Linux CXL
 help / color / mirror / Atom feed
* [PATCH] cxl/core: Skip einj_inject creation when devm_add_action_or_reset() fails
@ 2026-09-15  6:01 Guixin Liu
  2026-09-16  0:44 ` Jonathan Cameron
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Guixin Liu @ 2026-09-15  6:01 UTC (permalink / raw)
  To: Davidlohr Bueso, Jonathan Cameron, Dave Jiang, Alison Schofield,
	Vishal Verma, Dan Williams, Ira Weiny, Li Ming
  Cc: linux-cxl

cxl_debugfs_create_dport_dir() ignores the devm_add_action_or_reset()
result and creates the einj_inject file below @dir unconditionally.

When the devres allocation fails, remove_debugfs() has already run
before devm_add_action_or_reset() returns, i.e. debugfs_remove() has
released @dir. The subsequent debugfs_create_file() would then use
that dentry as its parent although its final reference was dropped in
the removal and its memory is subject to call_rcu() delayed freeing.

Skip the file creation in that case, consistent with how the rest of
the helper tolerates debugfs failures.

Fixes: 9185b1a3043c ("cxl/core: Fix dport use-after-free via the einj_inject debugfs file")
Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
---
 drivers/cxl/core/port.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/cxl/core/port.c b/drivers/cxl/core/port.c
index 8d715739995b..95c0be57ed53 100644
--- a/drivers/cxl/core/port.c
+++ b/drivers/cxl/core/port.c
@@ -837,7 +837,8 @@ static void cxl_debugfs_create_dport_dir(struct cxl_dport *dport)
 
 	dir = cxl_debugfs_create_dir(dev_name(dport->dport_dev));
 
-	devm_add_action_or_reset(dport_to_host(dport), remove_debugfs, dir);
+	if (devm_add_action_or_reset(dport_to_host(dport), remove_debugfs, dir))
+		return;
 
 	debugfs_create_file("einj_inject", 0200, dir, dport,
 			    &cxl_einj_inject_fops);
-- 
2.43.7


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH] cxl/core: Skip einj_inject creation when devm_add_action_or_reset() fails
  2026-09-15  6:01 [PATCH] cxl/core: Skip einj_inject creation when devm_add_action_or_reset() fails Guixin Liu
@ 2026-09-16  0:44 ` Jonathan Cameron
  2026-09-16 12:35 ` Li Ming
  2026-09-18 15:41 ` Dave Jiang
  2 siblings, 0 replies; 4+ messages in thread
From: Jonathan Cameron @ 2026-09-16  0:44 UTC (permalink / raw)
  To: Guixin Liu
  Cc: Davidlohr Bueso, Dave Jiang, Alison Schofield, Vishal Verma,
	Dan Williams, Ira Weiny, Li Ming, linux-cxl

On Tue, 15 Sep 2026 14:01:38 +0800
Guixin Liu <kanie@linux.alibaba.com> wrote:

> cxl_debugfs_create_dport_dir() ignores the devm_add_action_or_reset()
> result and creates the einj_inject file below @dir unconditionally.
> 
> When the devres allocation fails, remove_debugfs() has already run
> before devm_add_action_or_reset() returns, i.e. debugfs_remove() has
> released @dir. The subsequent debugfs_create_file() would then use
> that dentry as its parent although its final reference was dropped in
> the removal and its memory is subject to call_rcu() delayed freeing.
> 
> Skip the file creation in that case, consistent with how the rest of
> the helper tolerates debugfs failures.
> 
> Fixes: 9185b1a3043c ("cxl/core: Fix dport use-after-free via the einj_inject debugfs file")
> Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
Reviewed-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] cxl/core: Skip einj_inject creation when devm_add_action_or_reset() fails
  2026-09-15  6:01 [PATCH] cxl/core: Skip einj_inject creation when devm_add_action_or_reset() fails Guixin Liu
  2026-09-16  0:44 ` Jonathan Cameron
@ 2026-09-16 12:35 ` Li Ming
  2026-09-18 15:41 ` Dave Jiang
  2 siblings, 0 replies; 4+ messages in thread
From: Li Ming @ 2026-09-16 12:35 UTC (permalink / raw)
  To: Guixin Liu, Davidlohr Bueso, Jonathan Cameron, Dave Jiang,
	Alison Schofield, Vishal Verma, Dan Williams, Ira Weiny
  Cc: linux-cxl

On 9/15/2026 2:01 PM, Guixin Liu wrote:
> cxl_debugfs_create_dport_dir() ignores the devm_add_action_or_reset()
> result and creates the einj_inject file below @dir unconditionally.
>
> When the devres allocation fails, remove_debugfs() has already run
> before devm_add_action_or_reset() returns, i.e. debugfs_remove() has
> released @dir. The subsequent debugfs_create_file() would then use
> that dentry as its parent although its final reference was dropped in
> the removal and its memory is subject to call_rcu() delayed freeing.
>
> Skip the file creation in that case, consistent with how the rest of
> the helper tolerates debugfs failures.
>
> Fixes: 9185b1a3043c ("cxl/core: Fix dport use-after-free via the einj_inject debugfs file")
> Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
Reviewed-by: Li Ming <ming.li@zohomail.com>
> ---
>  drivers/cxl/core/port.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/cxl/core/port.c b/drivers/cxl/core/port.c
> index 8d715739995b..95c0be57ed53 100644
> --- a/drivers/cxl/core/port.c
> +++ b/drivers/cxl/core/port.c
> @@ -837,7 +837,8 @@ static void cxl_debugfs_create_dport_dir(struct cxl_dport *dport)
>  
>  	dir = cxl_debugfs_create_dir(dev_name(dport->dport_dev));
>  
> -	devm_add_action_or_reset(dport_to_host(dport), remove_debugfs, dir);
> +	if (devm_add_action_or_reset(dport_to_host(dport), remove_debugfs, dir))
> +		return;
>  
>  	debugfs_create_file("einj_inject", 0200, dir, dport,
>  			    &cxl_einj_inject_fops);



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] cxl/core: Skip einj_inject creation when devm_add_action_or_reset() fails
  2026-09-15  6:01 [PATCH] cxl/core: Skip einj_inject creation when devm_add_action_or_reset() fails Guixin Liu
  2026-09-16  0:44 ` Jonathan Cameron
  2026-09-16 12:35 ` Li Ming
@ 2026-09-18 15:41 ` Dave Jiang
  2 siblings, 0 replies; 4+ messages in thread
From: Dave Jiang @ 2026-09-18 15:41 UTC (permalink / raw)
  To: Guixin Liu, Davidlohr Bueso, Jonathan Cameron, Alison Schofield,
	Vishal Verma, Dan Williams, Ira Weiny, Li Ming
  Cc: linux-cxl



On 9/14/26 11:01 PM, Guixin Liu wrote:
> cxl_debugfs_create_dport_dir() ignores the devm_add_action_or_reset()
> result and creates the einj_inject file below @dir unconditionally.
> 
> When the devres allocation fails, remove_debugfs() has already run
> before devm_add_action_or_reset() returns, i.e. debugfs_remove() has
> released @dir. The subsequent debugfs_create_file() would then use
> that dentry as its parent although its final reference was dropped in
> the removal and its memory is subject to call_rcu() delayed freeing.
> 
> Skip the file creation in that case, consistent with how the rest of
> the helper tolerates debugfs failures.
> 
> Fixes: 9185b1a3043c ("cxl/core: Fix dport use-after-free via the einj_inject debugfs file")
> Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>

Applied to cxl/next:
b25af6afd2f2

> ---
>  drivers/cxl/core/port.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/cxl/core/port.c b/drivers/cxl/core/port.c
> index 8d715739995b..95c0be57ed53 100644
> --- a/drivers/cxl/core/port.c
> +++ b/drivers/cxl/core/port.c
> @@ -837,7 +837,8 @@ static void cxl_debugfs_create_dport_dir(struct cxl_dport *dport)
>  
>  	dir = cxl_debugfs_create_dir(dev_name(dport->dport_dev));
>  
> -	devm_add_action_or_reset(dport_to_host(dport), remove_debugfs, dir);
> +	if (devm_add_action_or_reset(dport_to_host(dport), remove_debugfs, dir))
> +		return;
>  
>  	debugfs_create_file("einj_inject", 0200, dir, dport,
>  			    &cxl_einj_inject_fops);


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-18 15:41 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-15  6:01 [PATCH] cxl/core: Skip einj_inject creation when devm_add_action_or_reset() fails Guixin Liu
2026-09-16  0:44 ` Jonathan Cameron
2026-09-16 12:35 ` Li Ming
2026-09-18 15:41 ` Dave Jiang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox