Re: [PATCH] misc: mei: fix race condition between client teardown and read completion
| Newsgroups | gmane.linux.kernel.stable,gmane.linux.kernel |
|---|---|
| Message-ID | <2026082330-saint-relearn-1244@gregkh> |
On Sun, Aug 23, 2026 at 01:26:09PM +0000, [email protected] wrote: > In mei_release(), a host client is torn down upon close(). During this > teardown sequence, mei_cl_disconnect() is invoked, which releases > dev->device_lock while waiting for the firmware response. > > If an in-flight read request was previously submitted, an incoming > completion interrupt processed concurrently by the MEI interrupt > handler can add a completed callback into cl->rd_completed via > mei_cl_add_rd_completed(). > > Because mei_cl_flush_queues(cl, NULL) was invoked before mei_cl_unlink(cl), > an incoming completion callback can slip into cl->rd_completed after the > flush has completed but before the client is unlinked from dev->file_list. > When mei_cl_unlink() is subsequently called, the invariant check at > drivers/misc/mei/client.c:698 triggers: > > WARN_ON(!list_empty(&cl->rd_completed) || > !list_empty(&cl->rd_pending) || > !list_empty(&cl->link)); > > Call trace: > WARNING: CPU: 2 PID: 5056 at drivers/misc/mei/client.c:698 mei_cl_unlink+0xaa/0x140 [mei] > RIP: 0010:mei_cl_unlink+0xaa/0x140 [mei] > Call Trace: > <TASK> > mei_release+0x202/0x270 [mei] > __fput+0x105/0x2e0 > __x64_sys_close+0x90/0x140 > do_syscall_64+0xaa/0x660 > entry_SYSCALL_64_after_hwframe+0x77/0x7f > </TASK> > > Immediately following mei_cl_unlink(), mei_release() calls kfree(cl). > If any remaining or deferred callback references the freed client, a > use-after-free occurs. > > Fix this by flushing queues after unlinking the client from dev->file_list > inside mei_cl_unlink(), preventing concurrent IRQ completions from > populating the client's completed queue during teardown. > > Reported-by: Nirbhay Kumar <[email protected]> > Signed-off-by: Nirbhay Kumar <[email protected]> No need for Reported-by as you authored and signed off on this. And did you forget an Assisted-by: tag? and what commit id does this fix? Also, no need to attach this at all, just send it using git send-email as-is. thanks, greg k-h