From: Danish Khateeb <danishkhateeb03@gmail.com>
To: Rodolfo Giometti <giometti@enneenne.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Calvin Owens <calvin@wbinvd.org>, Yibo Tan <lhfff@tju.edu.cn>,
linux-kernel@vger.kernel.org,
Danish Khateeb <danishkhateeb03@gmail.com>,
stable@vger.kernel.org
Subject: [PATCH v2 3/4] pps: generators: stop the generator on unregister
Date: Tue, 29 Sep 2026 07:49:36 -0500 [thread overview]
Message-ID: <20260929124937.51114-4-danishkhateeb03@gmail.com> (raw)
In-Reply-To: <20260929124937.51114-1-danishkhateeb03@gmail.com>
Both generator drivers stop their timer and then call
pps_gen_unregister_source(): pps_gen_tio_remove() cancels its hrtimer
and disables the TIO, and pps_gen_dummy_exit() deletes its timer. But
/dev/pps-genN and the sysfs "enable" attribute are still there until
the unregister, and a PPS_GEN_SETENABLE or a write to "enable" in
between starts the timer again. Nothing stops it after that: TIO's
hrtimer keeps running in the devm memory freed by the unbind, and the
dummy's timer is left in the unloaded module.
The drivers can't avoid this by unregistering first, as TIO's timer
callback uses pps_gen, which the unregister may free.
Stop the generator in pps_gen_unregister_cdev() instead, under
info_lock after the device and its sysfs files are gone, when nothing
can enable it again. pps_gen_unregister_source() then also does what
its kernel-doc says: "it disables the generator so no pulses are
generated anymore".
Fixes: 86b525bed275 ("drivers pps: add PPS generators support")
Cc: stable@vger.kernel.org
Suggested-by: Rodolfo Giometti <giometti@enneenne.com>
Assisted-by: LLM
Signed-off-by: Danish Khateeb <danishkhateeb03@gmail.com>
---
Notes:
Tested in the same setup, with patches 1/4 and 2/4 applied. The test
driver got a periodic hrtimer in its devm memory, like TIO's, and a
remove() that cancels it and then enables the generator again before
unregistering, as a PPS_GEN_SETENABLE landing there would. Without this
patch the timer keeps running after the unbind:
BUG: KASAN: slab-use-after-free in rb_erase+0x174d/0x1a70
__remove_hrtimer+0x138/0x450
__hrtimer_run_queues+0x2c5/0x7f0
hrtimer_interrupt+0x3db/0x910
...
Freed by task 175:
kfree+0x25a/0x6d0
release_nodes+0xd1/0x140
devres_release_all+0x10e/0x1a0
device_unbind_cleanup+0x71/0x250
device_release_driver_internal+0x41b/0x570
unbind_store+0xd9/0x100
With it, unregister calls enable(false), the timer is stopped, and
there are no reports. Unbinding the test driver while enabled, and
unloading pps_gen-dummy while its file is open and enabled, are clean
too.
drivers/pps/generators/pps_gen.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/pps/generators/pps_gen.c b/drivers/pps/generators/pps_gen.c
index d80e28dc31dc..452cc12a96f2 100644
--- a/drivers/pps/generators/pps_gen.c
+++ b/drivers/pps/generators/pps_gen.c
@@ -228,9 +228,18 @@ static void pps_gen_unregister_cdev(struct pps_gen_device *pps_gen)
* An open file keeps pps_gen around, but the driver may free info as
* soon as we return. The sysfs files are gone now, so wait for the
* ioctls using info and make later ones fail.
+ *
+ * The driver may have stopped the generator before calling us, but
+ * userspace could have enabled it again since. Nothing can enable it
+ * after this point, so stop it here for good.
*/
- scoped_guard(mutex, &pps_gen->info_lock)
+ scoped_guard(mutex, &pps_gen->info_lock) {
+ if (pps_gen->enabled) {
+ pps_gen->info->enable(pps_gen, false);
+ pps_gen->enabled = false;
+ }
pps_gen->info = NULL;
+ }
put_device(&pps_gen->dev);
}
--
2.55.0
next prev parent reply other threads:[~2026-09-29 12:49 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 12:49 [PATCH v2 0/4] pps: generators: fix use-after-free on unregister with the file open Danish Khateeb
2026-09-29 12:49 ` [PATCH v2 1/4] pps: generators: fix use-after-free when closing a removed device Danish Khateeb
2026-09-29 12:49 ` [PATCH v2 2/4] pps: generators: don't use the driver's info after unregister Danish Khateeb
2026-09-29 12:49 ` Danish Khateeb [this message]
2026-09-29 12:49 ` [PATCH v2 4/4] pps: generators: wake up PPS_GEN_FETCHEVENT readers on unregister Danish Khateeb
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929124937.51114-4-danishkhateeb03@gmail.com \
--to=danishkhateeb03@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=calvin@wbinvd.org \
--cc=giometti@enneenne.com \
--cc=gregkh@linuxfoundation.org \
--cc=lhfff@tju.edu.cn \
--cc=linux-kernel@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®