Skip to content

Commit 4b9a9a6

Browse files
ian-abbottgregkh
authored andcommitted
comedi: Reinit dev->spinlock between attachments to low-level drivers
`struct comedi_device` is the main controlling structure for a COMEDI device created by the COMEDI subsystem. It contains a member `spinlock` containing a spin-lock that is initialized by the COMEDI subsystem, but is reserved for use by a low-level driver attached to the COMEDI device (at least since commit 25436dc ("Staging: comedi: remove RT code")). Some COMEDI devices (those created on initialization of the COMEDI subsystem when the "comedi.comedi_num_legacy_minors" parameter is non-zero) can be attached to different low-level drivers over their lifetime using the `COMEDI_DEVCONFIG` ioctl command. This can result in inconsistent lock states being reported when there is a mismatch in the spin-lock locking levels used by each low-level driver to which the COMEDI device has been attached. Fix it by reinitializing `dev->spinlock` before calling the low-level driver's `attach` function pointer if `CONFIG_LOCKDEP` is enabled. Reported-by: syzbot+cc9f7f4a7df09f53c4a4@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=cc9f7f4a7df09f53c4a4 Fixes: ed9eccb ("Staging: add comedi core") Cc: stable <stable@kernel.org> Signed-off-by: Ian Abbott <abbotti@mev.co.uk> Link: https://patch.msgid.link/20260225132427.86578-1-abbotti@mev.co.uk Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent cc797d4 commit 4b9a9a6

1 file changed

Lines changed: 8 additions & 0 deletions

File tree

drivers/comedi/drivers.c

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1063,6 +1063,14 @@ int comedi_device_attach(struct comedi_device *dev, struct comedi_devconfig *it)
10631063
ret = -EIO;
10641064
goto out;
10651065
}
1066+
if (IS_ENABLED(CONFIG_LOCKDEP)) {
1067+
/*
1068+
* dev->spinlock is for private use by the attached low-level
1069+
* driver. Reinitialize it to stop lock-dependency tracking
1070+
* between attachments to different low-level drivers.
1071+
*/
1072+
spin_lock_init(&dev->spinlock);
1073+
}
10661074
dev->driver = driv;
10671075
dev->board_name = dev->board_ptr ? *(const char **)dev->board_ptr
10681076
: dev->driver->driver_name;

0 commit comments

Comments
 (0)