From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-00082601.pphosted.com (mx0a-00082601.pphosted.com [67.231.145.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 39DBA3570DA for ; Fri, 30 Jan 2026 17:00:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=67.231.145.42 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769792418; cv=none; b=Y4i8x2h1rQg+L95Se851X0hjx5OU0x15z4Pf3ftDlNXBEudgDb8vXED0KturEqOsmqEG6/t1QbrrR+GkLEuXgiZ6rUsgvJt9ePGASlKoYbnIskKVIHrrRnQprIP9C8/zN3Fp25biT/BrsO+Xlc0FOgXkay6j+PVc9xtXXLC+SD0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769792418; c=relaxed/simple; bh=JyBRMQSQuxvl3z8pwOXAeqgUK9hw9MiYTK2ahHd4AHs=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=FcPYlZo3uIX20fHTiWEkByIYbKeHJvCnFqpPDvrUDh57LJvdMqqcZVyHQvSegkeEK595y9dIKc1xj6Clwsl2iMW5aCkUMUfVG0JKya4unnZ1Mf9kN26bKC/z7H8RfQwtPX/rFM/OtT0iFm55d0+ikXpxZSGWINkpLGkxl6NXNy0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=meta.com; spf=pass smtp.mailfrom=meta.com; dkim=pass (2048-bit key) header.d=meta.com header.i=@meta.com header.b=m27aXN2m; arc=none smtp.client-ip=67.231.145.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=meta.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=meta.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=meta.com header.i=@meta.com header.b="m27aXN2m" Received: from pps.filterd (m0044010.ppops.net [127.0.0.1]) by mx0a-00082601.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 60UGZ5nv643644 for ; Fri, 30 Jan 2026 09:00:16 -0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=meta.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=s2048-2025-q2; bh=Mm+xOkZ24YFd5RjWStEPyEiVdlh2cY8+P++RYXeeNlA=; b=m27aXN2mAG+e ez4zm7jZzRaxhytqzIvPVQpZw8dSPXOVVwYRJUoVs0x/Ts7AiNo7i+Kh+nS/e61l 8GKDxve7wHyt8jNCp82wGUbAAQtYCclS4a5cnBbFOmbfcX5foxShfeqytUpw2p48 RnoiB+kw+m835G+uXtPlYWcX8NaCeJfmEKFPr4aYKB6M86bFeWfAZJELtzSbts1D ompmX06B9I4d6pnh/wEAWPPY3U2nOhhGeIi7IwnZrxQOUBpr8ucpa6kvpFOhGtD6 mNtu0GXHLmPM8V18a/spDpXkmZM8kRFquJeFxnTEVodqPWryyVcFczJKT0K7LmXN kwuO+nfnyQ== Received: from mail.thefacebook.com ([163.114.134.16]) by mx0a-00082601.pphosted.com (PPS) with ESMTPS id 4c109v09vn-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NOT) for ; Fri, 30 Jan 2026 09:00:16 -0800 (PST) Received: from twshared108583.15.frc2.facebook.com (2620:10d:c085:108::4) by mail.thefacebook.com (2620:10d:c08b:78::c78f) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.2.2562.35; Fri, 30 Jan 2026 17:00:15 +0000 Received: by devbig197.nha3.facebook.com (Postfix, from userid 544533) id 84E026EAF1B1; Fri, 30 Jan 2026 09:00:04 -0800 (PST) From: Keith Busch To: , CC: , , , , , , Keith Busch Subject: [PATCHv2 1/4] PCI: Fix incorrect unlocking in pci_slot_trylock() Date: Fri, 30 Jan 2026 08:59:50 -0800 Message-ID: <20260130165953.751063-2-kbusch@meta.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260130165953.751063-1-kbusch@meta.com> References: <20260130165953.751063-1-kbusch@meta.com> Precedence: bulk X-Mailing-List: linux-pci@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-FB-Internal: Safe Content-Type: text/plain X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwMTMwMDEzOSBTYWx0ZWRfXwZpQWr09zEXQ 6/54ecBCkwvo0EdGibSfXkfZAD2q4Z1LceVHG2vNvMQRYHpCJr95oinUhXFY+zMeaemE/VArSvJ 6mDDStlAqKtNK77cC3jmxa9rvCkPNMWosWsHsPTV+JzSpf0PMj/0BqMaOhsxJ4bm0R4iz05FRaz Pqn+aj7b0TuxUE+KHBs4HgmpJjQhRe5ix+v3eeF2rzqybTUGo8P4AahYXRjCi4NiyCe4cfc33wp i9E6umolTbQWNIYVFgJw8z+iLd2laVJeBqwjG2Cd0k4VGoFzR5J7muUlwNcN9rrPrff0uJ5hIzp XE951e9FxjN8SpUaOAaL6eH8dkwlIiR36H2tbZqOSTgVM81sz75BomGZusXma99B1brsou3mLYe V18pIctKODaQ2r3O2zgoeU/6d3eCYrgd07cS/+Vt4rACHa6n/YnLMNLiFV9qm7NRGyTQqtGHH60 1D0bd0YRBi4HKk+KwBQ== X-Proofpoint-GUID: Eeb_yvFN2uz-1dC3Lwd8jWuUXbDbCBsP X-Proofpoint-ORIG-GUID: Eeb_yvFN2uz-1dC3Lwd8jWuUXbDbCBsP X-Authority-Analysis: v=2.4 cv=AvLjHe9P c=1 sm=1 tr=0 ts=697ce3a0 cx=c_pps a=CB4LiSf2rd0gKozIdrpkBw==:117 a=CB4LiSf2rd0gKozIdrpkBw==:17 a=vUbySO9Y5rIA:10 a=VkNPw1HP01LnGYTKEx00:22 a=968KyxNXAAAA:8 a=VwQbUJbxAAAA:8 a=QyXUC8HyAAAA:8 a=KowqXwEJNvZSKAjHX7EA:9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1121,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-01-30_02,2026-01-30_03,2025-10-01_01 From: Jinhui Guo Commit a4e772898f8b ("PCI: Add missing bridge lock to pci_bus_lock()") delegates the bridge device's pci_dev_trylock() to pci_bus_trylock() in pci_slot_trylock(), but it forgets to remove the corresponding pci_dev_unlock() when pci_bus_trylock() fails. Before the commit, the code did: if (!pci_dev_trylock(dev)) /* <- lock bridge device */ goto unlock; if (dev->subordinate) { if (!pci_bus_trylock(dev->subordinate)) { pci_dev_unlock(dev); /* <- unlock bridge device */ goto unlock; } } After the commit the bridge-device lock is no longer taken, but the pci_dev_unlock(dev) on the failure path was left in place, leading to the bug. This yields one of two errors: 1. A warning that the lock is being unlocked when no one holds it. 2. An incorrect unlock of a lock that belongs to another thread. Fix it by removing the now-redundant pci_dev_unlock(dev) on the failure path. Fixes: a4e772898f8b ("PCI: Add missing bridge lock to pci_bus_lock()") Cc: stable@vger.kernel.org Reviewed-by: Dan Williams Signed-off-by: Jinhui Guo Signed-off-by: Keith Busch --- drivers/pci/pci.c | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/drivers/pci/pci.c b/drivers/pci/pci.c index 13dbb405dc31f..59319e08fca61 100644 --- a/drivers/pci/pci.c +++ b/drivers/pci/pci.c @@ -5346,10 +5346,8 @@ static int pci_slot_trylock(struct pci_slot *slot) if (!dev->slot || dev->slot !=3D slot) continue; if (dev->subordinate) { - if (!pci_bus_trylock(dev->subordinate)) { - pci_dev_unlock(dev); + if (!pci_bus_trylock(dev->subordinate)) goto unlock; - } } else if (!pci_dev_trylock(dev)) goto unlock; } --=20 2.47.3