From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF9124279F4 for ; Wed, 21 Jan 2026 08:12:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768983167; cv=none; b=iyxF4flML1dNG5H3YUqTcu2Tbjem8s/dxZrRDH+FnPvGIHWUU7ZXJ5wKlYnf2h0z0JB7by/wRvPBKXHpY6zwgvSBxbF7V8+q0QubbVp/h6jNCbUcvy+gjgZZbbN3mQs5mGyEtEwOq3vFkigxnWfHbmTxTc4BVZ3XLMVs+8TlzP4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768983167; c=relaxed/simple; bh=B+nROEHFlvfOOfYFEWBgVEwWR6c0vlc8vSr/ZaFzVyg=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=fs0ex74h2xCpLZrxjMYYJsbXT9LRf5zPmqGzBMQvqvMtz6673bGDysVtMTdjKWj1qJVE/fhv6m8XCBvr8xe9QbjrdCilX+wFsVmu07LGISCxG7kE8VyjPcpQbsFB3g2pf6Har/+sr8IbM6XVYYy9JCtTIu07iS9RxrDfNodhLno= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Q95H4x8o; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Q95H4x8o" Received: by smtp.kernel.org (Postfix) with ESMTPSA id DC400C16AAE; Wed, 21 Jan 2026 08:12:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1768983167; bh=B+nROEHFlvfOOfYFEWBgVEwWR6c0vlc8vSr/ZaFzVyg=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=Q95H4x8o6igoqVwNTwvjlWe35rtM0mCljenpkCYN/yKt6vM6bZoQfVHDyVKRiql/f lmcyixnv93UFttmIJFfXnx575Hm1lWadTr1Ow7F17r7wluh0NUCez/mdUqFcdHnjqb WqT93LhXIhNUSSY6jwoQ0sWI9KVDmA2OGlO7h36c= Date: Wed, 21 Jan 2026 09:12:44 +0100 From: Greg KH To: Gui-Dong Han Cc: Danilo Krummrich , Mark Brown , rafael@kernel.org, linux-kernel@vger.kernel.org, baijiaju1990@gmail.com, Qiu-ji Chen , Aishwarya.TCV@arm.com, Marek Szyprowski Subject: Re: [PATCH v5] driver core: enforce device_lock for driver_match_device() Message-ID: <2026012107-pried-unfazed-4913@gregkh> References: <7ae38e31-ef31-43ad-9106-7c76ea0e8596@sirena.org.uk> <4ec6cf46-990e-489c-836e-49124034b67f@sirena.org.uk> <47a4290a-6e5b-4648-b798-e9d967b570b4@sirena.org.uk> <2026012133-deploy-chief-3a7f@gregkh> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <2026012133-deploy-chief-3a7f@gregkh> On Wed, Jan 21, 2026 at 08:56:26AM +0100, Greg KH wrote: > On Wed, Jan 21, 2026 at 03:41:56PM +0800, Gui-Dong Han wrote: > > On Wed, Jan 21, 2026 at 3:18 PM Gui-Dong Han wrote: > > > > > > On Wed, Jan 21, 2026 at 9:11 AM Danilo Krummrich wrote: > > > > > > > > On Tue Jan 20, 2026 at 10:18 PM CET, Danilo Krummrich wrote: > > > > > Anyways, this should work: > > > > > > > > I Just notied that I pasted the wrong diff, which was nonsense of course, since > > > > it just unlocks all the suppressed false positives. (Should not have sent it > > > > during a meeting. :) > > > > > > > > What I actually intended (not neat, but hopefully helps): > > > > > > Thanks for the updated diff. > > > > > > I tested it on my QEMU setup. Since I couldn't reproduce the hang > > > there, I didn't see any lockdep splats regarding the deadlock. > > > However, since the physical lock is removed, my PoCs successfully > > > triggered the UAF on both paths as expected. > > > > > > I did notice a lockdep warning during boot, which happens every time. > > > I suspect this is because faux_bus_init is an __init function, so we > > > are registering a key from memory that gets freed. This seems specific > > > to the debug code, but I'm pasting it below for reference. > > > > I figured out the root cause. > > > > The warning is triggered because faux_bus_root is a static object. > > lockdep_register_key() has a WARN_ON_ONCE(static_obj(key)) check that > > forbids registering keys residing in static memory. It is not about > > __init memory being freed. > > > > Anyway, this is not a big deal and doesn't impact the testing results. > > Ooh, nice catch. Let me go make that a dynamic object. It really > shouldn't be a static one, I hate static struct device usage, and > complain about it from everyone else. So there's no reason I should > have used that myself :( Totally untested patch below. Give me a few hours before I can reboot and try this, but if you wish to use it, please do! From: Greg Kroah-Hartman Date: Wed, 21 Jan 2026 09:10:21 +0100 Subject: [PATCH] driver core: faux: stop using static struct device faux_bus_root should not have been a static struct device, but rather a dynamically created structure so that lockdep and other testing tools do not trip over it (as well as being the right thing overall to do.) Fix this up by making it properly dynamic. Reported-by: Gui-Dong Han Signed-off-by: Greg Kroah-Hartman --- drivers/base/faux.c | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/drivers/base/faux.c b/drivers/base/faux.c index 21dd02124231..23d725817232 100644 --- a/drivers/base/faux.c +++ b/drivers/base/faux.c @@ -29,9 +29,7 @@ struct faux_object { }; #define to_faux_object(dev) container_of_const(dev, struct faux_object, faux_dev.dev) -static struct device faux_bus_root = { - .init_name = "faux", -}; +static struct device *faux_bus_root; static int faux_match(struct device *dev, const struct device_driver *drv) { @@ -152,7 +150,7 @@ struct faux_device *faux_device_create_with_groups(const char *name, if (parent) dev->parent = parent; else - dev->parent = &faux_bus_root; + dev->parent = faux_bus_root; dev->bus = &faux_bus_type; dev_set_name(dev, "%s", name); device_set_pm_not_required(dev); @@ -236,9 +234,15 @@ int __init faux_bus_init(void) { int ret; - ret = device_register(&faux_bus_root); + faux_bus_root = kzalloc(sizeof(*faux_bus_root), GFP_KERNEL); + if (!faux_bus_root) + return -ENOMEM; + + dev_set_name(faux_bus_root, "faux"); + + ret = device_register(faux_bus_root); if (ret) { - put_device(&faux_bus_root); + put_device(faux_bus_root); return ret; } @@ -256,6 +260,6 @@ int __init faux_bus_init(void) bus_unregister(&faux_bus_type); error_bus: - device_unregister(&faux_bus_root); + device_unregister(faux_bus_root); return ret; } -- 2.52.0