mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-27 21:03:31 -04:00
dibs: initialise dibs->lock in dibs_dev_alloc()
dibs->lock is initialised by dibs_dev_add(), but a dibs device can
already take interrupts before that call: ism_probe() runs
ism_dev_init(), and hence request_irq(), before it calls
dibs_dev_add(). No client can have registered a dmb at that point, so
no dmb interrupt can occur, but a GID event interrupt can, and
ism_handle_irq() takes dibs->lock unconditionally on entry, before it
inspects anything else.
Initialise the lock in dibs_dev_alloc() instead, so that it is valid as
soon as a driver can publish the device to its interrupt handler.
Fixes: cc21191b58 ("dibs: Move data path to dibs layer")
Cc: stable@vger.kernel.org
Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
Link: https://patch.msgid.link/20260730124227.167829-1-hidayath@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
committed by
Jakub Kicinski
parent
8ae344eb54
commit
c27e360545
@@ -138,6 +138,7 @@ struct dibs_dev *dibs_dev_alloc(void)
|
||||
dibs = kzalloc_obj(*dibs);
|
||||
if (!dibs)
|
||||
return dibs;
|
||||
spin_lock_init(&dibs->lock);
|
||||
dibs->dev.release = dibs_dev_release;
|
||||
dibs->dev.class = &dibs_class;
|
||||
device_initialize(&dibs->dev);
|
||||
@@ -186,7 +187,6 @@ int dibs_dev_add(struct dibs_dev *dibs)
|
||||
int i, ret;
|
||||
|
||||
max_dmbs = dibs->ops->max_dmbs();
|
||||
spin_lock_init(&dibs->lock);
|
||||
dibs->dmb_clientid_arr = kzalloc(max_dmbs, GFP_KERNEL);
|
||||
if (!dibs->dmb_clientid_arr)
|
||||
return -ENOMEM;
|
||||
|
||||
@@ -439,7 +439,7 @@ static inline void *dibs_get_priv(struct dibs_dev *dev,
|
||||
/**
|
||||
* dibs_dev_alloc() - allocate and reference device structure
|
||||
*
|
||||
* The following fields will be valid upon successful return: dev
|
||||
* The following fields will be valid upon successful return: dev, lock
|
||||
* NOTE: Use put_device(dibs_get_dev(@dibs)) to give up your reference instead
|
||||
* of freeing @dibs @dev directly once you have successfully called this
|
||||
* function.
|
||||
|
||||
Reference in New Issue
Block a user