| Message ID | ca5cac44353fdae4d664b22de709cc45837414ee.1785338381.git.sean@mess.org (mailing list archive) |
|---|---|
| State | New |
| Headers |
Return-Path: <linux-sunxi+bounces-24796-sunxi=pue.re@lists.linux.dev> X-Original-To: noreply@patchwork.local Delivered-To: noreply@patchwork.local Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) by mxe881.netcup.net (Postfix) with ESMTPS id 385E41C05CD for <noreply@patchwork.local>; Wed, 29 Jul 2026 17:44:23 +0200 (CEST) Authentication-Results: mxe881; dkim=pass header.d=mess.org; dkim=pass header.d=mess.org; spf=pass (sender IP is 172.105.105.114) smtp.mailfrom=linux-sunxi+bounces-24796-noreply=patchwork.local@lists.linux.dev smtp.helo=tor.lore.kernel.org Received-SPF: pass (mxe881: domain of lists.linux.dev designates 172.105.105.114 as permitted sender) client-ip=172.105.105.114; envelope-from=linux-sunxi+bounces-24796-noreply=patchwork.local@lists.linux.dev; helo=tor.lore.kernel.org; Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 1E31B30377B6 for <noreply@patchwork.local>; Wed, 29 Jul 2026 15:23:53 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id A3DEB4D8DB7; Wed, 29 Jul 2026 15:23:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=mess.org header.i=@mess.org header.b="W0o2E3Ic"; dkim=pass (2048-bit key) header.d=mess.org header.i=@mess.org header.b="m0l850kX" X-Original-To: linux-sunxi@lists.linux.dev Received: from extorris.mess.org (extorris.mess.org [92.243.27.206]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 80CC74B8DF2 for <linux-sunxi@lists.linux.dev>; Wed, 29 Jul 2026 15:23:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=92.243.27.206 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785338596; cv=none; b=QJ/Jp/9bcaGVmM109Aal+wJJYaS7H1Luqq6eD17FGTTcnu2jbeWaKbn2CbYQMQP+YDJojpsSCI90fNsPYRDBuHd8KZcV7DNHKIYaWAByc51bsxD7cgVOhQ0Xucw3ZdrPZqPNPVneC4+SL48S4+NjHAbyVaxEisickJm9Ds0Y6/Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785338596; c=relaxed/simple; bh=jyAFNCAff7ONHFxb/FIrT3odoLHFfMrGUvGh9kBzBcY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qOctMJpUfQOGw4xC5euD2SgftB17M4HhenwpK8JQ9sKQZXCvrcwxYuCfTUXyyigtTAiDCnraSL7gUV6e7ZorYNUKsJajXgymdw9I6jx2/PxYjRoV7b1FRUvLpimKADDC6ldSw8u5Rme0ZcHUBa+UZh4N4EZRuAd4J/PiWpuqonI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=mess.org; spf=pass smtp.mailfrom=mess.org; dkim=pass (2048-bit key) header.d=mess.org header.i=@mess.org header.b=W0o2E3Ic; dkim=pass (2048-bit key) header.d=mess.org header.i=@mess.org header.b=m0l850kX; arc=none smtp.client-ip=92.243.27.206 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=mess.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=mess.org DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mess.org; s=2020; t=1785338593; bh=jyAFNCAff7ONHFxb/FIrT3odoLHFfMrGUvGh9kBzBcY=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=W0o2E3IcHUPcqjHRulLpkwmEad+b0z+jEKoSlYZ0KUVRCzb7ZgA6dkP6b3X2wqKo1 L3a3qBGUlBCIEMlkAFksukQZnYzQ0Xn6TjFH01SWkbKPKNcTf0KPK+neIvpCuA68nx hFO87IOOc78Y0bynDu6l2jcmJlmwPJmRyLJBORtBNYw3vwk1d5xw4/h2vdaTKsu0Wi Y89lm1YIB2ZoG0tyP0tXK77ARbKyLWsu13LjiTOlcmqN81iSXqXjKRwLC1hW/WZVmQ Q55XEu9H5ZdbOTbZ+uOXlF2zjlVmegmm2pLEFVZYUXcZqmT8AQRavGjjvuE3extGru 2BDUnhCy5F0oA== Received: by extorris.mess.org (Postfix, from userid 1004) id 0F13542548; Wed, 29 Jul 2026 16:23:13 +0100 (BST) X-Spam-Level: DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mess.org; s=2020; t=1785338592; bh=jyAFNCAff7ONHFxb/FIrT3odoLHFfMrGUvGh9kBzBcY=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=m0l850kXaZmCw8zaVg9tUIrPXj7WRgopm7tAw+Iam+5Pzh/vt5z94AM5i/EvBzYp2 I7ccCtN1ZTXiGFFYp9sKIls9+YkwU/+aHvDbnR9K1gk71m04rsV/LLi/qF5+936AD5 9KS7Z61nA9mOHdDIuLtPOCV+LPR5XSk50d49lBCfOXZ4efjaw3HMI3B0YACYfTc19U bL0tAMcEIeCxvlgkapt6RvZdSKokA1W3xc6WkhccEHe1FhRIwpDmHCT13q+bjVz4ix 9bxf+WxC7LSipQf4k8Ew5oriQPyvLLEAqn07hCXTXOJtXDXsdl4gkurGPt6gWmbRqF 09pGN+gl53mWQ== Received: from maru.local (unknown [62.232.99.130]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by extorris.mess.org (Postfix) with ESMTPSA id 619344017A; Wed, 29 Jul 2026 16:23:12 +0100 (BST) From: Sean Young <sean@mess.org> To: linux-media@vger.kernel.org, Sean Young <sean@mess.org>, Mauro Carvalho Chehab <mchehab@kernel.org>, Chen-Yu Tsai <wens@kernel.org>, Jernej Skrabec <jernej.skrabec@gmail.com>, Samuel Holland <samuel@sholland.org>, Patrice Chotard <patrice.chotard@foss.st.com>, Hans Verkuil <hverkuil+cisco@kernel.org> Cc: stable@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org Subject: [PATCH v5 06/15] media: sunxi-cir: Ensure no more interrupts can occur before free Date: Wed, 29 Jul 2026 16:22:44 +0100 Message-ID: <ca5cac44353fdae4d664b22de709cc45837414ee.1785338381.git.sean@mess.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <cover.1785338381.git.sean@mess.org> References: <cover.1785338381.git.sean@mess.org> Precedence: bulk X-Mailing-List: linux-sunxi@lists.linux.dev List-Id: <linux-sunxi.lists.linux.dev> List-Subscribe: <mailto:linux-sunxi+subscribe@lists.linux.dev> List-Unsubscribe: <mailto:linux-sunxi+unsubscribe@lists.linux.dev> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-MORS-Enabled: yes X-MORS-DOMAIN: patchwork.local X-MORS-HOSTING: hosting172546 X-MORS-USER: hosting172546 X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= |
| Series |
None
|
|
Commit Message
Sean Young
July 29, 2026, 3:22 p.m. UTC
Only call rc_free_device() once the hardware has been stopped.
Fixes: dccc0c3ddf8f ("media: rc: fix race between unregister and urb/irq callbacks")
Signed-off-by: Sean Young <sean@mess.org>
Cc: stable@vger.kernel.org
---
drivers/media/rc/sunxi-cir.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
Comments
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: Pre-existing issues: - [High] The teardown race between `sunxi_ir_remove()` and `sunxi_ir_irq()` is not resolved by the patch. The interrupt remains active and unsynchronized while clocks are disabled and memory is freed, leading to synchronous external aborts and use-after-free vulnerabilities. A similar issue exists in `probe()` where the IRQ is requested before clocks are enabled. -- --- Patch [6]: [PATCH v5 06/15] media: sunxi-cir: Ensure no more interrupts can occur before free --- commit 485344025b667511dbe1afe16a5fb9cab1f312f6 Author: Sean Young <sean@mess.org> media: sunxi-cir: Ensure no more interrupts can occur before free This commit delays rc_free_device() until after sunxi_ir_hw_exit() in the remove path. It attempts to ensure the hardware is stopped and no further interrupts can occur before the device memory is freed. Cc: stable@vger.kernel.org > diff --git a/drivers/media/rc/sunxi-cir.c b/drivers/media/rc/sunxi-cir.c > index 28e840a7e5b8c..af1ee08ffdbec 100644 > --- a/drivers/media/rc/sunxi-cir.c > +++ b/drivers/media/rc/sunxi-cir.c > @@ -374,8 +374,8 @@ static void sunxi_ir_remove(struct platform_device *pdev) > struct sunxi_ir *ir = platform_get_drvdata(pdev); > > rc_unregister_device(ir->rc); > - rc_free_device(ir->rc); > sunxi_ir_hw_exit(&pdev->dev); > + rc_free_device(ir->rc); [Severity: High] This is a pre-existing issue, but does this actually prevent interrupts from occurring before the free? The driver requests the IRQ via devm_request_irq() in sunxi_ir_probe(), which means the IRQ is not freed or synchronized until devres cleanup runs after sunxi_ir_remove() returns. While sunxi_ir_hw_exit() disables the APB clock, it does not explicitly disable or synchronize the IRQ handler. If an interrupt executes concurrently, can it fault when reading unclocked MMIO registers? drivers/media/rc/sunxi-cir.c:sunxi_ir_irq() { ... status = readl(ir->base + SUNXI_IR_RXSTA_REG); ... ir_raw_event_store_with_filter(ir->rc, &rawir); } Because the IRQ handler is unsynchronized, could it also dereference the freed ir->rc if it races with or runs after rc_free_device()? Additionally, is there a similar window in sunxi_ir_probe()? drivers/media/rc/sunxi-cir.c:sunxi_ir_probe() { ... ret = devm_request_irq(dev, ir->irq, sunxi_ir_irq, 0, SUNXI_IR_DEV, ir); ... ret = sunxi_ir_hw_init(dev); ... } The IRQ handler is requested and enabled before sunxi_ir_hw_init() enables the APB clock. Could a pending interrupt trigger the handler and access unclocked registers during boot? > } > > static void sunxi_ir_shutdown(struct platform_device *pdev)
diff --git a/drivers/media/rc/sunxi-cir.c b/drivers/media/rc/sunxi-cir.c index 28e840a7e5b8..af1ee08ffdbe 100644 --- a/drivers/media/rc/sunxi-cir.c +++ b/drivers/media/rc/sunxi-cir.c @@ -374,8 +374,8 @@ static void sunxi_ir_remove(struct platform_device *pdev) struct sunxi_ir *ir = platform_get_drvdata(pdev); rc_unregister_device(ir->rc); - rc_free_device(ir->rc); sunxi_ir_hw_exit(&pdev->dev); + rc_free_device(ir->rc); } static void sunxi_ir_shutdown(struct platform_device *pdev)