Commit 2b0e9643 authored by Mark Brown's avatar Mark Brown Committed by Zeng Heng
Browse files

spi: Fix deadlock when adding SPI controllers on SPI buses

mainline inclusion
from mainline-v5.15-rc6
commit 6098475d
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/I9RBZI
CVE: CVE-2021-47469

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=6098475d4cb48d821bdf453c61118c56e26294f0



--------------------------------

Currently we have a global spi_add_lock which we take when adding new
devices so that we can check that we're not trying to reuse a chip
select that's already controlled.  This means that if the SPI device is
itself a SPI controller and triggers the instantiation of further SPI
devices we trigger a deadlock as we try to register and instantiate
those devices while in the process of doing so for the parent controller
and hence already holding the global spi_add_lock.  Since we only care
about concurrency within a single SPI bus move the lock to be per
controller, avoiding the deadlock.

This can be easily triggered in the case of spi-mux.

Reported-by: default avatarUwe Kleine-König <u.kleine-koenig@pengutronix.de>
Signed-off-by: default avatarMark Brown <broonie@kernel.org>
Conflicts:
	drivers/spi/spi.c
[Resolve conflicts due to several refactor patches not merged.]
Signed-off-by: default avatarZeng Heng <zengheng4@huawei.com>
parent acc28460
Loading
Loading
Loading
Loading
+5 −10
Original line number Diff line number Diff line
@@ -472,12 +472,6 @@ static LIST_HEAD(spi_controller_list);
 */
static DEFINE_MUTEX(board_lock);

/*
 * Prevents addition of devices with same chip select and
 * addition of devices below an unregistering controller.
 */
static DEFINE_MUTEX(spi_add_lock);

/**
 * spi_alloc_device - Allocate a new SPI device
 * @ctlr: Controller to which device is connected
@@ -581,7 +575,7 @@ int spi_add_device(struct spi_device *spi)
	 * chipselect **BEFORE** we call setup(), else we'll trash
	 * its configuration.  Lock against concurrent add() calls.
	 */
	mutex_lock(&spi_add_lock);
	mutex_lock(&ctlr->add_lock);

	status = bus_for_each_dev(&spi_bus_type, NULL, spi, spi_dev_check);
	if (status) {
@@ -625,7 +619,7 @@ int spi_add_device(struct spi_device *spi)
	}

done:
	mutex_unlock(&spi_add_lock);
	mutex_unlock(&ctlr->add_lock);
	return status;
}
EXPORT_SYMBOL_GPL(spi_add_device);
@@ -2730,6 +2724,7 @@ int spi_register_controller(struct spi_controller *ctlr)
	spin_lock_init(&ctlr->bus_lock_spinlock);
	mutex_init(&ctlr->bus_lock_mutex);
	mutex_init(&ctlr->io_mutex);
	mutex_init(&ctlr->add_lock);
	ctlr->bus_lock_flag = 0;
	init_completion(&ctlr->xfer_completion);
	if (!ctlr->max_dma_len)
@@ -2875,7 +2870,7 @@ void spi_unregister_controller(struct spi_controller *ctlr)

	/* Prevent addition of new devices, unregister existing ones */
	if (IS_ENABLED(CONFIG_SPI_DYNAMIC))
		mutex_lock(&spi_add_lock);
		mutex_lock(&ctlr->add_lock);

	device_for_each_child(&ctlr->dev, NULL, __unregister);

@@ -2906,7 +2901,7 @@ void spi_unregister_controller(struct spi_controller *ctlr)
	mutex_unlock(&board_lock);

	if (IS_ENABLED(CONFIG_SPI_DYNAMIC))
		mutex_unlock(&spi_add_lock);
		mutex_unlock(&ctlr->add_lock);
}
EXPORT_SYMBOL_GPL(spi_unregister_controller);

+3 −0
Original line number Diff line number Diff line
@@ -527,6 +527,9 @@ struct spi_controller {
	/* I/O mutex */
	struct mutex		io_mutex;

	/* Used to avoid adding the same CS twice */
	struct mutex		add_lock;

	/* lock and mutex for SPI bus locking */
	spinlock_t		bus_lock_spinlock;
	struct mutex		bus_lock_mutex;