firmware: arm_scmi: Quiesce notifications before teardown

scmi_notification_exit() clears and releases the notification instance,
but transport callbacks can still deliver incoming notifications until
the TX/RX channels are freed. During remove, an RX interrupt in that
window can enter scmi_notify() while notification state is being torn
down and then dereference freed memory. The same ordering exists on the
probe error path after notification initialization.

The notification late-init worker has a separate lifetime issue: protocol
event registration queues ni->init_work on the system workqueue, so
destroying ni->notify_wq does not drain that work. If the devres group is
released while init_work is still pending or running, the late-init worker
can dereference the freed notification instance.

Quiesce the notification core before TX/RX channels are torn down, then
clean up the channels before releasing the notification core resources.
Use disable_work_sync() so future late-init queueing is rejected and any
already queued or running late-init work has completed before channel
teardown starts.

Fixes: 1e7cbfaa66 ("firmware: arm_scmi: Free mailbox channels if probe fails")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-3-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
This commit is contained in:
Sudeep Holla 2026-07-14 13:56:22 +01:00
parent 66a0bbf30c
commit 8e49055d0d
3 changed files with 29 additions and 6 deletions

View File

@ -3325,7 +3325,7 @@ static int scmi_probe(struct platform_device *pdev)
dev_err(dev, "%s", err_str);
return 0;
}
goto notification_exit;
goto raw_mode_cleanup;
}
mutex_lock(&scmi_list_mutex);
@ -3367,17 +3367,18 @@ static int scmi_probe(struct platform_device *pdev)
return 0;
notification_exit:
raw_mode_cleanup:
if (IS_ENABLED(CONFIG_ARM_SCMI_RAW_MODE_SUPPORT))
scmi_raw_mode_cleanup(info->raw);
scmi_notification_exit(&info->handle);
clear_dev_req_notifier:
blocking_notifier_chain_unregister(&scmi_requested_devices_nh,
&info->dev_req_nb);
clear_bus_notifier:
bus_unregister_notifier(&scmi_bus_type, &info->bus_nb);
clear_txrx_setup:
scmi_notification_quiesce(&info->handle);
scmi_cleanup_txrx_channels(info);
scmi_notification_exit(&info->handle);
clear_ida:
ida_free(&scmi_id, info->id);
@ -3404,6 +3405,9 @@ static void scmi_remove(struct platform_device *pdev)
blocking_notifier_chain_unregister(&scmi_requested_devices_nh,
&info->dev_req_nb);
/* Stop transport callbacks before tearing down notifications. */
scmi_notification_quiesce(&info->handle);
scmi_cleanup_txrx_channels(info);
scmi_notification_exit(&info->handle);
mutex_lock(&info->protocols_mtx);
@ -3416,9 +3420,6 @@ static void scmi_remove(struct platform_device *pdev)
bus_unregister_notifier(&scmi_bus_type, &info->bus_nb);
/* Safe to free channels since no more users */
scmi_cleanup_txrx_channels(info);
ida_free(&scmi_id, info->id);
}

View File

@ -1697,6 +1697,25 @@ int scmi_notification_init(struct scmi_handle *handle)
return -ENOMEM;
}
/**
* scmi_notification_quiesce() - Stop notification late initialization
* @handle: The handle identifying the platform instance to quiesce
*
* Prevent new late-init work from being queued and wait for any already queued
* or running late-init work to complete before transport channels are torn
* down.
*/
void scmi_notification_quiesce(struct scmi_handle *handle)
{
struct scmi_notify_instance *ni;
ni = scmi_notification_instance_data_get(handle);
if (!ni)
return;
disable_work_sync(&ni->init_work);
}
/**
* scmi_notification_exit() - Shutdown and clean Notification core
* @handle: The handle identifying the platform instance to shutdown
@ -1708,6 +1727,8 @@ void scmi_notification_exit(struct scmi_handle *handle)
ni = scmi_notification_instance_data_get(handle);
if (!ni)
return;
scmi_notification_quiesce(handle);
scmi_notification_instance_data_set(handle, NULL);
/* Destroy while letting pending work complete */

View File

@ -82,6 +82,7 @@ struct scmi_protocol_events {
};
int scmi_notification_init(struct scmi_handle *handle);
void scmi_notification_quiesce(struct scmi_handle *handle);
void scmi_notification_exit(struct scmi_handle *handle);
int scmi_register_protocol_events(const struct scmi_handle *handle, u8 proto_id,
const struct scmi_protocol_handle *ph,