Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp4557988imu; Tue, 29 Jan 2019 03:46:29 -0800 (PST) X-Google-Smtp-Source: ALg8bN77h3Oa1Hn7voCCRVAGuc2abG05CQZghScpo6OjMEtm/89RklRrf4BX03IPtys+UXv2sX3G X-Received: by 2002:a63:5d55:: with SMTP id o21mr22877698pgm.92.1548762389489; Tue, 29 Jan 2019 03:46:29 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1548762389; cv=none; d=google.com; s=arc-20160816; b=VsgpETGrk0J8TFZMVZCUmBCZooWkvtMJKB5GYDkHAzrlO7s/Ra7Zl6Iof7QZo56JWi Nqa4etLhyJDP+7/lTtOGHfQjcIR3jcos5b9aqtMYZ7Qry1U12RuEUoyKSBhkj/dmZJ4W owoRomLSGujxv7BYmskNcGWdoq0PdLgsmDakhdrfGlW95L2IHYgT0Jf3xUSaIMfEk5sS Pf0keaiUKKuD4V/BSNfx/bfskTX+0rcUeSViQcfEbrxorgUNYVm6CUtr2fSyRfj2BBDw BWcErog93mLotq7owfCKZ/4rZTV46FYblnSWnbce/ZoWWpl9Sy42xWkWArRZfdQ+IQ4y uYdw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=+FTHf64Mhun2hw0842mvwJqXpFL4PFzLBuaobnQFGec=; b=I6w+X8vg9hjJFSx64lT+QJ9km2/AQsiJpyGf+RCyX+F2QIwM1IQqz7paUBTXVZ+kHr +nNkVuHE3ux4t3zh+GQ2tWSKRmGuWAwkzYEVEuopIjpD1RU+IoYvBWcjbmsu1nl6uiG1 BExBKPaJqIKcEkkgvR7frSGq11b2nbGU+WJGKcQCydUZwSQz0rMNpUJ9gP5IS05WsMvj dFStIi6r1sHwhL66GMHq4ulpK1+hZvffGuyw+kmj+rXWN+SfapKGWYpcdVZS2mLSbWYP oBWq1w7PGK7A7e8k1+S/1IUg0lTnOgM4yKHpanNikED7ZacKEpzAHO0JiDUvkGR9RPHC lrZg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=GjqWwjmD; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id z4si7216968pgv.534.2019.01.29.03.46.14; Tue, 29 Jan 2019 03:46:29 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=GjqWwjmD; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1730002AbfA2LoY (ORCPT + 99 others); Tue, 29 Jan 2019 06:44:24 -0500 Received: from mail.kernel.org ([198.145.29.99]:34628 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729123AbfA2LoV (ORCPT ); Tue, 29 Jan 2019 06:44:21 -0500 Received: from localhost (5356596B.cm-6-7b.dynamic.ziggo.nl [83.86.89.107]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 689D721852; Tue, 29 Jan 2019 11:44:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1548762259; bh=L0jvKxNsXLsGfVl+P3cPRJSmSp5ADbAC7XvBmPqKNDQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=GjqWwjmD4i60Mk9j870GULj42wEl8G9hRdY8vZB6Iekq/Qlp2JQ4IktD9JMBm0vnp 5RIIljrRlSvggOMBZq3ibvZ73mjSONy7X6bEFzoOB99eDmHMVICrKIIS0TKzeA04iL FAN6DAzoA+al19DEfU26mj3K/lqk9uypRxEdQsZw= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Elie Roudninski , Remi Pommarel , Ulf Hansson Subject: [PATCH 4.19 045/103] mmc: meson-gx: Free irq in release() callback Date: Tue, 29 Jan 2019 12:35:22 +0100 Message-Id: <20190129113202.187680035@linuxfoundation.org> X-Mailer: git-send-email 2.20.1 In-Reply-To: <20190129113159.567154026@linuxfoundation.org> References: <20190129113159.567154026@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review X-Patchwork-Hint: ignore MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.19-stable review patch. If anyone has any objections, please let me know. ------------------ From: Remi Pommarel commit bb364890323cca6e43f13e86d190ebf34a7d8cea upstream. Because the irq was requested through device managed resources API (devm_request_threaded_irq()) it was freed after meson_mmc_remove() completion, thus after mmc_free_host() has reclaimed meson_host memory. As this irq is IRQF_SHARED, while using CONFIG_DEBUG_SHIRQ, its handler get called by free_irq(). So meson_mmc_irq() was called after the meson_host memory reclamation and was using invalid memory. We ended up with the following scenario: device_release_driver() meson_mmc_remove() mmc_free_host() /* Freeing host memory */ ... devres_release_all() devm_irq_release() __free_irq() meson_mmc_irq() /* Uses freed memory */ To avoid this, the irq is released in meson_mmc_remove() and in mseon_mmc_probe() error path before mmc_free_host() gets called. Reported-by: Elie Roudninski Signed-off-by: Remi Pommarel Cc: stable@vger.kernel.org Signed-off-by: Ulf Hansson Signed-off-by: Greg Kroah-Hartman --- drivers/mmc/host/meson-gx-mmc.c | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) --- a/drivers/mmc/host/meson-gx-mmc.c +++ b/drivers/mmc/host/meson-gx-mmc.c @@ -174,6 +174,8 @@ struct meson_host { struct sd_emmc_desc *descs; dma_addr_t descs_dma_addr; + int irq; + bool vqmmc_enabled; }; @@ -1181,7 +1183,7 @@ static int meson_mmc_probe(struct platfo struct resource *res; struct meson_host *host; struct mmc_host *mmc; - int ret, irq; + int ret; mmc = mmc_alloc_host(sizeof(struct meson_host), &pdev->dev); if (!mmc) @@ -1228,8 +1230,8 @@ static int meson_mmc_probe(struct platfo goto free_host; } - irq = platform_get_irq(pdev, 0); - if (irq <= 0) { + host->irq = platform_get_irq(pdev, 0); + if (host->irq <= 0) { dev_err(&pdev->dev, "failed to get interrupt resource.\n"); ret = -EINVAL; goto free_host; @@ -1283,9 +1285,8 @@ static int meson_mmc_probe(struct platfo writel(IRQ_CRC_ERR | IRQ_TIMEOUTS | IRQ_END_OF_CHAIN, host->regs + SD_EMMC_IRQ_EN); - ret = devm_request_threaded_irq(&pdev->dev, irq, meson_mmc_irq, - meson_mmc_irq_thread, IRQF_SHARED, - NULL, host); + ret = request_threaded_irq(host->irq, meson_mmc_irq, + meson_mmc_irq_thread, IRQF_SHARED, NULL, host); if (ret) goto err_init_clk; @@ -1303,7 +1304,7 @@ static int meson_mmc_probe(struct platfo if (host->bounce_buf == NULL) { dev_err(host->dev, "Unable to map allocate DMA bounce buffer.\n"); ret = -ENOMEM; - goto err_init_clk; + goto err_free_irq; } host->descs = dma_alloc_coherent(host->dev, SD_EMMC_DESC_BUF_LEN, @@ -1322,6 +1323,8 @@ static int meson_mmc_probe(struct platfo err_bounce_buf: dma_free_coherent(host->dev, host->bounce_buf_size, host->bounce_buf, host->bounce_dma_addr); +err_free_irq: + free_irq(host->irq, host); err_init_clk: clk_disable_unprepare(host->mmc_clk); err_core_clk: @@ -1339,6 +1342,7 @@ static int meson_mmc_remove(struct platf /* disable interrupts */ writel(0, host->regs + SD_EMMC_IRQ_EN); + free_irq(host->irq, host); dma_free_coherent(host->dev, SD_EMMC_DESC_BUF_LEN, host->descs, host->descs_dma_addr);