mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Austin via B4 Relay <devnull+austin.schlegel.arthrex.com@kernel.org>
To: Laxman Dewangan <ldewangan@nvidia.com>,
	 Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	 Jiri Slaby <jirislaby@kernel.org>,
	 Thierry Reding <thierry.reding@kernel.org>,
	 Jonathan Hunter <jonathanh@nvidia.com>
Cc: linux-kernel@vger.kernel.org, linux-serial@vger.kernel.org,
	 linux-tegra@vger.kernel.org,
	Austin <austin.schlegel@arthrex.com>
Subject: [PATCH 2/2] serial: tegra: fix TX DMA descriptor use-after-free
Date: Thu, 01 Oct 2026 15:04:02 -0400	[thread overview]
Message-ID: <20261001-tty-linus-v1-2-ecb8576c802d@arthrex.com> (raw)
In-Reply-To: <20261001-tty-linus-v1-0-ecb8576c802d@arthrex.com>

From: Austin <austin.schlegel@arthrex.com>

tegra_uart_stop_tx() calls dmaengine_terminate_all() and then
async_tx_ack(tup->tx_dma_desc) on the descriptor that was just
terminated. With the GPC DMA driver, dmaengine_terminate_all() frees
the active descriptor immediately, so the ack call that follows
touches freed memory, the same use-after-free pattern fixed for the
RX path in tegra_uart_terminate_rx_dma() ("serial: tegra: fix RX DMA
descriptor use-after-free"). dmaengine clients must not touch a
descriptor once dmaengine_terminate_all() has returned.

Move the ack before dmaengine_terminate_all(), while the descriptor
is still owned by the driver. tegra_uart_tx_dma_complete() already
acks inside the completion callback, where the descriptor is valid,
and is unaffected.

Found by code inspection while fixing the analogous RX bug; not
reproduced on hardware, since triggering it requires stopping an
in-flight TX DMA transfer (e.g. via a modem control line or flush)
at the right moment. The RX and TX paths share the same
dmaengine_terminate_all()-then-ack structure and the same root cause.

Signed-off-by: Austin <austin.schlegel@arthrex.com>
---
 drivers/tty/serial/serial-tegra.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/tty/serial/serial-tegra.c b/drivers/tty/serial/serial-tegra.c
index c9ec633e7164..0d1a2ebe2a59 100644
--- a/drivers/tty/serial/serial-tegra.c
+++ b/drivers/tty/serial/serial-tegra.c
@@ -625,9 +625,9 @@ static void tegra_uart_stop_tx(struct uart_port *u)
 
 	dmaengine_pause(tup->tx_dma_chan);
 	dmaengine_tx_status(tup->tx_dma_chan, tup->tx_cookie, &state);
+	async_tx_ack(tup->tx_dma_desc);
 	dmaengine_terminate_all(tup->tx_dma_chan);
 	count = tup->tx_bytes_requested - state.residue;
-	async_tx_ack(tup->tx_dma_desc);
 	uart_xmit_advance(&tup->uport, count);
 	tup->tx_in_progress = 0;
 }

-- 
2.53.0



  parent reply	other threads:[~2026-10-01 19:04 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 19:04 [PATCH 0/2] serial: tegra: fix RX/TX " Austin via B4 Relay
2026-10-01 19:04 ` [PATCH 1/2] serial: tegra: fix RX " Austin via B4 Relay
2026-10-02  4:06   ` Austin Schlegel
2026-10-02  5:53     ` Greg Kroah-Hartman
2026-10-01 19:04 ` Austin via B4 Relay [this message]
2026-10-02  4:07   ` [PATCH 2/2] serial: tegra: fix TX " Austin Schlegel
2026-10-02  4:06 ` [PATCH 0/2] serial: tegra: fix RX/TX " Austin Schlegel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001-tty-linus-v1-2-ecb8576c802d@arthrex.com \
    --to=devnull+austin.schlegel.arthrex.com@kernel.org \
    --cc=austin.schlegel@arthrex.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=jirislaby@kernel.org \
    --cc=jonathanh@nvidia.com \
    --cc=ldewangan@nvidia.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-serial@vger.kernel.org \
    --cc=linux-tegra@vger.kernel.org \
    --cc=thierry.reding@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®