The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: "Mark Brown" <broonie@kernel.org>,
	"Uwe Kleine-König" <u.kleine-koenig@pengutronix.de>,
	"Sasha Levin" <sashal@kernel.org>,
	linux-spi@vger.kernel.org
Subject: [PATCH AUTOSEL 5.14 20/26] spi: Fix deadlock when adding SPI controllers on SPI buses
Date: Wed, 20 Oct 2021 20:20:17 -0400	[thread overview]
Message-ID: <20211021002023.1128949-20-sashal@kernel.org> (raw)
In-Reply-To: <20211021002023.1128949-1-sashal@kernel.org>

From: Mark Brown <broonie@kernel.org>

[ Upstream commit 6098475d4cb48d821bdf453c61118c56e26294f0 ]

Currently we have a global spi_add_lock which we take when adding new
devices so that we can check that we're not trying to reuse a chip
select that's already controlled.  This means that if the SPI device is
itself a SPI controller and triggers the instantiation of further SPI
devices we trigger a deadlock as we try to register and instantiate
those devices while in the process of doing so for the parent controller
and hence already holding the global spi_add_lock.  Since we only care
about concurrency within a single SPI bus move the lock to be per
controller, avoiding the deadlock.

This can be easily triggered in the case of spi-mux.

Reported-by: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/spi/spi.c       | 17 ++++++-----------
 include/linux/spi/spi.h |  3 +++
 2 files changed, 9 insertions(+), 11 deletions(-)

diff --git a/drivers/spi/spi.c b/drivers/spi/spi.c
index f95f7666cb5b..2c342bded058 100644
--- a/drivers/spi/spi.c
+++ b/drivers/spi/spi.c
@@ -480,12 +480,6 @@ static LIST_HEAD(spi_controller_list);
  */
 static DEFINE_MUTEX(board_lock);
 
-/*
- * Prevents addition of devices with same chip select and
- * addition of devices below an unregistering controller.
- */
-static DEFINE_MUTEX(spi_add_lock);
-
 /**
  * spi_alloc_device - Allocate a new SPI device
  * @ctlr: Controller to which device is connected
@@ -638,9 +632,9 @@ int spi_add_device(struct spi_device *spi)
 	 * chipselect **BEFORE** we call setup(), else we'll trash
 	 * its configuration.  Lock against concurrent add() calls.
 	 */
-	mutex_lock(&spi_add_lock);
+	mutex_lock(&ctlr->add_lock);
 	status = __spi_add_device(spi);
-	mutex_unlock(&spi_add_lock);
+	mutex_unlock(&ctlr->add_lock);
 	return status;
 }
 EXPORT_SYMBOL_GPL(spi_add_device);
@@ -660,7 +654,7 @@ static int spi_add_device_locked(struct spi_device *spi)
 	/* Set the bus ID string */
 	spi_dev_set_name(spi);
 
-	WARN_ON(!mutex_is_locked(&spi_add_lock));
+	WARN_ON(!mutex_is_locked(&ctlr->add_lock));
 	return __spi_add_device(spi);
 }
 
@@ -2832,6 +2826,7 @@ int spi_register_controller(struct spi_controller *ctlr)
 	spin_lock_init(&ctlr->bus_lock_spinlock);
 	mutex_init(&ctlr->bus_lock_mutex);
 	mutex_init(&ctlr->io_mutex);
+	mutex_init(&ctlr->add_lock);
 	ctlr->bus_lock_flag = 0;
 	init_completion(&ctlr->xfer_completion);
 	if (!ctlr->max_dma_len)
@@ -2968,7 +2963,7 @@ void spi_unregister_controller(struct spi_controller *ctlr)
 
 	/* Prevent addition of new devices, unregister existing ones */
 	if (IS_ENABLED(CONFIG_SPI_DYNAMIC))
-		mutex_lock(&spi_add_lock);
+		mutex_lock(&ctlr->add_lock);
 
 	device_for_each_child(&ctlr->dev, NULL, __unregister);
 
@@ -2999,7 +2994,7 @@ void spi_unregister_controller(struct spi_controller *ctlr)
 	mutex_unlock(&board_lock);
 
 	if (IS_ENABLED(CONFIG_SPI_DYNAMIC))
-		mutex_unlock(&spi_add_lock);
+		mutex_unlock(&ctlr->add_lock);
 }
 EXPORT_SYMBOL_GPL(spi_unregister_controller);
 
diff --git a/include/linux/spi/spi.h b/include/linux/spi/spi.h
index 97b8d12b5f2b..5d80c6fd2a22 100644
--- a/include/linux/spi/spi.h
+++ b/include/linux/spi/spi.h
@@ -527,6 +527,9 @@ struct spi_controller {
 	/* I/O mutex */
 	struct mutex		io_mutex;
 
+	/* Used to avoid adding the same CS twice */
+	struct mutex		add_lock;
+
 	/* lock and mutex for SPI bus locking */
 	spinlock_t		bus_lock_spinlock;
 	struct mutex		bus_lock_mutex;
-- 
2.33.0


  parent reply	other threads:[~2021-10-21  0:21 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-10-21  0:19 [PATCH AUTOSEL 5.14 01/26] kunit: fix reference count leak in kfree_at_end Sasha Levin
2021-10-21  0:19 ` [PATCH AUTOSEL 5.14 02/26] drm/msm/a6xx: Serialize GMU communication Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 03/26] gcc-plugins/structleak: add makefile var for disabling structleak Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 04/26] iio/test-format: build kunit tests without structleak plugin Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 05/26] device property: " Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 06/26] thunderbolt: " Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 07/26] bitfield: " Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 08/26] objtool: Check for gelf_update_rel[a] failures Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 09/26] objtool: Update section header before relocations Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 10/26] ALSA: hda: intel: Allow repeatedly probing on codec configuration errors Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 11/26] btrfs: deal with errors when checking if a dir entry exists during log replay Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 12/26] net: stmmac: add support for dwmac 3.40a Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 13/26] ARM: dts: spear3xx: Fix gmac node Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 14/26] nfc: nci: fix the UAF of rf_conn_info object Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 15/26] isdn: cpai: check ctr->cnr to avoid array index out of bound Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 16/26] isdn: mISDN: Fix sleeping function called from invalid context Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 17/26] platform/x86: intel_scu_ipc: Increase virtual timeout to 10s Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 18/26] platform/x86: intel_scu_ipc: Update timeout value in comment Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 19/26] ALSA: hda: avoid write to STATESTS if controller is in reset Sasha Levin
2021-10-21  0:20 ` Sasha Levin [this message]
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 21/26] spi-mux: Fix false-positive lockdep splats Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 22/26] libperf test evsel: Fix build error on !x86 architectures Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 23/26] libperf tests: Fix test_stat_cpu Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 24/26] perf/x86/msr: Add Sapphire Rapids CPU support Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 25/26] Input: snvs_pwrkey - add clk handling Sasha Levin
2021-10-21  0:20 ` [PATCH AUTOSEL 5.14 26/26] Input: xpad - add support for another USB ID of Nacon GC-100 Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20211021002023.1128949-20-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=broonie@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-spi@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=u.kleine-koenig@pengutronix.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox