From: "Gary Guo" <gary@garyguo.net>
To: "Markus Probst" <markus.probst@posteo.de>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Boqun Feng" <boqun@kernel.org>, "Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Andreas Hindborg" <a.hindborg@kernel.org>,
"Alice Ryhl" <aliceryhl@google.com>,
"Trevor Gross" <tmgross@umich.edu>,
"Danilo Krummrich" <dakr@kernel.org>,
"Daniel Almeida" <daniel.almeida@collabora.com>,
"Tamir Duberstein" <tamird@kernel.org>,
"Alexandre Courbot" <acourbot@nvidia.com>,
"Onur Özkan" <work@onurozkan.dev>,
"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>
Cc: <linux-serial@vger.kernel.org>, <rust-for-linux@vger.kernel.org>,
<linux-kernel@vger.kernel.org>,
"Sashiko Bot" <sashiko-bot@kernel.org>
Subject: Re: [PATCH] rust: serdev: Fix race condition on driver probe fail
Date: Sat, 05 Sep 2026 15:24:24 +0100 [thread overview]
Message-ID: <DL7G9BAEFESY.2LS09S43WOK9V@garyguo.net> (raw)
In-Reply-To: <1b247f730001ea39b6e4044f5673e1a01e187362.camel@posteo.de>
On Sat Sep 5, 2026 at 1:22 AM BST, Markus Probst wrote:
> On Fri, 2026-09-04 at 23:54 +0000, Markus Probst wrote:
>> If `Driver::probe` fails, the pointer to the driver data (`PrivateData`)
>> will first be set to NULL by `drvdata_obtain` and only after that the
>> serdev device will be closed by Drop. Thus there is a small window in
>> which the serdev device is still open, but the pointer to the driver data
>> is NULL. Therefore it is possible that `receive_buf_callback` might try to
>> access the `active` mutex on a null pointer.
> It seems, Sashiko found the same issue in a different unrelated place
> too (while reviewing this patch):
>
> https://sashiko.dev/#/patchset/20260905-rust_serdev_fix-v1-1-2ea92b154a6b%40posteo.de
>
> Unfortunately, I cannot fix this one so easily, because the serdev
> device needs to be open for the entire lifetime of the "real" driver
> data (Driver::Data).
What would go wrong if the device is closed before destroying the driver data?
Best,
Gary
next prev parent reply other threads:[~2026-09-05 14:24 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 23:54 [PATCH] rust: serdev: Fix race condition on driver probe fail Markus Probst
2026-09-05 0:08 ` sashiko-bot
2026-09-05 0:22 ` Markus Probst
2026-09-05 14:24 ` Gary Guo [this message]
2026-09-05 14:29 ` Markus Probst
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DL7G9BAEFESY.2LS09S43WOK9V@garyguo.net \
--to=gary@garyguo.net \
--cc=a.hindborg@kernel.org \
--cc=acourbot@nvidia.com \
--cc=aliceryhl@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun@kernel.org \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-serial@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=markus.probst@posteo.de \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=sashiko-bot@kernel.org \
--cc=tamird@kernel.org \
--cc=tmgross@umich.edu \
--cc=work@onurozkan.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.