mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Dominik Brodowski <linux@dominikbrodowski.net>
To: Greg KH <greg@kroah.com>, mochel@digitalimplant.org
Cc: dtor_core@ameritech.net, linux-kernel@vger.kernel.org,
	linux-usb-devel@lists.sourceforge.net,
	Kay Sievers <kay.sievers@vrfy.org>
Subject: Re: [RFC] Changes to the driver model class code.
Date: Sun, 27 Mar 2005 16:42:47 +0200	[thread overview]
Message-ID: <20050327144246.GA9800@dominikbrodowski.de> (raw)
In-Reply-To: <20050315221431.GC28880@kroah.com>

On Tue, Mar 15, 2005 at 02:14:31PM -0800, Greg KH wrote:
> It will not make the reference counting logic easier to get wrong, or
> easier to get right.  It totally takes it away from the user, and makes
> them implement it themselves if they so wish (like the USB HCD patch
> does.)

Hi,

While looking more closely at your patches, I noticed the following race:

A) attribute is opened -> class_device's reference count is increased

B) usb/host/ohci-dbg.c::remove_debug_files() -- succeeds, as it doesn't check
   class_device's reference count()
B) usb/core/hcd.c::usb_deregister_count() -- class_device_unregister doesn't
   wait until class_device's reference count reaches zero, so 
   struct class_device still has "struct usb_bus *bus" saved as class_data
   and continues to exist.

B) possibly the kref count of struct usb_bus reaches zero, and struct usb_bus *
   is kfreed.

A) attribute is read -> e.g. usb/host/ohci-dbg.c::show_periodic()
        bus = class_get_devdata(class_dev);
        hcd = bus->hcpriv;
  --> accessing kfree'd structure. Ooops.

A) ... [if it hadn't oopsed] attribute is closed, reference count reaches zero,
   class_device is removed.


If both reference counts were kept unified (as with previous struct 
class{,_device} design) this couldn't happen. The proper reference counting
for dynamically allocated objects and their "attributes" is _the_ advantage 
of sysfs/driver model in favour of procfs.

Or am I missing something?

Thanks and Happy Easter,
	Dominik

  parent reply	other threads:[~2005-03-27 14:57 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-03-15 17:08 Greg KH
2005-03-15 17:09 ` Greg KH
2005-03-15 17:10   ` Greg KH
2005-03-15 17:10     ` Greg KH
2005-03-15 17:11       ` Greg KH
2005-03-15 17:47 ` Dmitry Torokhov
2005-03-15 19:34   ` Greg KH
2005-03-15 19:47     ` [linux-usb-devel] " Dmitry Torokhov
2005-03-15 20:15     ` Dominik Brodowski
2005-03-15 22:14       ` Greg KH
2005-03-16  1:01         ` Dominik Brodowski
2005-03-16  3:42         ` Dmitry Torokhov
2005-03-27 14:42         ` Dominik Brodowski [this message]
2005-03-15 19:08 ` Dominik Brodowski
2005-03-15 19:30   ` [linux-usb-devel] " Dmitry Torokhov
2005-03-15 19:34   ` Sean
2005-03-15 19:45   ` John Lenz
2005-03-15 19:51   ` Greg KH
2005-03-15 20:06     ` Dominik Brodowski
2005-03-15 20:14     ` [linux-usb-devel] " Dmitry Torokhov
2005-03-15 20:35       ` David Brownell
2005-03-15 20:48         ` Dmitry Torokhov
2005-03-15 21:14           ` David Brownell
2005-03-15 21:23             ` Dominik Brodowski
2005-03-15 22:05             ` Dmitry Torokhov
2005-03-15 22:29               ` David Brownell
2005-03-16 23:16 ` Jon Smirl
2005-03-17  6:17   ` Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20050327144246.GA9800@dominikbrodowski.de \
    --to=linux@dominikbrodowski.net \
    --cc=dtor_core@ameritech.net \
    --cc=greg@kroah.com \
    --cc=kay.sievers@vrfy.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-usb-devel@lists.sourceforge.net \
    --cc=mochel@digitalimplant.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome