Linux Serial subsystem development
 help / color / mirror / Atom feed
* [PATCH] serial: max3100: Fix a data race on s->rts in max3100_work()
@ 2026-09-22  5:31 Ginger Li
  2026-09-22  5:40 ` sashiko-bot
                   ` (2 more replies)
  0 siblings, 3 replies; 10+ messages in thread
From: Ginger Li @ 2026-09-22  5:31 UTC (permalink / raw)
  To: jirislaby, gregkh; +Cc: linux-serial

max3100_work() reads s->rts when it processes a pending RTS update and when
it transmits a character, both times without holding s->conf_lock.
max3100_set_mctrl() updates s->rts under that lock when the requested RTS
state changes, so the two accesses race and the work handler can program the
old RTS state in the hardware.

Take the value of s->rts in the s->conf_lock protected snapshot at the top of
the loop, like the other configuration fields.

Fixes: 7831d56b0a35 ("tty: MAX3100")
Signed-off-by: Ginger Li <ginger.jzllee@gmail.com>
---
 drivers/tty/serial/max3100.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/tty/serial/max3100.c b/drivers/tty/serial/max3100.c
--- a/drivers/tty/serial/max3100.c
+++ b/drivers/tty/serial/max3100.c
@@ -236,6 +236,7 @@ static void max3100_work(struct work_struct *w)
 	struct tty_port *tport = &s->port.state->port;
 	unsigned char ch;
 	int conf, cconf, cloopback, crts;
+	bool rts;
 	int rxchars;
 	u16 tx, rx;
 
@@ -251,6 +252,7 @@ static void max3100_work(struct work_struct *w)
 		s->loopback_commit = 0;
 		crts = s->rts_commit;
 		s->rts_commit = 0;
+		rts = s->rts;
 		spin_unlock(&s->conf_lock);
 		if (cconf)
 			max3100_sr(s, MAX3100_WC | conf, &rx);
@@ -258,7 +260,7 @@ static void max3100_work(struct work_struct *w)
 			max3100_sr(s, 0x4001, &rx);
 		if (crts) {
 			max3100_sr(s, MAX3100_WD | MAX3100_TE |
-				   (s->rts ? MAX3100_RTS : 0), &rx);
+				   (rts ? MAX3100_RTS : 0), &rx);
 			rxchars += max3100_handlerx(s, rx);
 		}
 
@@ -277,7 +279,7 @@ static void max3100_work(struct work_struct *w)
 			}
 			if (tx != 0xffff) {
 				max3100_calc_parity(s, &tx);
-				tx |= MAX3100_WD | (s->rts ? MAX3100_RTS : 0);
+				tx |= MAX3100_WD | (rts ? MAX3100_RTS : 0);
 				max3100_sr(s, tx, &rx);
 				rxchars += max3100_handlerx(s, rx);
 			}
-- 
2.43.0


^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-09-24  8:32 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-22  5:31 [PATCH] serial: max3100: Fix a data race on s->rts in max3100_work() Ginger Li
2026-09-22  5:40 ` sashiko-bot
2026-09-22  8:17 ` Maarten Brock
2026-09-22  8:26   ` Ginger
2026-09-22  9:25     ` Maarten Brock
2026-09-22 17:04       ` Ginger
2026-09-22 17:02 ` [PATCH v2] " Ginger Li
2026-09-22 17:12   ` sashiko-bot
2026-09-23 10:31   ` Greg KH
2026-09-24  8:32   ` Maarten Brock

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox