On Wed, Oct 14, 2020 at 04:09:12PM +0200, Lukas Wunner wrote:
> Apparently the problem is that spi_unregister_controller() drops the
> last ref on the controller, causing it to be freed, and afterwards we
> access the controller's private data, which is part of the same
> allocation as struct spi_controller:
>
> bcm2835_spi_remove()
>   spi_unregister_controller()
>     device_unregister()
>       put_device()
>         spi_controller_release()  #  spi_master_class.dev_release()
>         kfree(ctlr)
>   bcm2835_dma_release(ctlr, bs)
>   ...

Also see these threads:
https://lore.kernel.org/linux-spi/[email protected]/T/#t
https://lore.kernel.org/linux-spi/[email protected]/T/#u
And here's how _not_ to fix it:
https://lore.kernel.org/linux-spi/[email protected]/T/#t
At least without some care to not break other things:
https://lore.kernel.org/linux-spi/[email protected]/T/#t

Reply via email to