1. Jul 04, 2023
    • Chengfeng Ye's avatar
      ipmi: fix potential deadlock on &kcs_bmc->lock · b02bb79e
      Chengfeng Ye authored
      
      
      As kcs_bmc_handle_event() is executed inside both a timer and a hardirq,
      it should disable irq before lock acquisition otherwise deadlock could
      happen if the timmer is preemtped by the irq.
      
      Possible deadlock scenario:
      aspeed_kcs_check_obe() (timer)
          -> kcs_bmc_handle_event()
          -> spin_lock(&kcs_bmc->lock)
              <irq interruption>
              -> aspeed_kcs_irq()
              -> kcs_bmc_handle_event()
              -> spin_lock(&kcs_bmc->lock) (deadlock here)
      
      This flaw was found using an experimental static analysis tool we are
      developing for irq-related deadlock.
      
      The tentative patch fix the potential deadlock by spin_lock_irqsave()
      
      Signed-off-by: default avatarChengfeng Ye <dg573847474@gmail.com>
      Message-Id: <20230627152449.36093-1-dg573847474@gmail.com>
      Signed-off-by: default avatarCorey Minyard <minyard@acm.org>
      b02bb79e
  2. Jun 29, 2023
    • Yi Yang's avatar
      ipmi_si: fix a memleak in try_smi_init() · 6cf1a126
      Yi Yang authored
      Kmemleak reported the following leak info in try_smi_init():
      
      unreferenced object 0xffff00018ecf9400 (size 1024):
        comm "modprobe", pid 2707763, jiffies 4300851415 (age 773.308s)
        backtrace:
          [<000000004ca5b312>] __kmalloc+0x4b8/0x7b0
          [<00000000953b1072>] try_smi_init+0x148/0x5dc [ipmi_si]
          [<000000006460d325>] 0xffff800081b10148
          [<0000000039206ea5>] do_one_initcall+0x64/0x2a4
          [<00000000601399ce>] do_init_module+0x50/0x300
          [<000000003c12ba3c>] load_module+0x7a8/0x9e0
          [<00000000c246fffe>] __se_sys_init_module+0x104/0x180
          [<00000000eea99093>] __arm64_sys_init_module+0x24/0x30
          [<0000000021b1ef87>] el0_svc_common.constprop.0+0x94/0x250
          [<0000000070f4f8b7>] do_el0_svc+0x48/0xe0
          [<000000005a05337f>] el0_svc+0x24/0x3c
          [<000000005eb248d6>] el0_sync_handler+0x160/0x164
          [<0000000030a59039>] el0_sync+0x160/0x180
      
      The problem was that when an error occurred before handlers registration
      and after allocating `new_smi->si_sm`, the variable wouldn't be freed in
      the error handling afterwards since `shutdown_smi()` hadn't been
      registered yet. Fix it by adding a `kfree()` in the error handling path
      in `try_smi_init()`.
      
      Cc: stable@vger.kernel.org # 4.19+
      Fixes: 7960f18a
      
       ("ipmi_si: Convert over to a shutdown handler")
      Signed-off-by: default avatarYi Yang <yiyang13@huawei.com>
      Co-developed-by: default avatarGONG, Ruiqi <gongruiqi@huaweicloud.com>
      Signed-off-by: default avatarGONG, Ruiqi <gongruiqi@huaweicloud.com>
      Message-Id: <20230629123328.2402075-1-gongruiqi@huaweicloud.com>
      Signed-off-by: default avatarCorey Minyard <minyard@acm.org>
      6cf1a126
  3. Jun 20, 2023
  4. Jun 10, 2023
  5. May 26, 2023
  6. May 19, 2023
  7. May 18, 2023
  8. May 16, 2023
  9. May 15, 2023
  10. May 14, 2023