Netdev List
 help / color / mirror / Atom feed
* [PATCH net] net: mctp: i3c: serialize probe with bus removal
@ 2026-09-02  6:01 XingWang Xiang
  2026-09-03  8:57 ` Matt Johnston
  0 siblings, 1 reply; 2+ messages in thread
From: XingWang Xiang @ 2026-09-02  6:01 UTC (permalink / raw)
  To: jk, matt, netdev
  Cc: andrew+netdev, davem, edumazet, kuba, pabeni, linux-kernel,
	XingWang Xiang

mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A
concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus
netdev before probe passes its private data to mctp_i3c_add_device().
The latter consequently adds a list node through a freed mbus pointer.

Keep busdevs_lock held until the device has been added. This also
satisfies the __must_hold annotation on mctp_i3c_add_device().

Fixes: c8755b29b58e ("mctp i3c: MCTP I3C driver")
Signed-off-by: XingWang Xiang <v3rdant.xiang@gmail.com>
---
 drivers/net/mctp/mctp-i3c.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/net/mctp/mctp-i3c.c b/drivers/net/mctp/mctp-i3c.c
index 88d9e36cd..4e857dd5d 100644
--- a/drivers/net/mctp/mctp-i3c.c
+++ b/drivers/net/mctp/mctp-i3c.c
@@ -288,6 +288,7 @@ __must_hold(&busdevs_lock)
 static int mctp_i3c_probe(struct i3c_device *i3c)
 {
 	struct mctp_i3c_bus *b = NULL, *mbus = NULL;
+	int rc;
 
 	/* Look for a known bus */
 	mutex_lock(&busdevs_lock);
@@ -296,14 +297,16 @@ static int mctp_i3c_probe(struct i3c_device *i3c)
 			mbus = b;
 			break;
 		}
-	mutex_unlock(&busdevs_lock);
 
 	if (!mbus) {
 		/* probably no "mctp-controller" property on the i3c bus */
-		return -ENODEV;
+		rc = -ENODEV;
+	} else {
+		rc = mctp_i3c_add_device(mbus, i3c);
 	}
+	mutex_unlock(&busdevs_lock);
 
-	return mctp_i3c_add_device(mbus, i3c);
+	return rc;
 }
 
 static void mctp_i3c_remove_device(struct mctp_i3c_device *mi)

base-commit: 70f3995830d3f1e79faa14eb0605914f778feca9
-- 
2.52.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH net] net: mctp: i3c: serialize probe with bus removal
  2026-09-02  6:01 [PATCH net] net: mctp: i3c: serialize probe with bus removal XingWang Xiang
@ 2026-09-03  8:57 ` Matt Johnston
  0 siblings, 0 replies; 2+ messages in thread
From: Matt Johnston @ 2026-09-03  8:57 UTC (permalink / raw)
  To: XingWang Xiang, jk, netdev
  Cc: andrew+netdev, davem, edumazet, kuba, pabeni, linux-kernel

On Wed, 2026-09-02 at 15:01 +0900, XingWang Xiang wrote:
> mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A
> concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus
> netdev before probe passes its private data to mctp_i3c_add_device().
> The latter consequently adds a list node through a freed mbus pointer.
> 
> Keep busdevs_lock held until the device has been added. This also
> satisfies the __must_hold annotation on mctp_i3c_add_device().

Thanks, this looks right. Building with CONTEXT_ANALYSIS caught this as well
as some other problems, 
I'll send patches separately. 

For this patch Sashiko reports some other existing problems in mctp-i3c, I'll
check those.

Acked-by: Matt Johnston <matt@codeconstruct.com.au>

Cheers,
Matt

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-03  8:57 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02  6:01 [PATCH net] net: mctp: i3c: serialize probe with bus removal XingWang Xiang
2026-09-03  8:57 ` Matt Johnston

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox