From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f181.google.com (mail-qt1-f181.google.com [209.85.160.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 54EDD305E28 for ; Wed, 24 Jun 2026 19:47:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782330475; cv=none; b=BfvdStt9riCCcV3CSEP0MNNSL4WuTX5yICW01O0OTFO8ggQPbbtm1/jLmPKR3UxKMF2Kj2IzTJ8Q3QGV5Mtg1xB4vpumVBIR0RFUxyAAK/aMnMPY7rxDXuH9+izt4coa+TNcseDGhl6n90cNabJmQpLWB65hHe40K+brfXe+xmk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782330475; c=relaxed/simple; bh=KwdPnWw9FxeQQo1LyaoDgKO4tsPG/dkTumWsoQdW4vs=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=hH/01Nx+CXM5qPeMX4ufOof50826nE72Pm1ABwc8eIdkLO4x2LoYkbsgl1/ITk6YmiFQOjEfxNIr9aNbOoTb6dJbbt3LJcBmPGKXCf7+F0R6+S9rJrJp/IG+W6ddkxM2YZt/9SGPPUL3Ubdrc1OG+PJed8PZ+BEI/hSxH2o7AQA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FsWLIOme; arc=none smtp.client-ip=209.85.160.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FsWLIOme" Received: by mail-qt1-f181.google.com with SMTP id d75a77b69052e-51a1fe8f578so14740211cf.2 for ; Wed, 24 Jun 2026 12:47:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782330473; x=1782935273; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=Ekyl/8/QtHKvvGajGkVG4PfRvwZFSzg3Yjsd6R/4y98=; b=FsWLIOmeNRq6V5eu94kEyI2lXFbhRJtz9jMir88uOd79u9rWBCIepQxr0aNzPAI1m1 sPIbBr95AUgnPMjHddA57QHEHLt6I9B2Ixce4xNsZQ1s2JGwKMkF8OcWokn2YaJSjS7s 4Y3e0MFELrGakHLcnypFsgBsmkDpUTr1NXylPj8ejcc6TGFdQ0zJSylkk9yqPt446L+x Lo/Zi/8OVoMzAJI5yT8i7o4J1ANeRjJRCd+VzsIlNZ2YstHdFITgjbkCFVOeHjXIOPj8 FJfObMNRPuxUXfIkY7sVDvL41+chgISYZf5pVYQ13QzHE/7bhfmsr4/24NctVa1gAj0+ DYzg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782330473; x=1782935273; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=Ekyl/8/QtHKvvGajGkVG4PfRvwZFSzg3Yjsd6R/4y98=; b=JNFdE77xH7Jm6wcn3B9S7EltFBOwb8Ch5MmBdpb8JNjpI7Hf8n7+Talt36IVo333Fi 0FageOXod1DHS6mUfP4GkM2nPx5Y770OAW9P/xNzLRhUOMWyiQNWUMoaNwNT77eB5e8r WscUJ4h/pQxP5B1aFcvE76iYlJHCWo4J6cjO49Sph10W2PnQkV7/SLXUZMaZG3m4r4LA PjAdbLfV+J/HEbxqGYO5HxdbFY2oQSdQlt5djbNcpnL4/EV0v2VUQkxnKPNm7mnAKixC jl1ti7VamAsva8MHgYci7GoV0+1Ahe1Al5yfkuAhFDMytyrQO4U1Z4EIJteK3S2FlUX0 s44A== X-Gm-Message-State: AOJu0YwZvxGzKm0ghEB+Kx5Y+2O3LrvgDucsrBf57fj6iv90t8f+pjrI 93wYLDgC0vP5Y00wQf3ClHjGlzOjbiiH3L0I3xtLyMq4UTHjU4S8C+rQH5ickQ== X-Gm-Gg: AfdE7cnET03064CYPx3+vitX/f0swJ6asMcX/F0OCj/ktaK0spMVnoo8U6fDVzZX57l e+g+JGL3gUsGDeNM5vqoQk8CX9QDPGdO3OI8v0zbY/9J2NV9x6i9Lg5UXPOX2fkddSwlHtu3Ksy wM/SmlecCYjBzRWuS+2Mb1C7Q3IbQa6KqTAsl0g4MnKXAS20KrejZgiziFH6YVi1ui0TYGLNLr7 3IqBqBoCQZNNuizkcP6xBWxGpp+QDC0iUuxHWBcE/4U89AMrlD5WM7Ci3sEvaaUA2tdfRF41Lu9 VwA7knjskT8l4c+CyhSA0PTzPTUKFB9r9J9QAN+ASpyPABTpLa0kDFvQFp7Nzx0MHDpdQnG4NIg ppnGNja1a132pz/FAp5Q7OWRdaMJAU+QWwEEqWqxIHGveK5dB75JP7KBg32gRT+hBv9DIu295kY nsb4EDH4EOVBf8eFzhKCAMCuJUswLAIY17uG/hqq0RbZo= X-Received: by 2002:a05:622a:4:b0:517:5b79:c109 with SMTP id d75a77b69052e-51a548c4f5fmr120057161cf.56.1782330473198; Wed, 24 Jun 2026 12:47:53 -0700 (PDT) Received: from smtpclient.apple ([104.39.165.68]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-51a515ccdbbsm54217661cf.11.2026.06.24.12.47.52 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 24 Jun 2026 12:47:52 -0700 (PDT) Content-Type: text/plain; charset=us-ascii Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.600.51.1.1\)) Subject: Re: [RFC] ipack: ipoctal: fix use-after-free on remove From: Shuangpeng In-Reply-To: <78d586276bdb049f06af77d7f484116e213ba58c.1782200408.git.xiaopei01@kylinos.cn> Date: Wed, 24 Jun 2026 15:47:22 -0400 Cc: linux-kernel@vger.kernel.org Content-Transfer-Encoding: quoted-printable Message-Id: <2424869F-ABF4-4102-8DD4-6F2E0BCAB25E@gmail.com> References: <78d586276bdb049f06af77d7f484116e213ba58c.1782200408.git.xiaopei01@kylinos.cn> To: Pei Xiao X-Mailer: Apple Mail (2.3864.600.51.1.1) Hi Pei, Thanks for working on this! I applied the patch to commit: 390d73adf896bf4883c7d3bcd13c1b53d64351e3 (Jun 19 2026) and reran the same reproducer. The original slab-use-after-free report = did not show up in the same form, but the reproducer still triggers another KASAN report in ipoctal_write_tty(): [ 73.728267] Oops: general protection fault, probably for = non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN PTI [ 73.730941] KASAN: null-ptr-deref in range = [0x0000000000000000-0x0000000000000007] [ 73.731780] CPU: 0 UID: 0 PID: 8289 Comm: ipoctal_fd_afte Not tainted = 7.1.0-10997-g390d73adf896-dirty #33 PREEMPT(full) [ 73.734223] RIP: 0010:ipoctal_write_tty = (drivers/ipack/devices/ipoctal.c:453 = drivers/ipack/devices/ipoctal.c:470) Call Trace: [ 73.746486] n_tty_write (drivers/tty/n_tty.c:2388) [ 73.752256] file_tty_write (drivers/tty/tty_io.c:1006 = drivers/tty/tty_io.c:1081) [ 73.752746] vfs_write (fs/read_write.c:595 fs/read_write.c:687) [ 73.754695] ksys_write (fs/read_write.c:739) [ 73.756837] do_syscall_64 (arch/x86/entry/syscall_64.c:63 = arch/x86/entry/syscall_64.c:94) [ 73.757309] entry_SYSCALL_64_after_hwframe = (arch/x86/entry/entry_64.S:121) So the same open-tty-fd-after-tpci200-unbind reproducer still crashes = the kernel after this patch. Best, Shuangpeng > On Jun 23, 2026, at 03:50, Pei Xiao wrote: >=20 > A use-after-free occurs when the device is removed while a tty > session is still active. The remove callback frees the ipoctal > structure via kfree() while ipoctal_write_tty() and other tty ops > may still access it. >=20 > Fix this by introducing kref-based lifetime management for the > ipoctal structure. A kref is taken in ipoctal_install() when a tty is > initialized, and released in ipoctal_cleanup() when the tty is finally > destroyed. The remove callback replaces direct kfree() with = kref_put(), > ensuring the memory is only freed after all tty references have been > released. >=20 > Reported-by: Shuangpeng Bai > Closes: = https://lore.kernel.org/lkml/178144969601.60470.1257088106279546587@gmail.= com/ > Fixes: 05e5027efc9c ("Staging: ipack: move out of staging") > Signed-off-by: Pei Xiao > --- > drivers/ipack/devices/ipoctal.c | 19 +++++++++++++++++-- > 1 file changed, 17 insertions(+), 2 deletions(-) >=20 > diff --git a/drivers/ipack/devices/ipoctal.c = b/drivers/ipack/devices/ipoctal.c > index 1bbefc6de708..079bda93ad5a 100644 > --- a/drivers/ipack/devices/ipoctal.c > +++ b/drivers/ipack/devices/ipoctal.c > @@ -10,6 +10,7 @@ > #include > #include > #include > +#include > #include > #include > #include > @@ -25,6 +26,8 @@ >=20 > static const struct tty_operations ipoctal_fops; >=20 > +static void ipoctal_release(struct kref *kref); > + > struct ipoctal_channel { > struct ipoctal_stats stats; > unsigned int nb_bytes; > @@ -49,6 +52,7 @@ struct ipoctal { > struct tty_driver *tty_drv; > u8 __iomem *mem8_space; > u8 __iomem *int_space; > + struct kref kref; > }; >=20 > static inline struct ipoctal *chan_to_ipoctal(struct ipoctal_channel = *chan, > @@ -95,6 +99,7 @@ static int ipoctal_install(struct tty_driver = *driver, struct tty_struct *tty) > if (res) > goto err_put_carrier; >=20 > + kref_get(&ipoctal->kref); > tty->driver_data =3D channel; >=20 > return 0; > @@ -666,6 +671,7 @@ static void ipoctal_cleanup(struct tty_struct = *tty) >=20 > /* release the carrier driver */ > ipack_put_carrier(ipoctal->dev); > + kref_put(&ipoctal->kref, ipoctal_release); > } >=20 > static const struct tty_operations ipoctal_fops =3D { > @@ -683,6 +689,13 @@ static const struct tty_operations ipoctal_fops =3D= { > .cleanup =3D ipoctal_cleanup, > }; >=20 > +static void ipoctal_release(struct kref *kref) > +{ > + struct ipoctal *ipoctal =3D container_of(kref, struct ipoctal, = kref); > + > + kfree(ipoctal); > +} > + > static int ipoctal_probe(struct ipack_device *dev) > { > int res; > @@ -692,6 +705,8 @@ static int ipoctal_probe(struct ipack_device *dev) > if (ipoctal =3D=3D NULL) > return -ENOMEM; >=20 > + kref_init(&ipoctal->kref); > + > ipoctal->dev =3D dev; > res =3D ipoctal_inst_slot(ipoctal, dev->bus->bus_nr, dev->slot); > if (res) > @@ -701,7 +716,7 @@ static int ipoctal_probe(struct ipack_device *dev) > return 0; >=20 > out_uninst: > - kfree(ipoctal); > + kref_put(&ipoctal->kref, ipoctal_release); > return res; > } >=20 > @@ -725,7 +740,7 @@ static void __ipoctal_remove(struct ipoctal = *ipoctal) > tty_unregister_driver(ipoctal->tty_drv); > kfree(ipoctal->tty_drv->name); > tty_driver_kref_put(ipoctal->tty_drv); > - kfree(ipoctal); > + kref_put(&ipoctal->kref, ipoctal_release); > } >=20 > static void ipoctal_remove(struct ipack_device *idev) > --=20 > 2.25.1 >=20