Skip to content

Commit bb17d11

Browse files
krzkgregkh
authored andcommitted
rpmsg: Fix calling device_lock() on non-initialized device
driver_set_override() helper uses device_lock() so it should not be called before rpmsg_register_device() (which calls device_register()). Effect can be seen with CONFIG_DEBUG_MUTEXES: DEBUG_LOCKS_WARN_ON(lock->magic != lock) WARNING: CPU: 3 PID: 57 at kernel/locking/mutex.c:582 __mutex_lock+0x1ec/0x430 ... Call trace: __mutex_lock+0x1ec/0x430 mutex_lock_nested+0x44/0x50 driver_set_override+0x124/0x150 qcom_glink_native_probe+0x30c/0x3b0 glink_rpm_probe+0x274/0x350 platform_probe+0x6c/0xe0 really_probe+0x17c/0x3d0 __driver_probe_device+0x114/0x190 driver_probe_device+0x3c/0xf0 ... Refactor the rpmsg_register_device() function to use two-step device registering (initialization + add) and call driver_set_override() in proper moment. This moves the code around, so while at it also NULL-ify the rpdev->driver_override in error path to be sure it won't be kfree() second time. Fixes: 42cd402 ("rpmsg: Fix kfree() of static memory on setting driver_override") Reported-by: Marek Szyprowski <m.szyprowski@samsung.com> Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org> Tested-by: Marek Szyprowski <m.szyprowski@samsung.com> Link: https://lore.kernel.org/r/20220429195946.1061725-2-krzysztof.kozlowski@linaro.org Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 6370b04 commit bb17d11

File tree

4 files changed

+40
-29
lines changed

4 files changed

+40
-29
lines changed

drivers/rpmsg/rpmsg_core.c

Lines changed: 30 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -593,24 +593,51 @@ static struct bus_type rpmsg_bus = {
593593
.remove = rpmsg_dev_remove,
594594
};
595595

596-
int rpmsg_register_device(struct rpmsg_device *rpdev)
596+
/*
597+
* A helper for registering rpmsg device with driver override and name.
598+
* Drivers should not be using it, but instead rpmsg_register_device().
599+
*/
600+
int rpmsg_register_device_override(struct rpmsg_device *rpdev,
601+
const char *driver_override)
597602
{
598603
struct device *dev = &rpdev->dev;
599604
int ret;
600605

606+
if (driver_override)
607+
strcpy(rpdev->id.name, driver_override);
608+
601609
dev_set_name(&rpdev->dev, "%s.%s.%d.%d", dev_name(dev->parent),
602610
rpdev->id.name, rpdev->src, rpdev->dst);
603611

604612
rpdev->dev.bus = &rpmsg_bus;
605613

606-
ret = device_register(&rpdev->dev);
614+
device_initialize(dev);
615+
if (driver_override) {
616+
ret = driver_set_override(dev, &rpdev->driver_override,
617+
driver_override,
618+
strlen(driver_override));
619+
if (ret) {
620+
dev_err(dev, "device_set_override failed: %d\n", ret);
621+
return ret;
622+
}
623+
}
624+
625+
ret = device_add(dev);
607626
if (ret) {
608-
dev_err(dev, "device_register failed: %d\n", ret);
627+
dev_err(dev, "device_add failed: %d\n", ret);
628+
kfree(rpdev->driver_override);
629+
rpdev->driver_override = NULL;
609630
put_device(&rpdev->dev);
610631
}
611632

612633
return ret;
613634
}
635+
EXPORT_SYMBOL(rpmsg_register_device_override);
636+
637+
int rpmsg_register_device(struct rpmsg_device *rpdev)
638+
{
639+
return rpmsg_register_device_override(rpdev, NULL);
640+
}
614641
EXPORT_SYMBOL(rpmsg_register_device);
615642

616643
/*

drivers/rpmsg/rpmsg_internal.h

Lines changed: 1 addition & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -94,19 +94,7 @@ int rpmsg_release_channel(struct rpmsg_device *rpdev,
9494
*/
9595
static inline int rpmsg_ctrldev_register_device(struct rpmsg_device *rpdev)
9696
{
97-
int ret;
98-
99-
strcpy(rpdev->id.name, "rpmsg_ctrl");
100-
ret = driver_set_override(&rpdev->dev, &rpdev->driver_override,
101-
rpdev->id.name, strlen(rpdev->id.name));
102-
if (ret)
103-
return ret;
104-
105-
ret = rpmsg_register_device(rpdev);
106-
if (ret)
107-
kfree(rpdev->driver_override);
108-
109-
return ret;
97+
return rpmsg_register_device_override(rpdev, "rpmsg_ctrl");
11098
}
11199

112100
#endif

drivers/rpmsg/rpmsg_ns.c

Lines changed: 1 addition & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -20,22 +20,10 @@
2020
*/
2121
int rpmsg_ns_register_device(struct rpmsg_device *rpdev)
2222
{
23-
int ret;
24-
25-
strcpy(rpdev->id.name, "rpmsg_ns");
26-
ret = driver_set_override(&rpdev->dev, &rpdev->driver_override,
27-
rpdev->id.name, strlen(rpdev->id.name));
28-
if (ret)
29-
return ret;
30-
3123
rpdev->src = RPMSG_NS_ADDR;
3224
rpdev->dst = RPMSG_NS_ADDR;
3325

34-
ret = rpmsg_register_device(rpdev);
35-
if (ret)
36-
kfree(rpdev->driver_override);
37-
38-
return ret;
26+
return rpmsg_register_device_override(rpdev, "rpmsg_ns");
3927
}
4028
EXPORT_SYMBOL(rpmsg_ns_register_device);
4129

include/linux/rpmsg.h

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -165,6 +165,8 @@ static inline __rpmsg64 cpu_to_rpmsg64(struct rpmsg_device *rpdev, u64 val)
165165

166166
#if IS_ENABLED(CONFIG_RPMSG)
167167

168+
int rpmsg_register_device_override(struct rpmsg_device *rpdev,
169+
const char *driver_override);
168170
int rpmsg_register_device(struct rpmsg_device *rpdev);
169171
int rpmsg_unregister_device(struct device *parent,
170172
struct rpmsg_channel_info *chinfo);
@@ -192,6 +194,12 @@ ssize_t rpmsg_get_mtu(struct rpmsg_endpoint *ept);
192194

193195
#else
194196

197+
static inline int rpmsg_register_device_override(struct rpmsg_device *rpdev,
198+
const char *driver_override)
199+
{
200+
return -ENXIO;
201+
}
202+
195203
static inline int rpmsg_register_device(struct rpmsg_device *rpdev)
196204
{
197205
return -ENXIO;

0 commit comments

Comments
 (0)