Linux Serial subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Abel Vesa" <abel.vesa@oss.qualcomm.com>
Cc: linux-serial@vger.kernel.org
Subject: Re: [PATCH] serial: qcom-geni: Fix unbalanced runtime PM resume for no_console_suspend
Date: Fri, 28 Aug 2026 14:43:07 +0000	[thread overview]
Message-ID: <20260828144307.79A7D1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260828-serial-qcom-geni-fix-unbalanced-rpm-resume-v1-1-af3e5aef17a6@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:

Pre-existing issues:
- [Critical] Reallocating the DMA receive buffer in setup_fifos() frees the active DMA-mapped memory without unmapping it, leading to DMA use-after-free and massive out-of-bounds reads/writes.
- [High] Asynchronous pm_runtime_put() is used on the probe error path before devres pm_runtime_disable(), leaving hardware powered on indefinitely.
- [High] Missing rollback in qcom_geni_serial_suspend() if pm_runtime_force_suspend() fails, leaving the UART port permanently disabled.
- [High] IDA line ID is freed before the UART port is unregistered, allowing a race condition with a concurrent probe.
--

commit 7fc2859a848a4f1ec1c0bc7d7815a5c518730a33
Author: Abel Vesa <abel.vesa@oss.qualcomm.com>

serial: qcom-geni: Fix unbalanced runtime PM resume for no_console_suspend

When no_console_suspend is set for the serial console, the system
suspend callback skips pm_runtime_force_suspend() to keep the console
active. The resume callback still unconditionally calls
pm_runtime_force_resume(), which triggers an "Unbalanced
pm_runtime_enable!" warning.

> diff --git a/drivers/tty/serial/qcom_geni_serial.c b/drivers/tty/serial/qcom_geni_serial.c
> index 3633723acef8d..a180a00c9e23d 100644
> --- a/drivers/tty/serial/qcom_geni_serial.c
> +++ b/drivers/tty/serial/qcom_geni_serial.c
> @@ -1074,10 +1074,10 @@ static int setup_fifos(struct qcom_geni_serial_port *port)
[ ... ]
> 	if (port->rx_buf && (old_rx_fifo_depth != port->rx_fifo_depth) && port->rx_fifo_depth) {
> 		/*
> 		 * Use krealloc rather than krealloc_array because rx_buf is
> 		 * accessed as 1 byte entries as well as 4 byte entries so it's
> 		 * not necessarily an array.
> 		 */
> 		port->rx_buf = devm_krealloc(uport->dev, port->rx_buf,
> 					     port->rx_fifo_depth * sizeof(u32),
> 					     GFP_KERNEL);

[Severity: Critical]
This is a pre-existing issue, but it looks like devm_krealloc() frees the
original active DMA-mapped memory buffer here without updating
port->rx_dma_addr or unmapping the original DMA mapping.

Could this allow the hardware DMA to write to the freed memory block, and
cause handle_rx_uart() to later read out-of-bounds from the newly allocated,
shrunk port->rx_buf, leaking kernel heap memory to the TTY layer?

> @@ -1991,7 +1991,7 @@ static int qcom_geni_serial_probe(struct platform_device *pdev)
[ ... ]
> 	ret = pm_runtime_resume_and_get(uport->dev);
> 	if (ret < 0) {
> 		dev_err(uport->dev, "Failed to resume and get %d\n", ret);
> 		goto error;
> 	}
> 
> 	ret = uart_add_one_port(drv, uport);
> 	pm_runtime_put(uport->dev);
> 	if (ret)
> 		goto error;

[Severity: High]
This isn't a bug introduced by this patch, but doesn't using an asynchronous
pm_runtime_put() here on the probe error path leave the hardware powered on
indefinitely?

The devres pm_runtime_disable() that follows will cancel any pending
asynchronous suspend work.

> @@ -2022,6 +2022,6 @@ static void qcom_geni_serial_remove(struct platform_device *pdev)
[ ... ]
> 	WRITE_ONCE(port->tx_kick_enabled, false);
> 	irq_work_sync(&port->tx_kick);
> 	dev_pm_clear_wake_irq(&pdev->dev);
> 	device_init_wakeup(&pdev->dev, false);
> 	ida_free(&port_ida, uport->line);
> 	uart_remove_one_port(drv, &port->uport);

[Severity: High]
This is a pre-existing issue, but is the IDA line ID prematurely freed here
before the UART port is completely unregistered on the next line?

If a concurrent device probe allocates the just-freed IDA line ID while
uart_remove_one_port() is still running for the old device, it seems this
could cause a collision in the serial core due to duplicate line IDs being
registered simultaneously.

> @@ -2086,10 +2086,10 @@ static int qcom_geni_serial_suspend(struct device *dev)
[ ... ]
> 	/*
> 	 * When no_console_suspend is set the console must remain active
> 	 * across system sleep, so skip the force suspend path.
> 	 */
> 	if (!console_suspend_enabled && uart_console(uport))
> 		return 0;
> 
> 	return pm_runtime_force_suspend(dev);

[Severity: High]
This isn't a bug introduced by this patch, but if pm_runtime_force_suspend()
fails, does this return the error without reverting the effects of
uart_suspend_port() and geni_icc_set_tag() executed earlier in the function?

It seems this could leave the UART port permanently disabled.

>  }
>  
>  static int qcom_geni_serial_resume(struct device *dev)
>  {
>  	int ret;
>  	struct qcom_geni_serial_port *port = dev_get_drvdata(dev);
>  	struct uart_port *uport = &port->uport;
>  	struct qcom_geni_private_data *private_data = uport->private_data;
>  
> -	ret = pm_runtime_force_resume(dev);
> -	if (ret)
> -		return ret;
> +	if (console_suspend_enabled || !uart_console(uport)) {
> +		ret = pm_runtime_force_resume(dev);
> +		if (ret)
> +			return ret;
> +	}
>  
>  	ret = uart_resume_port(private_data->drv, uport);
>  	if (uart_console(uport)) {

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260828-serial-qcom-geni-fix-unbalanced-rpm-resume-v1-1-af3e5aef17a6@oss.qualcomm.com?part=1

      parent reply	other threads:[~2026-08-28 14:43 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-28 14:32 [PATCH] serial: qcom-geni: Fix unbalanced runtime PM resume for no_console_suspend Abel Vesa
2026-08-28 14:40 ` Praveen Talari
2026-08-28 14:43 ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260828144307.79A7D1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=abel.vesa@oss.qualcomm.com \
    --cc=linux-serial@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox