From: sashiko-bot@kernel.org
To: "Johan Hovold" <johan@kernel.org>
Cc: linux-serial@vger.kernel.org
Subject: Re: [PATCH v3 2/4] serial: fix ioctl hangup race
Date: Mon, 07 Sep 2026 07:00:34 +0000 [thread overview]
Message-ID: <20260907070034.DF3B01F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260907064418.92953-3-johan@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] uart_set_ldisc misses the tty_io_error(tty) check while holding port->mutex, allowing hardware access after the port has been shut down.
--
commit 3a1dbe6dd850d3b9aa0ddbed8997abbaa897c8af
Author: Johan Hovold <johan@kernel.org>
serial: fix ioctl hangup race
The tty ioctls can race with hangup and end up calling into a tty
driver for a device that is already gone or powered down.
Add the missing checks to make sure the port has not been hung up before
accessing the hardware to avoid issues like kernel panic due to
unclocked accesses.
> diff --git a/drivers/tty/serial/serial_core.c b/drivers/tty/serial/serial_core.c
> index 1553bc6cbe7ba..4213fa3dc988b 100644
> --- a/drivers/tty/serial/serial_core.c
> +++ b/drivers/tty/serial/serial_core.c
[ ... ]
> @@ -1647,7 +1658,7 @@ static void uart_set_termios(struct tty_struct *tty,
> guard(mutex)(&state->port.mutex);
>
> uport = uart_port_check(state);
> - if (!uport)
> + if (!uport || tty_io_error(tty))
> return;
>
> /*
[Severity: High]
This isn't a bug introduced by this patch, but should a similar check be
added to uart_set_ldisc?
uart_set_ldisc() also acquires port->mutex and checks if the port is valid,
but it does not check tty_io_error(tty) before calling uport->ops->set_ldisc:
static void uart_set_ldisc(struct tty_struct *tty)
{
...
guard(mutex)(&state->port.mutex);
uport = uart_port_check(state);
if (uport && uport->ops->set_ldisc)
uport->ops->set_ldisc(uport, &tty->termios);
}
If a privileged user executes TIOCSERCONFIG concurrently with a TIOCSETD ioctl,
uart_do_autoconfig() can acquire the mutex, call uart_shutdown() to shut down
the hardware, and set TTY_IO_ERROR. If uart_set_ldisc() then acquires the
mutex, could it invoke the uport->ops->set_ldisc hardware callback on a
powered-down device since it doesn't verify tty_io_error(tty)?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260907064418.92953-1-johan@kernel.org?part=2
next prev parent reply other threads:[~2026-09-07 7:00 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 6:44 [PATCH v3 0/4] serial: fix ioctl hangup race Johan Hovold
2026-09-07 6:44 ` [PATCH v3 1/4] serial: revert guards in uart_wait_modem_status() Johan Hovold
2026-09-07 6:47 ` Jiri Slaby
2026-09-07 6:51 ` Jiri Slaby
2026-09-07 7:37 ` Johan Hovold
2026-09-07 6:51 ` sashiko-bot
2026-09-07 6:44 ` [PATCH v3 2/4] serial: fix ioctl hangup race Johan Hovold
2026-09-07 7:00 ` sashiko-bot [this message]
2026-09-07 7:14 ` Johan Hovold
2026-09-07 6:44 ` [PATCH v3 3/4] serial: fix TIOCMIWAIT race Johan Hovold
2026-09-07 6:50 ` sashiko-bot
2026-09-07 6:44 ` [PATCH v3 4/4] serial: abort TIOCMIWAIT on hangup Johan Hovold
2026-09-07 6:51 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260907070034.DF3B01F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=johan@kernel.org \
--cc=linux-serial@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox