Archive-only list for patches
 help / color / mirror / Atom feed
diff for duplicates of <20260917151557.456504194@linuxfoundation.org>

diff --git a/a/1.txt b/N1/1.txt
index 5eb20da..e528bd9 100644
--- a/a/1.txt
+++ b/N1/1.txt
@@ -1,45 +1,59 @@
-6.18-stable review patch.  If anyone has any objections, please let me know.
+6.12-stable review patch.  If anyone has any objections, please let me know.
 
 ------------------
 
-From: Dave Penkler <dpenkler@gmail.com>
+From: XingWang Xiang <v3rdant.xiang@gmail.com>
 
-[ Upstream commit 7c19b47f5a1839817e5ddc5ba589224fcfb6255d ]
+[ Upstream commit 2b4707a149a55e8fa75c9ef32b359d60f470a566 ]
 
-The NI USB adapter sets the END bit in the status word when an error
-occurs such as a read being interrupted by the setting of ATN. This
-happens for example when a device clear is received from the
-controller in charge during a read.
+mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A
+concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus
+netdev before probe passes its private data to mctp_i3c_add_device().
+The latter consequently adds a list node through a freed mbus pointer.
 
-The common driver changes the error return to 0 whenever the END bit
-is set in order to avoid errors such as timeout or interrupt to be
-reported after the full message has actually been read. The behaviour
-of the NI USB adapter in setting the END bit on errors was causing
-actual errors (-EINTR, -ETIMEDOUT) not to be reported.
+Keep busdevs_lock held until the device has been added. This also
+satisfies the __must_hold annotation on mctp_i3c_add_device().
 
-We avoid setting the END bit in the ni_usb_gpib driver when an error
-is reported in error_code of the status from the adaptor.
-
-Signed-off-by: Dave Penkler <dpenkler@gmail.com>
-Link: https://patch.msgid.link/20260422074807.3194-1-dpenkler@gmail.com
-Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+Fixes: c8755b29b58e ("mctp i3c: MCTP I3C driver")
+Signed-off-by: XingWang Xiang <v3rdant.xiang@gmail.com>
+Acked-by: Matt Johnston <matt@codeconstruct.com.au>
+Signed-off-by: David S. Miller <davem@davemloft.net>
 Signed-off-by: Sasha Levin <sashal@kernel.org>
 ---
- drivers/staging/gpib/ni_usb/ni_usb_gpib.c | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/drivers/staging/gpib/ni_usb/ni_usb_gpib.c b/drivers/staging/gpib/ni_usb/ni_usb_gpib.c
-index b6fddb437f552..67cc3398e2831 100644
---- a/drivers/staging/gpib/ni_usb/ni_usb_gpib.c
-+++ b/drivers/staging/gpib/ni_usb/ni_usb_gpib.c
-@@ -720,7 +720,7 @@ static int ni_usb_read(struct gpib_board *board, u8 *buffer, size_t length,
- 		break;
+ drivers/net/mctp/mctp-i3c.c | 9 ++++++---
+ 1 file changed, 6 insertions(+), 3 deletions(-)
+
+diff --git a/drivers/net/mctp/mctp-i3c.c b/drivers/net/mctp/mctp-i3c.c
+index fbcd48f1971a4..dd74f916e3172 100644
+--- a/drivers/net/mctp/mctp-i3c.c
++++ b/drivers/net/mctp/mctp-i3c.c
+@@ -288,6 +288,7 @@ __must_hold(&busdevs_lock)
+ static int mctp_i3c_probe(struct i3c_device *i3c)
+ {
+ 	struct mctp_i3c_bus *b = NULL, *mbus = NULL;
++	int rc;
+ 
+ 	/* Look for a known bus */
+ 	mutex_lock(&busdevs_lock);
+@@ -296,14 +297,16 @@ static int mctp_i3c_probe(struct i3c_device *i3c)
+ 			mbus = b;
+ 			break;
+ 		}
+-	mutex_unlock(&busdevs_lock);
+ 
+ 	if (!mbus) {
+ 		/* probably no "mctp-controller" property on the i3c bus */
+-		return -ENODEV;
++		rc = -ENODEV;
++	} else {
++		rc = mctp_i3c_add_device(mbus, i3c);
  	}
- 	ni_usb_soft_update_status(board, status.ibsta, 0);
--	if (status.ibsta & END)
-+	if ((status.ibsta & END) && (status.error_code == NIUSB_NO_ERROR))
- 		*end = 1;
- 	else
- 		*end = 0;
++	mutex_unlock(&busdevs_lock);
+ 
+-	return mctp_i3c_add_device(mbus, i3c);
++	return rc;
+ }
+ 
+ static void mctp_i3c_remove_device(struct mctp_i3c_device *mi)
 -- 
 2.53.0
diff --git a/a/content_digest b/N1/content_digest
index 4518ead..703c1df 100644
--- a/a/content_digest
+++ b/N1/content_digest
@@ -1,58 +1,74 @@
- "ref\020260917151551.901433442@linuxfoundation.org\0"
+ "ref\020260917151539.408551884@linuxfoundation.org\0"
  "From\0Greg Kroah-Hartman <gregkh@linuxfoundation.org>\0"
- "Subject\0[PATCH 6.18 0197/1250] gpib: Suppress setting END on error from NI_USB dongle\0"
- "Date\0Thu, 17 Sep 2026 15:59:52 +0100\0"
+ "Subject\0[PATCH 6.12 0685/1102] net: mctp: i3c: serialize probe with bus removal\0"
+ "Date\0Thu, 17 Sep 2026 16:10:28 +0100\0"
  "To\0stable@vger.kernel.org\0"
  "Cc\0Greg Kroah-Hartman <gregkh@linuxfoundation.org>"
   patches@lists.linux.dev
-  Dave Penkler <dpenkler@gmail.com>
+  XingWang Xiang <v3rdant.xiang@gmail.com>
+  Matt Johnston <matt@codeconstruct.com.au>
+  David S. Miller <davem@davemloft.net>
  " Sasha Levin <sashal@kernel.org>\0"
  "\00:1\0"
  "b\0"
- "6.18-stable review patch.  If anyone has any objections, please let me know.\n"
+ "6.12-stable review patch.  If anyone has any objections, please let me know.\n"
  "\n"
  "------------------\n"
  "\n"
- "From: Dave Penkler <dpenkler@gmail.com>\n"
+ "From: XingWang Xiang <v3rdant.xiang@gmail.com>\n"
  "\n"
- "[ Upstream commit 7c19b47f5a1839817e5ddc5ba589224fcfb6255d ]\n"
+ "[ Upstream commit 2b4707a149a55e8fa75c9ef32b359d60f470a566 ]\n"
  "\n"
- "The NI USB adapter sets the END bit in the status word when an error\n"
- "occurs such as a read being interrupted by the setting of ATN. This\n"
- "happens for example when a device clear is received from the\n"
- "controller in charge during a read.\n"
+ "mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A\n"
+ "concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus\n"
+ "netdev before probe passes its private data to mctp_i3c_add_device().\n"
+ "The latter consequently adds a list node through a freed mbus pointer.\n"
  "\n"
- "The common driver changes the error return to 0 whenever the END bit\n"
- "is set in order to avoid errors such as timeout or interrupt to be\n"
- "reported after the full message has actually been read. The behaviour\n"
- "of the NI USB adapter in setting the END bit on errors was causing\n"
- "actual errors (-EINTR, -ETIMEDOUT) not to be reported.\n"
+ "Keep busdevs_lock held until the device has been added. This also\n"
+ "satisfies the __must_hold annotation on mctp_i3c_add_device().\n"
  "\n"
- "We avoid setting the END bit in the ni_usb_gpib driver when an error\n"
- "is reported in error_code of the status from the adaptor.\n"
- "\n"
- "Signed-off-by: Dave Penkler <dpenkler@gmail.com>\n"
- "Link: https://patch.msgid.link/20260422074807.3194-1-dpenkler@gmail.com\n"
- "Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>\n"
+ "Fixes: c8755b29b58e (\"mctp i3c: MCTP I3C driver\")\n"
+ "Signed-off-by: XingWang Xiang <v3rdant.xiang@gmail.com>\n"
+ "Acked-by: Matt Johnston <matt@codeconstruct.com.au>\n"
+ "Signed-off-by: David S. Miller <davem@davemloft.net>\n"
  "Signed-off-by: Sasha Levin <sashal@kernel.org>\n"
  "---\n"
- " drivers/staging/gpib/ni_usb/ni_usb_gpib.c | 2 +-\n"
- " 1 file changed, 1 insertion(+), 1 deletion(-)\n"
+ " drivers/net/mctp/mctp-i3c.c | 9 ++++++---\n"
+ " 1 file changed, 6 insertions(+), 3 deletions(-)\n"
  "\n"
- "diff --git a/drivers/staging/gpib/ni_usb/ni_usb_gpib.c b/drivers/staging/gpib/ni_usb/ni_usb_gpib.c\n"
- "index b6fddb437f552..67cc3398e2831 100644\n"
- "--- a/drivers/staging/gpib/ni_usb/ni_usb_gpib.c\n"
- "+++ b/drivers/staging/gpib/ni_usb/ni_usb_gpib.c\n"
- "@@ -720,7 +720,7 @@ static int ni_usb_read(struct gpib_board *board, u8 *buffer, size_t length,\n"
- " \t\tbreak;\n"
+ "diff --git a/drivers/net/mctp/mctp-i3c.c b/drivers/net/mctp/mctp-i3c.c\n"
+ "index fbcd48f1971a4..dd74f916e3172 100644\n"
+ "--- a/drivers/net/mctp/mctp-i3c.c\n"
+ "+++ b/drivers/net/mctp/mctp-i3c.c\n"
+ "@@ -288,6 +288,7 @@ __must_hold(&busdevs_lock)\n"
+ " static int mctp_i3c_probe(struct i3c_device *i3c)\n"
+ " {\n"
+ " \tstruct mctp_i3c_bus *b = NULL, *mbus = NULL;\n"
+ "+\tint rc;\n"
+ " \n"
+ " \t/* Look for a known bus */\n"
+ " \tmutex_lock(&busdevs_lock);\n"
+ "@@ -296,14 +297,16 @@ static int mctp_i3c_probe(struct i3c_device *i3c)\n"
+ " \t\t\tmbus = b;\n"
+ " \t\t\tbreak;\n"
+ " \t\t}\n"
+ "-\tmutex_unlock(&busdevs_lock);\n"
+ " \n"
+ " \tif (!mbus) {\n"
+ " \t\t/* probably no \"mctp-controller\" property on the i3c bus */\n"
+ "-\t\treturn -ENODEV;\n"
+ "+\t\trc = -ENODEV;\n"
+ "+\t} else {\n"
+ "+\t\trc = mctp_i3c_add_device(mbus, i3c);\n"
  " \t}\n"
- " \tni_usb_soft_update_status(board, status.ibsta, 0);\n"
- "-\tif (status.ibsta & END)\n"
- "+\tif ((status.ibsta & END) && (status.error_code == NIUSB_NO_ERROR))\n"
- " \t\t*end = 1;\n"
- " \telse\n"
- " \t\t*end = 0;\n"
+ "+\tmutex_unlock(&busdevs_lock);\n"
+ " \n"
+ "-\treturn mctp_i3c_add_device(mbus, i3c);\n"
+ "+\treturn rc;\n"
+ " }\n"
+ " \n"
+ " static void mctp_i3c_remove_device(struct mctp_i3c_device *mi)\n"
  "-- \n"
  2.53.0
 
-0084a69bc5c23047627f691442362a25aaf207d1fb860c145d6ac76455cc3cb5
+b7f13ccf067f7581670cea1821fe9902f08b00fe36276d071188f980b7d91605

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox