From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CED473E5A24 for ; Wed, 3 Jun 2026 03:08:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.41 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780456098; cv=none; b=BS8GQJqLIuk/1qMVaskNLr0EObDP+nh+icDkpKyvuMr5GeVydXx98VcA+6Ym5QPnu91wjGKjtgUv1cTFXQPF3gZIeW6kVPhXdtxt59HlmCf7TiCmN0DAZgyS6JP9smADhg7SUDlnr8X3ptVBuVjmdHLsfBkdPsad7b2w9TMfNkw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780456098; c=relaxed/simple; bh=+PVqljYAEuaHeLfyyM+CGl4qW0A24vMOocrK+WLBCf8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=c0XkJdCp12u57cJAqarJjAjdHgU1/5JSMmUtwb47aXrMRR11Aw6DDHKKqJTWauFyVyjZqvFouW59d1po/EpQUVSuDppxhX8HfF0ofeJgOoNLgYP6UzyNWzsfcnEOIeVuXk09qfXgz+8VFNtnG38fSxNHVAN4vnJIizCxnE5HY/A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=cu5++uHB; arc=none smtp.client-ip=209.85.216.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="cu5++uHB" Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-36bd175fdbaso2774779a91.0 for ; Tue, 02 Jun 2026 20:08:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780456096; x=1781060896; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=RD449MAq8gcYE5XoSdNvMg3UoSZBswuYPEgYBJrnJS4=; b=cu5++uHBq0jeWVyVb5uLRQIxJI22DX6gA36+TJXNqFi2FczCD80J0dE0ZmfMYmhfR7 Ez+2G3OwqrbOVLrlpIdbHR1ujPWbYA91i6OyWpBb+IpTq2JLEyihcehsZyl4TAB0XsG+ 81jK0kCOBS8NyG2qEYcTjxHDRwvvkRsEpA90FLI6jN98g+i0BDpxDFgfp3zudnYs04IF uPbQkQRkDMLVrgFDqnOP6BY9UpZki/UsfeY4fpZmnSGpPF236zUfD7FvLUYOOmH/hyfs 7+W0WiPHtXywTQL8ef+1eV7Lvw3u5gJwCduel5YJdD4bbYmpMHS8NU4zUv8Xa07iSjGA B5sw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780456096; x=1781060896; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=RD449MAq8gcYE5XoSdNvMg3UoSZBswuYPEgYBJrnJS4=; b=X1fVrBMOnyRNQ1wKhoowsX1GD8E1xnWDeM3+PoveBqlJi2WuTmE8eqA9od7R6ecNsb cVzJuvt7hB5w1sqNsCvCp4wLLQdRzZHRoE1DSsa5yrJkwmY2+acssCwBQr6iZZpASN/E pzXnc/cqbX7iEsjRG0X37Ax7NHLnfUCfOhw8kWFu17dqK67Vu/2otuIfLtvPPvf5/BHL T0XDTP8MbYHy1aRZRJiL2tUEqLNnU9mFo7ixnvoN7FWlYllPXvbbDjVlYFnGScCbEx5r A4yHo307gTySC3o1c4Bn3zvmCXKGM+1ScANWZcPdCCxNQwHWwIDZ/Ggm/bE3aC7tuL7N 76FA== X-Forwarded-Encrypted: i=1; AFNElJ/37XdL2xoXtbz1O9LmE5w8CZ7dp2j3XTkY4p3i4Ty9MbJt4T1CxJgKbqHTvxSRfQbQfpCiBP0mDr4LSqA=@vger.kernel.org X-Gm-Message-State: AOJu0YyrWz+XtQvbfJkF6ryDjKz1GNl80Ipv3yBDfwfRc4pnoQQfyD91 D25V815LjrW09NnLIlXBgt1Swz4I+pC7DrfyakcRUOBYrYri3eUQXjr6 X-Gm-Gg: Acq92OFq5c+ZawooRlKbyEYeX23yRIjrJAqMEQboE/LgSxvphRA3/A1c9VS7ipvIYc/ HYzN9L9CWycuCAG+HcAZmQY0QhWIghm29zByPL3fbygd2hpJ1WlLzQY8M+gKDceVtcOvoHu/2lp vWoQY+KsYMD7WDP28zTYulapy8HaFuBtTQCh3M0OyJa0rN/ZlT4IBqtfCtBvhetXptHGmmbuc3T NdPO3O6UNIHDyKNtFDI+e+s631xPX20yUqx4b+Ju9toY4ToEroD7B3a4CdeviHzltRowwTYKwQp xG/JiJlESNzTxioMxi8/d0Gz6LQlAcjMYAIEja7qLp6QTKpNjz6iy9LdAtb84VnaLQO3hyVpM8y HOuklCw/fXQkpW9FVp/XJts32n6ES+A+BOaD9+iwLJ3wOa2nnxGYJdy3lTi+unM1thMgzvbeyNO 7GnMn7tWJwEY+jIh9tvoHa48foev0ZBFuyr0srlg8I8tPuNVcooPPsOUEDcekxfDRj44el8jYHs hYpaGFy4XWFJDxeWzUoZbXY0qAgzhbe2Z19bONRCQVKtg== X-Received: by 2002:a17:90b:1fc7:b0:36d:8f51:fe29 with SMTP id 98e67ed59e1d1-36e32285958mr1450616a91.17.1780456096056; Tue, 02 Jun 2026 20:08:16 -0700 (PDT) Received: from ryzen ([2601:644:8000:5b5d:7285:c2ff:fe45:8a32]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-36e0a186741sm1247102a91.8.2026.06.02.20.08.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 02 Jun 2026 20:08:15 -0700 (PDT) From: Rosen Penev To: dmaengine@vger.kernel.org Cc: Peter Ujfalusi , Vinod Koul , Frank Li , Kees Cook , "Gustavo A. R. Silva" , Haotian Zhang , Tony Lindgren , Russell King , linux-kernel@vger.kernel.org (open list), linux-hardening@vger.kernel.org (open list:KERNEL HARDENING (not covered by other areas):Keyword:\b__counted_by(_le|_be|_ptr)?\b) Subject: [PATCHv3 2/8] dmaengine: ti: omap-dma: synchronize CPU PM notifier removal Date: Tue, 2 Jun 2026 20:07:48 -0700 Message-ID: <20260603030754.288757-3-rosenp@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260603030754.288757-1-rosenp@gmail.com> References: <20260603030754.288757-1-rosenp@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit cpu_pm_notify() walks the raw notifier chain under rcu_read_lock(), while cpu_pm_unregister_notifier() only unlinks the notifier block. The controller is devres allocated and can be freed shortly after remove returns. Wait for an RCU grace period after unregistering the CPU PM notifier so concurrent CPU PM readers cannot dereference a freed notifier block. Fixes: 4c74ecf79227 ("dmaengine: ti: omap-dma: Add device tree match data and use it for cpu_pm") Cc: stable@vger.kernel.org Assisted-by: Codex:GPT-5 Signed-off-by: Rosen Penev --- drivers/dma/ti/omap-dma.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/drivers/dma/ti/omap-dma.c b/drivers/dma/ti/omap-dma.c index 0f6dd6b0a301..15be3c90440a 100644 --- a/drivers/dma/ti/omap-dma.c +++ b/drivers/dma/ti/omap-dma.c @@ -14,6 +14,7 @@ #include #include #include +#include #include #include #include @@ -1853,8 +1854,10 @@ static void omap_dma_remove(struct platform_device *pdev) struct omap_dmadev *od = platform_get_drvdata(pdev); int irq; - if (od->cfg->may_lose_context) + if (od->cfg->may_lose_context) { cpu_pm_unregister_notifier(&od->nb); + synchronize_rcu(); + } if (pdev->dev.of_node) of_dma_controller_free(pdev->dev.of_node); -- 2.54.0