Re: [PATCH] optee: register TEE devices only once fully initialized
From: Jens Wiklander
Date: Fri Sep 25 2026 - 08:22:12 EST
Hi,
On Fri, Sep 18, 2026 at 12:12 PM Shao-Fu Chen <shf.chen@xxxxxxxxxxxx> wrote:
>
> optee_probe() called tee_device_register() on both the client and the
> supplicant device before the rest of struct optee had been initialized.
>
> tee_device_register() calls cdev_device_add(), which does two things at
> once: it creates /dev/tee0 and /dev/teepriv0, and it links the device
> into the tee class so that class_find_device() can find it. From that
> moment on the device is reachable both from user space via tee_open()
> and from kernel space via tee_client_open_context(). The only gate in
> teedev_open() is tee_device_get(), which merely checks that
> teedev->desc is non-NULL, which was already set by tee_device_alloc().
> Therefore, there is effectively no gate at all.
>
> A context opened in that window can run against a struct optee where
>
> - optee->call_queue.mutex is not initialized by optee_cq_init()
> - optee->supp mutex and completions is not initialized by
> optee_supp_init()
> - optee->rpmb_dev_mutex is not initialized yet,
> - the message argument cache is not initialized by
> optee_shm_arg_cache_init()
> - optee->ctx is still NULL
>
> Any open session or invoke during this window takes uninitialized
> mutexes and dereferences a NULL pointer.
>
> Fix it by moving both tee_device_register() calls down to the point
> where all of struct optee is set up.
>
> Signed-off-by: Shao-Fu Chen <shf.chen@xxxxxxxxxxxx>
> ---
> drivers/tee/optee/ffa_abi.c | 16 ++++++++--------
> drivers/tee/optee/smc_abi.c | 17 ++++++++---------
> 2 files changed, 16 insertions(+), 17 deletions(-)
Looks good, I'm picking this up.
Cheers,
Jens