Re: [PATCH] tty: nozomi: lock tty_icount reads against the IRQ update path
From: Greg KH
Date: Wed Sep 23 2026 - 06:48:27 EST
On Sun, Sep 20, 2026 at 12:23:49AM +0500, Muhammad Bilal wrote:
> receive_flow_control() updates port->tty_icount.{cts,dsr,rng,dcd}
> while interrupt_handler() holds dc->spin_mutex, but ntty_tiocgicount()
> and the TIOCMIWAIT snapshot/compare loop in ntty_ioctl()/
> ntty_cflags_changed() read the same multi-field struct with no lock
> at all. A concurrent update can be observed mid-copy, and KCSAN flags
> the unlocked access.
>
> Add ntty_get_icount() to snapshot port->tty_icount under
> dc->spin_mutex and use it at all three read sites, matching the lock
> already used on the update side.
>
> Fixes: 20fd1e3bea55 ("nozomi driver")
> Signed-off-by: Muhammad Bilal <meatuni001@xxxxxxxxx>
> ---
> drivers/tty/nozomi.c | 19 ++++++++++++++++---
> 1 file changed, 16 insertions(+), 3 deletions(-)
You forgot an Assisted-by: tag, right?
And how did you test this?
>
> diff --git a/drivers/tty/nozomi.c b/drivers/tty/nozomi.c
> index ed99dbc9f990..4b2e224c0aa2 100644
> --- a/drivers/tty/nozomi.c
> +++ b/drivers/tty/nozomi.c
> @@ -1671,10 +1671,23 @@ static int ntty_tiocmset(struct tty_struct *tty,
> return 0;
> }
>
> +static struct async_icount ntty_get_icount(struct port *port)
> +{
> + struct nozomi *dc = port->dc;
> + struct async_icount cnow;
> + unsigned long flags;
> +
> + spin_lock_irqsave(&dc->spin_mutex, flags);
> + cnow = port->tty_icount;
> + spin_unlock_irqrestore(&dc->spin_mutex, flags);
> +
> + return cnow;
This is text-book LLM-written code as they do not know how to write
"modern" Linux kernel code. Please fix.
thanks,
greg k-h