From: Gregory Price <gourry@gourry.net>
To: Dave Jiang <dave.jiang@intel.com>
Cc: linux-cxl@vger.kernel.org, dave@stgolabs.net, jic23@kernel.org,
alison.schofield@intel.com, ming.li@zohomail.com,
icheng@nvidia.com, stable@vger.kernel.org,
Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Subject: Re: [PATCH v2 1/2] cxl/port: Clear cached dport pointers when a dport is removed
Date: Tue, 29 Sep 2026 12:45:06 -0400 [thread overview]
Message-ID: <arvrAEJ14KRtypKt@gourry-fedora-PF4VCD3F> (raw)
In-Reply-To: <20260928230341.2315153-2-dave.jiang@intel.com>
On Mon, Sep 28, 2026 at 04:03:40PM -0700, Dave Jiang wrote:
> Switch decoders cache dport pointers in cxlsd->target[], and nothing
> clears them when a dport is freed. Readers then dereference freed memory.
>
> KASAN caught it under a cxl_test load/unload loop with concurrent sysfs
> reads (abbreviated).
>
> Clear the matching slots from cxl_dport_remove(), walking the port's
> decoders the way cxl_port_update_decoder_targets() does on the add side.
> Scan all nr_targets slots, the target[] allocation size, and clear every
> hit.
>
> Fixes: 8330671c57c7 ("cxl: Add helper to delete dport")
> Cc: stable@vger.kernel.org
> Signed-off-by: Dave Jiang <dave.jiang@intel.com>
> Assisted-by: LLM
> Reviewed-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Reviewed-by: Gregory Price (Meta) <gourry@gourry.net>
next prev parent reply other threads:[~2026-09-29 16:45 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 23:03 [PATCH v2 0/2] cxl: dport fixes from sashiko reports Dave Jiang
2026-09-28 23:03 ` [PATCH v2 1/2] cxl/port: Clear cached dport pointers when a dport is removed Dave Jiang
2026-09-29 2:57 ` Li Ming
2026-09-29 16:45 ` Gregory Price [this message]
2026-09-28 23:03 ` [PATCH v2 2/2] cxl/core: Hold the dport host lock across dport lookup and use Dave Jiang
2026-09-29 9:21 ` Li Ming
2026-09-29 15:57 ` Dave Jiang
2026-09-30 5:14 ` Li Ming
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arvrAEJ14KRtypKt@gourry-fedora-PF4VCD3F \
--to=gourry@gourry.net \
--cc=alison.schofield@intel.com \
--cc=dave.jiang@intel.com \
--cc=dave@stgolabs.net \
--cc=icheng@nvidia.com \
--cc=jic23@kernel.org \
--cc=jonathan.cameron@oss.qualcomm.com \
--cc=linux-cxl@vger.kernel.org \
--cc=ming.li@zohomail.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.