From: Greg KH <gregkh@linuxfoundation.org>
To: cuigaosheng <cuigaosheng1@huawei.com>
Cc: sashiko-bot@kernel.org, lujialin4@huawei.com,
jirislaby@kernel.org, hvilleneuve@dimonoff.com,
kmehltretter@gmail.com, john.ogness@linutronix.de,
andriy.shevchenko@linux.intel.com, tony@atomide.com,
linux-serial@vger.kernel.org
Subject: Re: [PATCH -next] serial: core: fix NULL/dangling port_dev on failed re-register
Date: Thu, 24 Sep 2026 16:37:05 +0200 [thread overview]
Message-ID: <2026092440-wobbling-gecko-210d@gregkh> (raw)
In-Reply-To: <d3cb66b5-5b2a-ee57-8eb6-4e66d7e575be@huawei.com>
On Thu, Sep 24, 2026 at 09:28:23PM +0800, cuigaosheng wrote:
> Thanks for the review, I have submitted v2 of the patch.
Great, but please do not top-post, you just lost all relevant
information :(
> I have tested on x86_64 linux-next (7.2.0-rc7) with KASAN, failslab and
> fault injection debugfs enabled;
>
> It takes two unbind rounds to reproduce since
> serial8250_unregister_port() first unregisters and then re-registers
> the port: the fault injection must hit the re-registration to plant
> the stale port_dev, and only the next unbind dereferences it.
What do you mean by this? What fault injection and why do we care about
that if it can never hit in real life?
> The
> reproducer is a small userspace program that loops over sysfs
> bind/unbind of serial8250 and scans /proc/self/fail-nth from 1 to
> 6000, making the Nth slab allocation on the re-register path fail
> with -ENOMEM:
bind/unbind is not a normal operation that a user can do, and is for
debugging only. So are you sure this is a real issue?
thanks,
greg k-h
prev parent reply other threads:[~2026-09-24 14:37 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 13:51 [PATCH -next] serial: core: fix NULL/dangling port_dev on failed re-register Gaosheng Cui
2026-09-14 14:23 ` sashiko-bot
2026-09-23 12:52 ` Greg KH
2026-09-24 13:28 ` cuigaosheng
2026-09-24 14:37 ` Greg KH [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026092440-wobbling-gecko-210d@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=andriy.shevchenko@linux.intel.com \
--cc=cuigaosheng1@huawei.com \
--cc=hvilleneuve@dimonoff.com \
--cc=jirislaby@kernel.org \
--cc=john.ogness@linutronix.de \
--cc=kmehltretter@gmail.com \
--cc=linux-serial@vger.kernel.org \
--cc=lujialin4@huawei.com \
--cc=sashiko-bot@kernel.org \
--cc=tony@atomide.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox