[PATCH 1/2] firewire: cdev: hold client reference for fw_iso_resource_auto lifetime

From: Takashi Sakamoto

Date: Wed Sep 23 2026 - 14:19:32 EST


The fw_iso_resource_auto object can outlive the operation that created
it since hte main operation for it is done in a work item. This work and
release paths access members of the client structure, therefore the
client structure must remain valid for the lifetime of an
fw_iso_resource_auto object.

Hold a reference to the client structure for the lifetime of the
fw_iso_resource_auto object.

Signed-off-by: Takashi Sakamoto <o-takashi@xxxxxxxxxxxxx>
---
drivers/firewire/core-cdev.c | 5 +++++
1 file changed, 5 insertions(+)

diff --git a/drivers/firewire/core-cdev.c b/drivers/firewire/core-cdev.c
index 50419f10b04f..9964c66f2989 100644
--- a/drivers/firewire/core-cdev.c
+++ b/drivers/firewire/core-cdev.c
@@ -1406,6 +1406,7 @@ static void iso_resource_auto_work(struct work_struct *work)
// xarray and prepare for deletion, unless the client is shutting down.
scoped_guard(spinlock_irq, &client->lock) {
if (!client->in_shutdown && xa_erase(&client->resource_xa, index)) {
+ // For the incrementation by add_client_resource().
client_put(client);
free = true;
}
@@ -1445,6 +1446,9 @@ static void iso_resource_auto_work(struct work_struct *work)
kfree(r->e_alloc);
kfree(r->e_dealloc);
kfree(r);
+
+ // For the incrementation by ioctl_allocate_iso_resource().
+ client_put(client);
}
out:
client_put(client);
@@ -1491,6 +1495,7 @@ static int ioctl_allocate_iso_resource(struct client *client, union ioctl_arg *a
if (err < 0)
return err;
request->handle = r->resource.handle;
+ client_get(client);

retain_and_null_ptr(e1);
retain_and_null_ptr(e2);
--
2.53.0