From: Dave Jiang <dave.jiang@intel.com>
To: "Rafael J. Wysocki" <rafael@kernel.org>,
Linux ACPI <linux-acpi@vger.kernel.org>
Cc: Dan Williams <djbw@kernel.org>,
LKML <linux-kernel@vger.kernel.org>,
Vishal Verma <vishal.l.verma@intel.com>,
nvdimm@lists.linux.dev,
Alison Schofield <alison.schofield@intel.com>,
Xiang Chen <chenxiang66@hisilicon.com>
Subject: Re: [PATCH v2 2/4] ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
Date: Wed, 3 Jun 2026 16:06:25 -0700 [thread overview]
Message-ID: <f3fff3f8-89e3-496f-9af5-868ef329d137@intel.com> (raw)
In-Reply-To: <1963615.tdWV9SEqCh@rafael.j.wysocki>
On 6/3/26 10:57 AM, Rafael J. Wysocki wrote:
> From: "Rafael J. Wysocki" <rafael.j.wysocki@intel.com>
>
> If acpi_nfit_init() fails after adding the acpi_desc object to the
> acpi_descs list, that object is never removed from that list because
> the acpi_nfit_shutdown() devm action is not added for the NFIT device
> in that case. Next, the acpi_nfit_init() failure causes
> acpi_nfit_probe() to fail, the acpi_desc object is freed, and a
> dangling pointer is left behind in the acpi_descs. Any subsequent
> ACPI Machine Check Exception will trigger nfit_handle_mce() which
> iterates over acpi_descs and so a use-after-free will occur.
>
> Moreover, if acpi_nfit_probe() returns 0 after installing a notify
> handler for the NFIT device and without allocating the acpi_desc
> object and setting the NFIT device's driver data pointer, the
> acpi_desc object will be allocated by acpi_nfit_update_notify()
> and acpi_nfit_init() will be called to initialize it. Regardless
> of whether or not acpi_nfit_init() fails in that case, the
> acpi_nfit_shutdown() devm action is not added for the NFIT device
> and acpi_desc is never removed from the acpi_descs list. If the
> acpi_desc object is freed subsequently on driver removal, any
> subsequent ACPI MCE will lead to a use-after-free like in the
> previous case.
>
> To address the first issue mentioned above, make acpi_nfit_probe()
> call acpi_nfit_shutdown() directly on acpi_nfit_init() failures and
> to address the other one, add a remove callback to the driver and
> make it call acpi_nfit_shutdown(). Also, since it is now possible to
> pass NULL to acpi_nfit_shutdown() or the acpi_desc object passed to it
> may not have been initialized, add checks against NULL for acpi_desc and
> its nvdimm_bus field to that function and make acpi_nfit_unregister()
> clear the latter after unregistering the NVDIMM bus.
>
> Fixes: a61fe6f7902e ("nfit, tools/testing/nvdimm: unify common init for acpi_nfit_desc")
> Fixes: fbabd829fe76 ("acpi, nfit: fix module unload vs workqueue shutdown race")
> Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
> Cc: All applicable <stable@vger.kernel.org>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
> ---
> drivers/acpi/nfit/core.c | 18 +++++++++++++++---
> 1 file changed, 15 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/acpi/nfit/core.c b/drivers/acpi/nfit/core.c
> index 8024cd3cad14..01c73be0bd00 100644
> --- a/drivers/acpi/nfit/core.c
> +++ b/drivers/acpi/nfit/core.c
> @@ -3069,6 +3069,8 @@ static void acpi_nfit_unregister(void *data)
> struct acpi_nfit_desc *acpi_desc = data;
>
> nvdimm_bus_unregister(acpi_desc->nvdimm_bus);
> + /* The nvdimm_bus object may have been freed, so clear the pointer. */
> + acpi_desc->nvdimm_bus = NULL;
> }
>
> int acpi_nfit_init(struct acpi_nfit_desc *acpi_desc, void *data, acpi_size sz)
> @@ -3301,7 +3303,10 @@ static void acpi_nfit_notify(acpi_handle handle, u32 event, void *data)
> void acpi_nfit_shutdown(void *data)
> {
> struct acpi_nfit_desc *acpi_desc = data;
> - struct device *bus_dev = to_nvdimm_bus_dev(acpi_desc->nvdimm_bus);
> + struct device *bus_dev;
> +
> + if (!acpi_desc || !acpi_desc->nvdimm_bus)
> + return;
>
> /*
> * Destruct under acpi_desc_lock so that nfit_handle_mce does not
> @@ -3316,6 +3321,7 @@ void acpi_nfit_shutdown(void *data)
> mutex_unlock(&acpi_desc->init_mutex);
> cancel_delayed_work_sync(&acpi_desc->dwork);
>
> + bus_dev = to_nvdimm_bus_dev(acpi_desc->nvdimm_bus);
> /*
> * Bounce the nvdimm bus lock to make sure any in-flight
> * acpi_nfit_ars_rescan() submissions have had a chance to
> @@ -3388,9 +3394,14 @@ static int acpi_nfit_probe(struct platform_device *pdev)
> sz - sizeof(struct acpi_table_nfit));
>
> if (rc)
> - return rc;
> + acpi_nfit_shutdown(acpi_desc);
>
> - return devm_add_action_or_reset(dev, acpi_nfit_shutdown, acpi_desc);
> + return rc;
> +}
> +
> +static void acpi_nfit_remove(struct platform_device *pdev)
> +{
> + acpi_nfit_shutdown(platform_get_drvdata(pdev));
> }
>
> static void acpi_nfit_update_notify(struct device *dev, acpi_handle handle)
> @@ -3474,6 +3485,7 @@ MODULE_DEVICE_TABLE(acpi, acpi_nfit_ids);
>
> static struct platform_driver acpi_nfit_driver = {
> .probe = acpi_nfit_probe,
> + .remove = acpi_nfit_remove,
> .driver = {
> .name = "acpi-nfit",
> .acpi_match_table = acpi_nfit_ids,
next prev parent reply other threads:[~2026-06-03 23:07 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-03 17:55 [PATCH v2 0/4] ACPI: NFIT: core: Fix multiple issues related to concurrency and cleanup Rafael J. Wysocki
2026-06-03 17:56 ` [PATCH v2 1/4] ACPI: NFIT: core: Fix possible NULL pointer dereference Rafael J. Wysocki
2026-06-03 22:33 ` Dave Jiang
2026-06-03 17:57 ` [PATCH v2 2/4] ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup Rafael J. Wysocki
2026-06-03 23:06 ` Dave Jiang [this message]
2026-06-03 17:57 ` [PATCH v2 3/4] ACPI: NFIT: core: Eliminate redundant local variable Rafael J. Wysocki
2026-06-03 23:07 ` Dave Jiang
2026-06-03 17:58 ` [PATCH v2 4/4] ACPI: NFIT: core: Fix possible deadlock and missing notifications Rafael J. Wysocki
2026-06-03 23:10 ` Dave Jiang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f3fff3f8-89e3-496f-9af5-868ef329d137@intel.com \
--to=dave.jiang@intel.com \
--cc=alison.schofield@intel.com \
--cc=chenxiang66@hisilicon.com \
--cc=djbw@kernel.org \
--cc=linux-acpi@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nvdimm@lists.linux.dev \
--cc=rafael@kernel.org \
--cc=vishal.l.verma@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®