From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 72CE9C7618A for ; Mon, 20 Mar 2023 12:09:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:Message-ID:MIME-Version:References: In-Reply-To:Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=QZCuVPTFjoyUbNxbJkq99RKRsnDb7LvQERJtKokFzLQ=; b=UfqbOwpwcT7Eak TNGlt4GL4bTK9X8GDEVMnuayqI79eBn76b1Q5XHCTqtEQfYGdfs2d6aeNGIF9+Bsev4jTXXWbUv6l ha9t3KB+kKHfTz8E2B6ux1tGkG5hU/FWrcvm0rLDUze5GUT9N/FvNveB9DXDyPj2zoriynvOzukuB u4UO8/Yd71wjbigF6CrOfoO62420N1wKL269IGqzsBq0wwhPN3TcGHVV0xJ1EDiZoPzEZCJJ7TXMt 1M6cInIpBO6SamT/Uem8SXh9H2O2vTdTdeA7a5Wx0LHMbcAE6FyN8u3s1Cm7U1SRGlA4KToU0sNW2 V9m1P7NebQh46JIOx1UA==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1peEJC-008vyb-2u; Mon, 20 Mar 2023 12:08:14 +0000 Received: from m12.mail.163.com ([220.181.12.216] helo=163.com) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1peEJ9-008vxT-02 for linux-arm-kernel@lists.infradead.org; Mon, 20 Mar 2023 12:08:13 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=163.com; s=s110527; h=Date:From:Subject:Content-Type:MIME-Version: Message-ID; bh=any2LG+UghBJpBtb2ma/J/4il5qY3mBNhe3dnfW5z/Q=; b=d AcBBvPyUjhVgvrxySDNo1G2N7EEYCzSznCUb45LjeljfW7k0ruM4Yt+QaAHhTJDR ShWDEliV92Wk5kQ9Z5PKSWpL1V23wvX0WHBAIZ+Fe85O9ukGN5I9vDxGFrBFvQb8 WxaEQ4FP5iBKHy5ZPtvPwMByfO0pRn66FmXZWMJjNA= Received: from zyytlz.wz$163.com ( [111.206.145.21] ) by ajax-webmail-wmsvr91 (Coremail) ; Mon, 20 Mar 2023 20:07:52 +0800 (CST) X-Originating-IP: [111.206.145.21] Date: Mon, 20 Mar 2023 20:07:52 +0800 (CST) From: =?GBK?B?zfXV9w==?= To: "Nicolas Ferre" Cc: eugen.hristev@collabora.com, jic23@kernel.org, lars@metafoo.de, alexandre.belloni@bootlin.com, claudiu.beznea@microchip.com, linux-iio@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, hackerzheng666@gmail.com, 1395428693sheep@gmail.com, alex000young@gmail.com Subject: Re:Re: [PATCH] iio: at91-sama5d2_adc: Fix use after free bug in at91_adc_remove due to race condition X-Priority: 3 X-Mailer: Coremail Webmail Server Version XT5.0.14 build 20230109(dcb5de15) Copyright (c) 2002-2023 www.mailtech.cn 163com In-Reply-To: <954acc8c-0df3-23a4-7237-ecbc31811a56@microchip.com> References: <20230310091239.1440279-1-zyytlz.wz@163.com> <954acc8c-0df3-23a4-7237-ecbc31811a56@microchip.com> X-NTES-SC: AL_QuycC/+au0gs5CGYbekXn0oRjuY8XsK3v/kl3YNXP5k0pir36yEsXkV8OHnYzuOSJyqciiKKcSJIxftbZ6pBVLiEa/JRVsfb8BpEatx+iClf MIME-Version: 1.0 Message-ID: <2220fb68.10ff7.186feeb3231.Coremail.zyytlz.wz@163.com> X-Coremail-Locale: zh_CN X-CM-TRANSID: _____wDHza2YTBhkAocUAA--.24180W X-CM-SenderInfo: h2113zf2oz6qqrwthudrp/1tbiGhg4U1aEEohinAAAsf X-Coremail-Antispam: 1U5529EdanIXcx71UUUUU7vcSsGvfC2KfnxnUU== X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20230320_050811_801086_589C6E7D X-CRM114-Status: GOOD ( 18.26 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org At 2023-03-20 16:35:24, "Nicolas Ferre" wrote: >On 10/03/2023 at 10:12, Zheng Wang wrote: >> In at91_adc_probe, &st->touch_st.workq is bound with >> at91_adc_workq_handler. Then it will be started by irq >> handler at91_adc_touch_data_handler >> >> If we remove the driver which will call at91_adc_remove >> to make cleanup, there may be a unfinished work. >> >> The possible sequence is as follows: >> >> Fix it by finishing the work before cleanup in the at91_adc_remove >> >> CPU0 CPU1 >> >> |at91_adc_workq_handler >> at91_adc_remove | >> iio_device_unregister| >> iio_dev_release | >> kfree(iio_dev_opaque);| >> | >> |iio_push_to_buffers >> |&iio_dev_opaque->buffer_list >> |//use > >There is no such thing as a SMP platform using this driver (yet?), so we >agree that this fix is purely theoretical, cannot be reproduced nor its >fix validated. > >That being said, I'm happy that enhancements are provided to this >driver, no doubt about that. > Hi Nicolas, Thanks for your reply. I'm not familiar with the module and I think you're right. > >> Fixes: 23ec2774f1cc ("iio: adc: at91-sama5d2_adc: add support for position and pressure channels") >> Signed-off-by: Zheng Wang >> --- >> drivers/iio/adc/at91-sama5d2_adc.c | 2 ++ >> 1 file changed, 2 insertions(+) >> >> diff --git a/drivers/iio/adc/at91-sama5d2_adc.c b/drivers/iio/adc/at91-sama5d2_adc.c >> index 50d02e5fc6fc..1b95d18d9e0b 100644 >> --- a/drivers/iio/adc/at91-sama5d2_adc.c >> +++ b/drivers/iio/adc/at91-sama5d2_adc.c >> @@ -2495,6 +2495,8 @@ static int at91_adc_remove(struct platform_device *pdev) >> struct iio_dev *indio_dev = platform_get_drvdata(pdev); >> struct at91_adc_state *st = iio_priv(indio_dev); >> >> + disable_irq_nosync(st->irq); >> + cancel_work_sync(&st->touch_st.workq); > >About stopping the source of interrupt, I would recommend using a >sequence already exposed in at91_adc_hw_init (and possibly make it >common), like: > > if (st->soc_info.platform->layout->EOC_IDR) > at91_adc_writel(st, EOC_IDR, 0xffffffff); > at91_adc_writel(st, IDR, 0xffffffff); > Thanks fou your advice. I'll apply it in the next version. Best regards, Zheng >Regards, > Nicolas > >> iio_device_unregister(indio_dev); >> >> at91_adc_dma_disable(st); >> -- >> 2.25.1 >> > >-- >Nicolas Ferre _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel