From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752436AbbC3KET (ORCPT ); Mon, 30 Mar 2015 06:04:19 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:41065 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750875AbbC3KEQ (ORCPT ); Mon, 30 Mar 2015 06:04:16 -0400 Date: Mon, 30 Mar 2015 12:04:11 +0200 From: "gregkh@linuxfoundation.org" To: EunTaik Lee Cc: "linux-kernel@vger.kernel.org" Subject: Re: [PATCH] fix race condition between device_del and device_add Message-ID: <20150330100411.GB15916@kroah.com> References: <4A.CC.15273.32219155@epcpsbgx1.samsung.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <4A.CC.15273.32219155@epcpsbgx1.samsung.com> User-Agent: Mutt/1.5.23 (2014-03-12) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Mar 30, 2015 at 09:06:43AM +0000, EunTaik Lee wrote: > There is a possible race condition when a device > is added while another device with the same parent > , with ref count of one, is deleted. > > CPU0 CPU1 > device_add() device_del() > get_device_parent() put_device(parent); > kobj = kobject_get(k); kobject_put() > kref_put() > refcount=0 > refcount is 0 > WARNS it was 0 but > return kobj frees kobj > uses the freed parent kobj > > The race condition exists because kref_put() and the > release function is not atomic. > Using kobject_get_unless_zero() instead of > kobject_get() in get_device_parent() will prevent > this race condition. The bus that the device is on should prevent this, why isn't that working for you? What type of device/bus do you see this problem on? > Signed-off-by: eun.taik.lee We need a "real" name here, I don't think your name has '.' in it, right? > --- > drivers/base/core.c | 2 +- > include/linux/kobject.h | 2 ++ > lib/kobject.c | 2 +- > 3 files changed, 4 insertions(+), 2 deletions(-) > > diff --git a/drivers/base/core.c b/drivers/base/core.c > index 07304a3..ec2f211 100644 > --- a/drivers/base/core.c > +++ b/drivers/base/core.c > @@ -761,7 +761,7 @@ static struct kobject *get_device_parent(struct device > *dev, > spin_lock(&dev->class->p->glue_dirs.list_lock); > list_for_each_entry(k, &dev->class->p->glue_dirs.list, entry) > if (k->parent == parent_kobj) { > - kobj = kobject_get(k); > + kobj = kobject_get_unless_zero(k); > break; Your email client turned all tabs to spaces and made the patch unable to be applied. thanks, greg k-h