mirror of
https://github.com/torvalds/linux.git
synced 2026-09-24 06:24:02 +02:00
firmware: arm_scmi: Fix SCMI device destroy lifetimes
scmi_child_dev_find() drops the reference returned by
device_find_child() before returning the scmi_device pointer. A
concurrent unregister can then release the device while the destroy path
is still using the returned pointer.
Make the lookup helper return the device_find_child() reference and keep
it until scmi_device_destroy() has finished unregistering the child.
Also split device_unregister() in __scmi_device_destroy() so the SCMI bus
ID is not made reusable until after device_del() has removed the old
scmi_dev.N name from sysfs. This avoids a new SCMI device reusing the
same ID while the old device is still registered.
The final device release callback is also a possible cleanup path when
SCMI children are deleted by driver core recursion rather than
__scmi_device_destroy(). Release the SCMI bus ID from a common helper
used by destroy, register-failure and final-release paths, and clear
scmi_dev->id after freeing it so the final release cannot free the same
ID again.
Fixes: 9ca67840c0 ("firmware: arm_scmi: Balance device refcount when destroying devices")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-15-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
This commit is contained in:
parent
f3e3773c4e
commit
6abe8fe36b
|
|
@ -237,8 +237,9 @@ static int scmi_match_by_id_table(struct device *dev, const void *data)
|
|||
return scmi_dev_match_by_id_table(scmi_dev, id_table);
|
||||
}
|
||||
|
||||
static struct scmi_device *scmi_child_dev_find(struct device *parent,
|
||||
int prot_id, const char *name)
|
||||
/* Returns a device_find_child() reference which must be dropped by caller. */
|
||||
static struct scmi_device *
|
||||
scmi_child_dev_find_get(struct device *parent, int prot_id, const char *name)
|
||||
{
|
||||
struct scmi_device_id id_table[2] = { 0 };
|
||||
struct device *dev;
|
||||
|
|
@ -250,9 +251,6 @@ static struct scmi_device *scmi_child_dev_find(struct device *parent,
|
|||
if (!dev)
|
||||
return NULL;
|
||||
|
||||
/* Drop the refcnt bumped implicitly by device_find_child */
|
||||
put_device(dev);
|
||||
|
||||
return to_scmi_dev(dev);
|
||||
}
|
||||
|
||||
|
|
@ -390,17 +388,22 @@ void scmi_driver_unregister(struct scmi_driver *driver)
|
|||
}
|
||||
EXPORT_SYMBOL_GPL(scmi_driver_unregister);
|
||||
|
||||
static void scmi_device_release_syspower(struct scmi_device *scmi_dev)
|
||||
static void scmi_device_release_resources(struct scmi_device *scmi_dev)
|
||||
{
|
||||
if (scmi_dev->protocol_id == SCMI_PROTOCOL_SYSTEM)
|
||||
cmpxchg(&scmi_syspower_registered, scmi_dev, NULL);
|
||||
|
||||
if (scmi_dev->id) {
|
||||
ida_free(&scmi_bus_id, scmi_dev->id);
|
||||
scmi_dev->id = 0;
|
||||
}
|
||||
}
|
||||
|
||||
static void scmi_device_release(struct device *dev)
|
||||
{
|
||||
struct scmi_device *scmi_dev = to_scmi_dev(dev);
|
||||
|
||||
scmi_device_release_syspower(scmi_dev);
|
||||
scmi_device_release_resources(scmi_dev);
|
||||
of_node_put(dev->of_node);
|
||||
kfree_const(scmi_dev->name);
|
||||
kfree(scmi_dev);
|
||||
|
|
@ -413,9 +416,9 @@ static void __scmi_device_destroy(struct scmi_device *scmi_dev)
|
|||
dev_name(&scmi_dev->dev), scmi_dev->protocol_id,
|
||||
scmi_dev->name);
|
||||
|
||||
scmi_device_release_syspower(scmi_dev);
|
||||
ida_free(&scmi_bus_id, scmi_dev->id);
|
||||
device_unregister(&scmi_dev->dev);
|
||||
device_del(&scmi_dev->dev);
|
||||
scmi_device_release_resources(scmi_dev);
|
||||
put_device(&scmi_dev->dev);
|
||||
}
|
||||
|
||||
static struct scmi_device *
|
||||
|
|
@ -433,9 +436,11 @@ __scmi_device_create(struct device_node *np, struct device *parent,
|
|||
* each DT defined protocol at probe time, and the concurrent
|
||||
* registration of SCMI drivers.
|
||||
*/
|
||||
scmi_dev = scmi_child_dev_find(parent, protocol, name);
|
||||
if (scmi_dev)
|
||||
scmi_dev = scmi_child_dev_find_get(parent, protocol, name);
|
||||
if (scmi_dev) {
|
||||
put_device(&scmi_dev->dev);
|
||||
return scmi_dev;
|
||||
}
|
||||
|
||||
scmi_dev = kzalloc_obj(*scmi_dev);
|
||||
if (!scmi_dev)
|
||||
|
|
@ -479,13 +484,13 @@ __scmi_device_create(struct device_node *np, struct device *parent,
|
|||
|
||||
return scmi_dev;
|
||||
put_dev:
|
||||
scmi_device_release_resources(scmi_dev);
|
||||
put_device(&scmi_dev->dev);
|
||||
ida_free(&scmi_bus_id, id);
|
||||
return NULL;
|
||||
free_name:
|
||||
kfree_const(scmi_dev->name);
|
||||
free_dev:
|
||||
scmi_device_release_syspower(scmi_dev);
|
||||
scmi_device_release_resources(scmi_dev);
|
||||
kfree(scmi_dev);
|
||||
return NULL;
|
||||
}
|
||||
|
|
@ -567,9 +572,11 @@ void scmi_device_destroy(struct device *parent, int protocol, const char *name)
|
|||
{
|
||||
struct scmi_device *scmi_dev;
|
||||
|
||||
scmi_dev = scmi_child_dev_find(parent, protocol, name);
|
||||
if (scmi_dev)
|
||||
scmi_dev = scmi_child_dev_find_get(parent, protocol, name);
|
||||
if (scmi_dev) {
|
||||
__scmi_device_destroy(scmi_dev);
|
||||
put_device(&scmi_dev->dev);
|
||||
}
|
||||
}
|
||||
EXPORT_SYMBOL_GPL(scmi_device_destroy);
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user