* [PATCH net] net: mctp: i3c: serialize probe with bus removal
@ 2026-09-02 6:01 XingWang Xiang
2026-09-03 8:57 ` Matt Johnston
0 siblings, 1 reply; 2+ messages in thread
From: XingWang Xiang @ 2026-09-02 6:01 UTC (permalink / raw)
To: jk, matt, netdev
Cc: andrew+netdev, davem, edumazet, kuba, pabeni, linux-kernel,
XingWang Xiang
mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A
concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus
netdev before probe passes its private data to mctp_i3c_add_device().
The latter consequently adds a list node through a freed mbus pointer.
Keep busdevs_lock held until the device has been added. This also
satisfies the __must_hold annotation on mctp_i3c_add_device().
Fixes: c8755b29b58e ("mctp i3c: MCTP I3C driver")
Signed-off-by: XingWang Xiang <v3rdant.xiang@gmail.com>
---
drivers/net/mctp/mctp-i3c.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/drivers/net/mctp/mctp-i3c.c b/drivers/net/mctp/mctp-i3c.c
index 88d9e36cd..4e857dd5d 100644
--- a/drivers/net/mctp/mctp-i3c.c
+++ b/drivers/net/mctp/mctp-i3c.c
@@ -288,6 +288,7 @@ __must_hold(&busdevs_lock)
static int mctp_i3c_probe(struct i3c_device *i3c)
{
struct mctp_i3c_bus *b = NULL, *mbus = NULL;
+ int rc;
/* Look for a known bus */
mutex_lock(&busdevs_lock);
@@ -296,14 +297,16 @@ static int mctp_i3c_probe(struct i3c_device *i3c)
mbus = b;
break;
}
- mutex_unlock(&busdevs_lock);
if (!mbus) {
/* probably no "mctp-controller" property on the i3c bus */
- return -ENODEV;
+ rc = -ENODEV;
+ } else {
+ rc = mctp_i3c_add_device(mbus, i3c);
}
+ mutex_unlock(&busdevs_lock);
- return mctp_i3c_add_device(mbus, i3c);
+ return rc;
}
static void mctp_i3c_remove_device(struct mctp_i3c_device *mi)
base-commit: 70f3995830d3f1e79faa14eb0605914f778feca9
--
2.52.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH net] net: mctp: i3c: serialize probe with bus removal
2026-09-02 6:01 [PATCH net] net: mctp: i3c: serialize probe with bus removal XingWang Xiang
@ 2026-09-03 8:57 ` Matt Johnston
0 siblings, 0 replies; 2+ messages in thread
From: Matt Johnston @ 2026-09-03 8:57 UTC (permalink / raw)
To: XingWang Xiang, jk, netdev
Cc: andrew+netdev, davem, edumazet, kuba, pabeni, linux-kernel
On Wed, 2026-09-02 at 15:01 +0900, XingWang Xiang wrote:
> mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A
> concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus
> netdev before probe passes its private data to mctp_i3c_add_device().
> The latter consequently adds a list node through a freed mbus pointer.
>
> Keep busdevs_lock held until the device has been added. This also
> satisfies the __must_hold annotation on mctp_i3c_add_device().
Thanks, this looks right. Building with CONTEXT_ANALYSIS caught this as well
as some other problems,
I'll send patches separately.
For this patch Sashiko reports some other existing problems in mctp-i3c, I'll
check those.
Acked-by: Matt Johnston <matt@codeconstruct.com.au>
Cheers,
Matt
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-03 8:57 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 6:01 [PATCH net] net: mctp: i3c: serialize probe with bus removal XingWang Xiang
2026-09-03 8:57 ` Matt Johnston
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox