| Message ID | e74a0caf91aaefaf98476a191e6489c606632bf1.1783673420.git.sean@mess.org (mailing list archive) |
|---|---|
| State | New |
| Headers |
Return-Path: <linux-sunxi+bounces-24305-sunxi=pue.re@lists.linux.dev> X-Original-To: noreply@patchwork.local Delivered-To: noreply@patchwork.local Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) by mxe881.netcup.net (Postfix) with ESMTPS id A4DC91C2B4E for <noreply@patchwork.local>; Fri, 10 Jul 2026 11:04:02 +0200 (CEST) Authentication-Results: mxe881; dkim=pass header.d=mess.org; dkim=pass header.d=mess.org; spf=pass (sender IP is 172.105.105.114) smtp.mailfrom=linux-sunxi+bounces-24305-noreply=patchwork.local@lists.linux.dev smtp.helo=tor.lore.kernel.org Received-SPF: pass (mxe881: domain of lists.linux.dev designates 172.105.105.114 as permitted sender) client-ip=172.105.105.114; envelope-from=linux-sunxi+bounces-24305-noreply=patchwork.local@lists.linux.dev; helo=tor.lore.kernel.org; Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id CFE333046C64 for <noreply@patchwork.local>; Fri, 10 Jul 2026 08:55:25 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id A17683DE451; Fri, 10 Jul 2026 08:54:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=mess.org header.i=@mess.org header.b="UT4zSjal"; dkim=pass (2048-bit key) header.d=mess.org header.i=@mess.org header.b="Q7tS2vmA" X-Original-To: linux-sunxi@lists.linux.dev Received: from extorris.mess.org (extorris.mess.org [92.243.27.206]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ED4D23C8C43 for <linux-sunxi@lists.linux.dev>; Fri, 10 Jul 2026 08:53:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=92.243.27.206 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783673640; cv=none; b=ijmbmde4VhUvePvkVEtUCCt+vYYtsUklFcHPIm4M9infzgdNGRHJoaeoCoGRFcU8D552RMzPtQDjO8hGAGFOwJdjjIXL3hriGTgoU0w+pd5g6kU9HGAxU5BKtMlK9cF1WdEfVrYU6hVVJYWdpJwUseodSW4wp+Bk4LBaUQqJr2w= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783673640; c=relaxed/simple; bh=PFYYQhVg4NRarAQ81g5gFeRQ3Pkd+XUXZYeUxj9P9Kk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lvgdxHRNvGMAVbkw01qMqMPp0riHjQCn4Ys90grTRTEDXJmhNhZb0TTprZMnUne13tAb7FaWDaTUMOuGqoWA27ichEEDHYvNGInitburxsb9PJ8LNvH3DHwX9iyVn1ci1z2xSFzZzwN6efSoevlQgtPnKqV3YfZ6Z5ZxWsT2wTU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=mess.org; spf=pass smtp.mailfrom=mess.org; dkim=pass (2048-bit key) header.d=mess.org header.i=@mess.org header.b=UT4zSjal; dkim=pass (2048-bit key) header.d=mess.org header.i=@mess.org header.b=Q7tS2vmA; arc=none smtp.client-ip=92.243.27.206 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=mess.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=mess.org DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mess.org; s=2020; t=1783673631; bh=PFYYQhVg4NRarAQ81g5gFeRQ3Pkd+XUXZYeUxj9P9Kk=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=UT4zSjalRJqXyQhA/FSCEtu4h11D7ROz/3tcubYOueYKd4fy1BE6vBGljRiGu5dR7 DyYiH+aCgVnl15gpEKIdzavkb98YvIBA0xDNT7MGqg8vCve6ZQnvAeRCRONkdrcNvc SxSMr6xrOze/6EomAamObvaS1asgJ1wJ7GZZ/SbYkGw++N+hCU6LMeK5jaDY1EDUML tm3hl8pNOXDop1WTfLI74QnHQ3V/yBlFNr9PmBAnQ9I2IlA0Q9xjFoJ9OJJwKF1pHp LP4NCPAfOHmFwYCIHS2RqJLNGrHmCS4ScflCXkgo8UUP9W9s+SmWZELJGmJ/yP470N 592JPHiCEnxZw== Received: by extorris.mess.org (Postfix, from userid 1004) id BF25C40194; Fri, 10 Jul 2026 09:53:51 +0100 (BST) X-Spam-Level: DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mess.org; s=2020; t=1783673629; bh=PFYYQhVg4NRarAQ81g5gFeRQ3Pkd+XUXZYeUxj9P9Kk=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=Q7tS2vmA86o248eMBvJZbYEhyUISrTe2nv47HVo3EBB7Wxrw/q2cjF2Q/s1a683pj BoBwF+MTN5v6MmQc7WN1g5SAoqY0NzP9lX+ggsZPVjvkpArpwCtP34JWz2KigVZg4e 6L0xbtr9uexxKL+seFkxe6wfL9blzBpwgYSgfoEFoYy6gvzgZ3t9n0FXXuHercC8Gb ArHomzEUtOdrVqrjnuDjawTYJZawhFr+ZEK3GKuww4egj8dYWc46AUqlVpofx+Ap1z aJPjdLb7TV96CXOc2nFahvHojnRrNmcHsgaXzd50an5BycQdq1m405O6IWFL8/cCJK Z4M3GggQWecXA== Received: from maru.local (unknown [62.232.99.130]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by extorris.mess.org (Postfix) with ESMTPSA id B556540B4C; Fri, 10 Jul 2026 09:53:49 +0100 (BST) From: Sean Young <sean@mess.org> To: linux-media@vger.kernel.org, Sean Young <sean@mess.org>, Mauro Carvalho Chehab <mchehab@kernel.org>, Chen-Yu Tsai <wens@kernel.org>, Jernej Skrabec <jernej.skrabec@gmail.com>, Samuel Holland <samuel@sholland.org>, Hans Verkuil <hverkuil+cisco@kernel.org>, Patrice Chotard <patrice.chotard@foss.st.com> Cc: linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org Subject: [PATCH 4/7] media: sunxi-cir: Ensure no more interrupts can occur before free Date: Fri, 10 Jul 2026 09:53:32 +0100 Message-ID: <e74a0caf91aaefaf98476a191e6489c606632bf1.1783673420.git.sean@mess.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <cover.1783673420.git.sean@mess.org> References: <cover.1783673420.git.sean@mess.org> Precedence: bulk X-Mailing-List: linux-sunxi@lists.linux.dev List-Id: <linux-sunxi.lists.linux.dev> List-Subscribe: <mailto:linux-sunxi+subscribe@lists.linux.dev> List-Unsubscribe: <mailto:linux-sunxi+unsubscribe@lists.linux.dev> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Rspamd-Server: rspamd-worker-8404 X-Spamd-Result: default: False [4.84 / 15.00]; RBL_SENDERSCORE(2.00)[172.105.105.114:from]; SUSPICIOUS_RECIPS(1.50)[]; MID_CONTAINS_FROM(1.00)[]; R_MISSING_CHARSET(0.50)[]; MAILLIST(-0.15)[generic]; BAD_REP_POLICIES(0.10)[]; MIME_GOOD(-0.10)[text/plain]; HAS_LIST_UNSUB(-0.01)[]; FROM_HAS_DN(0.00)[]; FUZZY_BLOCKED(0.00)[rspamd.com]; RCVD_COUNT_FIVE(0.00)[6]; PRECEDENCE_BULK(0.00)[]; TAGGED_RCPT(0.00)[cisco]; R_DKIM_ALLOW(0.00)[mess.org:s=2020]; DBL_BLOCKED_OPENRESOLVER(0.00)[tor.lore.kernel.org:rdns,tor.lore.kernel.org:helo]; FROM_NEQ_ENVFROM(0.00)[sean@mess.org,linux-sunxi@lists.linux.dev]; ARC_ALLOW(0.00)[subspace.kernel.org:s=arc-20240116:i=1]; TAGGED_FROM(0.00)[bounces-24305-noreply=patchwork.local]; DKIM_TRACE(0.00)[mess.org:+]; DMARC_POLICY_ALLOW(0.00)[mess.org,none]; R_SPF_ALLOW(0.00)[+ip4:172.105.105.114:c]; TO_DN_SOME(0.00)[]; FORGED_SENDER_MAILLIST(0.00)[]; RCPT_COUNT_SEVEN(0.00)[11]; FORGED_RECIPIENTS_MAILLIST(0.00)[]; ASN(0.00)[asn:63949, ipnet:172.105.96.0/20, country:SG]; FREEMAIL_TO(0.00)[vger.kernel.org,mess.org,kernel.org,gmail.com,sholland.org,foss.st.com]; RCVD_TLS_LAST(0.00)[]; MIME_TRACE(0.00)[0:+]; RCVD_VIA_SMTP_AUTH(0.00)[] X-Rspamd-Queue-Id: A4DC91C2B4E X-MORS-Enabled: yes X-MORS-DOMAIN: patchwork.local X-MORS-HOSTING: hosting172546 X-MORS-USER: hosting172546 X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= |
| Series |
None
|
|
Commit Message
Sean Young
July 10, 2026, 8:53 a.m. UTC
Only call rc_free_device() once the hardware has been stopped.
Fixes: dccc0c3ddf8f ("media: rc: fix race between unregister and urb/irq callbacks")
Signed-off-by: Sean Young <sean@mess.org>
---
drivers/media/rc/sunxi-cir.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
Comments
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider: Pre-existing issues: - [High] The patch fails to fix the IRQ Use-After-Free race condition and exacerbates a bus fault vulnerability by disabling hardware clocks without synchronizing the devm-managed interrupt. - [High] The interrupt is requested before the hardware is initialized in the probe function, leading to a possible bus fault on spurious interrupts and a Use-After-Free in the error path. -- --- Patch [4]: [PATCH 4/7] media: sunxi-cir: Ensure no more interrupts can occur before free --- commit 8ac4bdb72847c70ea6f26a6012ec7552bc70de07 Author: Sean Young <sean@mess.org> media: sunxi-cir: Ensure no more interrupts can occur before free This commit reorders the device removal sequence to call rc_free_device() only after the hardware has been stopped via sunxi_ir_hw_exit(). The stated intent is to prevent interrupts from occurring after the device is freed. > diff --git a/drivers/media/rc/sunxi-cir.c b/drivers/media/rc/sunxi-cir.c > index 28e840a7e5b8c..af1ee08ffdbec 100644 > --- a/drivers/media/rc/sunxi-cir.c > +++ b/drivers/media/rc/sunxi-cir.c > @@ -374,8 +374,8 @@ static void sunxi_ir_remove(struct platform_device *pdev) > struct sunxi_ir *ir = platform_get_drvdata(pdev); > > rc_unregister_device(ir->rc); > - rc_free_device(ir->rc); > sunxi_ir_hw_exit(&pdev->dev); > + rc_free_device(ir->rc); [Severity: High] This is a pre-existing issue, but does this sequence completely prevent interrupts from occurring before the free? Because the interrupt is managed by devm_request_irq(), it remains active until devres cleanup runs after sunxi_ir_remove() completes. Since sunxi_ir_hw_exit() only disables clocks, if a pending or spurious interrupt fires afterward, sunxi_ir_irq() will access unclocked memory-mapped registers and trigger a bus fault. Additionally, if the interrupt handler runs concurrently on another processor: sunxi_ir_irq() ir_raw_event_overflow(ir->rc); could it access ir->rc after it is freed by rc_free_device() here, since there is no synchronize_irq() or disable_irq() in sunxi_ir_remove()? [Severity: High] This is also a pre-existing issue, but does sunxi_ir_probe() suffer from a similar race condition? In sunxi_ir_probe(), devm_request_irq() is called to unmask the interrupt before sunxi_ir_hw_init() enables the clock. If a pending interrupt from a previous boot or a spurious interrupt fires during this window, sunxi_ir_irq() will execute before the clock is enabled, potentially causing a bus fault. Also, if sunxi_ir_hw_init() fails, the error path eventually calls rc_free_device() without explicitly disabling the active interrupt, which leaves a window for a use-after-free on ir->rc. > }
diff --git a/drivers/media/rc/sunxi-cir.c b/drivers/media/rc/sunxi-cir.c index 28e840a7e5b8..af1ee08ffdbe 100644 --- a/drivers/media/rc/sunxi-cir.c +++ b/drivers/media/rc/sunxi-cir.c @@ -374,8 +374,8 @@ static void sunxi_ir_remove(struct platform_device *pdev) struct sunxi_ir *ir = platform_get_drvdata(pdev); rc_unregister_device(ir->rc); - rc_free_device(ir->rc); sunxi_ir_hw_exit(&pdev->dev); + rc_free_device(ir->rc); } static void sunxi_ir_shutdown(struct platform_device *pdev)