From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id DDC81C6FD1D for ; Mon, 20 Mar 2023 03:59:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:Cc:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:Message-ID:MIME-Version:References: In-Reply-To:Subject:To:From:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=2O4BwWieUYjQ357wvyByVUU0NPGNagnlCud5RvMFz8Q=; b=2vzw+CmEd8/WaN cj2t80Coepc9G+GqarkFTnsjAYpPorPKlTge+gK86NpIyBN63w6QfrG5xwne3tlaT/zf9x5KpyOBt NaurDBPto5bagSjmT+dxvMUTotMSbdU1FvXablIRX3v/xeJ8FjZAJGRCfIwdzCRh1OpdaiTG+PlTH bG6to3GBrl3KwDqNVgrMt8T5PpLOlT5DczJvMg5tkFrL395RPQK3D6+6UyExhYCCEEtzjTgNGWT/7 V5+D9E6f/LxwFvi6fUUiIZldFJYIu+RfvFDwAjHcqmy38TeDVS/qfyQQAgefmiInHRdmSLPP/XRps YiAfL7XdTpn9nrSpqx1g==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1pe6ej-0081lQ-2h; Mon, 20 Mar 2023 03:57:57 +0000 Received: from m12.mail.163.com ([220.181.12.198] helo=163.com) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1pe6eg-0081kw-1b for linux-arm-kernel@lists.infradead.org; Mon, 20 Mar 2023 03:57:56 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=163.com; s=s110527; h=Date:From:Subject:Content-Type:MIME-Version: Message-ID; bh=/gLyn9NgV9a5Loqbhm+Q8jjDGShVTpb10p5zf1UgHHo=; b=L gEg7qg3I4NUN8/U4j4mPZ0Fnm6geYv4aYGqM5iOmClZFr0r51oPwopcSl1JT75Qn pTj8HBrp+SoIG7n9rrGHHJSwkWel4th4VmOyGjxJ9Yha7EEYlzVwux05vVvRErnv LonaVfYC6yUZuegOgu/bnzk7+lM5CrnJTonRUH3AV0= Received: from zyytlz.wz$163.com ( [111.206.145.21] ) by ajax-webmail-wmsvr12 (Coremail) ; Mon, 20 Mar 2023 11:40:28 +0800 (CST) X-Originating-IP: [111.206.145.21] Date: Mon, 20 Mar 2023 11:40:28 +0800 (CST) From: =?GBK?B?zfXV9w==?= To: "Jonathan Cameron" Subject: Re:Re: [PATCH] iio: at91-sama5d2_adc: Fix use after free bug in at91_adc_remove due to race condition X-Priority: 3 X-Mailer: Coremail Webmail Server Version XT5.0.14 build 20230109(dcb5de15) Copyright (c) 2002-2023 www.mailtech.cn 163com In-Reply-To: <20230318173913.19e8a1b1@jic23-huawei> References: <20230310091239.1440279-1-zyytlz.wz@163.com> <20230318173913.19e8a1b1@jic23-huawei> X-NTES-SC: AL_QuycC/6TvE4p7iWYZOkXn0oRjuY8XsK3v/kl3YNXP5k0vynH/gsFYl9FHVb32ci2LieikDinXz9i2/5fbZt4RoS8WqxpNClyu2Lf2aqKoHtC MIME-Version: 1.0 Message-ID: <6c72d3e3.4dde.186fd1aa9d7.Coremail.zyytlz.wz@163.com> X-Coremail-Locale: zh_CN X-CM-TRANSID: _____wAntSSs1RdkZvwSAA--.12543W X-CM-SenderInfo: h2113zf2oz6qqrwthudrp/1tbiXQs3U1WBo93sHAABsp X-Coremail-Antispam: 1U5529EdanIXcx71UUUUU7vcSsGvfC2KfnxnUU== X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20230319_205754_919873_17103E80 X-CRM114-Status: GOOD ( 16.77 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: alexandre.belloni@bootlin.com, lars@metafoo.de, linux-iio@vger.kernel.org, eugen.hristev@collabora.com, linux-kernel@vger.kernel.org, claudiu.beznea@microchip.com, linux-arm-kernel@lists.infradead.org Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org At 2023-03-19 00:39:13, "Jonathan Cameron" wrote: >On Fri, 10 Mar 2023 17:12:39 +0800 >Zheng Wang wrote: > >> In at91_adc_probe, &st->touch_st.workq is bound with >> at91_adc_workq_handler. Then it will be started by irq >> handler at91_adc_touch_data_handler >> >> If we remove the driver which will call at91_adc_remove >> to make cleanup, there may be a unfinished work. >> >> The possible sequence is as follows: >> >> Fix it by finishing the work before cleanup in the at91_adc_remove >> >> CPU0 CPU1 >> >> |at91_adc_workq_handler >> at91_adc_remove | >> iio_device_unregister| >> iio_dev_release | >> kfree(iio_dev_opaque);| >> | >> |iio_push_to_buffers >> |&iio_dev_opaque->buffer_list >> |//use >> Fixes: 23ec2774f1cc ("iio: adc: at91-sama5d2_adc: add support for position and pressure channels") >> Signed-off-by: Zheng Wang >> --- >> drivers/iio/adc/at91-sama5d2_adc.c | 2 ++ >> 1 file changed, 2 insertions(+) >> >> diff --git a/drivers/iio/adc/at91-sama5d2_adc.c b/drivers/iio/adc/at91-sama5d2_adc.c >> index 50d02e5fc6fc..1b95d18d9e0b 100644 >> --- a/drivers/iio/adc/at91-sama5d2_adc.c >> +++ b/drivers/iio/adc/at91-sama5d2_adc.c >> @@ -2495,6 +2495,8 @@ static int at91_adc_remove(struct platform_device *pdev) >> struct iio_dev *indio_dev = platform_get_drvdata(pdev); >> struct at91_adc_state *st = iio_priv(indio_dev); >> >> + disable_irq_nosync(st->irq); >> + cancel_work_sync(&st->touch_st.workq); > >I'd like some input form someone more familiar with this driver than I am. > >In particular, whilst it fixes the bug seen I'm not sure what the most >logical ordering for the disable is or the best way to do it. > >I'd prefer to see the irq cut off at source by disabling it at the device >feature that is generating the irq followed by cancelling or waiting for >completion of any in flight work. Hi, Sorry for my late reply. I think we need to replace disable_irq_nosync with free_irq. Thanks, Zheng > >> iio_device_unregister(indio_dev); >> >> at91_adc_dma_disable(st); _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel