All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Danilo Krummrich" <dakr@kernel.org>
To: "Mukesh Ojha" <mukesh.ojha@oss.qualcomm.com>
Cc: "Luis Chamberlain" <mcgrof@kernel.org>,
	"Russ Weight" <russ.weight@linux.dev>,
	"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
	"Rafael J. Wysocki" <rafael@kernel.org>,
	"Anirudh Rayabharam" <mail@anirudhrb.com>,
	"Shuah Khan" <skhan@linuxfoundation.org>,
	<driver-core@lists.linux.dev>, <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH] firmware_loader: do not queue completed sysfs fallback requests
Date: Mon, 03 Aug 2026 20:40:06 +0200	[thread overview]
Message-ID: <DKFJ13ZEUX8M.29CDWH9A0OF6U@kernel.org> (raw)
In-Reply-To: <20260803181237.kkfi4mtmmd637e7w@hu-mojha-hyd.qualcomm.com>

On Mon Aug 3, 2026 at 8:12 PM CEST, Mukesh Ojha wrote:
> On Thu, Jul 16, 2026 at 01:46:01PM +0530, Mukesh Ojha wrote:
>> fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to
>> pending_fw_head. device_add() publishes the fallback loading interface, so
>> a userspace helper which discovers the device by scanning sysfs can write 0
>> to the loading attribute and complete the request before it is queued as
>> pending.
>> 
>> In that interleaving firmware_loading_store() calls fw_state_done() while
>> pending_list still points to itself, so it cannot remove an entry from
>> pending_fw_head. The subsequent unconditional list_add() then queues an
>> already-completed fw_priv. Once the request is released, pending_fw_head
>> can retain a pointer to freed memory and the next fallback request can
>> fault while validating the list.
>> 
>> Only in-flight fallback requests need suspend or reboot abort handling. If
>> the request is already DONE after device_add(), return success from the
>> fallback path without sending another uevent, waiting again, or queueing it
>> as pending. This preserves the invariant that pending_fw_head contains only
>> active fallback requests.
>> 
>> Fixes: 75d95e2e39b2 ("firmware_loader: fix use-after-free in firmware_fallback_sysfs")
>> Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
>
> Can we consider this fix for this mentioned issue ?

Sure, how did you come across this issue?

>> ---
>>  drivers/base/firmware_loader/fallback.c | 9 +++++++++
>>  1 file changed, 9 insertions(+)
>> 
>> diff --git a/drivers/base/firmware_loader/fallback.c b/drivers/base/firmware_loader/fallback.c
>> index 3ef0b312ae71..ffe1b3784788 100644
>> --- a/drivers/base/firmware_loader/fallback.c
>> +++ b/drivers/base/firmware_loader/fallback.c
>> @@ -95,6 +95,15 @@ static int fw_load_sysfs_fallback(struct fw_sysfs *fw_sysfs, long timeout)
>>  		retval = -EINTR;
>>  		goto out;
>>  	}
>> +	/*
>> +	 * device_add() exposes the loading interface before pending_list is
>> +	 * linked into pending_fw_head, so fw_state_done() may run first.
>> +	 */
>> +	if (fw_state_is_done(fw_priv)) {
>> +		mutex_unlock(&fw_lock);
>> +		goto out;
>> +	}
>> +
>>  	list_add(&fw_priv->pending_list, &pending_fw_head);
>>  	mutex_unlock(&fw_lock);
>>  
>> -- 
>> 2.53.0
>> 
>
> -- 
> -Mukesh Ojha


  reply	other threads:[~2026-08-03 18:40 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-16  8:16 [PATCH] firmware_loader: do not queue completed sysfs fallback requests Mukesh Ojha
2026-08-03 18:12 ` Mukesh Ojha
2026-08-03 18:40   ` Danilo Krummrich [this message]
2026-08-04 13:29     ` Mukesh Ojha
2026-08-06 21:38 ` Danilo Krummrich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DKFJ13ZEUX8M.29CDWH9A0OF6U@kernel.org \
    --to=dakr@kernel.org \
    --cc=driver-core@lists.linux.dev \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mail@anirudhrb.com \
    --cc=mcgrof@kernel.org \
    --cc=mukesh.ojha@oss.qualcomm.com \
    --cc=rafael@kernel.org \
    --cc=russ.weight@linux.dev \
    --cc=skhan@linuxfoundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.