usb: roles: fix NULL pointer issue when put module's reference

commit 1c9be13846c0b2abc2480602f8ef421360e1ad9e upstream.

In current design, usb role class driver will get usb_role_switch parent's
module reference after the user get usb_role_switch device and put the
reference after the user put the usb_role_switch device. However, the
parent device of usb_role_switch may be removed before the user put the
usb_role_switch. If so, then, NULL pointer issue will be met when the user
put the parent module's reference.

This will save the module pointer in structure of usb_role_switch. Then,
we don't need to find module by iterating long relations.

Fixes: 5c54fcac9a ("usb: roles: Take care of driver module reference counting")
cc: stable@vger.kernel.org
Signed-off-by: Xu Yang <xu.yang_2@nxp.com>
Acked-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://lore.kernel.org/r/20240129093739.2371530-1-xu.yang_2@nxp.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
Xu Yang
2024-01-29 17:37:38 +08:00
committed by Greg Kroah-Hartman
parent 2cb66b62a5
commit ef982fc410

View File

@@ -19,6 +19,7 @@ static struct class *role_class;
struct usb_role_switch { struct usb_role_switch {
struct device dev; struct device dev;
struct mutex lock; /* device lock*/ struct mutex lock; /* device lock*/
struct module *module; /* the module this device depends on */
enum usb_role role; enum usb_role role;
/* From descriptor */ /* From descriptor */
@@ -133,7 +134,7 @@ struct usb_role_switch *usb_role_switch_get(struct device *dev)
usb_role_switch_match); usb_role_switch_match);
if (!IS_ERR_OR_NULL(sw)) if (!IS_ERR_OR_NULL(sw))
WARN_ON(!try_module_get(sw->dev.parent->driver->owner)); WARN_ON(!try_module_get(sw->module));
return sw; return sw;
} }
@@ -155,7 +156,7 @@ struct usb_role_switch *fwnode_usb_role_switch_get(struct fwnode_handle *fwnode)
sw = fwnode_connection_find_match(fwnode, "usb-role-switch", sw = fwnode_connection_find_match(fwnode, "usb-role-switch",
NULL, usb_role_switch_match); NULL, usb_role_switch_match);
if (!IS_ERR_OR_NULL(sw)) if (!IS_ERR_OR_NULL(sw))
WARN_ON(!try_module_get(sw->dev.parent->driver->owner)); WARN_ON(!try_module_get(sw->module));
return sw; return sw;
} }
@@ -170,7 +171,7 @@ EXPORT_SYMBOL_GPL(fwnode_usb_role_switch_get);
void usb_role_switch_put(struct usb_role_switch *sw) void usb_role_switch_put(struct usb_role_switch *sw)
{ {
if (!IS_ERR_OR_NULL(sw)) { if (!IS_ERR_OR_NULL(sw)) {
module_put(sw->dev.parent->driver->owner); module_put(sw->module);
put_device(&sw->dev); put_device(&sw->dev);
} }
} }
@@ -187,15 +188,18 @@ struct usb_role_switch *
usb_role_switch_find_by_fwnode(const struct fwnode_handle *fwnode) usb_role_switch_find_by_fwnode(const struct fwnode_handle *fwnode)
{ {
struct device *dev; struct device *dev;
struct usb_role_switch *sw = NULL;
if (!fwnode) if (!fwnode)
return NULL; return NULL;
dev = class_find_device_by_fwnode(role_class, fwnode); dev = class_find_device_by_fwnode(role_class, fwnode);
if (dev) if (dev) {
WARN_ON(!try_module_get(dev->parent->driver->owner)); sw = to_role_switch(dev);
WARN_ON(!try_module_get(sw->module));
}
return dev ? to_role_switch(dev) : NULL; return sw;
} }
EXPORT_SYMBOL_GPL(usb_role_switch_find_by_fwnode); EXPORT_SYMBOL_GPL(usb_role_switch_find_by_fwnode);
@@ -337,6 +341,7 @@ usb_role_switch_register(struct device *parent,
sw->set = desc->set; sw->set = desc->set;
sw->get = desc->get; sw->get = desc->get;
sw->module = parent->driver->owner;
sw->dev.parent = parent; sw->dev.parent = parent;
sw->dev.fwnode = desc->fwnode; sw->dev.fwnode = desc->fwnode;
sw->dev.class = role_class; sw->dev.class = role_class;