[PATCH net] net: mctp: i3c: serialize probe with bus removal

XingWang Xiang posted 1 patch 3 weeks, 3 days ago
drivers/net/mctp/mctp-i3c.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
[PATCH net] net: mctp: i3c: serialize probe with bus removal
Posted by XingWang Xiang 3 weeks, 3 days ago
mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A
concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus
netdev before probe passes its private data to mctp_i3c_add_device().
The latter consequently adds a list node through a freed mbus pointer.

Keep busdevs_lock held until the device has been added. This also
satisfies the __must_hold annotation on mctp_i3c_add_device().

Fixes: c8755b29b58e ("mctp i3c: MCTP I3C driver")
Signed-off-by: XingWang Xiang <v3rdant.xiang@gmail.com>
---
 drivers/net/mctp/mctp-i3c.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/net/mctp/mctp-i3c.c b/drivers/net/mctp/mctp-i3c.c
index 88d9e36cd..4e857dd5d 100644
--- a/drivers/net/mctp/mctp-i3c.c
+++ b/drivers/net/mctp/mctp-i3c.c
@@ -288,6 +288,7 @@ __must_hold(&busdevs_lock)
 static int mctp_i3c_probe(struct i3c_device *i3c)
 {
 	struct mctp_i3c_bus *b = NULL, *mbus = NULL;
+	int rc;
 
 	/* Look for a known bus */
 	mutex_lock(&busdevs_lock);
@@ -296,14 +297,16 @@ static int mctp_i3c_probe(struct i3c_device *i3c)
 			mbus = b;
 			break;
 		}
-	mutex_unlock(&busdevs_lock);
 
 	if (!mbus) {
 		/* probably no "mctp-controller" property on the i3c bus */
-		return -ENODEV;
+		rc = -ENODEV;
+	} else {
+		rc = mctp_i3c_add_device(mbus, i3c);
 	}
+	mutex_unlock(&busdevs_lock);
 
-	return mctp_i3c_add_device(mbus, i3c);
+	return rc;
 }
 
 static void mctp_i3c_remove_device(struct mctp_i3c_device *mi)

base-commit: 70f3995830d3f1e79faa14eb0605914f778feca9
-- 
2.52.0
Re: [PATCH net] net: mctp: i3c: serialize probe with bus removal
Posted by Matt Johnston 3 weeks, 2 days ago
On Wed, 2026-09-02 at 15:01 +0900, XingWang Xiang wrote:
> mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A
> concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus
> netdev before probe passes its private data to mctp_i3c_add_device().
> The latter consequently adds a list node through a freed mbus pointer.
> 
> Keep busdevs_lock held until the device has been added. This also
> satisfies the __must_hold annotation on mctp_i3c_add_device().

Thanks, this looks right. Building with CONTEXT_ANALYSIS caught this as well
as some other problems, 
I'll send patches separately. 

For this patch Sashiko reports some other existing problems in mctp-i3c, I'll
check those.

Acked-by: Matt Johnston <matt@codeconstruct.com.au>

Cheers,
Matt