diff for duplicates of <20260917151557.456504194@linuxfoundation.org> diff --git a/a/1.txt b/N1/1.txt index 5eb20da..e528bd9 100644 --- a/a/1.txt +++ b/N1/1.txt @@ -1,45 +1,59 @@ -6.18-stable review patch. If anyone has any objections, please let me know. +6.12-stable review patch. If anyone has any objections, please let me know. ------------------ -From: Dave Penkler <dpenkler@gmail.com> +From: XingWang Xiang <v3rdant.xiang@gmail.com> -[ Upstream commit 7c19b47f5a1839817e5ddc5ba589224fcfb6255d ] +[ Upstream commit 2b4707a149a55e8fa75c9ef32b359d60f470a566 ] -The NI USB adapter sets the END bit in the status word when an error -occurs such as a read being interrupted by the setting of ATN. This -happens for example when a device clear is received from the -controller in charge during a read. +mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A +concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus +netdev before probe passes its private data to mctp_i3c_add_device(). +The latter consequently adds a list node through a freed mbus pointer. -The common driver changes the error return to 0 whenever the END bit -is set in order to avoid errors such as timeout or interrupt to be -reported after the full message has actually been read. The behaviour -of the NI USB adapter in setting the END bit on errors was causing -actual errors (-EINTR, -ETIMEDOUT) not to be reported. +Keep busdevs_lock held until the device has been added. This also +satisfies the __must_hold annotation on mctp_i3c_add_device(). -We avoid setting the END bit in the ni_usb_gpib driver when an error -is reported in error_code of the status from the adaptor. - -Signed-off-by: Dave Penkler <dpenkler@gmail.com> -Link: https://patch.msgid.link/20260422074807.3194-1-dpenkler@gmail.com -Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> +Fixes: c8755b29b58e ("mctp i3c: MCTP I3C driver") +Signed-off-by: XingWang Xiang <v3rdant.xiang@gmail.com> +Acked-by: Matt Johnston <matt@codeconstruct.com.au> +Signed-off-by: David S. Miller <davem@davemloft.net> Signed-off-by: Sasha Levin <sashal@kernel.org> --- - drivers/staging/gpib/ni_usb/ni_usb_gpib.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/drivers/staging/gpib/ni_usb/ni_usb_gpib.c b/drivers/staging/gpib/ni_usb/ni_usb_gpib.c -index b6fddb437f552..67cc3398e2831 100644 ---- a/drivers/staging/gpib/ni_usb/ni_usb_gpib.c -+++ b/drivers/staging/gpib/ni_usb/ni_usb_gpib.c -@@ -720,7 +720,7 @@ static int ni_usb_read(struct gpib_board *board, u8 *buffer, size_t length, - break; + drivers/net/mctp/mctp-i3c.c | 9 ++++++--- + 1 file changed, 6 insertions(+), 3 deletions(-) + +diff --git a/drivers/net/mctp/mctp-i3c.c b/drivers/net/mctp/mctp-i3c.c +index fbcd48f1971a4..dd74f916e3172 100644 +--- a/drivers/net/mctp/mctp-i3c.c ++++ b/drivers/net/mctp/mctp-i3c.c +@@ -288,6 +288,7 @@ __must_hold(&busdevs_lock) + static int mctp_i3c_probe(struct i3c_device *i3c) + { + struct mctp_i3c_bus *b = NULL, *mbus = NULL; ++ int rc; + + /* Look for a known bus */ + mutex_lock(&busdevs_lock); +@@ -296,14 +297,16 @@ static int mctp_i3c_probe(struct i3c_device *i3c) + mbus = b; + break; + } +- mutex_unlock(&busdevs_lock); + + if (!mbus) { + /* probably no "mctp-controller" property on the i3c bus */ +- return -ENODEV; ++ rc = -ENODEV; ++ } else { ++ rc = mctp_i3c_add_device(mbus, i3c); } - ni_usb_soft_update_status(board, status.ibsta, 0); -- if (status.ibsta & END) -+ if ((status.ibsta & END) && (status.error_code == NIUSB_NO_ERROR)) - *end = 1; - else - *end = 0; ++ mutex_unlock(&busdevs_lock); + +- return mctp_i3c_add_device(mbus, i3c); ++ return rc; + } + + static void mctp_i3c_remove_device(struct mctp_i3c_device *mi) -- 2.53.0 diff --git a/a/content_digest b/N1/content_digest index 4518ead..703c1df 100644 --- a/a/content_digest +++ b/N1/content_digest @@ -1,58 +1,74 @@ - "ref\020260917151551.901433442@linuxfoundation.org\0" + "ref\020260917151539.408551884@linuxfoundation.org\0" "From\0Greg Kroah-Hartman <gregkh@linuxfoundation.org>\0" - "Subject\0[PATCH 6.18 0197/1250] gpib: Suppress setting END on error from NI_USB dongle\0" - "Date\0Thu, 17 Sep 2026 15:59:52 +0100\0" + "Subject\0[PATCH 6.12 0685/1102] net: mctp: i3c: serialize probe with bus removal\0" + "Date\0Thu, 17 Sep 2026 16:10:28 +0100\0" "To\0stable@vger.kernel.org\0" "Cc\0Greg Kroah-Hartman <gregkh@linuxfoundation.org>" patches@lists.linux.dev - Dave Penkler <dpenkler@gmail.com> + XingWang Xiang <v3rdant.xiang@gmail.com> + Matt Johnston <matt@codeconstruct.com.au> + David S. Miller <davem@davemloft.net> " Sasha Levin <sashal@kernel.org>\0" "\00:1\0" "b\0" - "6.18-stable review patch. If anyone has any objections, please let me know.\n" + "6.12-stable review patch. If anyone has any objections, please let me know.\n" "\n" "------------------\n" "\n" - "From: Dave Penkler <dpenkler@gmail.com>\n" + "From: XingWang Xiang <v3rdant.xiang@gmail.com>\n" "\n" - "[ Upstream commit 7c19b47f5a1839817e5ddc5ba589224fcfb6255d ]\n" + "[ Upstream commit 2b4707a149a55e8fa75c9ef32b359d60f470a566 ]\n" "\n" - "The NI USB adapter sets the END bit in the status word when an error\n" - "occurs such as a read being interrupted by the setting of ATN. This\n" - "happens for example when a device clear is received from the\n" - "controller in charge during a read.\n" + "mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A\n" + "concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus\n" + "netdev before probe passes its private data to mctp_i3c_add_device().\n" + "The latter consequently adds a list node through a freed mbus pointer.\n" "\n" - "The common driver changes the error return to 0 whenever the END bit\n" - "is set in order to avoid errors such as timeout or interrupt to be\n" - "reported after the full message has actually been read. The behaviour\n" - "of the NI USB adapter in setting the END bit on errors was causing\n" - "actual errors (-EINTR, -ETIMEDOUT) not to be reported.\n" + "Keep busdevs_lock held until the device has been added. This also\n" + "satisfies the __must_hold annotation on mctp_i3c_add_device().\n" "\n" - "We avoid setting the END bit in the ni_usb_gpib driver when an error\n" - "is reported in error_code of the status from the adaptor.\n" - "\n" - "Signed-off-by: Dave Penkler <dpenkler@gmail.com>\n" - "Link: https://patch.msgid.link/20260422074807.3194-1-dpenkler@gmail.com\n" - "Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>\n" + "Fixes: c8755b29b58e (\"mctp i3c: MCTP I3C driver\")\n" + "Signed-off-by: XingWang Xiang <v3rdant.xiang@gmail.com>\n" + "Acked-by: Matt Johnston <matt@codeconstruct.com.au>\n" + "Signed-off-by: David S. Miller <davem@davemloft.net>\n" "Signed-off-by: Sasha Levin <sashal@kernel.org>\n" "---\n" - " drivers/staging/gpib/ni_usb/ni_usb_gpib.c | 2 +-\n" - " 1 file changed, 1 insertion(+), 1 deletion(-)\n" + " drivers/net/mctp/mctp-i3c.c | 9 ++++++---\n" + " 1 file changed, 6 insertions(+), 3 deletions(-)\n" "\n" - "diff --git a/drivers/staging/gpib/ni_usb/ni_usb_gpib.c b/drivers/staging/gpib/ni_usb/ni_usb_gpib.c\n" - "index b6fddb437f552..67cc3398e2831 100644\n" - "--- a/drivers/staging/gpib/ni_usb/ni_usb_gpib.c\n" - "+++ b/drivers/staging/gpib/ni_usb/ni_usb_gpib.c\n" - "@@ -720,7 +720,7 @@ static int ni_usb_read(struct gpib_board *board, u8 *buffer, size_t length,\n" - " \t\tbreak;\n" + "diff --git a/drivers/net/mctp/mctp-i3c.c b/drivers/net/mctp/mctp-i3c.c\n" + "index fbcd48f1971a4..dd74f916e3172 100644\n" + "--- a/drivers/net/mctp/mctp-i3c.c\n" + "+++ b/drivers/net/mctp/mctp-i3c.c\n" + "@@ -288,6 +288,7 @@ __must_hold(&busdevs_lock)\n" + " static int mctp_i3c_probe(struct i3c_device *i3c)\n" + " {\n" + " \tstruct mctp_i3c_bus *b = NULL, *mbus = NULL;\n" + "+\tint rc;\n" + " \n" + " \t/* Look for a known bus */\n" + " \tmutex_lock(&busdevs_lock);\n" + "@@ -296,14 +297,16 @@ static int mctp_i3c_probe(struct i3c_device *i3c)\n" + " \t\t\tmbus = b;\n" + " \t\t\tbreak;\n" + " \t\t}\n" + "-\tmutex_unlock(&busdevs_lock);\n" + " \n" + " \tif (!mbus) {\n" + " \t\t/* probably no \"mctp-controller\" property on the i3c bus */\n" + "-\t\treturn -ENODEV;\n" + "+\t\trc = -ENODEV;\n" + "+\t} else {\n" + "+\t\trc = mctp_i3c_add_device(mbus, i3c);\n" " \t}\n" - " \tni_usb_soft_update_status(board, status.ibsta, 0);\n" - "-\tif (status.ibsta & END)\n" - "+\tif ((status.ibsta & END) && (status.error_code == NIUSB_NO_ERROR))\n" - " \t\t*end = 1;\n" - " \telse\n" - " \t\t*end = 0;\n" + "+\tmutex_unlock(&busdevs_lock);\n" + " \n" + "-\treturn mctp_i3c_add_device(mbus, i3c);\n" + "+\treturn rc;\n" + " }\n" + " \n" + " static void mctp_i3c_remove_device(struct mctp_i3c_device *mi)\n" "-- \n" 2.53.0 -0084a69bc5c23047627f691442362a25aaf207d1fb860c145d6ac76455cc3cb5 +b7f13ccf067f7581670cea1821fe9902f08b00fe36276d071188f980b7d91605
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox