From: Greg KH <gregkh@linuxfoundation.org>
To: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>,
guocai.he.cn@windriver.com, stable@vger.kernel.org,
ian.ray@gehealthcare.com, bartosz.golaszewski@linaro.org
Subject: Re: [PATCH][5.15.y] gpio: pca953x: fix pca953x_irq_bus_sync_unlock race
Date: Fri, 13 Dec 2024 12:08:56 +0100 [thread overview]
Message-ID: <2024121322-conjuror-gap-b542@gregkh> (raw)
In-Reply-To: <cead071a-f60c-42ac-80dd-f3fb1d937e48@oracle.com>
On Fri, Dec 13, 2024 at 04:15:09PM +0530, Harshit Mogalapalli wrote:
> Hi Guocai,
>
> On 13/12/24 16:01, guocai.he.cn@windriver.com wrote:
> > From: Ian Ray <ian.ray@gehealthcare.com>
> >
> > [ Upstream commit bfc6444b57dc7186b6acc964705d7516cbaf3904 ]
> >
> > Ensure that `i2c_lock' is held when setting interrupt latch and mask in
> > pca953x_irq_bus_sync_unlock() in order to avoid races.
> >
> > The other (non-probe) call site pca953x_gpio_set_multiple() ensures the
> > lock is held before calling pca953x_write_regs().
> >
> > The problem occurred when a request raced against irq_bus_sync_unlock()
> > approximately once per thousand reboots on an i.MX8MP based system.
> >
> > * Normal case
> >
> > 0-0022: write register AI|3a {03,02,00,00,01} Input latch P0
> > 0-0022: write register AI|49 {fc,fd,ff,ff,fe} Interrupt mask P0
> > 0-0022: write register AI|08 {ff,00,00,00,00} Output P3
> > 0-0022: write register AI|12 {fc,00,00,00,00} Config P3
> >
> > * Race case
> >
> > 0-0022: write register AI|08 {ff,00,00,00,00} Output P3
> > 0-0022: write register AI|08 {03,02,00,00,01} *** Wrong register ***
> > 0-0022: write register AI|12 {fc,00,00,00,00} Config P3
> > 0-0022: write register AI|49 {fc,fd,ff,ff,fe} Interrupt mask P0
> >
> > Signed-off-by: Ian Ray <ian.ray@gehealthcare.com>
> > Link: https://lore.kernel.org/r/20240620042915.2173-1-ian.ray@gehealthcare.com
> > Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@linaro.org>
> > Signed-off-by: Guocai He <guocai.he.cn@windriver.com>
> > ---
> > This commit is to solve the CVE-2024-42253. Please merge this commit to linux-5.15.y.
> >
> > drivers/gpio/gpio-pca953x.c | 2 ++
> > 1 file changed, 2 insertions(+)
> >
> > diff --git a/drivers/gpio/gpio-pca953x.c b/drivers/gpio/gpio-pca953x.c
> > index 4860bf3b7e00..4e97b6ae4f72 100644
> > --- a/drivers/gpio/gpio-pca953x.c
> > +++ b/drivers/gpio/gpio-pca953x.c
> > @@ -672,6 +672,8 @@ static void pca953x_irq_bus_sync_unlock(struct irq_data *d)
> > int level;
> > if (chip->driver_data & PCA_PCAL) {
> > + guard(mutex)(&chip->i2c_lock);
>
> This wouldn't compile on 5.15.y
Which means that no one is actually testing these backports.
Ok, I'm frustrated enough. No more windriver backports for stable trees
will now be accepted until you all get your act together and figure out
how to do this properly.
As to "how" you prove that you all know what you are doing, I will
leave that up to you to come up with a proper proposal and proof.
ugh.
greg k-h
next prev parent reply other threads:[~2024-12-13 11:08 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-12-13 10:31 [PATCH][5.15.y] gpio: pca953x: fix pca953x_irq_bus_sync_unlock race guocai.he.cn
2024-12-13 10:45 ` Harshit Mogalapalli
2024-12-13 11:08 ` Greg KH [this message]
2024-12-13 15:13 ` Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2024121322-conjuror-gap-b542@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=bartosz.golaszewski@linaro.org \
--cc=guocai.he.cn@windriver.com \
--cc=harshit.m.mogalapalli@oracle.com \
--cc=ian.ray@gehealthcare.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox