• Steven Rostedt (Google)'s avatar
    treewide: Convert del_timer*() to timer_shutdown*() · 292a089d
    Steven Rostedt (Google) authored
    Due to several bugs caused by timers being re-armed after they are
    shutdown and just before they are freed, a new state of timers was added
    called "shutdown".  After a timer is set to this state, then it can no
    longer be re-armed.
    
    The following script was run to find all the trivial locations where
    del_timer() or del_timer_sync() is called in the same function that the
    object holding the timer is freed.  It also ignores any locations where
    the timer->function is modified between the del_timer*() and the free(),
    as that is not considered a "trivial" case.
    
    This was created by using a coccinelle script and the following
    commands:
    
        $ cat timer.cocci
        @@
        expression ptr, slab;
        identifier timer, rfield;
        @@
        (
        -       del_timer(&ptr->timer);
        +       timer_shutdown(&ptr->timer);
        |
        -       del_timer_sync(&ptr->timer);
        +       timer_shutdown_sync(&ptr->timer);
        )
          ... when strict
              when != ptr->timer
        (
                kfree_rcu(ptr, rfield);
        |
                kmem_cache_free(slab, ptr);
        |
                kfree(ptr);
        )
    
        $ spatch timer.cocci . > /tmp/t.patch
        $ patch -p1 < /tmp/t.patch
    
    Link: https://lore.kernel.org/lkml/20221123201306.823305113@linutronix.de/Signed-off-by: default avatarSteven Rostedt (Google) <rostedt@goodmis.org>
    Acked-by: Pavel Machek <pavel@ucw.cz> [ LED ]
    Acked-by: Kalle Valo <kvalo@kernel.org> [ wireless ]
    Acked-by: Paolo Abeni <pabeni@redhat.com> [ networking ]
    Signed-off-by: default avatarLinus Torvalds <torvalds@linux-foundation.org>
    292a089d
hostap_ap.c 85.1 KB