[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAAo+4rVpp7g2hd+T6cx4qjahrgBUa3SXabYD7u5=M2yd93wnTQ@mail.gmail.com>
Date: Tue, 10 Feb 2026 20:30:48 +0800
From: Chengfeng Ye <dg573847474@...il.com>
To: Lee Trager <lee@...ger.us>
Cc: kernel-team@...a.com, andrew+netdev@...n.ch, davem@...emloft.net,
edumazet@...gle.com, pabeni@...hat.com, jacob.e.keller@...el.com,
horms@...nel.org, "alexander.duyck@...il.com" <alexander.duyck@...il.com>, netdev@...r.kernel.org,
linux-kernel@...r.kernel.org
Subject: Re: [PATCH] fbnic: close fw_log race between users and teardown
> > Concurrent teardown in
> > fbnic_fw_log_free() could clear and free the log buffer after the check
> > because there is no proper synchronization, leading to list traversal or
> > buffer access on freed memory.
>
> fbnic_fw_log_free() is only called when the driver is removed, after
> DebugFS has been disabled. Before freeing the buffer the driver sends an
> explicit message to firmware to stop sending new message.
>
Yes, the more noteworthy case is that an in-flight IRQ already starts
in response to one firmware message previously sent before stopping
the firmware.
Thanks,
Chengfeng
Powered by blists - more mailing lists