Received: by 2002:ac0:8845:0:0:0:0:0 with SMTP id g63csp350046img; Tue, 26 Feb 2019 00:54:13 -0800 (PST) X-Google-Smtp-Source: AHgI3IZpinqxtkBkSTcJijRFP6gmpGWUtFjpf4LF4Yj9wzRAYI3x+O83kO4F26mNrwyb7r4ihwfS X-Received: by 2002:a17:902:1101:: with SMTP id d1mr24258057pla.19.1551171253555; Tue, 26 Feb 2019 00:54:13 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1551171253; cv=none; d=google.com; s=arc-20160816; b=IxvJw50DXIAKfMKyW4FeVB02uocOh1pXGwm+FzydpBgcFNbbahUpY4052tGSaFoJJf 3/zH3so92tEXvgVbvRp5XXANPVSAqi4AN+Has7m06smlrIhi8vb1n+i5274NU5NNqKfC BnMLIcpZ5uOMfus2n8VwRV+MN/Pxtq+eQ715d73xLpxBq2/Bn3Vk7vROEdRmKAzG++ZQ v7DvIUZTupyhtYJulMZuD3KPbmqPWIadX/IVJwUDPbq9QAY05rr+j8fW2DoM3h5kWBxT B0ohspBPQO6HxpIeoS9+Utcm3GayLiof/tyMSvoKfoLWRASCGLjT6v+OT/LUqNUvc1mo JTGw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:to:references:message-id :content-transfer-encoding:cc:date:in-reply-to:from:subject :mime-version; bh=r6U8v8rlZ2TCH2ZYGTSqp1qv4Q7eP/IjRGjhNOC86OE=; b=GXNuQ0JN/nA+SFovk74yCUcZ69ofOPejzb//vyi2kJaCYXPNw4SMnVL5urt7hUD3y/ 9WMm4Mu7FZw8gXc6l+dGPMpQ+oR130+AW3LCL79d2rfBznXpK/F2NgMKIUzGjINe5xKu KVdhJMyCYeH9Z/4LLgAnNtuH4AR1LRp8XDn3OcZB1Bq+fDnmMyo/Qq7NkbTIeCnlWXvE mnYfaaZgOadH2RJWqPJ1VuPkyX1FUVVLKFCFDJllOzN4hOPMLsHtb3T2bZEeSFMz8jxG vai/VTy3/8AfvvnR2N4x0e0//Zu3+0tDcXLhma0UZuCIomnxs82Mp9ZPI5J2DE9gQJh3 wU6Q== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id k22si11733996pfi.256.2019.02.26.00.53.58; Tue, 26 Feb 2019 00:54:13 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727245AbfBZIxb convert rfc822-to-8bit (ORCPT + 99 others); Tue, 26 Feb 2019 03:53:31 -0500 Received: from coyote.holtmann.net ([212.227.132.17]:45547 "EHLO mail.holtmann.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725977AbfBZIxa (ORCPT ); Tue, 26 Feb 2019 03:53:30 -0500 Received: from marcel-macpro.fritz.box (p4FF9F361.dip0.t-ipconnect.de [79.249.243.97]) by mail.holtmann.org (Postfix) with ESMTPSA id 6021ECF2A3; Tue, 26 Feb 2019 10:01:23 +0100 (CET) Content-Type: text/plain; charset=utf-8 Mime-Version: 1.0 (Mac OS X Mail 12.2 \(3445.102.3\)) Subject: Re: [PATCH] Bluetooth: hci_bcm: fix double-free irq on removal From: Marcel Holtmann In-Reply-To: <20190225195010.32277-1-andreas@kemnade.info> Date: Tue, 26 Feb 2019 09:53:27 +0100 Cc: Johan Hedberg , linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, josua.mayer@jm0.eu Content-Transfer-Encoding: 8BIT Message-Id: References: <20190225195010.32277-1-andreas@kemnade.info> To: Andreas Kemnade X-Mailer: Apple Mail (2.3445.102.3) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi Andreas, > after rmmod hci_uart a warning about doubly freed > interrupts appears, so do it only once. Instead disable it. > It is already implicitely freed by the devm framework. > > [ 230.782948] ------------[ cut here ]------------ > [ 230.787708] WARNING: CPU: 0 PID: 2715 at kernel/irq/devres.c:146 devm_free_irq+0x59/0x60 > [ 230.798345] Modules linked in: usb_f_ecm u_ether libcomposite spidev hidp rfcomm hci_uart(-) btbcm bluetooth ecdh_generic brcmfmac brcmutil cfg80211 rfkill evdev sun8i_codec_analog sun8i_adda_pr_regmap snd_soc_core snd_pcm_dmaengine pwrseq_simple snd_pcm snd_timer snd soundcore hih6130 cpufreq_dt uio_pdrv_genirq gpio_keys uio thermal_sys > [ 230.828282] CPU: 0 PID: 2715 Comm: rmmod Not tainted 5.0.0-rc8+ #14 > [ 230.834540] Hardware name: Allwinner sun8i Family > [ 230.839266] [] (unwind_backtrace) from [] (show_stack+0x11/0x14) > [ 230.847014] [] (show_stack) from [] (dump_stack+0x67/0x74) > [ 230.854240] [] (dump_stack) from [] (__warn+0xb9/0xcc) > [ 230.861115] [] (__warn) from [] (warn_slowpath_null+0x2f/0x34) > [ 230.868681] [] (warn_slowpath_null) from [] (devm_free_irq+0x59/0x60) > [ 230.876881] [] (devm_free_irq) from [] (bcm_close+0x35/0xa8 [hci_uart]) > [ 230.885264] [] (bcm_close [hci_uart]) from [] (hci_uart_unregister_device+0x33/0x3c [hci_uart]) > [ 230.895708] [] (hci_uart_unregister_device [hci_uart]) from [] (bcm_serdev_remove+0xf/0x10 [hci_uart]) > [ 230.906755] [] (bcm_serdev_remove [hci_uart]) from [] (serdev_drv_remove+0x13/0x20) > [ 230.916150] [] (serdev_drv_remove) from [] (device_release_driver_internal+0xf7/0x158) > [ 230.925799] [] (device_release_driver_internal) from [] (driver_detach+0x49/0x78) > [ 230.935013] [] (driver_detach) from [] (bus_remove_driver+0x31/0x70) > [ 230.943108] [] (bus_remove_driver) from [] (bcm_deinit+0x1b/0xcc4 [hci_uart]) > [ 230.951994] [] (bcm_deinit [hci_uart]) from [] (hci_uart_exit+0x1b/0x34 [hci_uart]) > [ 230.961389] [] (hci_uart_exit [hci_uart]) from [] (sys_delete_module+0x135/0x178) > [ 230.970603] [] (sys_delete_module) from [] (ret_fast_syscall+0x1/0x62) > [ 230.978855] Exception stack(0xd66b7fa8 to 0xd66b7ff0) > [ 230.983906] 7fa0: 00c3dd00 00000000 00c3dd3c 00000800 88297c00 88297c00 > [ 230.992078] 7fc0: 00c3dd00 00000000 bef05e82 00000081 bef05b88 00000001 bef05d7c 00000000 > [ 231.000245] 7fe0: 0045bf6c bef05b24 00441303 b6edab26 > [ 231.005332] ---[ end trace dc4caa46c945c790 ]--- > [ 231.009946] ------------[ cut here ]------------ > [ 231.014567] WARNING: CPU: 0 PID: 2715 at kernel/irq/manage.c:1600 __free_irq+0x83/0x20c > [ 231.025070] Trying to free already-free IRQ 92 > [ 231.029505] Modules linked in: usb_f_ecm u_ether libcomposite spidev hidp rfcomm hci_uart(-) btbcm bluetooth ecdh_generic brcmfmac brcmutil cfg80211 rfkill evdev sun8i_codec_analog sun8i_adda_pr_regmap snd_soc_core snd_pcm_dmaengine pwrseq_simple snd_pcm snd_timer snd soundcore hih6130 cpufreq_dt uio_pdrv_genirq gpio_keys uio thermal_sys > [ 231.059389] CPU: 0 PID: 2715 Comm: rmmod Tainted: G W 5.0.0-rc8+ #14 > [ 231.067032] Hardware name: Allwinner sun8i Family > [ 231.071740] [] (unwind_backtrace) from [] (show_stack+0x11/0x14) > [ 231.079481] [] (show_stack) from [] (dump_stack+0x67/0x74) > [ 231.086701] [] (dump_stack) from [] (__warn+0xb9/0xcc) > [ 231.093574] [] (__warn) from [] (warn_slowpath_fmt+0x33/0x48) > [ 231.101054] [] (warn_slowpath_fmt) from [] (__free_irq+0x83/0x20c) > [ 231.108966] [] (__free_irq) from [] (free_irq+0x27/0x5c) > [ 231.116012] [] (free_irq) from [] (devm_free_irq+0x3f/0x60) > [ 231.123326] [] (devm_free_irq) from [] (bcm_close+0x35/0xa8 [hci_uart]) > [ 231.131690] [] (bcm_close [hci_uart]) from [] (hci_uart_unregister_device+0x33/0x3c [hci_uart]) > [ 231.142133] [] (hci_uart_unregister_device [hci_uart]) from [] (bcm_serdev_remove+0xf/0x10 [hci_uart]) > [ 231.153174] [] (bcm_serdev_remove [hci_uart]) from [] (serdev_drv_remove+0x13/0x20) > [ 231.162562] [] (serdev_drv_remove) from [] (device_release_driver_internal+0xf7/0x158) > [ 231.172209] [] (device_release_driver_internal) from [] (driver_detach+0x49/0x78) > [ 231.181422] [] (driver_detach) from [] (bus_remove_driver+0x31/0x70) > [ 231.189517] [] (bus_remove_driver) from [] (bcm_deinit+0x1b/0xcc4 [hci_uart]) > [ 231.198399] [] (bcm_deinit [hci_uart]) from [] (hci_uart_exit+0x1b/0x34 [hci_uart]) > [ 231.207793] [] (hci_uart_exit [hci_uart]) from [] (sys_delete_module+0x135/0x178) > [ 231.217005] [] (sys_delete_module) from [] (ret_fast_syscall+0x1/0x62) > [ 231.225256] Exception stack(0xd66b7fa8 to 0xd66b7ff0) > [ 231.230305] 7fa0: 00c3dd00 00000000 00c3dd3c 00000800 88297c00 88297c00 > [ 231.238476] 7fc0: 00c3dd00 00000000 bef05e82 00000081 bef05b88 00000001 bef05d7c 00000000 > [ 231.246644] 7fe0: 0045bf6c bef05b24 00441303 b6edab26 > [ 231.251688] ---[ end trace dc4caa46c945c791 ]--- > > Signed-off-by: Andreas Kemnade > --- > drivers/bluetooth/hci_bcm.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/bluetooth/hci_bcm.c b/drivers/bluetooth/hci_bcm.c > index ddbe518c3e5b..97a8ba607d0c 100644 > --- a/drivers/bluetooth/hci_bcm.c > +++ b/drivers/bluetooth/hci_bcm.c > @@ -488,7 +488,7 @@ static int bcm_close(struct hci_uart *hu) > > if (bdev) { > if (IS_ENABLED(CONFIG_PM) && bdev->irq > 0) { > - devm_free_irq(bdev->dev, bdev->irq, bdev); > + disable_irq(bdev->irq); > device_init_wakeup(bdev->dev, false); > pm_runtime_disable(bdev->dev); > } this fix is too simplistic I think. If we don’t free it here, then subsequent calls to btattach will leave an IRQ around. Or driver unbind/rebind action might trigger this as well. Regards Marcel