This is a note to let you know that I've just added the patch titled interconnect: exynos: fix registration race to the 6.1-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: interconnect-exynos-fix-registration-race.patch and it can be found in the queue-6.1 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From c9e46ca612cfbb0cf890f7ae7389b742e90efe64 Mon Sep 17 00:00:00 2001 From: Johan Hovold <johan+linaro@xxxxxxxxxx> Date: Mon, 6 Mar 2023 08:56:43 +0100 Subject: interconnect: exynos: fix registration race From: Johan Hovold <johan+linaro@xxxxxxxxxx> commit c9e46ca612cfbb0cf890f7ae7389b742e90efe64 upstream. The current interconnect provider registration interface is inherently racy as nodes are not added until the after adding the provider. This can specifically cause racing DT lookups to trigger a NULL-pointer deference when either a NULL pointer or not fully initialised node is returned from exynos_generic_icc_xlate(). Switch to using the new API where the provider is not registered until after it has been fully initialised. Fixes: 2f95b9d5cf0b ("interconnect: Add generic interconnect driver for Exynos SoCs") Cc: stable@xxxxxxxxxxxxxxx # 5.11 Cc: Sylwester Nawrocki <s.nawrocki@xxxxxxxxxxx> Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@xxxxxxxxxx> Signed-off-by: Johan Hovold <johan+linaro@xxxxxxxxxx> Link: https://lore.kernel.org/r/20230306075651.2449-16-johan+linaro@xxxxxxxxxx Signed-off-by: Georgi Djakov <djakov@xxxxxxxxxx> Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- drivers/interconnect/samsung/exynos.c | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) --- a/drivers/interconnect/samsung/exynos.c +++ b/drivers/interconnect/samsung/exynos.c @@ -98,12 +98,13 @@ static int exynos_generic_icc_remove(str struct exynos_icc_priv *priv = platform_get_drvdata(pdev); struct icc_node *parent_node, *node = priv->node; + icc_provider_deregister(&priv->provider); + parent_node = exynos_icc_get_parent(priv->dev->parent->of_node); if (parent_node && !IS_ERR(parent_node)) icc_link_destroy(node, parent_node); icc_nodes_remove(&priv->provider); - icc_provider_del(&priv->provider); return 0; } @@ -132,15 +133,11 @@ static int exynos_generic_icc_probe(stru provider->inter_set = true; provider->data = priv; - ret = icc_provider_add(provider); - if (ret < 0) - return ret; + icc_provider_init(provider); icc_node = icc_node_create(pdev->id); - if (IS_ERR(icc_node)) { - ret = PTR_ERR(icc_node); - goto err_prov_del; - } + if (IS_ERR(icc_node)) + return PTR_ERR(icc_node); priv->node = icc_node; icc_node->name = devm_kasprintf(&pdev->dev, GFP_KERNEL, "%pOFn", @@ -171,14 +168,17 @@ static int exynos_generic_icc_probe(stru goto err_pmqos_del; } + ret = icc_provider_register(provider); + if (ret < 0) + goto err_pmqos_del; + return 0; err_pmqos_del: dev_pm_qos_remove_request(&priv->qos_req); err_node_del: icc_nodes_remove(provider); -err_prov_del: - icc_provider_del(provider); + return ret; } Patches currently in stable-queue which might be from johan+linaro@xxxxxxxxxx are queue-6.1/memory-tegra20-emc-fix-interconnect-registration-race.patch queue-6.1/memory-tegra124-emc-fix-interconnect-registration-race.patch queue-6.1/serial-qcom-geni-fix-console-shutdown-hang.patch queue-6.1/interconnect-exynos-fix-registration-race.patch queue-6.1/interconnect-imx-fix-registration-race.patch queue-6.1/memory-tegra30-emc-fix-interconnect-registration-race.patch queue-6.1/interconnect-qcom-msm8974-fix-registration-race.patch queue-6.1/memory-tegra-fix-interconnect-registration-race.patch queue-6.1/interconnect-qcom-rpm-fix-probe-child-node-error-handling.patch queue-6.1/interconnect-qcom-rpm-fix-registration-race.patch queue-6.1/interconnect-fix-provider-registration-api.patch queue-6.1/interconnect-fix-icc_provider_del-error-handling.patch queue-6.1/interconnect-qcom-rpmh-fix-registration-race.patch queue-6.1/interconnect-fix-mem-leak-when-freeing-nodes.patch queue-6.1/interconnect-qcom-rpmh-fix-probe-child-node-error-handling.patch queue-6.1/interconnect-exynos-fix-node-leak-in-probe-pm-qos-error-path.patch queue-6.1/interconnect-qcom-osm-l3-fix-registration-race.patch