Received: by 2002:a05:6a10:a0d1:0:0:0:0 with SMTP id j17csp2631137pxa; Mon, 17 Aug 2020 14:57:15 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxiwdatVYyY5oq4n7HBWXVQc21LmyD+bMuD/LiQEkRk964RiUF/qT/LjOM7xj2KMWSc2Byb X-Received: by 2002:aa7:d291:: with SMTP id w17mr17378963edq.257.1597701434955; Mon, 17 Aug 2020 14:57:14 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1597701434; cv=none; d=google.com; s=arc-20160816; b=YMiTfamYlXavfp/RVFp1gZjrJ+feRMeFEkauLv8wTortATFj03QxLIjfR6OaT5PS1H 6/lafvwdNXMWr3VbK79aYPNayVYsNKKllvcsDveSOiPHFZFsVUW7t66nRhPDRE3pvKXt XPayOR+erxUUv9gAKgy35eSVSxbqN9uIVdwK9tss7uYO+uThtu0RncIR2+vuQi/w+mNI 20sJiiA8ajlKvnj4qNlr/k3OWZa1IzTmwDh2ejWNtwAAq3ROUpAnOf/OTaOM6dNhUbzU FL1GI316sKqPhz8NDtusuITzu4Hnh8feS4jPCoERk1WAMr1E3f+YFYAaTl44jiPkSyO8 5CXw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=2R4iSqD5pydvQw+YhZwelsMmORYcMxXgh8yhMdFrEo0=; b=CPtc1ko28lG+4LsSJHZXPDGR1XNPyj/3MUOLlqpfQ5t8UKGgj04G58O/kDGs4V5TjS 5cOmwYvGUMFjcyiBJGEZDlGPJi1IVz4yq9hkeTbGr8ZIkLAqGVYl2QZPR4NyJ3AUs3yH GiVISOUncCjCSjQyA3X3twx+Snz4X7TdcZc86UaDIbMiX5Tn+OpMBOiz30RLaEJbHpJF m3h7UJTM72a9lkswyL8iaezi/LwlW9DbBeRzHvWkHyPPlIZCH6kAyIF2vmxd9a02AABW ytijnbfS++D9y+lIZrnbc6pelLjerIa+LCVbP2pVy7BqXhyWnSa2JG5Pt6tnSsEDaAkI V1hg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=1yCYbC+J; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id i21si12017061eje.143.2020.08.17.14.56.51; Mon, 17 Aug 2020 14:57:14 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=1yCYbC+J; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1730037AbgHQPcK (ORCPT + 99 others); Mon, 17 Aug 2020 11:32:10 -0400 Received: from mail.kernel.org ([198.145.29.99]:46944 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1730082AbgHQP3P (ORCPT ); Mon, 17 Aug 2020 11:29:15 -0400 Received: from localhost (83-86-89-107.cable.dynamic.v4.ziggo.nl [83.86.89.107]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id DD8A823A9B; Mon, 17 Aug 2020 15:29:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1597678153; bh=w5U96Fw6mjrn3JpYW7hRBEbu4JgEbS0Dkmw6fue0zYU=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=1yCYbC+J9WK3kOhzfac+bmy+2wNi0RZr0HdpyJJY5A17FXp2jHlcHt0+aiIRNLfFi XcbUNMPMtMldOjUkjGv9V2YAIinR2J9XAjBfbUy0m1BFR+d+l+QrZ9VvcDXWib439n ue88nbXR+E2JXxcs0FPo6jIqOn3dGAUmS/jZ54RA= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Naresh Kamboju , kernel test robot , "Rafael J. Wysocki" , Heikki Krogerus , "Rafael J. Wysocki" , Sasha Levin Subject: [PATCH 5.8 219/464] kobject: Avoid premature parent object freeing in kobject_cleanup() Date: Mon, 17 Aug 2020 17:12:52 +0200 Message-Id: <20200817143844.294781668@linuxfoundation.org> X-Mailer: git-send-email 2.28.0 In-Reply-To: <20200817143833.737102804@linuxfoundation.org> References: <20200817143833.737102804@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Heikki Krogerus [ Upstream commit 079ad2fb4bf9eba8a0aaab014b49705cd7f07c66 ] If kobject_del() is invoked by kobject_cleanup() to delete the target kobject, it may cause its parent kobject to be freed before invoking the target kobject's ->release() method, which effectively means freeing the parent before dealing with the child entirely. That is confusing at best and it may also lead to functional issues if the callers of kobject_cleanup() are not careful enough about the order in which these calls are made, so avoid the problem by making kobject_cleanup() drop the last reference to the target kobject's parent at the end, after invoking the target kobject's ->release() method. [ rjw: Rewrite the subject and changelog, make kobject_cleanup() drop the parent reference only when __kobject_del() has been called. ] Reported-by: Naresh Kamboju Reported-by: kernel test robot Fixes: 7589238a8cf3 ("Revert "software node: Simplify software_node_release() function"") Suggested-by: Rafael J. Wysocki Signed-off-by: Heikki Krogerus Signed-off-by: Rafael J. Wysocki Link: https://lore.kernel.org/r/1908555.IiAGLGrh1Z@kreacher Signed-off-by: Greg Kroah-Hartman Signed-off-by: Sasha Levin --- lib/kobject.c | 33 +++++++++++++++++++++++---------- 1 file changed, 23 insertions(+), 10 deletions(-) diff --git a/lib/kobject.c b/lib/kobject.c index 1e4b7382a88ed..3afb939f2a1cc 100644 --- a/lib/kobject.c +++ b/lib/kobject.c @@ -599,14 +599,7 @@ int kobject_move(struct kobject *kobj, struct kobject *new_parent) } EXPORT_SYMBOL_GPL(kobject_move); -/** - * kobject_del() - Unlink kobject from hierarchy. - * @kobj: object. - * - * This is the function that should be called to delete an object - * successfully added via kobject_add(). - */ -void kobject_del(struct kobject *kobj) +static void __kobject_del(struct kobject *kobj) { struct kernfs_node *sd; const struct kobj_type *ktype; @@ -632,9 +625,23 @@ void kobject_del(struct kobject *kobj) kobj->state_in_sysfs = 0; kobj_kset_leave(kobj); - kobject_put(kobj->parent); kobj->parent = NULL; } + +/** + * kobject_del() - Unlink kobject from hierarchy. + * @kobj: object. + * + * This is the function that should be called to delete an object + * successfully added via kobject_add(). + */ +void kobject_del(struct kobject *kobj) +{ + struct kobject *parent = kobj->parent; + + __kobject_del(kobj); + kobject_put(parent); +} EXPORT_SYMBOL(kobject_del); /** @@ -670,6 +677,7 @@ EXPORT_SYMBOL(kobject_get_unless_zero); */ static void kobject_cleanup(struct kobject *kobj) { + struct kobject *parent = kobj->parent; struct kobj_type *t = get_ktype(kobj); const char *name = kobj->name; @@ -684,7 +692,10 @@ static void kobject_cleanup(struct kobject *kobj) if (kobj->state_in_sysfs) { pr_debug("kobject: '%s' (%p): auto cleanup kobject_del\n", kobject_name(kobj), kobj); - kobject_del(kobj); + __kobject_del(kobj); + } else { + /* avoid dropping the parent reference unnecessarily */ + parent = NULL; } if (t && t->release) { @@ -698,6 +709,8 @@ static void kobject_cleanup(struct kobject *kobj) pr_debug("kobject: '%s': free name\n", name); kfree_const(name); } + + kobject_put(parent); } #ifdef CONFIG_DEBUG_KOBJECT_RELEASE -- 2.25.1