From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id B3E7AC6FD1D for ; Mon, 20 Mar 2023 03:59:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:Cc:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:Message-ID:MIME-Version:References: In-Reply-To:Subject:To:From:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=8sMgpkYqdqVNO1g2d5rkz/LvGGcB6Vjs++D+ph9bGjc=; b=llI2MjVJ09853T N6diU8B+/fWXtOVPk8Ip4W0e/Fy4tS28R3/Cz6Z26XFSsqjn8FuijZ4UYaPM8cYFp8HtBdt6XMXjf Ggts5ssZaScS8Y5M2ZGw8K9sN3jpgT4SnPgHCqqlRqiAkS+NWvLlp3WkzqPUzs+6rfmPaklN3Bise L6+6ZV9c6ii+jULip4nd9+h61d7iISQYoZOT32u12Pwa/uhAISiqxRtaKJRNpnKPfwNimnKaifuUu wT+ZuOTeRNIUO2avNvAU+H/3A6ghLwqMbFYqFFswl5Mx0Y0S/RMhmljLB0kRgnsNLBq21VLJK+C22 yhokgCXZDASAuXvlUfqg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1pe6fa-0081qP-0P; Mon, 20 Mar 2023 03:58:50 +0000 Received: from m12.mail.163.com ([220.181.12.199] helo=163.com) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1pe6fW-0081ph-0c for linux-arm-kernel@lists.infradead.org; Mon, 20 Mar 2023 03:58:47 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=163.com; s=s110527; h=Date:From:Subject:Content-Type:MIME-Version: Message-ID; bh=ghRA+C90vX1ZYTuZtFlOH1voPfmpFTzjKY619ZT9nyM=; b=f Bs7EogveCzgDJJbsiYMiQQkcJNMCxVkhGEA6jBb3wk66yVdLEUqCzAVjl3k2gnvO VwegpPadYo6rFLSnOUaks9Bciw9EkETgJJaQt6YPrGvfh1151iCu3pCZbQPN56ZT Gc8YC3eftUa+7DNGjQtTBpib+94MG3PB9LR019Lz/c= Received: from zyytlz.wz$163.com ( [111.206.145.21] ) by ajax-webmail-wmsvr12 (Coremail) ; Mon, 20 Mar 2023 11:41:27 +0800 (CST) X-Originating-IP: [111.206.145.21] Date: Mon, 20 Mar 2023 11:41:27 +0800 (CST) From: =?GBK?B?zfXV9w==?= To: "Lars-Peter Clausen" Subject: Re:Re: [PATCH] iio: at91-sama5d2_adc: Fix use after free bug in at91_adc_remove due to race condition X-Priority: 3 X-Mailer: Coremail Webmail Server Version XT5.0.14 build 20230109(dcb5de15) Copyright (c) 2002-2023 www.mailtech.cn 163com In-Reply-To: References: <20230310091239.1440279-1-zyytlz.wz@163.com> <20230318173913.19e8a1b1@jic23-huawei> X-NTES-SC: AL_QuycC/6TvE4j4SKdY+kXn0oRjuY8XsK3v/kl3YNXP5k0vynH/gsFYl9FHVb32ci2LieikDinXz9i2/5fbZt4RoRXKQgTdqlQirHsSO4ZsvUW MIME-Version: 1.0 Message-ID: <2fdfc137.4e1c.186fd1b8f5a.Coremail.zyytlz.wz@163.com> X-Coremail-Locale: zh_CN X-CM-TRANSID: _____wD3qRTn1Rdk1GYSAA--.867W X-CM-SenderInfo: h2113zf2oz6qqrwthudrp/1tbiXQs3U1WBo93sHAACsq X-Coremail-Antispam: 1U5529EdanIXcx71UUUUU7vcSsGvfC2KfnxnUU== X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20230319_205846_588340_63388C14 X-CRM114-Status: GOOD ( 16.35 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: alexandre.belloni@bootlin.com, linux-iio@vger.kernel.org, eugen.hristev@collabora.com, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, claudiu.beznea@microchip.com, Jonathan Cameron Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org At 2023-03-19 00:36:04, "Lars-Peter Clausen" wrote: >On 3/18/23 10:39, Jonathan Cameron wrote: >> On Fri, 10 Mar 2023 17:12:39 +0800 >> Zheng Wang wrote: >> >>> In at91_adc_probe, &st->touch_st.workq is bound with >>> at91_adc_workq_handler. Then it will be started by irq >>> handler at91_adc_touch_data_handler >>> >>> If we remove the driver which will call at91_adc_remove >>> to make cleanup, there may be a unfinished work. >>> >>> The possible sequence is as follows: >>> >>> Fix it by finishing the work before cleanup in the at91_adc_remove >>> >>> CPU0 CPU1 >>> >>> |at91_adc_workq_handler >>> at91_adc_remove | >>> iio_device_unregister| >>> iio_dev_release | >>> kfree(iio_dev_opaque);| >>> | >>> |iio_push_to_buffers >>> |&iio_dev_opaque->buffer_list >>> |//use >>> Fixes: 23ec2774f1cc ("iio: adc: at91-sama5d2_adc: add support for position and pressure channels") >>> Signed-off-by: Zheng Wang >>> --- >>> drivers/iio/adc/at91-sama5d2_adc.c | 2 ++ >>> 1 file changed, 2 insertions(+) >>> >>> diff --git a/drivers/iio/adc/at91-sama5d2_adc.c b/drivers/iio/adc/at91-sama5d2_adc.c >>> index 50d02e5fc6fc..1b95d18d9e0b 100644 >>> --- a/drivers/iio/adc/at91-sama5d2_adc.c >>> +++ b/drivers/iio/adc/at91-sama5d2_adc.c >>> @@ -2495,6 +2495,8 @@ static int at91_adc_remove(struct platform_device *pdev) >>> struct iio_dev *indio_dev = platform_get_drvdata(pdev); >>> struct at91_adc_state *st = iio_priv(indio_dev); >>> >>> + disable_irq_nosync(st->irq); >>> + cancel_work_sync(&st->touch_st.workq); >> I'd like some input form someone more familiar with this driver than I am. >> >> In particular, whilst it fixes the bug seen I'm not sure what the most >> logical ordering for the disable is or the best way to do it. >> >> I'd prefer to see the irq cut off at source by disabling it at the device >> feature that is generating the irq followed by cancelling or waiting for >> completion of any in flight work. >The usually way you'd do this by calling free_irq() before the >cancel_work_sync(). Hi, Thank you for your response and feedback on my patch. I appreciate your input and would like to address your concerns. Regarding the best way to disable the IRQ, I agree that calling free_irq() before cancel_work_sync() would be a better approach. This ensures that the IRQ is completely disabled at the source, and any in-flight work is finished before removing the driver. I will make this change in the patch. Best regards, Zheng Wang > _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel