diff options
| author | Fedor Pchelkin <pchelkin@ispras.ru> | 2026-08-31 10:58:09 +0300 |
|---|---|---|
| committer | Mika Westerberg <mika.westerberg@linux.intel.com> | 2026-09-02 09:07:46 +0200 |
| commit | 4310c6b8e75d6a47f7548e5948fbe6318aa4440a (patch) | |
| tree | 0032b584d8e218681a48126eb91f57091c351b83 /usr/include | |
| download | linux-stable-4310c6b8e75d6a47f7548e5948fbe6318aa4440a.tar.gz linux-stable-4310c6b8e75d6a47f7548e5948fbe6318aa4440a.zip | |
thunderbolt: Fix NULL dereference in tb_remove_work()grafted
There is a slight race between tb_remove_work() and tb_domain_remove()
which leads to dereferencing a NULL tb->root_switch pointer inside
tb_free_unplugged_xdomains():
Thread A Thread B
tb_remove_work()
tb_domain_remove()
mutex_lock(&tb->lock)
tb_stop()
/* doesn't cancel a running callback */
cancel_delayed_work(&tcm->remove_work)
...
tb_switch_remove(tb->root_switch)
tb->root_switch = NULL
mutex_unlock(&tb->lock)
mutex_lock(&tb->lock)
...
/* without checking ->root_switch */
tb_free_unplugged_xdomains(tb->root_switch)
mutex_unlock(&tb->lock)
Commit a8937f35cf39 ("thunderbolt: Remove XDomain from the bus without
holding tb->lock") doesn't seem right to move tb_free_unplugged_xdomains()
out of the &tb->lock section and the check for tb->root_switch, in
particular. It states:
For this reason separate removing the XDomain from the topology data
structures (where we need the lock) from unregistering the device from
the bus (where remove callbacks of the drivers are being called).
tb_free_unplugged_xdomains() belongs to the former group of functions
requiring the lock. And it also calls tb_xdomain_remove() which should
only be called with &tb->lock held.
Found by Linux Verification Center (linuxtesting.org) with Svace static
analysis tool.
Fixes: a8937f35cf39 ("thunderbolt: Remove XDomain from the bus without holding tb->lock")
Cc: stable@vger.kernel.org
Signed-off-by: Fedor Pchelkin <pchelkin@ispras.ru>
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Diffstat (limited to 'usr/include')
| -rw-r--r-- | usr/include/.gitignore | 2 | ||||
| -rw-r--r-- | usr/include/Makefile | 188 | ||||
| -rwxr-xr-x | usr/include/headers_check.pl | 96 |
3 files changed, 286 insertions, 0 deletions
diff --git a/usr/include/.gitignore b/usr/include/.gitignore new file mode 100644 index 000000000..17b0ba1bd --- /dev/null +++ b/usr/include/.gitignore @@ -0,0 +1,2 @@ +# SPDX-License-Identifier: GPL-2.0-only +/*/ diff --git a/usr/include/Makefile b/usr/include/Makefile new file mode 100644 index 000000000..ee69dd9d9 --- /dev/null +++ b/usr/include/Makefile @@ -0,0 +1,188 @@ +# SPDX-License-Identifier: GPL-2.0-only + +# Unlike the kernel space, exported headers are written in standard C. +# - Forbid C++ style comments +# - Use '__inline__', '__asm__' instead of 'inline', 'asm' +# +# -std=c90 (equivalent to -ansi) catches the violation of those. +# We cannot go as far as adding -Wpedantic since it emits too many warnings. +UAPI_CFLAGS := -std=c90 -Werror=implicit-function-declaration +UAPI_ARCH := $(or $(HEADER_ARCH),$(SRCARCH)) + +override c_flags = $(KBUILD_USERCFLAGS) $(UAPI_CFLAGS) -Wp,-MMD,$(depfile) +cxx_flags = $(filter-out -Wmissing-prototypes -Wstrict-prototypes -std=%, $(KBUILD_USERCFLAGS)) -std=c++98 + +# The following are excluded for now because they fail to build. +# +# Do not add a new header to the blacklist without legitimate reason. +# Please consider to fix the header first. +# +# Sorted alphabetically. +no-header-test += asm/ucontext.h +no-header-test += drm/vmwgfx_drm.h +no-header-test += linux/am437x-vpfe.h +no-header-test += linux/coda.h +no-header-test += linux/cyclades.h +no-header-test += linux/errqueue.h +no-header-test += linux/hdlc/ioctl.h +no-header-test += linux/ivtv.h +no-header-test += linux/matroxfb.h +no-header-test += linux/omap3isp.h +no-header-test += linux/omapfb.h +no-header-test += linux/patchkey.h +no-header-test += linux/phonet.h +no-header-test += linux/sctp.h +no-header-test += linux/sysctl.h +no-header-test += linux/usb/audio.h +no-header-test += linux/v4l2-mediabus.h +no-header-test += linux/v4l2-subdev.h +no-header-test += linux/videodev2.h +no-header-test += linux/vm_sockets.h +no-header-test += sound/asequencer.h +no-header-test += sound/asoc.h +no-header-test += sound/asound.h +no-header-test += sound/compress_offload.h +no-header-test += sound/emu10k1.h +no-header-test += sound/sfnt_info.h +no-header-test += xen/evtchn.h +no-header-test += xen/gntdev.h +no-header-test += xen/privcmd.h + +# More headers are broken in some architectures + +ifneq ($(filter arc openrisc xtensa nios2, $(UAPI_ARCH)),) +no-header-test += linux/bpf_perf_event.h +endif + +ifeq ($(UAPI_ARCH),sparc) +no-header-test += asm/uctx.h +no-header-test += asm/fbio.h +endif + +# asm-generic/*.h is used by asm/*.h, and should not be included directly +no-header-test += asm-generic/% + +# The following are not compatible with C++. +# +# Do not add a new header to the list without legitimate reason. +# Please consider to fix the header first. +# +# Sorted alphabetically. +no-header-test-cxx += linux/auto_dev-ioctl.h +no-header-test-cxx += linux/map_to_14segment.h +no-header-test-cxx += linux/map_to_7segment.h +no-header-test-cxx += linux/netfilter/xt_sctp.h +no-header-test-cxx += linux/target_core_user.h +no-header-test-cxx += linux/vhost.h +no-header-test-cxx += linux/vhost_types.h +no-header-test-cxx += linux/virtio_net.h +no-header-test-cxx += linux/virtio_ring.h +no-header-test-cxx += scsi/fc/fc_els.h + +ifeq ($(UAPI_ARCH),x86) +no-header-test-cxx += asm/elf.h +endif + +# The following are using libc header and types. +# +# Do not add a new header to the list without legitimate reason. +# Please consider to fix the header first. +# +# Sorted alphabetically. +uses-libc += linux/a.out.h +uses-libc += linux/atmbr2684.h +uses-libc += linux/auto_dev-ioctl.h +uses-libc += linux/auto_fs.h +uses-libc += linux/auto_fs4.h +uses-libc += linux/btrfs_tree.h +uses-libc += linux/cec-funcs.h +uses-libc += linux/cec.h +uses-libc += linux/dvb/dmx.h +uses-libc += linux/dvb/video.h +uses-libc += linux/ethtool.h +uses-libc += linux/ethtool_netlink.h +uses-libc += linux/fuse.h +uses-libc += linux/gsmmux.h +uses-libc += linux/icmp.h +uses-libc += linux/idxd.h +uses-libc += linux/if.h +uses-libc += linux/if_arp.h +uses-libc += linux/if_bonding.h +uses-libc += linux/if_pppox.h +uses-libc += linux/if_tunnel.h +uses-libc += linux/input.h +uses-libc += linux/ip6_tunnel.h +uses-libc += linux/joystick.h +uses-libc += linux/llc.h +uses-libc += linux/mctp.h +uses-libc += linux/mdio.h +uses-libc += linux/mii.h +uses-libc += linux/mptcp.h +uses-libc += linux/netdevice.h +uses-libc += linux/netfilter/xt_RATEEST.h +uses-libc += linux/netfilter/xt_hashlimit.h +uses-libc += linux/netfilter/xt_physdev.h +uses-libc += linux/netfilter/xt_rateest.h +uses-libc += linux/netfilter_arp/arp_tables.h +uses-libc += linux/netfilter_arp/arpt_mangle.h +uses-libc += linux/netfilter_bridge.h +uses-libc += linux/netfilter_bridge/ebtables.h +uses-libc += linux/netfilter_ipv4.h +uses-libc += linux/netfilter_ipv4/ip_tables.h +uses-libc += linux/netfilter_ipv6.h +uses-libc += linux/netfilter_ipv6/ip6_tables.h +uses-libc += linux/route.h +uses-libc += linux/shm.h +uses-libc += linux/soundcard.h +uses-libc += linux/string.h +uses-libc += linux/tipc_config.h +uses-libc += linux/uhid.h +uses-libc += linux/uinput.h +uses-libc += linux/vhost.h +uses-libc += linux/vhost_types.h +uses-libc += linux/virtio_ring.h +uses-libc += linux/wireless.h +uses-libc += regulator/regulator.h +uses-libc += scsi/fc/fc_els.h + +ifeq ($(UAPI_ARCH),hexagon) +uses-libc += asm/sigcontext.h +endif + +ifeq ($(UAPI_ARCH),nios2) +uses-libc += asm/ptrace.h +endif + +ifeq ($(UAPI_ARCH),s390) +uses-libc += asm/chpid.h +uses-libc += asm/chsc.h +endif + +always-y := $(patsubst $(obj)/%.h,%.hdrtest, $(shell find $(obj) -name '*.h' 2>/dev/null)) + +# $(cc-option) forces '-x c' which breaks '-x c++' detection. +cc-can-compile-cxx := $(call try-run,$(CC) $(CLANG_FLAGS) -c -x c++ /dev/null -o "$$TMP", 1) + +target-libc = $(filter $(uses-libc), $*.h) +target-can-compile = $(filter-out $(no-header-test), $*.h) +target-can-compile-cxx = $(and $(cc-can-compile-cxx), $(target-can-compile), $(filter-out $(no-header-test-cxx), $*.h)) + +hdrtest-flags = -fsyntax-only -Werror \ + -nostdinc -I $(obj) $(if $(target-libc), -I $(srctree)/usr/dummy-include) + +# Include the header twice to detect missing include guard. +quiet_cmd_hdrtest = HDRTEST $< + cmd_hdrtest = \ + $(CC) $(c_flags) $(hdrtest-flags) -x c /dev/null \ + $(if $(target-can-compile), -include $< -include $<); \ + $(if $(target-can-compile-cxx), \ + $(CC) $(cxx_flags) $(hdrtest-flags) -x c++ /dev/null -include $<;) \ + $(PERL) $(src)/headers_check.pl $(obj) $<; \ + touch $@ + +$(obj)/%.hdrtest: $(obj)/%.h $(src)/headers_check.pl FORCE + $(call if_changed_dep,hdrtest) + +# Since GNU Make 4.3, $(patsubst $(obj)/%/,%,$(wildcard $(obj)/*/)) works. +# To support older Make versions, use a somewhat tedious way. +clean-files += $(filter-out Makefile headers_check.pl, $(notdir $(wildcard $(obj)/*))) diff --git a/usr/include/headers_check.pl b/usr/include/headers_check.pl new file mode 100755 index 000000000..6cd6eb652 --- /dev/null +++ b/usr/include/headers_check.pl @@ -0,0 +1,96 @@ +#!/usr/bin/env perl +# SPDX-License-Identifier: GPL-2.0 +# +# headers_check.pl execute a number of trivial consistency checks +# +# Usage: headers_check.pl dir [files...] +# dir: dir to look for included files +# files: list of files to check +# +# The script reads the supplied files line by line and: +# +# 1) for each include statement it checks if the +# included file actually exists. +# Only include files located in asm* and linux* are checked. +# The rest are assumed to be system include files. +# +# 2) It is checked that prototypes does not use "extern" +# +# 3) Check for leaked CONFIG_ symbols + +use warnings; +use strict; +use File::Basename; + +my ($dir, @files) = @ARGV; + +my $ret = 0; +my $line; +my $lineno = 0; +my $filename; + +foreach my $file (@files) { + $filename = $file; + + open(my $fh, '<', $filename) + or die "$filename: $!\n"; + $lineno = 0; + while ($line = <$fh>) { + $lineno++; + &check_include(); + &check_asm_types(); + &check_declarations(); + } + close $fh; +} +exit $ret; + +sub check_include +{ + if ($line =~ m/^\s*#\s*include\s+<((asm|linux).*)>/) { + my $inc = $1; + my $found; + $found = stat($dir . "/" . $inc); + if (!$found) { + printf STDERR "$filename:$lineno: included file '$inc' is not exported\n"; + $ret = 1; + } + } +} + +sub check_declarations +{ + # soundcard.h is what it is + if ($line =~ m/^void seqbuf_dump\(void\);/) { + return; + } + # drm headers are being C++ friendly + if ($line =~ m/^extern "C"/) { + return; + } + if ($line =~ m/^(\s*extern|unsigned|char|short|int|long|void)\b/) { + printf STDERR "$filename:$lineno: " . + "userspace cannot reference function or " . + "variable defined in the kernel\n"; + $ret = 1; + } +} + +my $linux_asm_types; +sub check_asm_types +{ + if ($filename =~ /types.h|int-l64.h|int-ll64.h/o) { + return; + } + if ($lineno == 1) { + $linux_asm_types = 0; + } elsif ($linux_asm_types >= 1) { + return; + } + if ($line =~ m/^\s*#\s*include\s+<asm\/types.h>/) { + $linux_asm_types = 1; + printf STDERR "$filename:$lineno: " . + "include of <linux/types.h> is preferred over <asm/types.h>\n"; + $ret = 1; + } +} |
