mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Yi Sun <yi.sun@intel.com>
To: vinicius.gomes@intel.com, dmaengine@vger.kernel.org,
	linux-kernel@vger.kernel.org
Cc: dave.jiang@intel.com, yi.sun@intel.com, gordon.jin@intel.com,
	fenghuay@nvidia.com
Subject: [PATCH v3 0/2] dmaengine: idxd: Fix refcount and cleanup issues on module unload
Date: Tue, 17 Jun 2025 18:27:10 +0800	[thread overview]
Message-ID: <20250617102712.727333-1-yi.sun@intel.com> (raw)

This patch series addresses two issues related to the device reference
counting and cleanup path in the idxd driver.

Recent changes introduced improper put_device() calls and duplicated
cleanup logic, leading to refcount underflow and potential use-after-free
during module unload.

Patch 1 removes an unnecessary call to idxd_free(), which could result in a
use-after-free when paired with asynchronous put_device().

Patch 2 refactors the cleanup path to avoid redundant put_device() calls
introduced in commit a409e919ca3. The existing idxd_unregister_devices()
already handles proper device reference release.

Both patches have been verified on hardware platform.

Both patches have been run through `checkpatch.pl`. Patch 2 gets 1 error
and 1 warning. But these appear to be limitations in the checkpatch script
itself, not reflect issues with the patches.

---
Changes in V3:
- Removed function idxd_disable_sva which got removed recently (Vinicius)
Changes in v2:
- Reworded commit messages supplementing the call traces (Vinicius)
- Explain why the put_device are unnecessary. (Vinicius)

Yi Sun (2):
  dmaengine: idxd: Remove improper idxd_free
  dmaengine: idxd: Fix refcount underflow on module unload

 drivers/dma/idxd/init.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

-- 
2.43.0

             reply	other threads:[~2025-06-17 10:27 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-06-17 10:27 Yi Sun [this message]
2025-06-17 10:27 ` [PATCH v3 1/2] dmaengine: idxd: Remove improper idxd_free Yi Sun
2025-06-17 22:13   ` Fenghua Yu
2025-07-27  9:02     ` Yi Sun
2025-07-28  8:21       ` Shuai Xue
2025-06-17 10:27 ` [PATCH v3 2/2] dmaengine: idxd: Fix refcount underflow on module unload Yi Sun
2025-06-17 21:58   ` Fenghua Yu
2025-06-18  0:38     ` Vinicius Costa Gomes
2025-07-27  9:16     ` Yi Sun
2025-07-28  8:40       ` Shuai Xue
2025-07-28 11:43         ` Yi Sun
2025-07-29  2:46           ` Shuai Xue
2025-07-29  3:15             ` Yi Sun
2025-07-29  6:00               ` Shuai Xue
2025-07-31  0:17             ` Vinicius Costa Gomes

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250617102712.727333-1-yi.sun@intel.com \
    --to=yi.sun@intel.com \
    --cc=dave.jiang@intel.com \
    --cc=dmaengine@vger.kernel.org \
    --cc=fenghuay@nvidia.com \
    --cc=gordon.jin@intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=vinicius.gomes@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®