serial: 8250: fix potential deadlock in rs485-mode
authorTomas Melin <tomas.melin@vaisala.com>
Fri, 27 Oct 2017 12:16:30 +0000 (15:16 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 22 May 2021 08:57:43 +0000 (10:57 +0200)
[ Upstream commit b86f86e8e7c5264bb8f5835d60f9ec840d9f5a7a ]

Canceling hrtimer when holding uart spinlock can deadlock.

CPU0: syscall write
          -> get uart port spinlock
              -> write uart
                  -> start_tx_rs485
                      -> hrtimer_cancel
                          -> wait for hrtimer callback to finish

CPU1: hrtimer IRQ
          -> run hrtimer
              -> em485_handle_stop_tx
                  -> get uart port spinlock

CPU0 is waiting for the hrtimer callback to finish, but the hrtimer
callback running on CPU1 is waiting to get the uart port spinlock.

This deadlock can be avoided by not canceling the hrtimers in these paths.
Setting active_timer=NULL can be done without accessing hrtimer,
and that will effectively cancel operations that would otherwise have been
performed by the hrtimer callback.

Signed-off-by: Tomas Melin <tomas.melin@vaisala.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/tty/serial/8250/8250_port.c

index 9880a50d664fcb5a88de217355ffd8f9832ac832..25e8ccd6865aef864b6cf26c45ea1dc852a71ae8 100644 (file)
@@ -1527,7 +1527,6 @@ static inline void __stop_tx(struct uart_8250_port *p)
                        return;
 
                em485->active_timer = NULL;
-               hrtimer_cancel(&em485->start_tx_timer);
 
                __stop_tx_rs485(p);
        }
@@ -1591,8 +1590,6 @@ static inline void start_tx_rs485(struct uart_port *port)
                serial8250_stop_rx(&up->port);
 
        em485->active_timer = NULL;
-       if (hrtimer_is_queued(&em485->stop_tx_timer))
-               hrtimer_cancel(&em485->stop_tx_timer);
 
        mcr = serial8250_in_MCR(up);
        if (!!(up->port.rs485.flags & SER_RS485_RTS_ON_SEND) !=