All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] watchdog: shwdt: register device only after full driver init
@ 2026-09-14 12:36 Cong Nguyen
  2026-09-14 12:48 ` sashiko-bot
  2026-09-17  0:23 ` Guenter Roeck
  0 siblings, 2 replies; 3+ messages in thread
From: Cong Nguyen @ 2026-09-14 12:36 UTC (permalink / raw)
  To: Wim Van Sebroeck; +Cc: Guenter Roeck, linux-watchdog, linux-kernel

sh_wdt_probe() calls watchdog_register_device() -- exposing
/dev/watchdogN -- before timer_setup() and pm_runtime_enable() run. A
start command landing in that window calls mod_timer() on an
uninitialized timer (NULL ->function) and resumes via
pm_runtime_get_sync() before PM is enabled.

Move timer_setup() and pm_runtime_enable() before the register call,
matching the order already used by rzg2l_wdt.c/rzv2h_wdt.c. Add
pm_runtime_disable() on the now-possible post-enable register-failure
path.

Fixes: 8f5585ec3d17 ("watchdog: shwdt: driver model conversion.")
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
---
 drivers/watchdog/shwdt.c | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/drivers/watchdog/shwdt.c b/drivers/watchdog/shwdt.c
index 719f100aae60..c22b8e760476 100644
--- a/drivers/watchdog/shwdt.c
+++ b/drivers/watchdog/shwdt.c
@@ -263,19 +263,20 @@ static int sh_wdt_probe(struct platform_device *pdev)
 	dev_info(&pdev->dev, "configured with heartbeat=%d sec (nowayout=%d)\n",
 		 sh_wdt_dev.timeout, nowayout);
 
+	timer_setup(&wdt->timer, sh_wdt_ping, 0);
+	wdt->timer.expires	= next_ping_period(clock_division_ratio);
+
+	pm_runtime_enable(&pdev->dev);
+
 	rc = watchdog_register_device(&sh_wdt_dev);
 	if (unlikely(rc)) {
 		dev_err(&pdev->dev, "Can't register watchdog (err=%d)\n", rc);
+		pm_runtime_disable(&pdev->dev);
 		return rc;
 	}
 
-	timer_setup(&wdt->timer, sh_wdt_ping, 0);
-	wdt->timer.expires	= next_ping_period(clock_division_ratio);
-
 	dev_info(&pdev->dev, "initialized.\n");
 
-	pm_runtime_enable(&pdev->dev);
-
 	return 0;
 }
 
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] watchdog: shwdt: register device only after full driver init
  2026-09-14 12:36 [PATCH] watchdog: shwdt: register device only after full driver init Cong Nguyen
@ 2026-09-14 12:48 ` sashiko-bot
  2026-09-17  0:23 ` Guenter Roeck
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-14 12:48 UTC (permalink / raw)
  To: Cong Nguyen; +Cc: linux-watchdog

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:

Pre-existing issues:
- [High] Missing timer synchronization in `sh_wdt_remove` leads to a use-after-free when the `wdt` structure is automatically freed.
- [High] Calling non-synchronous `timer_delete` while holding `wdt->lock` in `sh_wdt_stop` allows the timer callback to execute concurrently, accessing suspended hardware and re-arming itself.
- [High] `sh_wdt_start` ignores the return values of `pm_runtime_get_sync` and `clk_enable`, potentially accessing hardware registers while powered down.
--

commit f766a8cc3f43e37c436ed7a87ffc702a473f6839
Author: Cong Nguyen <congnt264@gmail.com>

watchdog: shwdt: register device only after full driver init
    
sh_wdt_probe() calls watchdog_register_device() -- exposing
/dev/watchdogN -- before timer_setup() and pm_runtime_enable() run. A
start command landing in that window calls mod_timer() on an
uninitialized timer (NULL ->function) and resumes via
pm_runtime_get_sync() before PM is enabled.
    
Move timer_setup() and pm_runtime_enable() before the register call,
matching the order already used by rzg2l_wdt.c/rzv2h_wdt.c. Add
pm_runtime_disable() on the now-possible post-enable register-failure
path.

> diff --git a/drivers/watchdog/shwdt.c b/drivers/watchdog/shwdt.c
> index 719f100aae60d..c22b8e7604765 100644
> --- a/drivers/watchdog/shwdt.c
> +++ b/drivers/watchdog/shwdt.c
> @@ -263,19 +263,20 @@ static int sh_wdt_probe(struct platform_device *pdev)
>  	dev_info(&pdev->dev, "configured with heartbeat=%d sec (nowayout=%d)\n",
>  		 sh_wdt_dev.timeout, nowayout);
>  
> +	timer_setup(&wdt->timer, sh_wdt_ping, 0);
> +	wdt->timer.expires	= next_ping_period(clock_division_ratio);
> +
> +	pm_runtime_enable(&pdev->dev);
> +
>  	rc = watchdog_register_device(&sh_wdt_dev);
>  	if (unlikely(rc)) {
>  		dev_err(&pdev->dev, "Can't register watchdog (err=%d)\n", rc);
> +		pm_runtime_disable(&pdev->dev);
>  		return rc;
>  	}
>  
> -	timer_setup(&wdt->timer, sh_wdt_ping, 0);
> -	wdt->timer.expires	= next_ping_period(clock_division_ratio);
> -
>  	dev_info(&pdev->dev, "initialized.\n");
>  
> -	pm_runtime_enable(&pdev->dev);
> -
>  	return 0;
>  }

[Severity: High]
This is a pre-existing issue, but missing timer synchronization in
sh_wdt_remove() could lead to a use-after-free when the wdt structure is
automatically freed:

drivers/watchdog/shwdt.c:sh_wdt_remove() {
	watchdog_unregister_device(&sh_wdt_dev);

	pm_runtime_disable(&pdev->dev);
}

If the driver is unbound while the watchdog timer is active, sh_wdt_remove()
completes and returns without stopping or synchronizing the timer. The devres
framework then immediately frees the wdt structure allocated via
devm_kzalloc().

Could the lingering asynchronous timer eventually fire and dereference the
freed memory in sh_wdt_ping()? Would it be safer to explicitly stop and
synchronize the timer here before returning?

[Severity: High]
This isn't a bug introduced by this patch, but calling non-synchronous
timer_delete() while holding wdt->lock in sh_wdt_stop() allows the timer
callback to execute concurrently:

drivers/watchdog/shwdt.c:sh_wdt_stop() {
...
	spin_lock_irqsave(&wdt->lock, flags);

	timer_delete(&wdt->timer);

	csr = sh_wdt_read_csr();
	csr &= ~WTCSR_TME;
	sh_wdt_write_csr(csr);

	spin_unlock_irqrestore(&wdt->lock, flags);

	clk_disable(wdt->clk);
	pm_runtime_put_sync(wdt->dev);
...
}

If sh_wdt_ping() runs on CPU 1 just as sh_wdt_stop() runs on CPU 0, CPU 1
blocks on wdt->lock. CPU 0 calls timer_delete(), disables the clock,
drops the lock, and calls pm_runtime_put_sync().

CPU 1 then acquires the lock and continues execution in sh_wdt_ping():

drivers/watchdog/shwdt.c:sh_wdt_ping() {
...
		csr = sh_wdt_read_csr();
		csr &= ~WTCSR_IOVF;
		sh_wdt_write_csr(csr);

		sh_wdt_write_cnt(0);

		mod_timer(&wdt->timer, next_ping_period(clock_division_ratio));
...
}

Can this sequence allow CPU 1 to access the now unclocked and suspended
hardware registers, and then call mod_timer() to blindly re-arm the callback?
Note that simply changing timer_delete() to timer_delete_sync() inside the
spinlock would cause a deadlock against the callback.

[Severity: High]
This is a pre-existing issue, but sh_wdt_start() ignores the return values of
pm_runtime_get_sync() and clk_enable():

drivers/watchdog/shwdt.c:sh_wdt_start() {
...
	pm_runtime_get_sync(wdt->dev);
	clk_enable(wdt->clk);

	spin_lock_irqsave(&wdt->lock, flags);
...
}

If either fails, the device remains suspended or unclocked, but the code
proceeds to read and write to wdt->base.

Could this result in a bus fault due to accessing unclocked or powered-down
hardware if power or clock management fails when the device is opened?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260914123609.2186477-1-congnt264@gmail.com?part=1

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] watchdog: shwdt: register device only after full driver init
  2026-09-14 12:36 [PATCH] watchdog: shwdt: register device only after full driver init Cong Nguyen
  2026-09-14 12:48 ` sashiko-bot
@ 2026-09-17  0:23 ` Guenter Roeck
  1 sibling, 0 replies; 3+ messages in thread
From: Guenter Roeck @ 2026-09-17  0:23 UTC (permalink / raw)
  To: Cong Nguyen; +Cc: Wim Van Sebroeck, linux-watchdog, linux-kernel

On Mon, Sep 14, 2026 at 07:36:09PM +0700, Cong Nguyen wrote:
> sh_wdt_probe() calls watchdog_register_device() -- exposing
> /dev/watchdogN -- before timer_setup() and pm_runtime_enable() run. A
> start command landing in that window calls mod_timer() on an
> uninitialized timer (NULL ->function) and resumes via
> pm_runtime_get_sync() before PM is enabled.
> 
> Move timer_setup() and pm_runtime_enable() before the register call,
> matching the order already used by rzg2l_wdt.c/rzv2h_wdt.c. Add
> pm_runtime_disable() on the now-possible post-enable register-failure
> path.
> 
> Fixes: 8f5585ec3d17 ("watchdog: shwdt: driver model conversion.")
> Assisted-by: Claude:claude-opus-4
> Signed-off-by: Cong Nguyen <congnt264@gmail.com>

The other problems in this driver make me wonder if this change
is worth the trouble. Is this an actually observed problem ?
Because if not it would be better to leave the driver alone.
If this _is_ an actually observed problem, the code should be
rearranged to depend on the watchdog core for timer handling.

Thanks,
Guenter

> ---
>  drivers/watchdog/shwdt.c | 11 ++++++-----
>  1 file changed, 6 insertions(+), 5 deletions(-)
> 
> diff --git a/drivers/watchdog/shwdt.c b/drivers/watchdog/shwdt.c
> index 719f100aae60..c22b8e760476 100644
> --- a/drivers/watchdog/shwdt.c
> +++ b/drivers/watchdog/shwdt.c
> @@ -263,19 +263,20 @@ static int sh_wdt_probe(struct platform_device *pdev)
>  	dev_info(&pdev->dev, "configured with heartbeat=%d sec (nowayout=%d)\n",
>  		 sh_wdt_dev.timeout, nowayout);
>  
> +	timer_setup(&wdt->timer, sh_wdt_ping, 0);
> +	wdt->timer.expires	= next_ping_period(clock_division_ratio);
> +
> +	pm_runtime_enable(&pdev->dev);
> +
>  	rc = watchdog_register_device(&sh_wdt_dev);
>  	if (unlikely(rc)) {
>  		dev_err(&pdev->dev, "Can't register watchdog (err=%d)\n", rc);
> +		pm_runtime_disable(&pdev->dev);
>  		return rc;
>  	}
>  
> -	timer_setup(&wdt->timer, sh_wdt_ping, 0);
> -	wdt->timer.expires	= next_ping_period(clock_division_ratio);
> -
>  	dev_info(&pdev->dev, "initialized.\n");
>  
> -	pm_runtime_enable(&pdev->dev);
> -
>  	return 0;
>  }
>  

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-17  0:23 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-14 12:36 [PATCH] watchdog: shwdt: register device only after full driver init Cong Nguyen
2026-09-14 12:48 ` sashiko-bot
2026-09-17  0:23 ` Guenter Roeck

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.