|
|
Log in / Subscribe / Register

gpio: Adopt revocable mechanism for UAF prevention

From:  Tzung-Bi Shih <tzungbi-AT-kernel.org>
To:  Bartosz Golaszewski <brgl-AT-kernel.org>, Linus Walleij <linusw-AT-kernel.org>
Subject:  [PATCH v3 00/11] gpio: Adopt revocable mechanism for UAF prevention
Date:  Fri, 13 Feb 2026 09:29:47 +0000
Message-ID:  <20260213092958.864411-1-tzungbi@kernel.org>
Cc:  Greg Kroah-Hartman <gregkh-AT-linuxfoundation.org>, "Rafael J. Wysocki" <rafael-AT-kernel.org>, Danilo Krummrich <dakr-AT-kernel.org>, Jonathan Corbet <corbet-AT-lwn.net>, Shuah Khan <shuah-AT-kernel.org>, Laurent Pinchart <laurent.pinchart-AT-ideasonboard.com>, Wolfram Sang <wsa+renesas-AT-sang-engineering.com>, Jason Gunthorpe <jgg-AT-nvidia.com>, Johan Hovold <johan-AT-kernel.org>, "Paul E . McKenney" <paulmck-AT-kernel.org>, Dan Williams <dan.j.williams-AT-intel.com>, chrome-platform-AT-lists.linux.dev, tzungbi-AT-kernel.org, linux-gpio-AT-vger.kernel.org, linux-kselftest-AT-vger.kernel.org, linux-kernel-AT-vger.kernel.org
Archive-link:  Article

This series transitions the UAF prevention logic within the GPIO core
(gpiolib) to use the 'revocable' mechanism.

The existing code aims to prevent UAF issues when the underlying GPIO
chip is removed.  This series replaces that custom logic with the
generic 'revocable' API, which is designed to handle such lifecycle
dependencies.  There should be no changes in behavior.

The series applies after:
- https://lore.kernel.org/all/20260213092307.858908-1-tzung...
- https://lore.kernel.org/all/20260205092840.2574840-1-tzun...

Tzung-Bi Shih (11):
  gpio: Access `gpio_bus_type` in gpiochip_setup_dev()
  gpio: Remove redundant check for struct gpio_chip
  gpio: sysfs: Remove redundant check for struct gpio_chip
  gpio: Ensure struct gpio_chip for gpiochip_setup_dev()
  gpio: cdev: Don't check struct gpio_chip in gpio_chrdev_open()
=> The first 5 patches are refactors.  They try to make the subsequent
   changes easier or at least clear.

  selftests: gpio: Add gpio-cdev-uaf tests
=> The following patch adds kselftest cases for some classic UAF
   scenarios.

  gpio: Add revocable provider handle for struct gpio_chip
  gpio: cdev: Leverage revocable for accessing struct gpio_chip
  gpio: Remove gpio_chip_guard by using revocable
  gpio: Leverage revocable for accessing struct gpio_chip
=> The following 4 patches start to replace the existing code.

  gpio: Remove unused `chip` and `srcu` in struct gpio_device
=> The last patch removes the unused fields for the custom logic as all
   of them should be transiting to revocable.

---
v3:
- Change revocable API usages accordingly.

v2: https://lore.kernel.org/all/20260203061059.975605-1-tzung...
- Separate fixes patches from v1.  Some of them have been landed.
- Combine small patches into one as they become simpler after applying
  https://lore.kernel.org/all/20260129143733.45618-1-tzungb...

v1: https://lore.kernel.org/all/20260116081036.352286-1-tzung...

 drivers/gpio/gpiolib-cdev.c                   |  95 ++----
 drivers/gpio/gpiolib-cdev.h                   |   2 +-
 drivers/gpio/gpiolib-sysfs.c                  |  53 ++-
 drivers/gpio/gpiolib-sysfs.h                  |   8 +-
 drivers/gpio/gpiolib.c                        | 305 ++++++++----------
 drivers/gpio/gpiolib.h                        |  27 +-
 tools/testing/selftests/gpio/Makefile         |   5 +-
 tools/testing/selftests/gpio/gpio-cdev-uaf.c  | 292 +++++++++++++++++
 tools/testing/selftests/gpio/gpio-cdev-uaf.sh |  63 ++++
 9 files changed, 541 insertions(+), 309 deletions(-)
 create mode 100644 tools/testing/selftests/gpio/gpio-cdev-uaf.c
 create mode 100755 tools/testing/selftests/gpio/gpio-cdev-uaf.sh

-- 
2.53.0.310.g728cabbaf7-goog




Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds