From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F0A753FB7E5 for ; Fri, 31 Jul 2026 11:47:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785498460; cv=none; b=dN76E9tl3qEeY0dDIBK+tHPgvSOmuRkP+5oZqnx+thG1lELsRgZ8nENAd+ntjDQQuAR8lnR12cTcXpViQtQLNDnkuK9bNlxNjDWwuBZek0bu7QpqXs8YAZ44sXOWGAqJ08+PSDFTtj1/K8o4XX5uUkLOz3lonwhYOoD6L8Rzmlk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785498460; c=relaxed/simple; bh=DnhkgYMHfvCFu2QJMFO5Znf+coywQ8Bi1E6oL5tojWU=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=tRzyitDfibdzGCxNybS+5v4blNAirK84iCGIfpV9kilTLgl2yGOOSsjrl4/hLIf6hjfbOhK2mfMGl7nTuYdM4DUexaDOgCuryKml7FAc+dX3N65yd5KWkyBVgYuQQyE91xhQi3TxlYVHGFsKEzaVMmMMcfTBi/+VgEQTnOAYOHE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Ie0J/QDU; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=U2N8/qzw; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Ie0J/QDU"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="U2N8/qzw" Received: from pps.filterd (m0279864.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66VBdCUr3371068 for ; Fri, 31 Jul 2026 11:47:36 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= DVtpalNU2+7OReB55Y0D7oXXvik1+l9HeGh0NADjc0w=; b=Ie0J/QDUSkrKCND2 U31C008YtRYBOsu4hPT1zMqNx9Pw3SMjhw6XuL/Ea2fkJortvIbxgiXxmwdOiRBo GzFx069oSRe/CfpJSgjnW9pQcVZyw8J5fndZbpmubkTvMO0PsWwBsO54t4+cjDhp UAGvYEHC5RHr7x+wayBDdIMgDKDiTt7qQat4kopXRBpH6gUyxJTfVRys1IN18Tsb eN2c3NuJ1GNRZNxYonRi7PntPV92CDHCmehSnSGGGsWwZUV4x0ywS7hFzXJfYFzZ CcSmtgD9qU8B6hQK+tAUICse4bp3vty0uZ51dm6xsybBlmfH9N2kYLfZHY7qjAtU HEvC/A== Received: from mail-qv1-f72.google.com (mail-qv1-f72.google.com [209.85.219.72]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fru0y00v1-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 31 Jul 2026 11:47:36 +0000 (GMT) Received: by mail-qv1-f72.google.com with SMTP id 6a1803df08f44-8f21e4e8b66so2040406d6.3 for ; Fri, 31 Jul 2026 04:47:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785498455; x=1786103255; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=DVtpalNU2+7OReB55Y0D7oXXvik1+l9HeGh0NADjc0w=; b=U2N8/qzwsp1AHiZESctiJc0AQIPvZj7Ati/q6RzFAYc5JKZOTl+nc0o78j7DG0cSmT rk73M+S2cSzKilHCHi6W8Svnl+DprxjyVvyinvqXU8XY5+TPWgvc+LKfxkQTUx8Dr19m H/FfyCwXkmSFvFEp4eqx/k3NsrABk+yMsHg0tPXuIWVwFNX4FQOPZMEIj+payN07NsjP iooDf6QTi2tywJsegHF4Go1SrvtR/efHdW1N2u8C6oYrdO2v4YHyzfVUXapOnTOJfe6G oulA4haF0difAsdyotQK6eMq/2TCPBScQsumpEqEltAXnbpoVynvhBSx9ZAmqvvH0U+m tu+A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785498455; x=1786103255; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DVtpalNU2+7OReB55Y0D7oXXvik1+l9HeGh0NADjc0w=; b=E1A8mbj1w+tTE9sI017irL90SlY/+W/d3xir77BSe4dy9NR8uuxBvmFFCKEP2DWWqj OUqcc8at3Q09u2R9EUG15vp1sXRLDKzPqV882tsLdFBrbSOjzrcV5yvdUkhlUJuQ+er/ EPA+dKm+mNoqT8O66FP7vMQG6/FKtXj1ANz8NTTcTzbd6TqmfrhP6Y4zPu8HBK3cpdSz yooH42dwCR5kNyqAxvJKVJlL8oxMIceonD93fIH1po9sSWy4aXaoyWbqtscmOiyb3KDr 4JGXW0LFhat9y3eIXrBwVgAwZoHm7NnURLqXVTxl+6DVgI7dHXuInhUO1FUTjZ5LIpgR oCng== X-Forwarded-Encrypted: i=1; AHgh+RqzP3+7m2XXEhkWypPjY3QiT0LQI54HnyjX+0ciCtJavutfWAfY3+Y+Pf44DQbe3fwzNWkerrktibLPopQ=@vger.kernel.org X-Gm-Message-State: AOJu0YxTMspYB0UIgWsyAUAF0uKw/+nawfQuC43BwT1Sfu+YIWrxDk9e SLaSC8YNNQtt+BEJoL00g2i2nzDg2ioNZCn/AK8VqoC7Juyr42SJjcXp1Qw3mocbbHczP2mcAiM dPjy/ULQphDVkXZHXUvsVm85N3cgo3d925ksNftMcAB+hybPikVZdaTWecM1EqgcLRgU= X-Gm-Gg: AR+sD13fq0yohl/qeFPAc0FsXWXCa8pbCLJGz/jjS3qEJF1Th7Cd6l7R/yNDfwjvHY2 zLNnJz44Zlf6CK9mVwCawuljCLn/i7ksJQnqKbRRN3cDfdAhZDUO2tQFv9wdSVv7ylxGyUP6Ilf /8hTjsFNREAw9qv4tNOaB7fhHqh4qMlZ1945zhbhL/CgZIRkGZfyqnPyby2AIdBo4I+vtKW9u/v VlRtAJ2ojbBqBRVgN3PU8qh3MEU63xMJJ1Ds2XOjEvffNirEoZE/Fak54Dtxc44T1lMyVFxOi1W DpUmMuc9MqRtVm2/JBfc93wlRgK8tARio7FqliHlrof6fGMU7FKlL7QeopN1gVhyFfLSJnKHnRd +e3OIja+DZKz52hFc+/yI+ZJD X-Received: by 2002:a05:6214:258b:b0:8ef:4749:b1c9 with SMTP id 6a1803df08f44-90842433681mr23970906d6.5.1785498455017; Fri, 31 Jul 2026 04:47:35 -0700 (PDT) X-Received: by 2002:a05:6214:258b:b0:8ef:4749:b1c9 with SMTP id 6a1803df08f44-90842433681mr23970466d6.5.1785498454594; Fri, 31 Jul 2026 04:47:34 -0700 (PDT) Received: from [192.168.120.193] ([178.235.128.140]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1fd452d93dsm129675566b.49.2026.07.31.04.47.32 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 31 Jul 2026 04:47:33 -0700 (PDT) Message-ID: <83d5818c-d764-4385-b430-ccbdb33ddb88@oss.qualcomm.com> Date: Fri, 31 Jul 2026 13:47:31 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2 5/5] media: iris: reference count video instances To: Dmitry Baryshkov , Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Vedang Nagar Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> <20260731-iris-fixes-v2-5-94c002016a09@oss.qualcomm.com> Content-Language: en-US From: Konrad Dybcio In-Reply-To: <20260731-iris-fixes-v2-5-94c002016a09@oss.qualcomm.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Proofpoint-Spam-Info: AW1haW4tMjYwNzMxMDA5MCBTYWx0ZWRfX6XxZ2NN5nweh 4YvKv7Pp3DSSzsT1ET5GA2rt9QAVSf15yPvxvR+ByCI/9nZr2KQAyugmKJh7N9slr+P2mC8W0Uf Xx3bwKACCaobvyd0DD2N4tUxshMw8Hc= X-Authority-Analysis: v=2.4 cv=TcamcxQh c=1 sm=1 tr=0 ts=6a6c8b58 cx=c_pps a=7E5Bxpl4vBhpaufnMqZlrw==:117 a=PRfkaYvzSr8QmIIGAkY2Sg==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=DJpcGTmdVt4CTyJn9g5Z:22 a=VHsrxQYZaTBPj5NF5iQA:9 a=QEXdDO2ut3YA:10 a=pJ04lnu7RYOZP9TFuWaZ:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzMxMDA5MCBTYWx0ZWRfX2X+00UDEP4fA E44IDYnKCtDYHEP0/dDU0I6g2J5QBQu3ILK+tcQzGY7toHxcKnkU2wzi5gjVcE3tZB6sHi+rPzG ot6/gRxRP3r1INTgSgIHnXgupICZElx7LYwaBLKmhfYEF3L8eoA8TbFhxA1B55w0drFMzLpjNml vOyxekU7rMHWuuoI0OFBjQJN9xCbhWc0xQA+g9SeAeR21vyD26KqtVJgUVZawVJw7fkFp3CuHt4 EMIwupZzA3qSXccr+tzLSWTJrcVchL3YeE63+VTK+rDsaEwUeoaAmCZFZ5WDeRdBFqwW0mVDBSC uWWQwmK1HUbt8BJ48EtBm3EWVLpDZ3CILacryiirm/Y3VWLKb4qKfwVDIeG88Zujj4QcNlojcYW epZkn5ti/CUqu+nh3T18+Gq3VlU7vBO5mzx55N7dRDtxVhmdjX3UsCd8a1RtApz4DbVbB87z0e+ hPNrICbm9T7UsZWEMAw== X-Proofpoint-ORIG-GUID: 0zm_3F_PPe33ToQVjV22MAyGwqAqabjb X-Proofpoint-GUID: 0zm_3F_PPe33ToQVjV22MAyGwqAqabjb X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-31_04,2026-07-30_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 lowpriorityscore=0 bulkscore=0 malwarescore=0 phishscore=0 priorityscore=1501 suspectscore=0 spamscore=0 adultscore=0 clxscore=1015 impostorscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607310090 On 7/31/26 2:31 AM, Dmitry Baryshkov wrote: > iris_get_instance() looks up an instance on core->instances and returns > it after dropping core->lock, without taking any reference. The threaded > interrupt handler uses this to find the instance a firmware response > belongs to and then takes inst->lock. Meanwhile userspace may close the > same file descriptor: iris_close() removes the instance from the list, > destroys inst->lock and frees the instance. The interrupt handler then > operates on freed memory and a destroyed mutex, a use-after-free. [...] > @@ -92,6 +92,12 @@ struct iris_inst *iris_get_instance(struct iris_core *core, u32 session_id) > mutex_lock(&core->lock); > list_for_each_entry(inst, &core->instances, list) { > if (inst->session_id == session_id) { > + /* > + * Take a reference under core->lock, paired with > + * iris_inst_put() once the caller is done, so the > + * instance cannot be freed by a concurrent close(). > + */ > + kref_get(&inst->kref); > mutex_unlock(&core->lock); But none of the _puts() are under the core lock? Konrad