ACPI / APEI: Add missing synchronize_rcu() on NOTIFY_SCI removal
authorJames Morse <james.morse@arm.com>
Thu, 16 Mar 2017 14:30:39 +0000 (14:30 +0000)
committerWilly Tarreau <w@1wt.eu>
Thu, 2 Nov 2017 09:45:59 +0000 (10:45 +0100)
commit 7d64f82cceb21e6d95db312d284f5f195e120154 upstream.

When removing a GHES device notified by SCI, list_del_rcu() is used,
ghes_remove() should call synchronize_rcu() before it goes on to call
kfree(ghes), otherwise concurrent RCU readers may still hold this list
entry after it has been freed.

Signed-off-by: James Morse <james.morse@arm.com>
Reviewed-by: "Huang, Ying" <ying.huang@intel.com>
Fixes: 81e88fdc432a (ACPI, APEI, Generic Hardware Error Source POLL/IRQ/NMI notification type support)
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
drivers/acpi/apei/ghes.c

index 070b843c37ee0f6e3b8fd1eabb5ad091848c516a..8cff7cae7331c70387eb36ec71f4d503cb5ae2a1 100644 (file)
@@ -988,6 +988,7 @@ static int ghes_remove(struct platform_device *ghes_dev)
                if (list_empty(&ghes_sci))
                        unregister_acpi_hed_notifier(&ghes_notifier_sci);
                mutex_unlock(&ghes_list_mutex);
+               synchronize_rcu();
                break;
        case ACPI_HEST_NOTIFY_NMI:
                mutex_lock(&ghes_list_mutex);