= Received: by mail-wr1-f72.google.com with SMTP id ffacd0b85a97d-47f8580ed9eso156872f8f.0 for ; Thu, 30 Jul 2026 15:03:01 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785448980; x=1786053780; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/U6NCYIqKYeny+V7yFbvYYYCTzc3996iTQiY0kja4rs=; b=K+a7eTyOKsKuX4DWI2QI2qGHu/Hbtk8A4aCN1pCo1D96iWKPWSHzUlOFuYJyhB77uz EYUlkohDL/zAGSpLQv/4Y6Ir/gW1CBc2q2MYLKKr8giDzOuZmZGnTz9vb+Q+7E5Y30Ma jvEInu5h9tlnPsCAhOgkFCW67Eh9HR8CCoNg5SfZ6R6a2vMYq1xtnufqoKnoBa36BYdP zUOcROUDxs4VcMFikUKqOvBLrgENRZRpOo+3P7i3oUG8MFWh6ZPbSndcidtwKo5mbzJx nUL0at43DccNbKPpR/aPZmZtoNAaf3Kyc29E0dzkw3/BFrKUAOe3v1ZTHiyT+O5XlhDH Geyg== X-Forwarded-Encrypted: i=1; AHgh+RpQXVr5H4y9MCsK1f4tftScUzQztoqwxGioHaoE/CkzFg2Bmu4pgAYcCMDINskjf452uMKPqB9l3cxJnu8=@vger.kernel.org X-Gm-Message-State: AOJu0YyFkE3ArTLWWpUV5IWHEB99b2ZndTUhZVVAZvbD3f+TAxtybEYD VxnVW+r2Al4Z80Sjr7bQL2ip44rGDUejLRJX6KOY/g7Sgnjo/uBwVht2/pfo80ds8twWBn4FmZZ 79+sPlzSWhhYMl/QLeOtbZZqrfhyFie0yCyOCkupZLmrTUTPij8/B0A0UXXO80FS50Q/xGd6PnM cFMTwF6crJRFluQg== X-Gm-Gg: AR+sD10GJald3vcxrt+hapSSbUdCFA6G6zj1ufsiEsHifZMTUm9TB03MeNSd7vSOdjM 4Nx6oo222xkCM+OLVQuroKEBwybYTBJOsgzfezor+Yp0eUUroaLjIbMCRHQfQEjd+ctTRBzCVek ZLEeZftc2Y0mJ4GEnNUQjkKG/gHF9t8Dfz9uG9IKAzvOsBHKv232Ic2ZfjMoWqTJoCL6a1siNZo o+uSGpjWKKSgYnKJCrh9d0/4jPaFn+wr+UpnHAM9hl+WmYruzqIYKzYFuMyTz2cRyX0ECQuqPFd xfBCC07GbD+yH/Vmf0BCAZRPoyXWNPFgwBuARypWjRBXIEbME1oM3TG0zLMLPTdtLa/xQYNXjRK 8f1Yp X-Received: by 2002:a05:6000:310b:b0:47e:1d9a:1123 with SMTP id ffacd0b85a97d-47fc81e0112mr6445746f8f.3.1785448980575; Thu, 30 Jul 2026 15:03:00 -0700 (PDT) X-Received: by 2002:a05:6000:310b:b0:47e:1d9a:1123 with SMTP id ffacd0b85a97d-47fc81e0112mr6445717f8f.3.1785448980173; Thu, 30 Jul 2026 15:03:00 -0700 (PDT) Received: from localhost ([176.43.219.221]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fc8941717sm9947002f8f.34.2026.07.30.15.02.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 15:02:59 -0700 (PDT) From: Cengiz Can To: Wolfram Sang Cc: Linus Walleij , Bartosz Golaszewski , linux-gpio@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 0/2] gpio: sloppy-logic-analyzer: fix debugfs UAF on unbind Date: Fri, 31 Jul 2026 01:02:56 +0300 Message-ID: <20260730220258.358169-1-cengiz.can@canonical.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Patch 1 fixes a use-after-free. The "trigger" debugfs file uses debugfs_create_file_unsafe() with a hand-rolled ->write that dereferences the devres-freed gpio_la_poll_priv without holding a debugfs reference, so an unbind racing a write frees the object under the handler. Switching to debugfs_create_file() makes debugfs_remove_recursive() drain the handler first. Patch 2 converts the sibling "buf_size" and "capture" files to debugfs_create_file() as well, for consistency. They were already safe via DEFINE_DEBUGFS_ATTRIBUTE(); this is the cleanup requested on v1. v1 was a single patch that fixed only "trigger". v2 splits it so the fix carries the stable tag on its own, and adds the consistency conversion as a separate cleanup. Note: while testing this I found a pre-existing deadlock in the driver (gpio_la_poll_remove() holds blob_lock across debugfs_remove_recursive(), which drains the buf_size/capture handlers that also take blob_lock). It is unrelated to this series; I will send it separately. Cengiz Can (2): gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind gpio: sloppy-logic-analyzer: use debugfs_create_file() for buf_size and capture drivers/gpio/gpio-sloppy-logic-analyzer.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) -- 2.43.0