All of lore.kernel.org
 help / color / mirror / Atom feed
From: Guenter Roeck <linux@roeck-us.net>
To: Yibo Tan <lhfff@tju.edu.cn>
Cc: Paul Barker <pbarker@konsulko.com>,
	linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v1] hwmon: (pwm-fan) Stop RPM timer before freeing tach data
Date: Fri, 11 Sep 2026 07:50:08 -0700	[thread overview]
Message-ID: <6bd382f6-5e41-435e-8ebe-2f5598a393bb@roeck-us.net> (raw)
In-Reply-To: <20260911071809.130151-1-lhfff@tju.edu.cn>

On Fri, Sep 11, 2026 at 03:18:09PM +0800, Yibo Tan wrote:
> sample_timer() rearms the RPM timer and accesses the devm-managed
> ctx->tachs and ctx->pulses_per_revolution arrays. The cleanup action
> which stops the timer is registered before those arrays are allocated.
> 
> Since devres releases entries in reverse order, driver detach can free
> the arrays before pwm_fan_cleanup() shuts down the timer. A timer expiry
> in that window accesses the freed tach data.
> 
> With a KASAN kernel, a test-only kprobe delayed entry to
> pwm_fan_cleanup() while normal sysfs unbind ran. Each of three runs
> reported three four-byte reads and two four-byte writes in sample_timer()
> after its backing devm allocations had been freed. The helper did not
> invoke the timer callback, cleanup actions or free functions.
> 
> With the fix, three matching unbind runs completed without KASAN, BUG,
> WARNING, Oops or panic. Instrumentation confirmed that timer retirement
> completed before the first timer backing allocation was released.
> 
> Split timer retirement from the power cleanup and register its devres
> action after the timer backing data and IRQ actions are installed. This
> preserves the early power rollback action while ensuring the timer is
> retired before its backing data is released. Use timer_shutdown_sync()
> because the callback can rearm itself.
> 
> Fixes: 01695410d452 ("hwmon: (pwm-fan) Store tach data separately")
> Cc: stable@vger.kernel.org
> Assisted-by: Codex:GPT-5
> Signed-off-by: Yibo Tan <lhfff@tju.edu.cn>

Applied.

Thanks,
Guenter

      parent reply	other threads:[~2026-09-11 14:50 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-11  7:18 [PATCH v1] hwmon: (pwm-fan) Stop RPM timer before freeing tach data Yibo Tan
2026-09-11  7:30 ` sashiko-bot
2026-09-11 14:50 ` Guenter Roeck [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6bd382f6-5e41-435e-8ebe-2f5598a393bb@roeck-us.net \
    --to=linux@roeck-us.net \
    --cc=lhfff@tju.edu.cn \
    --cc=linux-hwmon@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pbarker@konsulko.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.