Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

power: supply: sc27xx: Fix external_power_changed race

sc27xx_fgu_external_power_changed() dereferences data->battery,
which gets sets in ab8500_btemp_probe() like this:

data->battery = devm_power_supply_register(dev, &sc27xx_fgu_desc,
&fgu_cfg);

As soon as devm_power_supply_register() has called device_add()
the external_power_changed callback can get called. So there is a window
where sc27xx_fgu_external_power_changed() may get called while
data->battery has not been set yet leading to a NULL pointer dereference.

Fixing this is easy. The external_power_changed callback gets passed
the power_supply which will eventually get stored in data->battery,
so sc27xx_fgu_external_power_changed() can simply directly use
the passed in psy argument which is always valid.

After this change sc27xx_fgu_external_power_changed() is reduced to just
"power_supply_changed(psy);" and it has the same prototype. While at it
simply replace it with making the external_power_changed callback
directly point to power_supply_changed.

Cc: Orson Zhai <orsonzhai@gmail.com>
Cc: Chunyan Zhang <zhang.lyra@gmail.com>
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>

authored by

Hans de Goede and committed by
Sebastian Reichel
4d5c129d 029a443b

+1 -8
+1 -8
drivers/power/supply/sc27xx_fuel_gauge.c
··· 733 733 return ret; 734 734 } 735 735 736 - static void sc27xx_fgu_external_power_changed(struct power_supply *psy) 737 - { 738 - struct sc27xx_fgu_data *data = power_supply_get_drvdata(psy); 739 - 740 - power_supply_changed(data->battery); 741 - } 742 - 743 736 static int sc27xx_fgu_property_is_writeable(struct power_supply *psy, 744 737 enum power_supply_property psp) 745 738 { ··· 767 774 .num_properties = ARRAY_SIZE(sc27xx_fgu_props), 768 775 .get_property = sc27xx_fgu_get_property, 769 776 .set_property = sc27xx_fgu_set_property, 770 - .external_power_changed = sc27xx_fgu_external_power_changed, 777 + .external_power_changed = power_supply_changed, 771 778 .property_is_writeable = sc27xx_fgu_property_is_writeable, 772 779 .no_thermal = true, 773 780 };