public inbox for linux-doc@vger.kernel.org
 help / color / mirror / Atom feed
From: Tzung-Bi Shih <tzungbi@kernel.org>
To: Benson Leung <bleung@chromium.org>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	"Rafael J . Wysocki" <rafael@kernel.org>,
	Danilo Krummrich <dakr@kernel.org>,
	Bartosz Golaszewski <brgl@bgdev.pl>,
	Linus Walleij <linusw@kernel.org>
Cc: Jonathan Corbet <corbet@lwn.net>, Shuah Khan <shuah@kernel.org>,
	linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org,
	chrome-platform@lists.linux.dev, linux-kselftest@vger.kernel.org,
	tzungbi@kernel.org,
	Laurent Pinchart <laurent.pinchart@ideasonboard.com>,
	Wolfram Sang <wsa+renesas@sang-engineering.com>,
	Simona Vetter <simona.vetter@ffwll.ch>,
	Dan Williams <dan.j.williams@intel.com>,
	Jason Gunthorpe <jgg@nvidia.com>,
	linux-gpio@vger.kernel.org
Subject: [PATCH 13/23] gpiolib: cdev: Leverage revocable for gpio_fileops
Date: Fri, 16 Jan 2026 08:10:26 +0000	[thread overview]
Message-ID: <20260116081036.352286-14-tzungbi@kernel.org> (raw)
In-Reply-To: <20260116081036.352286-1-tzungbi@kernel.org>

Struct gpio_device now provides a revocable provider to the underlying
struct gpio_chip.  Leverage revocable for gpio_fileops so that it doesn't
need to handle the synchronization by accessing the SRCU explicitly.

Also, it's unneeded to hold a reference count to the struct gpio_device
while the file is opening.  The struct gpio_device
(i.e., (struct gpio_chip *)->gpiodev)) is valid as long as struct
gpio_chip is valid.

Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
---
 drivers/gpio/gpiolib-cdev.c | 87 ++++++++++++++++++++++---------------
 1 file changed, 52 insertions(+), 35 deletions(-)

diff --git a/drivers/gpio/gpiolib-cdev.c b/drivers/gpio/gpiolib-cdev.c
index e42cfdb47885..832a542c4f7a 100644
--- a/drivers/gpio/gpiolib-cdev.c
+++ b/drivers/gpio/gpiolib-cdev.c
@@ -22,6 +22,7 @@
 #include <linux/overflow.h>
 #include <linux/pinctrl/consumer.h>
 #include <linux/poll.h>
+#include <linux/revocable.h>
 #include <linux/seq_file.h>
 #include <linux/spinlock.h>
 #include <linux/string.h>
@@ -2297,7 +2298,7 @@ static void gpio_desc_to_lineinfo(struct gpio_desc *desc,
 }
 
 struct gpio_chardev_data {
-	struct gpio_device *gdev;
+	struct revocable *chip_rev;
 	wait_queue_head_t wait;
 	DECLARE_KFIFO(events, struct gpio_v2_line_info_changed, 32);
 	struct notifier_block lineinfo_changed_nb;
@@ -2309,9 +2310,8 @@ struct gpio_chardev_data {
 	struct file *fp;
 };
 
-static int chipinfo_get(struct gpio_chardev_data *cdev, void __user *ip)
+static int chipinfo_get(struct gpio_device *gdev, void __user *ip)
 {
-	struct gpio_device *gdev = cdev->gdev;
 	struct gpiochip_info chipinfo;
 
 	memset(&chipinfo, 0, sizeof(chipinfo));
@@ -2339,7 +2339,8 @@ static int lineinfo_ensure_abi_version(struct gpio_chardev_data *cdata,
 	return abiv;
 }
 
-static int lineinfo_get_v1(struct gpio_chardev_data *cdev, void __user *ip,
+static int lineinfo_get_v1(struct gpio_chardev_data *cdev,
+			   struct gpio_device *gdev, void __user *ip,
 			   bool watch)
 {
 	struct gpio_desc *desc;
@@ -2350,7 +2351,7 @@ static int lineinfo_get_v1(struct gpio_chardev_data *cdev, void __user *ip,
 		return -EFAULT;
 
 	/* this doubles as a range check on line_offset */
-	desc = gpio_device_get_desc(cdev->gdev, lineinfo.line_offset);
+	desc = gpio_device_get_desc(gdev, lineinfo.line_offset);
 	if (IS_ERR(desc))
 		return PTR_ERR(desc);
 
@@ -2375,7 +2376,8 @@ static int lineinfo_get_v1(struct gpio_chardev_data *cdev, void __user *ip,
 }
 #endif
 
-static int lineinfo_get(struct gpio_chardev_data *cdev, void __user *ip,
+static int lineinfo_get(struct gpio_chardev_data *cdev,
+			struct gpio_device *gdev, void __user *ip,
 			bool watch)
 {
 	struct gpio_desc *desc;
@@ -2387,7 +2389,7 @@ static int lineinfo_get(struct gpio_chardev_data *cdev, void __user *ip,
 	if (!mem_is_zero(lineinfo.padding, sizeof(lineinfo.padding)))
 		return -EINVAL;
 
-	desc = gpio_device_get_desc(cdev->gdev, lineinfo.offset);
+	desc = gpio_device_get_desc(gdev, lineinfo.offset);
 	if (IS_ERR(desc))
 		return PTR_ERR(desc);
 
@@ -2410,14 +2412,15 @@ static int lineinfo_get(struct gpio_chardev_data *cdev, void __user *ip,
 	return 0;
 }
 
-static int lineinfo_unwatch(struct gpio_chardev_data *cdev, void __user *ip)
+static int lineinfo_unwatch(struct gpio_chardev_data *cdev,
+			    struct gpio_device *gdev, void __user *ip)
 {
 	__u32 offset;
 
 	if (copy_from_user(&offset, ip, sizeof(offset)))
 		return -EFAULT;
 
-	if (offset >= cdev->gdev->ngpio)
+	if (offset >= gdev->ngpio)
 		return -EINVAL;
 
 	if (!test_and_clear_bit(offset, cdev->watched_lines))
@@ -2432,37 +2435,38 @@ static int lineinfo_unwatch(struct gpio_chardev_data *cdev, void __user *ip)
 static long gpio_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
 {
 	struct gpio_chardev_data *cdev = file->private_data;
-	struct gpio_device *gdev = cdev->gdev;
+	struct gpio_chip *gc;
+	struct gpio_device *gdev;
 	void __user *ip = (void __user *)arg;
 
-	guard(srcu)(&gdev->srcu);
-
 	/* We fail any subsequent ioctl():s when the chip is gone */
-	if (!rcu_access_pointer(gdev->chip))
+	REVOCABLE_TRY_ACCESS_WITH(cdev->chip_rev, gc);
+	if (!gc)
 		return -ENODEV;
+	gdev = gc->gpiodev;
 
 	/* Fill in the struct and pass to userspace */
 	switch (cmd) {
 	case GPIO_GET_CHIPINFO_IOCTL:
-		return chipinfo_get(cdev, ip);
+		return chipinfo_get(gdev, ip);
 #ifdef CONFIG_GPIO_CDEV_V1
 	case GPIO_GET_LINEHANDLE_IOCTL:
 		return linehandle_create(gdev, ip);
 	case GPIO_GET_LINEEVENT_IOCTL:
 		return lineevent_create(gdev, ip);
 	case GPIO_GET_LINEINFO_IOCTL:
-		return lineinfo_get_v1(cdev, ip, false);
+		return lineinfo_get_v1(cdev, gdev, ip, false);
 	case GPIO_GET_LINEINFO_WATCH_IOCTL:
-		return lineinfo_get_v1(cdev, ip, true);
+		return lineinfo_get_v1(cdev, gdev, ip, true);
 #endif /* CONFIG_GPIO_CDEV_V1 */
 	case GPIO_V2_GET_LINEINFO_IOCTL:
-		return lineinfo_get(cdev, ip, false);
+		return lineinfo_get(cdev, gdev, ip, false);
 	case GPIO_V2_GET_LINEINFO_WATCH_IOCTL:
-		return lineinfo_get(cdev, ip, true);
+		return lineinfo_get(cdev, gdev, ip, true);
 	case GPIO_V2_GET_LINE_IOCTL:
 		return linereq_create(gdev, ip);
 	case GPIO_GET_LINEINFO_UNWATCH_IOCTL:
-		return lineinfo_unwatch(cdev, ip);
+		return lineinfo_unwatch(cdev, gdev, ip);
 	default:
 		return -EINVAL;
 	}
@@ -2585,10 +2589,10 @@ static __poll_t lineinfo_watch_poll(struct file *file,
 {
 	struct gpio_chardev_data *cdev = file->private_data;
 	__poll_t events = 0;
+	struct gpio_chip *gc;
 
-	guard(srcu)(&cdev->gdev->srcu);
-
-	if (!rcu_access_pointer(cdev->gdev->chip))
+	REVOCABLE_TRY_ACCESS_WITH(cdev->chip_rev, gc);
+	if (!gc)
 		return EPOLLHUP | EPOLLERR;
 
 	poll_wait(file, &cdev->wait, pollt);
@@ -2608,10 +2612,10 @@ static ssize_t lineinfo_watch_read(struct file *file, char __user *buf,
 	ssize_t bytes_read = 0;
 	int ret;
 	size_t event_size;
+	struct gpio_chip *gc;
 
-	guard(srcu)(&cdev->gdev->srcu);
-
-	if (!rcu_access_pointer(cdev->gdev->chip))
+	REVOCABLE_TRY_ACCESS_WITH(cdev->chip_rev, gc);
+	if (!gc)
 		return -ENODEV;
 
 #ifndef CONFIG_GPIO_CDEV_V1
@@ -2695,13 +2699,16 @@ static int gpio_chrdev_open(struct inode *inode, struct file *file)
 	if (!cdev)
 		return -ENOMEM;
 
+	cdev->chip_rev = revocable_alloc(gdev->chip_rp);
+	if (!cdev->chip_rev)
+		goto out_free_cdev;
+
 	cdev->watched_lines = bitmap_zalloc(gdev->ngpio, GFP_KERNEL);
 	if (!cdev->watched_lines)
-		goto out_free_cdev;
+		goto out_free_chip_rev;
 
 	init_waitqueue_head(&cdev->wait);
 	INIT_KFIFO(cdev->events);
-	cdev->gdev = gpio_device_get(gdev);
 
 	cdev->lineinfo_changed_nb.notifier_call = lineinfo_changed_notify;
 	scoped_guard(write_lock_irqsave, &gdev->line_state_lock)
@@ -2734,8 +2741,9 @@ static int gpio_chrdev_open(struct inode *inode, struct file *file)
 		raw_notifier_chain_unregister(&gdev->line_state_notifier,
 					      &cdev->lineinfo_changed_nb);
 out_free_bitmap:
-	gpio_device_put(gdev);
 	bitmap_free(cdev->watched_lines);
+out_free_chip_rev:
+	revocable_free(cdev->chip_rev);
 out_free_cdev:
 	kfree(cdev);
 	return ret;
@@ -2752,15 +2760,24 @@ static int gpio_chrdev_open(struct inode *inode, struct file *file)
 static int gpio_chrdev_release(struct inode *inode, struct file *file)
 {
 	struct gpio_chardev_data *cdev = file->private_data;
-	struct gpio_device *gdev = cdev->gdev;
+	struct gpio_chip *gc;
+	struct gpio_device *gdev;
+
+	REVOCABLE_TRY_ACCESS_SCOPED(cdev->chip_rev, gc) {
+		if (!gc)
+			break;
+		gdev = gc->gpiodev;
+
+		blocking_notifier_chain_unregister(&gdev->device_notifier,
+				&cdev->device_unregistered_nb);
+
+		scoped_guard(write_lock_irqsave, &gdev->line_state_lock)
+			raw_notifier_chain_unregister(&gdev->line_state_notifier,
+					&cdev->lineinfo_changed_nb);
+	}
+	revocable_free(cdev->chip_rev);
 
-	blocking_notifier_chain_unregister(&gdev->device_notifier,
-					   &cdev->device_unregistered_nb);
-	scoped_guard(write_lock_irqsave, &gdev->line_state_lock)
-		raw_notifier_chain_unregister(&gdev->line_state_notifier,
-					      &cdev->lineinfo_changed_nb);
 	bitmap_free(cdev->watched_lines);
-	gpio_device_put(gdev);
 	kfree(cdev);
 
 	return 0;
-- 
2.52.0.457.g6b5491de43-goog


  parent reply	other threads:[~2026-01-16  8:11 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-01-16  8:10 [PATCH 00/23] gpiolib: Adopt revocable mechanism for UAF prevention Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 01/23] gpiolib: Correct wrong kfree() usage for `kobj->name` Tzung-Bi Shih
2026-01-16 13:15   ` Bartosz Golaszewski
2026-01-16 13:27     ` Greg Kroah-Hartman
2026-01-16 13:30       ` Bartosz Golaszewski
2026-01-20  4:29     ` Tzung-Bi Shih
2026-01-16 14:13   ` Jason Gunthorpe
2026-01-16 14:38     ` Bartosz Golaszewski
2026-01-20  4:30       ` Tzung-Bi Shih
2026-01-20  9:43         ` Bartosz Golaszewski
2026-01-16  8:10 ` [PATCH 02/23] gpiolib: cdev: Fix resource leaks on errors in gpiolib_cdev_register() Tzung-Bi Shih
2026-01-20  8:50   ` Bartosz Golaszewski
2026-01-20  9:34     ` Tzung-Bi Shih
2026-01-20  9:39       ` Bartosz Golaszewski
2026-01-16  8:10 ` [PATCH 03/23] gpiolib: Fix resource leaks on errors in gpiochip_add_data_with_key() Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 04/23] gpiolib: Fix resource leaks on errors in lineinfo_changed_notify() Tzung-Bi Shih
2026-01-16 13:26   ` Bartosz Golaszewski
2026-01-20  3:11     ` Tzung-Bi Shih
2026-01-20  8:49       ` Bartosz Golaszewski
2026-01-16  8:10 ` [PATCH 05/23] gpiolib: cdev: Correct return code on memory allocation failure Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 06/23] gpiolib: Access `gpio_bus_type` in gpiochip_setup_dev() Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 07/23] gpiolib: Remove redundant check for struct gpio_chip Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 08/23] gpiolib: sysfs: " Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 09/23] gpiolib: Ensure struct gpio_chip for gpiochip_setup_dev() Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 10/23] gpiolib: cdev: Don't check struct gpio_chip in gpio_chrdev_open() Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 11/23] selftests: gpio: Add gpio-cdev-uaf tests Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 12/23] gpiolib: Add revocable provider handle for struct gpio_chip Tzung-Bi Shih
2026-01-16  8:10 ` Tzung-Bi Shih [this message]
2026-01-16  8:10 ` [PATCH 14/23] gpiolib: cdev: Leverage revocable for linehandle_fileops Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 15/23] gpiolib: cdev: Leverage revocable for line_fileops Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 16/23] gpiolib: cdev: Leverage revocable for lineevent_fileops Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 17/23] gpiolib: cdev: Leverage revocable for lineinfo_changed_notify Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 18/23] gpiolib: Leverage revocable for gpiolib_sops Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 19/23] revocable: Support to define revocable consumer handle on stack Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 20/23] revocable: Add Kunit test case for DEFINE_REVOCABLE() Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 21/23] selftests: revocable: Add " Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 22/23] gpiolib: Leverage revocable for other independent lifecycle instances Tzung-Bi Shih
2026-01-24 16:52   ` Johan Hovold
2026-01-26 13:58     ` Johan Hovold
2026-01-27 15:56       ` Tzung-Bi Shih
2026-01-16  8:10 ` [PATCH 23/23] gpiolib: Remove unused `chip` and `srcu` in struct gpio_device Tzung-Bi Shih
2026-01-16 10:35 ` [PATCH 00/23] gpiolib: Adopt revocable mechanism for UAF prevention Bartosz Golaszewski
2026-01-16 16:07   ` Laurent Pinchart
2026-01-17 12:48   ` Tzung-Bi Shih
2026-01-19  8:33     ` Bartosz Golaszewski
2026-01-21  4:17       ` Tzung-Bi Shih
2026-01-21 10:42         ` Bartosz Golaszewski
2026-01-19 14:21 ` (subset) " Bartosz Golaszewski
2026-01-20  3:13   ` Tzung-Bi Shih

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260116081036.352286-14-tzungbi@kernel.org \
    --to=tzungbi@kernel.org \
    --cc=bleung@chromium.org \
    --cc=brgl@bgdev.pl \
    --cc=chrome-platform@lists.linux.dev \
    --cc=corbet@lwn.net \
    --cc=dakr@kernel.org \
    --cc=dan.j.williams@intel.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=jgg@nvidia.com \
    --cc=laurent.pinchart@ideasonboard.com \
    --cc=linusw@kernel.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-gpio@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=rafael@kernel.org \
    --cc=shuah@kernel.org \
    --cc=simona.vetter@ffwll.ch \
    --cc=wsa+renesas@sang-engineering.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox