Re: [PATCH] serial: imx: cancel RS485 trigger hrtimers in shutdown and remove

From: Fan Wu

Date: Sun Sep 27 2026 - 10:37:19 EST


Hi Greg,

Honestly: when I sent the patch it was compile-tested only
(CONFIG_SERIAL_IMX=m, drivers/tty/serial/imx.o rebuilt with no warnings).
I should have said so. There was no runtime test behind it.

After your mail I built a QEMU/KASAN reproduction (i.MX6UL EVK machine,
armhf, kernel = this patch's base a13c140cc289 + CONFIG_KASAN). The
remove-side race is deterministic on the unpatched base:

- ttymxc0 is a registered console; configure RS485 via TIOCSRS485 with
delay_rts_after_send set (driver clamps it to 100 ms), write() - TX
completes and imx_uart_stop_tx() arms trigger_stop_tx
- with the port still open, unbind: for console ports
tty_port_shutdown() returns early, and serial_core_remove_one_port()
never calls the driver .shutdown, so nothing sync-cancels the timer
- imx_uart_remove() returns, devres frees struct imx_port, the queued
hrtimer expires and the hrtimer core walks the freed object:

BUG: KASAN: slab-use-after-free in rb_erase_linked+0x54/0xa8
Write of size 4 at addr c4046a8c by task swapper/0
Call trace:
rb_erase_linked from __remove_hrtimer+0x50/0x124
__remove_hrtimer from __hrtimer_run_queues+0x198/0x25c
__hrtimer_run_queues from hrtimer_interrupt+0x26c/0x624
hrtimer_interrupt from arch_timer_handler_phys+0x38/0x40
...
Allocated by task 1:
devm_kmalloc+0x34/0x144
imx_uart_probe+0x90/0xacc
...
Freed by task 1:
kfree+0xc8/0x2d8
devres_release_all+0x100/0x18c
device_unbind_cleanup+0x3c/0xe4
device_release_driver_internal+0x23c/0x294
unbind_store+0x64/0xa4
...
The buggy address is located 652 bytes inside of
freed 1024-byte region [c4046800, c4046c00)

i.e. the expired timer is still enqueued inside the freed struct imx_port.
A second report fires from task context via hrtimer_try_to_cancel ->
rb_erase, same alloc/free stacks.

With the patch applied the same sequence (fd-open unbind, and the
last-close-then-unbind variant) completes cleanly; repeated RS485
write/close/unbind cycles on a non-console port stay clean too, with no
new warnings or hangs. This is QEMU only - no i.MX hardware test yet,
so I have not added a Tested-by. I can send the reproducer initramfs and
the QEMU command line if that is useful.

Thanks,
Fan