Commit c4145ebf authored by Rafael J. Wysocki's avatar Rafael J. Wysocki Committed by Lin Yujun
Browse files

cpufreq: Rearrange locking in cpufreq_remove_dev()

stable inclusion
from stable-v5.10.219
commit 92aca16797e6f799737846887e31aaf1cf3cce96
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IA6SHN
CVE: CVE-2024-38615

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=92aca16797e6f799737846887e31aaf1cf3cce96



--------------------------------

[ Upstream commit f339f354 ]

Currently, cpufreq_remove_dev() invokes the ->exit() driver callback
without holding the policy rwsem which is inconsistent with what
happens if ->exit() is invoked directly from cpufreq_offline().

It also manipulates the real_cpus mask and removes the CPU device
symlink without holding the policy rwsem, but cpufreq_offline() holds
the rwsem around the modifications thereof.

For consistency, modify cpufreq_remove_dev() to hold the policy rwsem
until the ->exit() callback has been called (or it has been determined
that it is not necessary to call it).

Signed-off-by: default avatarRafael J. Wysocki <rafael.j.wysocki@intel.com>
Acked-by: default avatarViresh Kumar <viresh.kumar@linaro.org>
Stable-dep-of: b8f85833c057 ("cpufreq: exit() callback is optional")
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
Signed-off-by: default avatarLin Yujun <linyujun809@huawei.com>
parent 68b0ded8
Loading
Loading
Loading
Loading
+14 −7
Original line number Diff line number Diff line
@@ -1648,20 +1648,27 @@ static void cpufreq_remove_dev(struct device *dev, struct subsys_interface *sif)
	if (!policy)
		return;

	down_write(&policy->rwsem);

	if (cpu_online(cpu))
		cpufreq_offline(cpu);
		__cpufreq_offline(cpu, policy);

	cpumask_clear_cpu(cpu, policy->real_cpus);
	remove_cpu_dev_symlink(policy, dev);

	if (cpumask_empty(policy->real_cpus)) {
	if (!cpumask_empty(policy->real_cpus)) {
		up_write(&policy->rwsem);
		return;
	}

	/* We did light-weight exit earlier, do full tear down now */
	if (cpufreq_driver->offline)
		cpufreq_driver->exit(policy);

	up_write(&policy->rwsem);

	cpufreq_policy_free(policy);
}
}

/**
 *	cpufreq_out_of_sync - If actual and saved CPU frequency differs, we're