mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
pds_core: quiesce DMA before freeing resources
pdsc_teardown() frees DMA buffers but does not disable bus mastering, leaving the device able to perform DMA after the buffers are freed. This can lead to use-after-free if the device writes to freed memory. Add pci_clear_master() to pdsc_teardown() to disable bus mastering before freeing resources, ensuring all DMA is quiesced. Add pci_set_master() to pdsc_setup() to re-enable bus mastering, which is needed for the firmware recovery path since pdsc_teardown() now disables it. Signed-off-by: Nikhil P. Rao <nikhil.rao@amd.com> Link: https://patch.msgid.link/20260604213637.3844317-1-nikhil.rao@amd.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
b8e40c907b
commit
6443f4f20b
|
|
@ -446,6 +446,8 @@ int pdsc_setup(struct pdsc *pdsc, bool init)
|
|||
{
|
||||
int err;
|
||||
|
||||
pci_set_master(pdsc->pdev);
|
||||
|
||||
err = pdsc_dev_init(pdsc);
|
||||
if (err)
|
||||
return err;
|
||||
|
|
@ -480,6 +482,8 @@ void pdsc_teardown(struct pdsc *pdsc, bool removing)
|
|||
if (pdsc->adminqcq.work.func)
|
||||
cancel_work_sync(&pdsc->adminqcq.work);
|
||||
|
||||
pci_clear_master(pdsc->pdev);
|
||||
|
||||
pdsc_core_uninit(pdsc);
|
||||
|
||||
if (removing) {
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user