From a1434939a582474d5c07e759523b77d5b8ef28fc Mon Sep 17 00:00:00 2001 From: Greg Kroah-Hartman Date: Thu, 21 Nov 2024 22:00:15 +0000 Subject: [PATCH] Revert "spi: fix use-after-free of the add_lock mutex" This reverts commit 54c2c96eafcfd242e52e932ab54ace4784efe1dd which is commit 6c53b45c71b4920b5e62f0ea8079a1da382b9434 upstream. It breaks the Android kernel abi and can be brought back in the future in an abi-safe way if it is really needed. Bug: 161946584 Change-Id: Icce07d26ecdbeb799b479babd47730046b402902 Signed-off-by: Greg Kroah-Hartman --- drivers/spi/spi.c | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/drivers/spi/spi.c b/drivers/spi/spi.c index a54403b02f22..d5a845bd5564 100644 --- a/drivers/spi/spi.c +++ b/drivers/spi/spi.c @@ -2674,6 +2674,13 @@ void spi_unregister_controller(struct spi_controller *ctlr) device_del(&ctlr->dev); + /* Release the last reference on the controller if its driver + * has not yet been converted to devm_spi_alloc_master/slave(). + */ + if (!devres_find(ctlr->dev.parent, devm_spi_release_controller, + devm_spi_match_controller, ctlr)) + put_device(&ctlr->dev); + /* free bus id */ mutex_lock(&board_lock); if (found == ctlr) @@ -2682,13 +2689,6 @@ void spi_unregister_controller(struct spi_controller *ctlr) if (IS_ENABLED(CONFIG_SPI_DYNAMIC)) mutex_unlock(&ctlr->add_lock); - - /* Release the last reference on the controller if its driver - * has not yet been converted to devm_spi_alloc_master/slave(). - */ - if (!devres_find(ctlr->dev.parent, devm_spi_release_controller, - devm_spi_match_controller, ctlr)) - put_device(&ctlr->dev); } EXPORT_SYMBOL_GPL(spi_unregister_controller);