mirror of
https://github.com/raspberrypi/linux.git
synced 2025-12-06 01:49:46 +00:00
vfio/mdev: Do not allow a mdev_type to have a NULL parent pointer
[ Upstream commitb5a1f8921d] There is a small race where the parent is NULL even though the kobj has already been made visible in sysfs. For instance the attribute_group is made visible in sysfs_create_files() and the mdev_type_attr_show() does: ret = attr->show(kobj, type->parent->dev, buf); Which will crash on NULL parent. Move the parent setup to before the type pointer leaves the stack frame. Fixes:7b96953bc6("vfio: Mediated device Core driver") Reviewed-by: Christoph Hellwig <hch@lst.de> Reviewed-by: Kevin Tian <kevin.tian@intel.com> Reviewed-by: Max Gurtovoy <mgurtovoy@nvidia.com> Reviewed-by: Cornelia Huck <cohuck@redhat.com> Signed-off-by: Jason Gunthorpe <jgg@nvidia.com> Message-Id: <2-v2-d36939638fc6+d54-vfio2_jgg@nvidia.com> Signed-off-by: Alex Williamson <alex.williamson@redhat.com> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
87856f9af0
commit
b29d6a435e
@@ -105,6 +105,7 @@ static struct mdev_type *add_mdev_supported_type(struct mdev_parent *parent,
|
|||||||
return ERR_PTR(-ENOMEM);
|
return ERR_PTR(-ENOMEM);
|
||||||
|
|
||||||
type->kobj.kset = parent->mdev_types_kset;
|
type->kobj.kset = parent->mdev_types_kset;
|
||||||
|
type->parent = parent;
|
||||||
|
|
||||||
ret = kobject_init_and_add(&type->kobj, &mdev_type_ktype, NULL,
|
ret = kobject_init_and_add(&type->kobj, &mdev_type_ktype, NULL,
|
||||||
"%s-%s", dev_driver_string(parent->dev),
|
"%s-%s", dev_driver_string(parent->dev),
|
||||||
@@ -132,7 +133,6 @@ static struct mdev_type *add_mdev_supported_type(struct mdev_parent *parent,
|
|||||||
}
|
}
|
||||||
|
|
||||||
type->group = group;
|
type->group = group;
|
||||||
type->parent = parent;
|
|
||||||
return type;
|
return type;
|
||||||
|
|
||||||
attrs_failed:
|
attrs_failed:
|
||||||
|
|||||||
Reference in New Issue
Block a user