From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751801AbdAYKFn (ORCPT ); Wed, 25 Jan 2017 05:05:43 -0500 Received: from mga01.intel.com ([192.55.52.88]:52487 "EHLO mga01.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751588AbdAYKFm (ORCPT ); Wed, 25 Jan 2017 05:05:42 -0500 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.33,283,1477983600"; d="scan'208";a="57011018" Date: Wed, 25 Jan 2017 15:35:57 +0530 From: Vinod Koul To: iari@itu.dk Cc: Marek Szyprowski , Bartlomiej Zolnierkiewicz , Krzysztof Kozlowski , Dan Williams , dmaengine@vger.kernel.org, linux-kernel@vger.kernel.org, Iago Abal Subject: Re: [PATCH] dmaengine: pl330: fix double lock Message-ID: <20170125100557.GD3573@localhost> References: <1484139621-18706-1-git-send-email-iari@itu.dk> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1484139621-18706-1-git-send-email-iari@itu.dk> User-Agent: Mutt/1.5.21 (2010-09-15) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Jan 11, 2017 at 02:00:21PM +0100, iari@itu.dk wrote: > From: Iago Abal > > The static bug finder EBA (http://www.iagoabal.eu/eba/) reported the > following double-lock bug: > > Double lock: > 1. spin_lock_irqsave(pch->lock, flags) at pl330_free_chan_resources:2236; > 2. call to function `pl330_release_channel' immediately after; > 3. call to function `dma_pl330_rqcb' in line 1753; > 4. spin_lock_irqsave(pch->lock, flags) at dma_pl330_rqcb:1505. > > I have fixed it as suggested by Marek Szyprowski. > > First, I have replaced `pch->lock' with `pl330->lock' in functions > `pl330_alloc_chan_resources' and `pl330_free_chan_resources'. This avoids > the double-lock by acquiring a different lock than `dma_pl330_rqcb'. > > NOTE that, as a result, `pl330_free_chan_resources' executes > `list_splice_tail_init' on `pch->work_list' under lock `pl330->lock', > whereas in the rest of the code `pch->work_list' is protected by > `pch->lock'. I don't know if this may cause race conditions. Similarly > `pch->cyclic' is written by `pl330_alloc_chan_resources' under > `pl330->lock' but read by `pl330_tx_submit' under `pch->lock'. > > Second, I have removed locking from `pl330_request_channel' and > `pl330_release_channel' functions. Function `pl330_request_channel' is > only called from `pl330_alloc_chan_resources', so the lock is already > held. Function `pl330_release_channel' is called from > `pl330_free_chan_resources', which already holds the lock, and from > `pl330_del'. Function `pl330_del' is called in an error path of > `pl330_probe' and at the end of `pl330_remove', but I assume that there > cannot be concurrent accesses to the protected data at those points. Applied, thanks -- ~Vinod