From: "Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>
To: Danilo Krummrich <dakr@kernel.org>
Cc: "Russell King" <linux@armlinux.org.uk>,
"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
"Rafael J. Wysocki" <rafael@kernel.org>,
"Ioana Ciornei" <ioana.ciornei@nxp.com>,
"Nipun Gupta" <nipun.gupta@amd.com>,
"Nikhil Agarwal" <nikhil.agarwal@amd.com>,
"K. Y. Srinivasan" <kys@microsoft.com>,
"Haiyang Zhang" <haiyangz@microsoft.com>,
"Wei Liu" <wei.liu@kernel.org>,
"Dexuan Cui" <decui@microsoft.com>,
"Long Li" <longli@microsoft.com>,
"Bjorn Helgaas" <bhelgaas@google.com>,
"Armin Wolf" <W_Armin@gmx.de>,
"Bjorn Andersson" <andersson@kernel.org>,
"Mathieu Poirier" <mathieu.poirier@linaro.org>,
"Vineeth Vijayan" <vneethv@linux.ibm.com>,
"Peter Oberparleiter" <oberpar@linux.ibm.com>,
"Heiko Carstens" <hca@linux.ibm.com>,
"Vasily Gorbik" <gor@linux.ibm.com>,
"Alexander Gordeev" <agordeev@linux.ibm.com>,
"Christian Borntraeger" <borntraeger@linux.ibm.com>,
"Sven Schnelle" <svens@linux.ibm.com>,
"Harald Freudenberger" <freude@linux.ibm.com>,
"Holger Dengler" <dengler@linux.ibm.com>,
"Mark Brown" <broonie@kernel.org>,
"Michael S. Tsirkin" <mst@redhat.com>,
"Jason Wang" <jasowang@redhat.com>,
"Xuan Zhuo" <xuanzhuo@linux.alibaba.com>,
"Eugenio Pérez" <eperezma@redhat.com>,
"Alex Williamson" <alex@shazbot.org>,
"Juergen Gross" <jgross@suse.com>,
"Stefano Stabellini" <sstabellini@kernel.org>,
"Oleksandr Tyshchenko" <oleksandr_tyshchenko@epam.com>,
"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
LKML <linux-kernel@vger.kernel.org>,
driver-core@lists.linux.dev, linuxppc-dev@lists.ozlabs.org,
linux-hyperv@vger.kernel.org, linux-pci@vger.kernel.org,
platform-driver-x86@vger.kernel.org,
linux-arm-msm@vger.kernel.org, linux-remoteproc@vger.kernel.org,
linux-s390@vger.kernel.org, linux-spi@vger.kernel.org,
virtualization@lists.linux.dev, kvm@vger.kernel.org,
xen-devel@lists.xenproject.org,
linux-arm-kernel@lists.infradead.org,
"Gui-Dong Han" <hanguidong02@gmail.com>
Subject: Re: [PATCH 06/12] platform/wmi: use generic driver_override infrastructure
Date: Tue, 31 Mar 2026 18:02:33 +0300 (EEST) [thread overview]
Message-ID: <f15629e4-ef8f-b1b6-0158-064f40f111da@linux.intel.com> (raw)
In-Reply-To: <20260324005919.2408620-7-dakr@kernel.org>
On Tue, 24 Mar 2026, Danilo Krummrich wrote:
> When a driver is probed through __driver_attach(), the bus' match()
> callback is called without the device lock held, thus accessing the
> driver_override field without a lock, which can cause a UAF.
>
> Fix this by using the driver-core driver_override infrastructure taking
> care of proper locking internally.
>
> Note that calling match() from __driver_attach() without the device lock
> held is intentional. [1]
>
> Link: https://lore.kernel.org/driver-core/DGRGTIRHA62X.3RY09D9SOK77P@kernel.org/ [1]
> Reported-by: Gui-Dong Han <hanguidong02@gmail.com>
> Closes: https://bugzilla.kernel.org/show_bug.cgi?id=220789
> Fixes: 12046f8c77e0 ("platform/x86: wmi: Add driver_override support")
> Signed-off-by: Danilo Krummrich <dakr@kernel.org>
> ---
> drivers/platform/wmi/core.c | 36 +++++-------------------------------
> include/linux/wmi.h | 4 ----
> 2 files changed, 5 insertions(+), 35 deletions(-)
>
> diff --git a/drivers/platform/wmi/core.c b/drivers/platform/wmi/core.c
> index b8e6b9a421c6..750e3619724e 100644
> --- a/drivers/platform/wmi/core.c
> +++ b/drivers/platform/wmi/core.c
> @@ -842,39 +842,11 @@ static ssize_t expensive_show(struct device *dev,
> }
> static DEVICE_ATTR_RO(expensive);
>
> -static ssize_t driver_override_show(struct device *dev, struct device_attribute *attr,
> - char *buf)
> -{
> - struct wmi_device *wdev = to_wmi_device(dev);
> - ssize_t ret;
> -
> - device_lock(dev);
> - ret = sysfs_emit(buf, "%s\n", wdev->driver_override);
> - device_unlock(dev);
> -
> - return ret;
> -}
> -
> -static ssize_t driver_override_store(struct device *dev, struct device_attribute *attr,
> - const char *buf, size_t count)
> -{
> - struct wmi_device *wdev = to_wmi_device(dev);
> - int ret;
> -
> - ret = driver_set_override(dev, &wdev->driver_override, buf, count);
> - if (ret < 0)
> - return ret;
> -
> - return count;
> -}
> -static DEVICE_ATTR_RW(driver_override);
> -
> static struct attribute *wmi_attrs[] = {
> &dev_attr_modalias.attr,
> &dev_attr_guid.attr,
> &dev_attr_instance_count.attr,
> &dev_attr_expensive.attr,
> - &dev_attr_driver_override.attr,
> NULL
> };
> ATTRIBUTE_GROUPS(wmi);
> @@ -943,7 +915,6 @@ static void wmi_dev_release(struct device *dev)
> {
> struct wmi_block *wblock = dev_to_wblock(dev);
>
> - kfree(wblock->dev.driver_override);
> kfree(wblock);
> }
>
> @@ -952,10 +923,12 @@ static int wmi_dev_match(struct device *dev, const struct device_driver *driver)
> const struct wmi_driver *wmi_driver = to_wmi_driver(driver);
> struct wmi_block *wblock = dev_to_wblock(dev);
> const struct wmi_device_id *id = wmi_driver->id_table;
> + int ret;
>
> /* When driver_override is set, only bind to the matching driver */
> - if (wblock->dev.driver_override)
> - return !strcmp(wblock->dev.driver_override, driver->name);
> + ret = device_match_driver_override(dev, driver);
> + if (ret >= 0)
> + return ret;
>
> if (id == NULL)
> return 0;
> @@ -1076,6 +1049,7 @@ static struct class wmi_bus_class = {
> static const struct bus_type wmi_bus_type = {
> .name = "wmi",
> .dev_groups = wmi_groups,
> + .driver_override = true,
> .match = wmi_dev_match,
> .uevent = wmi_dev_uevent,
> .probe = wmi_dev_probe,
> diff --git a/include/linux/wmi.h b/include/linux/wmi.h
> index 75cb0c7cfe57..14fb644e1701 100644
> --- a/include/linux/wmi.h
> +++ b/include/linux/wmi.h
> @@ -18,16 +18,12 @@
> * struct wmi_device - WMI device structure
> * @dev: Device associated with this WMI device
> * @setable: True for devices implementing the Set Control Method
> - * @driver_override: Driver name to force a match; do not set directly,
> - * because core frees it; use driver_set_override() to
> - * set or clear it.
> *
> * This represents WMI devices discovered by the WMI driver core.
> */
> struct wmi_device {
> struct device dev;
> bool setable;
> - const char *driver_override;
> };
>
> /**
>
Hi,
I tried applying this to platform-drivers tree but it failed to compile so
I ended up dropping the changed.
--
i.
next prev parent reply other threads:[~2026-03-31 15:02 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-24 0:59 [PATCH 00/12] treewide: Convert buses to use generic driver_override Danilo Krummrich
2026-03-24 0:59 ` [PATCH 01/12] amba: use generic driver_override infrastructure Danilo Krummrich
2026-03-24 0:59 ` [PATCH 02/12] bus: fsl-mc: " Danilo Krummrich
2026-03-25 12:01 ` Ioana Ciornei
2026-03-28 12:10 ` Christophe Leroy (CS GROUP)
2026-04-04 16:56 ` Christophe Leroy (CS GROUP)
2026-03-24 0:59 ` [PATCH 03/12] cdx: " Danilo Krummrich
2026-03-24 0:59 ` [PATCH 04/12] hv: vmbus: " Danilo Krummrich
2026-03-25 17:28 ` Michael Kelley
2026-04-04 15:01 ` [PATCH v2] Drivers: " Danilo Krummrich
2026-03-24 0:59 ` [PATCH 05/12] PCI: " Danilo Krummrich
2026-03-25 3:08 ` Gui-Dong Han
2026-03-26 18:08 ` Bjorn Helgaas
2026-03-30 16:28 ` Danilo Krummrich
2026-03-30 17:38 ` Danilo Krummrich
2026-03-30 20:10 ` Alex Williamson
2026-03-31 8:06 ` Danilo Krummrich
2026-03-31 8:22 ` Danilo Krummrich
2026-03-31 19:18 ` Alex Williamson
2026-03-24 0:59 ` [PATCH 06/12] platform/wmi: " Danilo Krummrich
2026-03-24 19:41 ` Armin Wolf
2026-03-31 15:02 ` Ilpo Järvinen [this message]
2026-03-31 15:43 ` Danilo Krummrich
2026-03-31 15:50 ` Ilpo Järvinen
2026-03-24 0:59 ` [PATCH 07/12] rpmsg: " Danilo Krummrich
2026-03-25 15:49 ` Mathieu Poirier
2026-03-24 0:59 ` [PATCH 08/12] vdpa: " Danilo Krummrich
2026-03-25 10:17 ` Eugenio Perez Martin
2026-03-24 0:59 ` [PATCH 09/12] s390/cio: " Danilo Krummrich
2026-03-26 9:43 ` Vineeth Vijayan
2026-03-24 0:59 ` [PATCH 10/12] s390/ap: " Danilo Krummrich
2026-03-24 12:41 ` Harald Freudenberger
2026-03-24 12:58 ` Holger Dengler
2026-03-24 0:59 ` [PATCH 11/12] spi: " Danilo Krummrich
2026-03-24 0:59 ` [PATCH 12/12] driver core: remove driver_set_override() Danilo Krummrich
2026-03-24 8:09 ` Greg Kroah-Hartman
2026-03-24 15:00 ` (subset) [PATCH 00/12] treewide: Convert buses to use generic driver_override Mark Brown
2026-03-25 9:29 ` Michael S. Tsirkin
2026-03-26 17:38 ` Danilo Krummrich
2026-04-04 15:07 ` (subset) " Danilo Krummrich
2026-04-04 16:58 ` Christophe Leroy (CS GROUP)
2026-04-04 17:04 ` Danilo Krummrich
2026-04-04 17:09 ` Christophe Leroy (CS GROUP)
2026-04-04 19:20 ` Danilo Krummrich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f15629e4-ef8f-b1b6-0158-064f40f111da@linux.intel.com \
--to=ilpo.jarvinen@linux.intel.com \
--cc=W_Armin@gmx.de \
--cc=agordeev@linux.ibm.com \
--cc=alex@shazbot.org \
--cc=andersson@kernel.org \
--cc=bhelgaas@google.com \
--cc=borntraeger@linux.ibm.com \
--cc=broonie@kernel.org \
--cc=chleroy@kernel.org \
--cc=dakr@kernel.org \
--cc=decui@microsoft.com \
--cc=dengler@linux.ibm.com \
--cc=driver-core@lists.linux.dev \
--cc=eperezma@redhat.com \
--cc=freude@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=gregkh@linuxfoundation.org \
--cc=haiyangz@microsoft.com \
--cc=hanguidong02@gmail.com \
--cc=hca@linux.ibm.com \
--cc=ioana.ciornei@nxp.com \
--cc=jasowang@redhat.com \
--cc=jgross@suse.com \
--cc=kvm@vger.kernel.org \
--cc=kys@microsoft.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-hyperv@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux-remoteproc@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=linux-spi@vger.kernel.org \
--cc=linux@armlinux.org.uk \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=longli@microsoft.com \
--cc=mathieu.poirier@linaro.org \
--cc=mst@redhat.com \
--cc=nikhil.agarwal@amd.com \
--cc=nipun.gupta@amd.com \
--cc=oberpar@linux.ibm.com \
--cc=oleksandr_tyshchenko@epam.com \
--cc=platform-driver-x86@vger.kernel.org \
--cc=rafael@kernel.org \
--cc=sstabellini@kernel.org \
--cc=svens@linux.ibm.com \
--cc=virtualization@lists.linux.dev \
--cc=vneethv@linux.ibm.com \
--cc=wei.liu@kernel.org \
--cc=xen-devel@lists.xenproject.org \
--cc=xuanzhuo@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.