• Z
    driver core: fix deadlock in __driver_attach · 92cf6727
    Zhang Wensheng 提交于
    hulk inclusion
    category: bugfix
    bugzilla: https://gitee.com/openeuler/kernel/issues/I58CRT
    CVE: NA
    
    --------------------------------
    
    In __driver_attach function, The lock holding logic is as follows:
    ...
    __driver_attach
    if (driver_allows_async_probing(drv))
      device_lock(dev)      // get lock dev
        async_schedule_dev(__driver_attach_async_helper, dev); // func
          async_schedule_node
            async_schedule_node_domain(func)
              entry = kzalloc(sizeof(struct async_entry), GFP_ATOMIC);
    	  /* when fail or work limit, sync to execute func, but
    	     __driver_attach_async_helper will get lock dev as
    	     will, which will lead to A-A deadlock.  */
    	  if (!entry || atomic_read(&entry_count) > MAX_WORK) {
    	    func;
    	  else
    	    queue_work_node(node, system_unbound_wq, &entry->work)
      device_unlock(dev)
    
    As above show, when it is allowed to do async probes, because of
    out of memory or work limit, async work is not be allowed, to do
    sync execute instead. it will lead to A-A deadlock because of
    __driver_attach_async_helper getting lock dev.
    
    To fix the deadlock, move the async_schedule_dev outside device_lock,
    as we can see, in async_schedule_node_domain, the parameter of
    queue_work_node is system_unbound_wq, so it can accept concurrent
    operations. which will also not change the code logic, and will
    not lead to deadlock.
    
    Fixes: ef0ff683 ("driver core: Probe devices asynchronously instead of the driver")
    Signed-off-by: NZhang Wensheng <zhangwensheng5@huawei.com>
    Reviewed-by: NHou Tao <houtao1@huawei.com>
    Signed-off-by: NZheng Zengkai <zhengzengkai@huawei.com>
    92cf6727
dd.c 33.9 KB