mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 22:14:03 +02:00
firmware: arm_scmi: Quiesce notifications before teardown
scmi_notification_exit() clears and releases the notification instance,
but transport callbacks can still deliver incoming notifications until
the TX/RX channels are freed. During remove, an RX interrupt in that
window can enter scmi_notify() while notification state is being torn
down and then dereference freed memory. The same ordering exists on the
probe error path after notification initialization.
The notification late-init worker has a separate lifetime issue: protocol
event registration queues ni->init_work on the system workqueue, so
destroying ni->notify_wq does not drain that work. If the devres group is
released while init_work is still pending or running, the late-init worker
can dereference the freed notification instance.
Quiesce the notification core before TX/RX channels are torn down, then
clean up the channels before releasing the notification core resources.
Use disable_work_sync() so future late-init queueing is rejected and any
already queued or running late-init work has completed before channel
teardown starts.
Fixes: 1e7cbfaa66 ("firmware: arm_scmi: Free mailbox channels if probe fails")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-3-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
This commit is contained in:
parent
66a0bbf30c
commit
8e49055d0d
|
|
@ -3325,7 +3325,7 @@ static int scmi_probe(struct platform_device *pdev)
|
|||
dev_err(dev, "%s", err_str);
|
||||
return 0;
|
||||
}
|
||||
goto notification_exit;
|
||||
goto raw_mode_cleanup;
|
||||
}
|
||||
|
||||
mutex_lock(&scmi_list_mutex);
|
||||
|
|
@ -3367,17 +3367,18 @@ static int scmi_probe(struct platform_device *pdev)
|
|||
|
||||
return 0;
|
||||
|
||||
notification_exit:
|
||||
raw_mode_cleanup:
|
||||
if (IS_ENABLED(CONFIG_ARM_SCMI_RAW_MODE_SUPPORT))
|
||||
scmi_raw_mode_cleanup(info->raw);
|
||||
scmi_notification_exit(&info->handle);
|
||||
clear_dev_req_notifier:
|
||||
blocking_notifier_chain_unregister(&scmi_requested_devices_nh,
|
||||
&info->dev_req_nb);
|
||||
clear_bus_notifier:
|
||||
bus_unregister_notifier(&scmi_bus_type, &info->bus_nb);
|
||||
clear_txrx_setup:
|
||||
scmi_notification_quiesce(&info->handle);
|
||||
scmi_cleanup_txrx_channels(info);
|
||||
scmi_notification_exit(&info->handle);
|
||||
clear_ida:
|
||||
ida_free(&scmi_id, info->id);
|
||||
|
||||
|
|
@ -3404,6 +3405,9 @@ static void scmi_remove(struct platform_device *pdev)
|
|||
blocking_notifier_chain_unregister(&scmi_requested_devices_nh,
|
||||
&info->dev_req_nb);
|
||||
|
||||
/* Stop transport callbacks before tearing down notifications. */
|
||||
scmi_notification_quiesce(&info->handle);
|
||||
scmi_cleanup_txrx_channels(info);
|
||||
scmi_notification_exit(&info->handle);
|
||||
|
||||
mutex_lock(&info->protocols_mtx);
|
||||
|
|
@ -3416,9 +3420,6 @@ static void scmi_remove(struct platform_device *pdev)
|
|||
|
||||
bus_unregister_notifier(&scmi_bus_type, &info->bus_nb);
|
||||
|
||||
/* Safe to free channels since no more users */
|
||||
scmi_cleanup_txrx_channels(info);
|
||||
|
||||
ida_free(&scmi_id, info->id);
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -1697,6 +1697,25 @@ int scmi_notification_init(struct scmi_handle *handle)
|
|||
return -ENOMEM;
|
||||
}
|
||||
|
||||
/**
|
||||
* scmi_notification_quiesce() - Stop notification late initialization
|
||||
* @handle: The handle identifying the platform instance to quiesce
|
||||
*
|
||||
* Prevent new late-init work from being queued and wait for any already queued
|
||||
* or running late-init work to complete before transport channels are torn
|
||||
* down.
|
||||
*/
|
||||
void scmi_notification_quiesce(struct scmi_handle *handle)
|
||||
{
|
||||
struct scmi_notify_instance *ni;
|
||||
|
||||
ni = scmi_notification_instance_data_get(handle);
|
||||
if (!ni)
|
||||
return;
|
||||
|
||||
disable_work_sync(&ni->init_work);
|
||||
}
|
||||
|
||||
/**
|
||||
* scmi_notification_exit() - Shutdown and clean Notification core
|
||||
* @handle: The handle identifying the platform instance to shutdown
|
||||
|
|
@ -1708,6 +1727,8 @@ void scmi_notification_exit(struct scmi_handle *handle)
|
|||
ni = scmi_notification_instance_data_get(handle);
|
||||
if (!ni)
|
||||
return;
|
||||
|
||||
scmi_notification_quiesce(handle);
|
||||
scmi_notification_instance_data_set(handle, NULL);
|
||||
|
||||
/* Destroy while letting pending work complete */
|
||||
|
|
|
|||
|
|
@ -82,6 +82,7 @@ struct scmi_protocol_events {
|
|||
};
|
||||
|
||||
int scmi_notification_init(struct scmi_handle *handle);
|
||||
void scmi_notification_quiesce(struct scmi_handle *handle);
|
||||
void scmi_notification_exit(struct scmi_handle *handle);
|
||||
int scmi_register_protocol_events(const struct scmi_handle *handle, u8 proto_id,
|
||||
const struct scmi_protocol_handle *ph,
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user