[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <2025061838-frustrate-operative-bd34@gregkh>
Date: Wed, 18 Jun 2025 09:44:56 +0200
From: Greg KH <gregkh@...uxfoundation.org>
To: Krzysztof Kozlowski <krzysztof.kozlowski@...aro.org>
Cc: Krzysztof Kozlowski <krzk@...nel.org>,
"David S. Miller" <davem@...emloft.net>,
Eric Dumazet <edumazet@...gle.com>,
Jakub Kicinski <kuba@...nel.org>, Paolo Abeni <pabeni@...hat.com>,
Simon Horman <horms@...nel.org>,
Vincent Cuissard <cuissard@...vell.com>,
Samuel Ortiz <sameo@...ux.intel.com>, netdev@...r.kernel.org,
linux-kernel@...r.kernel.org,
Linus Torvalds <torvalds@...uxfoundation.org>,
stable@...r.kernel.org
Subject: Re: [PATCH] NFC: nci: uart: Set tty->disc_data only in success path
On Wed, Jun 18, 2025 at 09:36:50AM +0200, Krzysztof Kozlowski wrote:
> Setting tty->disc_data before opening the NCI device means we need to
> clean it up on error paths. This also opens some short window if device
> starts sending data, even before NCIUARTSETDRIVER IOCTL succeeded
> (broken hardware?). Close the window by exposing tty->disc_data only on
> the success path, when opening of the NCI device and try_module_get()
> succeeds.
>
> The code differs in error path in one aspect: tty->disc_data won't be
> ever assigned thus NULL-ified. This however should not be relevant
> difference, because of "tty->disc_data=NULL" in nci_uart_tty_open().
>
> Cc: Greg KH <gregkh@...uxfoundation.org>
> Cc: Linus Torvalds <torvalds@...uxfoundation.org>
> Cc: Paolo Abeni <pabeni@...hat.com>
> Cc: Jakub Kicinski <kuba@...nel.org>
> Fixes: 9961127d4bce ("NFC: nci: add generic uart support")
> Cc: <stable@...r.kernel.org>
> Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@...aro.org>
> ---
> net/nfc/nci/uart.c | 8 ++++----
> 1 file changed, 4 insertions(+), 4 deletions(-)
>
> diff --git a/net/nfc/nci/uart.c b/net/nfc/nci/uart.c
> index ed1508a9e093..aab107727f18 100644
> --- a/net/nfc/nci/uart.c
> +++ b/net/nfc/nci/uart.c
> @@ -119,22 +119,22 @@ static int nci_uart_set_driver(struct tty_struct *tty, unsigned int driver)
>
> memcpy(nu, nci_uart_drivers[driver], sizeof(struct nci_uart));
> nu->tty = tty;
> - tty->disc_data = nu;
> skb_queue_head_init(&nu->tx_q);
> INIT_WORK(&nu->write_work, nci_uart_write_work);
> spin_lock_init(&nu->rx_lock);
>
> ret = nu->ops.open(nu);
> if (ret) {
> - tty->disc_data = NULL;
> kfree(nu);
> + return ret;
> } else if (!try_module_get(nu->owner)) {
> nu->ops.close(nu);
> - tty->disc_data = NULL;
> kfree(nu);
> return -ENOENT;
> }
> - return ret;
> + tty->disc_data = nu;
> +
> + return 0;
> }
Looks good, thanks for cleaning this up:
Reviewed-by: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
Powered by blists - more mailing lists