From: Markus Probst <markus.probst@posteo.de>
To: "Miguel Ojeda" <ojeda@kernel.org>,
"Boqun Feng" <boqun@kernel.org>, "Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Andreas Hindborg" <a.hindborg@kernel.org>,
"Alice Ryhl" <aliceryhl@google.com>,
"Trevor Gross" <tmgross@umich.edu>,
"Danilo Krummrich" <dakr@kernel.org>,
"Daniel Almeida" <daniel.almeida@collabora.com>,
"Tamir Duberstein" <tamird@kernel.org>,
"Alexandre Courbot" <acourbot@nvidia.com>,
"Onur Özkan" <work@onurozkan.dev>,
"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>
Cc: linux-serial@vger.kernel.org, rust-for-linux@vger.kernel.org,
linux-kernel@vger.kernel.org,
Sashiko Bot <sashiko-bot@kernel.org>,
Markus Probst <markus.probst@posteo.de>
Subject: [PATCH v4] rust: serdev: Mitigate race conditions
Date: Sat, 05 Sep 2026 18:47:24 +0000 [thread overview]
Message-ID: <20260905-rust_serdev_fix-v4-1-31e1bbcc0c00@posteo.de> (raw)
There are currently 2 race conditions:
- in probe if `Driver::probe` returns Err
- in unbind
. In those cases the driver data will be set to NULL before the serdev
device was closed. If data is received while the driver data is dropped,
the `receive_buf_callback` might try to access the `active` mutex on a
null pointer. The race conditions can only occur if `Driver::receive` is
implemented.
The issue cannot be cleanly fixed without rewriting some logic, which
might introduce new regressions.
Temporarily disable the use of `Driver::receive`, until fixed in the
next release.
Fixes: 99f59aa82341 ("rust: add basic serial device bus abstractions")
Reported-by: Sashiko Bot <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-serial/20260905000836.C8FC91F00A3D@smtp.kernel.org/
Closes: https://lore.kernel.org/linux-serial/20260903222159.70A911F000E9@smtp.kernel.org/
Signed-off-by: Markus Probst <markus.probst@posteo.de>
---
I will submit a patch (for the next merge cycle) soon, which will
address this issue and make the probe and unbind code less convoluted.
---
Changes in v4:
- remove comments
- Link to v3: https://patch.msgid.link/20260905-rust_serdev_fix-v3-1-b86056c3f7a4@posteo.de
Changes in v3:
- mitigate it
- Link to v2: https://patch.msgid.link/20260905-rust_serdev_fix-v2-0-35dfcd06ef2e@posteo.de
Changes in v2:
- also fix race condition on unbind
- Link to v1: https://patch.msgid.link/20260905-rust_serdev_fix-v1-1-2ea92b154a6b@posteo.de
---
rust/kernel/serdev.rs | 6 +++---
samples/rust/rust_driver_serdev.rs | 13 +------------
2 files changed, 4 insertions(+), 15 deletions(-)
diff --git a/rust/kernel/serdev.rs b/rust/kernel/serdev.rs
index 17ca504b7f8d..f4c0f43b5273 100644
--- a/rust/kernel/serdev.rs
+++ b/rust/kernel/serdev.rs
@@ -148,9 +148,8 @@ fn drop(self: Pin<&mut Self>) {
impl<T: Driver> Adapter<T> {
const OPS: &'static bindings::serdev_device_ops = &bindings::serdev_device_ops {
- receive_buf: if T::HAS_RECEIVE {
- Some(Self::receive_buf_callback)
- } else {
+ receive_buf: {
+ const_assert!(!T::HAS_RECEIVE);
None
},
write_wakeup: Some(bindings::serdev_device_write_wakeup),
@@ -233,6 +232,7 @@ extern "C" fn remove_callback(sdev: *mut bindings::serdev_device) {
T::unbind(sdev, data_pinned);
}
+ #[expect(dead_code)]
extern "C" fn receive_buf_callback(
sdev: *mut bindings::serdev_device,
buf: *const u8,
diff --git a/samples/rust/rust_driver_serdev.rs b/samples/rust/rust_driver_serdev.rs
index 51b4898cd855..3fd3eef15371 100644
--- a/samples/rust/rust_driver_serdev.rs
+++ b/samples/rust/rust_driver_serdev.rs
@@ -4,10 +4,7 @@
use kernel::{
acpi,
- device::{
- Bound,
- Core, //
- },
+ device::Core,
of,
prelude::*,
serdev,
@@ -60,14 +57,6 @@ fn probe<'bound>(
Ok(Self { sdev: sdev.into() })
}
-
- fn receive<'bound>(
- sdev: &'bound serdev::Device<Bound>,
- _this: Pin<&Self>,
- data: &[u8],
- ) -> usize {
- sdev.write(data).unwrap_or_default() as usize
- }
}
impl Drop for SampleDriver {
---
base-commit: e5e04726cdd043e309677071ab1b65a4b18f422b
change-id: 20260904-rust_serdev_fix-be3ff9c8a5e8
next reply other threads:[~2026-09-05 18:47 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 18:47 Markus Probst [this message]
2026-09-05 18:53 ` [PATCH v4] rust: serdev: Mitigate race conditions sashiko-bot
2026-09-05 23:39 ` Gary Guo
2026-09-05 23:59 ` Markus Probst
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260905-rust_serdev_fix-v4-1-31e1bbcc0c00@posteo.de \
--to=markus.probst@posteo.de \
--cc=a.hindborg@kernel.org \
--cc=acourbot@nvidia.com \
--cc=aliceryhl@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun@kernel.org \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=gary@garyguo.net \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-serial@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=sashiko-bot@kernel.org \
--cc=tamird@kernel.org \
--cc=tmgross@umich.edu \
--cc=work@onurozkan.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.