Re: [PATCH v2] gpio: mpsse: fix race when arming the IRQ poll worker
From: Bartosz Golaszewski
Date: Mon Sep 28 2026 - 08:36:11 EST
On Mon, 28 Sep 2026 13:25:46 +0200, Fan Wu <fanwu01@xxxxxxxxxx> said:
> gpio_mpsse_irq_enable() schedules a poll worker before adding it to
> priv->workers. gpio_mpsse_disconnect() can miss the worker while
> tearing down the list, after which the worker can access freed priv.
>
> Publish and schedule the worker while holding irq_spin. Set dying under
> the same lock before disconnect tears down the list, so a worker created
> after teardown starts is neither published nor scheduled. Use
> kfree_rcu() for such a worker because irq_enable() runs with the IRQ
> descriptor raw lock held.
>
> This issue was found by an in-house static analysis tool.
>
> Fixes: 179ef1127d7a ("gpio: mpsse: ensure worker is torn down")
> Cc: stable@xxxxxxxxxxxxxxx
> Co-developed-by: Song Li <songl@xxxxxxxxxx>
> Signed-off-by: Song Li <songl@xxxxxxxxxx>
> Signed-off-by: Fan Wu <fanwu01@xxxxxxxxxx>
> ---
Please always include the changelog between iterations of the same series. I
have no idea what changed since v1.
Bart