mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 13:14:02 +02:00
dmaengine: wait for RCU readers before releasing dma_device
dma_issue_pending_all() walks the dma_device_list with list_for_each_entry_rcu() under rcu_read_lock(). dma_device_release() unlinks the device with list_del_rcu() and then calls device->device_release() (which in many drivers, such as plx_dma.c, directly calls kfree()). Because there is no grace period between unlinking the device and freeing it, concurrent RCU readers in dma_issue_pending_all() can access the device after it has been freed. The lockless walk originally relied on clients holding a dmaengine reference to pin the provider module, and therefore the device, for as long as they might traverse the list. Commit8ad342a863("dmaengine: Add reference counting to dma_device struct") decoupled the dma_device lifetime from the module reference, so the device can now be released while a reader is still walking the list. Add synchronize_rcu() before the device is freed, so RCU readers are guaranteed to have finished. Keep it unconditional: providers that do not implement device_release() free the device themselves once dma_async_device_unregister() returns. This call will delay for a grace period with dma_list_mutex held, which is safe and only teardown path is delayed. Fixes:2ba05622b8("dmaengine: provide a common 'issue_pending_all' implementation") Suggested-by: Sashiko <sashiko-bot@kernel.org> Link: https://sashiko.dev/#/patchset/20260526-dmaengine-kref-fix-v2-0-3df60afac01d@amd.com Reviewed-by: Frank Li <Frank.Li@nxp.com> Reviewed-by: Logan Gunthorpe <logang@deltatee.com> Signed-off-by: Shivank Garg <shivankg@amd.com> Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-4-d4a4ee47d927@amd.com Signed-off-by: Vinod Koul <vkoul@kernel.org>
This commit is contained in:
parent
e873c74132
commit
dc75042217
|
|
@ -428,6 +428,7 @@ static void dma_device_release(struct kref *ref)
|
|||
|
||||
list_del_rcu(&device->global_node);
|
||||
dma_channel_rebalance();
|
||||
synchronize_rcu();
|
||||
|
||||
if (device->device_release)
|
||||
device->device_release(device);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user