Re: [PATCH] serial: core: Shut down a running console port before removing it
From: Phil Rosenthal
Date: Thu Oct 08 2026 - 13:35:57 EST
> On Oct 8, 2026, at 1:03 PM, sashiko-bot@xxxxxxxxxx wrote:
>
> [Severity: Medium]
> Does this code introduce a regression by leaking port->xmit_buf if the serial
> device is unbound while suspended?
>
> If a console or normal serial port is suspended (e.g., via system or runtime
> PM), uart_suspend_port() clears the initialized flag but leaves
> port->xmit_buf allocated:
>
> drivers/tty/serial/serial_core.c:uart_suspend_port() {
> ...
> if (tty_port_initialized(port)) {
> ...
> tty_port_set_suspended(port, true);
> tty_port_set_initialized(port, false);
> ...
> }
>
> If the device is then removed or its driver is unbound,
> serial_core_remove_one_port() will evaluate tty_port_initialized(port) as
> false and skip calling uart_shutdown().
>
> Since uart_shutdown() is the only path in serial_core responsible for
> unconditionally calling uart_free_xmit_buf(port) and
> serial_base_port_shutdown(uport), skipping it appears to leak the
> page-sized transmit buffer.
>
>> + mutex_unlock(&port->mutex);
>> +
>> /*
>> * Free the port IO and memory resources, if any.
>> */
>
Sashiko pointed out that a console port removed while suspended is
skipped by the tty_port_initialized() check, because
uart_suspend_port() clears the initialized flag, so its xmit buffer
stays allocated and the suspended flag stays set.
That case is not new: without this patch the removal path never calls
uart_shutdown() at all. It only applies to system sleep, and the buffer
is reused if the line is registered again. But it is easy to cover:
calling uart_shutdown() without the check frees the buffer and clears
the flag, and uart_shutdown() already skips the hardware shutdown for a
port that is not initialized.
I have a v2 that does that, tested on the same setups. I will send it
after any other review comments, or now if you prefer.
Best Regards,
-Phil Rosenthal