Re: [PATCH] serial: core: shut down initialized port on removal
From: Greg KH
Date: Thu Oct 01 2026 - 05:25:40 EST
On Sat, Sep 26, 2026 at 04:05:31PM +0300, IgorpetinDev wrote:
> Hi Greg,
> Note: syzbot did not actually provide a reproducer for this crash -
> this patch is based on code analysis of the trace, not on hardware
> testing. The pcl812 trigger from syzkaller is synthetic.
>
> On a console port, tty_port_shutdown() skips ops->shutdown() because
> port->console is true, so the IRQ is never released.
> If the device is later unbound/removed, serial_core_remove_one_port()
> frees uport->name via kfree(), but the IRQ is never freed.
> Result: a stale irqaction pointing at freed memory in action->name,
> even without anything else requesting that IRQ line.
>
> sashiko-bot also pointed out a data race on port->console = false
> outside the mutex - separate issue, but relevant.
>
> If the underlying problem looks real to you, I'd rather withdraw this
> patch, put together an actual reproducer (unbind a console port, check
> for the stale irqaction), fix the locking properly, and send a v2.
Please do so, thanks.
greg k-h