From nobody Mon Sep 28 06:34:53 2026 Received: from mail-ot1-f45.google.com (mail-ot1-f45.google.com [209.85.210.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C74D9400994 for ; Tue, 25 Aug 2026 13:51:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787665864; cv=none; b=nzQJ3a9reVwU80u2QzFSH1ZeRGvmSd4BrPoD+xpwRv4XLntUQdP2VTP03F0C2Cowqk2Wfa+mBQGw019ZG/K/pj4oMLvX5e9q159+9xGnrddPtV7J8M0dv2sB0z6Whvslrwp8Gj9kBPnzbUa78EkLi0Dnf2crHXlKer3lzRhXIf0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787665864; c=relaxed/simple; bh=c4etVXU9KVvWXnZ2tOh1OmoBS1yBXEWVCGk5dP2gXjE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=eqxHlCMZJ5s6dCung7m3JF5doDtMC4tu78enDxK6+CgzOOT+suZWJ0jIXH4+xjExc/CIZn2wBVvR9V/ipcDUwaoUdfo7mdkQMGVaZbzLq5gemcE2zbK+YqZ1I7FmeWmWLksT/v0boMg8evS2NpvMvaSkB6jII18CDnOOZ+tdCQU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=manus.ai; spf=pass smtp.mailfrom=manus.ai; dkim=pass (2048-bit key) header.d=manus-ai.20251104.gappssmtp.com header.i=@manus-ai.20251104.gappssmtp.com header.b=gIMWhHwN; arc=none smtp.client-ip=209.85.210.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=manus.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=manus.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=manus-ai.20251104.gappssmtp.com header.i=@manus-ai.20251104.gappssmtp.com header.b="gIMWhHwN" Received: by mail-ot1-f45.google.com with SMTP id 46e09a7af769-7e9eaf04bfaso2466551a34.1 for ; Tue, 25 Aug 2026 06:51:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=manus-ai.20251104.gappssmtp.com; s=20251104; t=1787665860; x=1788270660; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=xSIgAOeBEvTO06U9QeOYGma3JENSo1h5usyjFLprsbk=; b=gIMWhHwNWJ/AuUaXrajUQL2t5BvnuSXirPrYEDoZD6W8kHe77jaFFgQ9Cyc683ifBZ kWoik416j/kZdAUw68vioYntMLChTJeri4Yqg1AC4Rj9PMYCiNvnJnxuFSqjYs9QyQYa cudqs2eNOW70iPT42RHOQ8f226l9fxC2n4J16Bpd1Qlp2S7cs9g0SAlPINAeQ6KL7DIq yocEdvfW+AgQHsEQkoF93BZ5XL58gLUWW1ScMFzm7XFqKrh6n/njYzXF7hrwC3BwvFsU r7DbY6qHt0E4IYzM73GBWmxSDrXo+9xM6DBFhwho9GX8OmgkKu9irF3s1/S8cFeTkIww hoCw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787665860; x=1788270660; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xSIgAOeBEvTO06U9QeOYGma3JENSo1h5usyjFLprsbk=; b=Kd1+tjaVQw+0DTBiNvic5loSvSbhR4CGcwoOHFACL4UHMkYWmJsmtcqBU1j/R+bO1N J6Z6b7hUBGhTMk9C00YgAnAQU8Z0bXi5OCUAbLRyZrezV86foTDmjlII8Ejdvn+UlNuS u/uF+JknhoVZXK7/8uiMMSkTixAUaRsA1xJ6vjXDyo/8Dtv87QhA/P6cVdG19RiYcCzx CmM8rAfjaHC2Wa5f7apadUehUa9gwCLzcPrArktG+8dq5dGoDOGSrUOaUKbiOK1O6ZUX 66oA7HPOhrG3kB0nVaOqfflqBtLN35x50yvUzcwnkJx5tH4ZJIcgmQCW7sa3hUhymuqV 1idw== X-Gm-Message-State: AFuF++k5L+z/j2+W1oxEPnLXwFrY3EFzaOMANbEXmme/pkirGao0314t iKQl1guzzROtwNevYYlcunwnvj4QDr0NHCO/CNjHu8uJ27I5PqU9lwzr7m4sEsZ2QM1wk+f+VTI plBVtxvGrFg== X-Gm-Gg: AR+sD103/5+pQS9U9GaJJp4udOVpd7hvN8ysMH2DBVZ/hXKPkSUpy8/YoMUBVeKTuvS Tj1pqnoixfW4lkrgaduixPtdtqMTsr0DYpGVbGWn2zYFzvBtj/aZt3DR1xw/k7T+BYTcnzdXdir XoFajsGfyd4ouPnA8sCsluxoM4pZApj69A5bw9+M6xiq0LhkclGlcPCtyL7yq9+rFr4SEz4hS2a fIRgE2EfZz01JPZEQwZNNJMBE9hOozoBySDoq93WoZoosE3vPreiaDWvFVR/wyLL0d+FnOtfbwh krTKcYFnHFmpHMXhRxN1++mKd8CVRglT3szzKF9uJn7aACgqmaTBPef9l5jr186P8nBuB1Zzfjm YFLjl/qmWuGofB8vbxi2UVrAUlxOcbKCX56w9gdqWe/8IdRHmTElsFjO2dyLAl3/22KHtOjNdnr zVfQ/tb2WyuA5XZuzgvH9w1i3qdeqHg1orMcJQtRigJG6FyLvZ/RzOr9LG7Yc9Ptx/LHK2xf2vB w== X-Received: by 2002:a05:6820:60b:b0:6b1:430f:1bd3 with SMTP id 006d021491bc7-6b16b1bef04mr22789789eaf.7.1787665860541; Tue, 25 Aug 2026 06:51:00 -0700 (PDT) Received: from localhost.localdomain ([104.30.178.117]) by smtp.gmail.com with ESMTPSA id 006d021491bc7-6b17cc2c70dsm6285813eaf.13.2026.08.25.06.50.58 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 25 Aug 2026 06:51:00 -0700 (PDT) From: Zhichen Wang To: "Jason A . Donenfeld" , Theodore Ts'o Cc: linux-kernel@vger.kernel.org, Zhichen Wang , stable@vger.kernel.org Subject: [PATCH] virt: vmgenid: set driver_data before registering notification handlers Date: Tue, 25 Aug 2026 21:50:54 +0800 Message-ID: <20260825135054.54883-1-wangzhichen@manus.ai> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Both probe paths register their notification handler before assigning driver_data, which the handler dereferences. In the devicetree path, the notification IRQ can fire as soon as devm_request_irq() registers the handler: the interrupt may already be pending at probe time, for example when a VMM injects the generation-changed notification while restoring a guest from a snapshot that was taken before the driver had probed (Firecracker does exactly this on snapshot restore). The IRQ is also requested with IRQF_SHARED, so another device sharing the line can trigger the handler just as early. The handler then calls vmgenid_notify(), which dereferences the still-NULL driver_data and panics: Unable to handle kernel NULL pointer dereference at virtual address 00000= 00000000010 CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.18.38+ #1 PREEMPT(none) Hardware name: linux,dummy-virt (DT) pc : vmgenid_notify.isra.0+0x24/0x8c lr : vmgenid_of_irq_handler+0x14/0x34 Call trace: vmgenid_notify.isra.0+0x24/0x8c (P) vmgenid_of_irq_handler+0x14/0x34 __handle_irq_event_percpu+0x44/0x1bc handle_irq_event+0x4c/0xb4 handle_fasteoi_irq+0xf8/0x1f8 The ACPI path has the same ordering problem: the handler is installed with acpi_install_notify_handler() before driver_data is assigned. ACPI notifications are dispatched asynchronously from a workqueue, so the window is narrow, but a notification arriving between the two calls hits the same NULL dereference. Assign driver_data before registering the handlers. The state is fully initialized at that point, so the handlers are safe to run. Should registration fail, the probe error path leaves no dangling pointer behind: the driver core clears driver_data in device_unbind_cleanup(). Fixes: 7b1bcd6b50a6 ("virt: vmgenid: add support for devicetree bindings") Fixes: e07606713a90 ("virt: vmgenid: change implementation to use a platfor= m driver") Cc: stable@vger.kernel.org Signed-off-by: Zhichen Wang --- Verified on Firecracker v1.14 (aarch64, devicetree) with a snapshot taken before the vmgenid driver had probed, so the injected notification IRQ is pending when the restored guest reaches probe: the unpatched kernel panics with the trace above, while the patched kernel handles the pending IRQ as soon as devm_request_irq() registers the handler (/proc/interrupts shows the vmgenid IRQ count at 1) and boot completes normally. The ACPI path change is compile-tested; the window there is analogous but much harder to hit. drivers/virt/vmgenid.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/drivers/virt/vmgenid.c b/drivers/virt/vmgenid.c index 66135eac3..92d9779c9 100644 --- a/drivers/virt/vmgenid.c +++ b/drivers/virt/vmgenid.c @@ -82,6 +82,8 @@ static int vmgenid_add_acpi(struct device *dev, struct vm= genid_state *state) } setup_vmgenid_state(state, virt_addr); =20 + dev->driver_data =3D state; + status =3D acpi_install_notify_handler(device->handle, ACPI_DEVICE_NOTIFY, vmgenid_acpi_handler, dev); if (ACPI_FAILURE(status)) { @@ -89,7 +91,6 @@ static int vmgenid_add_acpi(struct device *dev, struct vm= genid_state *state) goto out; } =20 - dev->driver_data =3D state; out: ACPI_FREE(parsed.pointer); return ret; @@ -123,12 +124,13 @@ static int vmgenid_add_of(struct platform_device *pde= v, if (ret < 0) return ret; =20 + pdev->dev.driver_data =3D state; + ret =3D devm_request_irq(&pdev->dev, ret, vmgenid_of_irq_handler, IRQF_SHARED, "vmgenid", &pdev->dev); if (ret < 0) return ret; =20 - pdev->dev.driver_data =3D state; return 0; } =20 base-commit: 66498c75b4f8017f62d720d9b59675bdf3abce91 --=20 2.47.3