[PATCH v2] crypto: ccp: Initialize DBC ioctl mutex before registering device

Runyu Xiao posted 1 patch 3 weeks, 6 days ago
drivers/crypto/ccp/dbc.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
[PATCH v2] crypto: ccp: Initialize DBC ioctl mutex before registering device
Posted by Runyu Xiao 3 weeks, 6 days ago
dbc_dev_init() registers the DBC misc device before initializing
ioctl_mutex. Once misc_register() publishes the device, userspace can
open it and invoke dbc_ioctl() while the mutex is still uninitialized.

Initialize ioctl_mutex before calling misc_register() so the published
ioctl callback always sees an initialized mutex.

Fixes: c04cf9e14f10 ("crypto: ccp - Add support for fetching a nonce for dynamic boost control")
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/all/20260829133410.1708684-1-runyu.xiao@seu.edu.cn/
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Assisted-by: Codex:GPT-5
---
v2:
- Move mutex initialization before setting up the misc device, as suggested
  by Tom Lendacky.

 drivers/crypto/ccp/dbc.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/crypto/ccp/dbc.c b/drivers/crypto/ccp/dbc.c
index 410084a9039c..4db49a14550c 100644
--- a/drivers/crypto/ccp/dbc.c
+++ b/drivers/crypto/ccp/dbc.c
@@ -235,6 +235,8 @@ int dbc_dev_init(struct psp_device *psp)
 		goto cleanup_mbox;
 	}
 
+	mutex_init(&dbc_dev->ioctl_mutex);
+
 	dbc_dev->char_dev.minor = MISC_DYNAMIC_MINOR;
 	dbc_dev->char_dev.name = "dbc";
 	dbc_dev->char_dev.fops = &dbc_fops;
@@ -243,8 +245,6 @@ int dbc_dev_init(struct psp_device *psp)
 	if (ret)
 		goto cleanup_mbox;
 
-	mutex_init(&dbc_dev->ioctl_mutex);
-
 	return 0;
 
 cleanup_mbox:
Re: [PATCH v2] crypto: ccp: Initialize DBC ioctl mutex before registering device
Posted by Herbert Xu 2 weeks, 1 day ago
Runyu Xiao <runyu.xiao@seu.edu.cn> wrote:
> dbc_dev_init() registers the DBC misc device before initializing
> ioctl_mutex. Once misc_register() publishes the device, userspace can
> open it and invoke dbc_ioctl() while the mutex is still uninitialized.
> 
> Initialize ioctl_mutex before calling misc_register() so the published
> ioctl callback always sees an initialized mutex.
> 
> Fixes: c04cf9e14f10 ("crypto: ccp - Add support for fetching a nonce for dynamic boost control")
> Cc: stable@vger.kernel.org
> Link: https://lore.kernel.org/all/20260829133410.1708684-1-runyu.xiao@seu.edu.cn/
> Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
> Assisted-by: Codex:GPT-5
> ---
> v2:
> - Move mutex initialization before setting up the misc device, as suggested
>  by Tom Lendacky.
> 
> drivers/crypto/ccp/dbc.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)

Patch applied.  Thanks.
-- 
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Re: [PATCH v2] crypto: ccp: Initialize DBC ioctl mutex before registering device
Posted by Mario Limonciello 3 weeks, 5 days ago

On 8/29/26 20:51, Runyu Xiao wrote:
> dbc_dev_init() registers the DBC misc device before initializing
> ioctl_mutex. Once misc_register() publishes the device, userspace can
> open it and invoke dbc_ioctl() while the mutex is still uninitialized.
> 
> Initialize ioctl_mutex before calling misc_register() so the published
> ioctl callback always sees an initialized mutex.
> 
> Fixes: c04cf9e14f10 ("crypto: ccp - Add support for fetching a nonce for dynamic boost control")
> Cc: stable@vger.kernel.org
> Link: https://lore.kernel.org/all/20260829133410.1708684-1-runyu.xiao@seu.edu.cn/
> Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
> Assisted-by: Codex:GPT-5
I mean my tag to come here, I didn't realize this was threaded with V1 
and V2 together.

Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>> ---
> v2:
> - Move mutex initialization before setting up the misc device, as suggested
>    by Tom Lendacky.
> 
>   drivers/crypto/ccp/dbc.c | 4 ++--
>   1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/crypto/ccp/dbc.c b/drivers/crypto/ccp/dbc.c
> index 410084a9039c..4db49a14550c 100644
> --- a/drivers/crypto/ccp/dbc.c
> +++ b/drivers/crypto/ccp/dbc.c
> @@ -235,6 +235,8 @@ int dbc_dev_init(struct psp_device *psp)
>   		goto cleanup_mbox;
>   	}
>   
> +	mutex_init(&dbc_dev->ioctl_mutex);
> +
>   	dbc_dev->char_dev.minor = MISC_DYNAMIC_MINOR;
>   	dbc_dev->char_dev.name = "dbc";
>   	dbc_dev->char_dev.fops = &dbc_fops;
> @@ -243,8 +245,6 @@ int dbc_dev_init(struct psp_device *psp)
>   	if (ret)
>   		goto cleanup_mbox;
>   
> -	mutex_init(&dbc_dev->ioctl_mutex);
> -
>   	return 0;
>   
>   cleanup_mbox:
Re: [PATCH v2] crypto: ccp: Initialize DBC ioctl mutex before registering device
Posted by Tom Lendacky 3 weeks, 6 days ago
On 8/29/26 20:51, Runyu Xiao wrote:
> dbc_dev_init() registers the DBC misc device before initializing
> ioctl_mutex. Once misc_register() publishes the device, userspace can
> open it and invoke dbc_ioctl() while the mutex is still uninitialized.
> 
> Initialize ioctl_mutex before calling misc_register() so the published
> ioctl callback always sees an initialized mutex.
> 
> Fixes: c04cf9e14f10 ("crypto: ccp - Add support for fetching a nonce for dynamic boost control")
> Cc: stable@vger.kernel.org
> Link: https://lore.kernel.org/all/20260829133410.1708684-1-runyu.xiao@seu.edu.cn/
> Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
> Assisted-by: Codex:GPT-5

Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>

> ---
> v2:
> - Move mutex initialization before setting up the misc device, as suggested
>   by Tom Lendacky.
> 
>  drivers/crypto/ccp/dbc.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/crypto/ccp/dbc.c b/drivers/crypto/ccp/dbc.c
> index 410084a9039c..4db49a14550c 100644
> --- a/drivers/crypto/ccp/dbc.c
> +++ b/drivers/crypto/ccp/dbc.c
> @@ -235,6 +235,8 @@ int dbc_dev_init(struct psp_device *psp)
>  		goto cleanup_mbox;
>  	}
>  
> +	mutex_init(&dbc_dev->ioctl_mutex);
> +
>  	dbc_dev->char_dev.minor = MISC_DYNAMIC_MINOR;
>  	dbc_dev->char_dev.name = "dbc";
>  	dbc_dev->char_dev.fops = &dbc_fops;
> @@ -243,8 +245,6 @@ int dbc_dev_init(struct psp_device *psp)
>  	if (ret)
>  		goto cleanup_mbox;
>  
> -	mutex_init(&dbc_dev->ioctl_mutex);
> -
>  	return 0;
>  
>  cleanup_mbox: