This series fixes two races in fastrpc_rpmsg_probe() that can be triggered when userspace opens a fastrpc device node concurrently with the rpmsg probe sequence.
fastrpc_device_register() calls misc_register() before the channel context is fully initialised. A concurrent open() in that window hits kref_get() on a zero refcount, and because fastrpc_cb_devices_create() has not yet run sesscount is 0, the error path calls kref_put() on the saturated refcount, triggering kfree() of the channel context. A subsequent IRQ-path fastrpc_rpmsg_callback() then dereferences the freed spinlock, causing a kernel panic. A NULL dereference in the fastrpc_device_open() error path when cctx->rpdev is concurrently cleared by fastrpc_rpmsg_remove() is also addressed. Signed-off-by: Vinayak Katoch <[email protected]> --- Vinayak Katoch (2): misc: fastrpc: fix NULL rpdev dereference when session alloc fails misc: fastrpc: fix init ordering race in rpmsg probe drivers/misc/fastrpc.c | 55 ++++++++++++++++++++++++++------------------------ 1 file changed, 29 insertions(+), 26 deletions(-) --- base-commit: 5c4d4169604b335c38bbc79bc1fc03042981fc6f change-id: 20260923-fastrpc-probe-fixes-30c1980b50e6 prerequisite-change-id: 20260609-dup-sessions-ea2acaac1994:v5 prerequisite-patch-id: 425dc9414848bbc3f2a053d067195d849898e2ae prerequisite-patch-id: 4fea14b47d11a5a3e18065d8cf3a461841ee2b86 prerequisite-patch-id: da0a3d55397a522ea4b77769e387df9faea8e024 Best regards, -- Vinayak Katoch <[email protected]>
