linux-gbmc: pmbus: protect regulator ops with mutex
Backport upstream patches for CVE-2026-31486 and CVE-2026-72395
to linux-gbmc 6.12 (linux-gbmc_lts.bb).
In the PMBus core driver, regulator routines get_voltage, set_voltage,
and list_voltage previously omitted data->update_lock acquisition,
allowing concurrent threads (e.g. hwmon polling) to interleave
PMBUS_PAGE register switching and corrupt telemetry or direct voltage
writes to the wrong rail.
This backport:
1. Protects regulator operations with update_lock.
2. Defers regulator_notifier_call_chain() dispatch to an asynchronous
workqueue outside update_lock to prevent recursive mutex deadlock
with pmbus_fault_handler().
3. Iterates over atomic fault event masks bit-by-bit to ensure
regulator_handle_critical() processes all simultaneous events.
Upstream-Status: Backport [https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=754bd2b4a084b90b5e7b630e1f423061a9b9b761]
Upstream-Status: Backport [https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b0ff6b6ae9c5183ef701ece7016698bde5a5bfba]
CVE: CVE-2026-31486
CVE: CVE-2026-72395
Tested:
- Successfully compiled full firmware image via BitBake:
bitbake obmc-phosphor-image (10,484 tasks passed, 0 patch fuzz).
- Signed and flashed image on real hardware (wkcw14-nfd11).
- Executed 5,000-cycle high-frequency concurrent page-switching stress
test (in1_input vs in2_input) without read failures or bus errors:
Total Iterations: 5000 | Read Failures: 0 | New Kernel Errors: 0
Google-Bug-Id: 540140798
Change-Id: Id5a541cf765384d6047a5fe2741e6ad149843007
Signed-off-by: Joseph Chan <josephctchan@google.com>
3 files changed