The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: "Danilo Krummrich" <dakr@kernel.org>
To: "Mukesh Ojha" <mukesh.ojha@oss.qualcomm.com>
Cc: "Luis Chamberlain" <mcgrof@kernel.org>,
	"Russ Weight" <russ.weight@linux.dev>,
	"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
	"Rafael J. Wysocki" <rafael@kernel.org>,
	"Anirudh Rayabharam" <mail@anirudhrb.com>,
	"Shuah Khan" <skhan@linuxfoundation.org>,
	<driver-core@lists.linux.dev>, <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH] firmware_loader: do not queue completed sysfs fallback requests
Date: Mon, 03 Aug 2026 20:40:06 +0200	[thread overview]
Message-ID: <DKFJ13ZEUX8M.29CDWH9A0OF6U@kernel.org> (raw)
In-Reply-To: <20260803181237.kkfi4mtmmd637e7w@hu-mojha-hyd.qualcomm.com>

On Mon Aug 3, 2026 at 8:12 PM CEST, Mukesh Ojha wrote:
> On Thu, Jul 16, 2026 at 01:46:01PM +0530, Mukesh Ojha wrote:
>> fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to
>> pending_fw_head. device_add() publishes the fallback loading interface, so
>> a userspace helper which discovers the device by scanning sysfs can write 0
>> to the loading attribute and complete the request before it is queued as
>> pending.
>> 
>> In that interleaving firmware_loading_store() calls fw_state_done() while
>> pending_list still points to itself, so it cannot remove an entry from
>> pending_fw_head. The subsequent unconditional list_add() then queues an
>> already-completed fw_priv. Once the request is released, pending_fw_head
>> can retain a pointer to freed memory and the next fallback request can
>> fault while validating the list.
>> 
>> Only in-flight fallback requests need suspend or reboot abort handling. If
>> the request is already DONE after device_add(), return success from the
>> fallback path without sending another uevent, waiting again, or queueing it
>> as pending. This preserves the invariant that pending_fw_head contains only
>> active fallback requests.
>> 
>> Fixes: 75d95e2e39b2 ("firmware_loader: fix use-after-free in firmware_fallback_sysfs")
>> Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
>
> Can we consider this fix for this mentioned issue ?

Sure, how did you come across this issue?

>> ---
>>  drivers/base/firmware_loader/fallback.c | 9 +++++++++
>>  1 file changed, 9 insertions(+)
>> 
>> diff --git a/drivers/base/firmware_loader/fallback.c b/drivers/base/firmware_loader/fallback.c
>> index 3ef0b312ae71..ffe1b3784788 100644
>> --- a/drivers/base/firmware_loader/fallback.c
>> +++ b/drivers/base/firmware_loader/fallback.c
>> @@ -95,6 +95,15 @@ static int fw_load_sysfs_fallback(struct fw_sysfs *fw_sysfs, long timeout)
>>  		retval = -EINTR;
>>  		goto out;
>>  	}
>> +	/*
>> +	 * device_add() exposes the loading interface before pending_list is
>> +	 * linked into pending_fw_head, so fw_state_done() may run first.
>> +	 */
>> +	if (fw_state_is_done(fw_priv)) {
>> +		mutex_unlock(&fw_lock);
>> +		goto out;
>> +	}
>> +
>>  	list_add(&fw_priv->pending_list, &pending_fw_head);
>>  	mutex_unlock(&fw_lock);
>>  
>> -- 
>> 2.53.0
>> 
>
> -- 
> -Mukesh Ojha


  reply	other threads:[~2026-08-03 18:40 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-16  8:16 [PATCH] firmware_loader: do not queue completed sysfs fallback requests Mukesh Ojha
2026-08-03 18:12 ` Mukesh Ojha
2026-08-03 18:40   ` Danilo Krummrich [this message]
2026-08-04 13:29     ` Mukesh Ojha
2026-08-06 21:38 ` Danilo Krummrich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DKFJ13ZEUX8M.29CDWH9A0OF6U@kernel.org \
    --to=dakr@kernel.org \
    --cc=driver-core@lists.linux.dev \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mail@anirudhrb.com \
    --cc=mcgrof@kernel.org \
    --cc=mukesh.ojha@oss.qualcomm.com \
    --cc=rafael@kernel.org \
    --cc=russ.weight@linux.dev \
    --cc=skhan@linuxfoundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox