Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1227727

[PATCH 3/7] phy: add proper phy struct device refcounting

From Russell King <rmk+kernel@arm.linux.org.uk>
Newsgroups linux.kernel
Subject [PATCH 3/7] phy: add proper phy struct device refcounting
Date 2015-09-18 12:00 +0200
Message-ID <qa0Cu-7v5-9@gated-at.bofh.it> (permalink)
References <qa0sO-7jM-21@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Take a refcount on the phy struct device when the phy device is attached
to a network device, and drop it after it's detached.  This ensures that
a refcount is held on the phy device while the device is being used by
a network device, thereby preventing the phy_device from being
unexpectedly kfree()'d by phy_device_release().

Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
---
 drivers/net/phy/phy_device.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c
index 03adf328f49b..97a4f52addac 100644
--- a/drivers/net/phy/phy_device.c
+++ b/drivers/net/phy/phy_device.c
@@ -578,6 +578,7 @@ EXPORT_SYMBOL(phy_init_hw);
  *     generic driver is used.  The phy_device is given a ptr to
  *     the attaching device, and given a callback for link status
  *     change.  The phy_device is returned to the attaching driver.
+ *     This function takes a reference on the phy device.
  */
 int phy_attach_direct(struct net_device *dev, struct phy_device *phydev,
 		      u32 flags, phy_interface_t interface)
@@ -591,6 +592,8 @@ int phy_attach_direct(struct net_device *dev, struct phy_device *phydev,
 		return -EIO;
 	}
 
+	get_device(d);
+
 	/* Assume that if there is no driver, that it doesn't
 	 * exist, and we should use the genphy driver.
 	 */
@@ -636,6 +639,7 @@ int phy_attach_direct(struct net_device *dev, struct phy_device *phydev,
 	return err;
 
 error:
+	put_device(d);
 	module_put(bus->owner);
 	return err;
 }
@@ -679,6 +683,9 @@ EXPORT_SYMBOL(phy_attach);
 /**
  * phy_detach - detach a PHY device from its network device
  * @phydev: target phy_device struct
+ *
+ * This detaches the phy device from its network device and the phy
+ * driver, and drops the reference count taken in phy_attach_direct().
  */
 void phy_detach(struct phy_device *phydev)
 {
@@ -701,8 +708,13 @@ void phy_detach(struct phy_device *phydev)
 		}
 	}
 
+	/*
+	 * The phydev might go away on the put_device() below, so avoid
+	 * a use-after-free bug by reading the underlying bus first.
+	 */
 	bus = phydev->bus;
 
+	put_device(&phydev->dev);
 	module_put(bus->owner);
 }
 EXPORT_SYMBOL(phy_detach);
-- 
2.1.0

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 0/7] Phy and mdiobus fixes Russell King - ARM Linux <linux@arm.linux.org.uk> - 2015-09-18 11:50 +0200
  [PATCH 4/7] of_mdio: fix MDIO phy device refcounting Russell King <rmk+kernel@arm.linux.org.uk> - 2015-09-18 12:00 +0200
  [PATCH 7/7] phy: add phy_device_remove() Russell King <rmk+kernel@arm.linux.org.uk> - 2015-09-18 12:00 +0200
  [PATCH 3/7] phy: add proper phy struct device refcounting Russell King <rmk+kernel@arm.linux.org.uk> - 2015-09-18 12:00 +0200
  [PATCH 5/7] net: fix phy refcounting in a bunch of drivers Russell King <rmk+kernel@arm.linux.org.uk> - 2015-09-18 12:00 +0200
  [PATCH 1/7] phy: fix of_mdio_find_bus() device refcount leak Russell King <rmk+kernel@arm.linux.org.uk> - 2015-09-18 12:00 +0200
    Re: [PATCH 1/7] phy: fix of_mdio_find_bus() device refcount leak David Miller <davem@davemloft.net> - 2015-09-21 21:10 +0200
      Re: [PATCH 1/7] phy: fix of_mdio_find_bus() device refcount leak Russell King - ARM Linux <linux@arm.linux.org.uk> - 2015-09-21 21:40 +0200
        Re: [PATCH 1/7] phy: fix of_mdio_find_bus() device refcount leak David Miller <davem@redhat.com> - 2015-09-22 00:10 +0200
  [PATCH 6/7] phy: fixed-phy: properly validate phy in  fixed_phy_update_state() Russell King <rmk+kernel@arm.linux.org.uk> - 2015-09-18 12:00 +0200
  [PATCH 2/7] phy: fix mdiobus module safety Russell King <rmk+kernel@arm.linux.org.uk> - 2015-09-18 12:00 +0200
  Re: [PATCH 0/7] Phy and mdiobus fixes Russell King - ARM Linux <linux@arm.linux.org.uk> - 2015-09-18 12:10 +0200
    Re: [PATCH 0/7] Phy and mdiobus fixes Russell King - ARM Linux <linux@arm.linux.org.uk> - 2015-09-18 17:30 +0200
  Re: [PATCH 0/7] Phy and mdiobus fixes Florian Fainelli <f.fainelli@gmail.com> - 2015-09-19 23:00 +0200

csiph-web