Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

HID: hid-sensor-hub: don't use stale platform-data on remove

The hid-sensor-hub creates the individual device structs and transfers them
to the created mfd platform-devices via the platform_data in the mfd_cell.

Before e651a1da442a ("HID: hid-sensor-hub: Allow parallel synchronous reads")
the sensor-hub was managing access centrally, with one "completion" in the
hub's data structure, which needed to be finished on removal at the latest.

The mentioned commit then moved this central management to each hid sensor
device, resulting on a completion in each struct hid_sensor_hub_device.
The remove procedure was adapted to go through all sensor devices and
finish any pending "completion".

What this didn't take into account was, platform_device_add_data() that is
used by mfd_add{_hotplug}_devices() does a kmemdup on the submitted
platform-data. So the data the platform-device gets is a copy of the
original data, meaning that the device worked on a different completion
than what sensor_hub_remove() currently wants to access.

To fix that, use device_for_each_child() to go through each child-device
similar to how mfd_remove_devices() unregisters the devices later and
with that get the live platform_data to finalize the correct completion.

Fixes: e651a1da442a ("HID: hid-sensor-hub: Allow parallel synchronous reads")
Cc: stable@vger.kernel.org
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Acked-by: Benjamin Tissoires <bentiss@kernel.org>
Acked-by: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
Acked-by: Jiri Kosina <jkosina@suse.com>
Link: https://lore.kernel.org/r/20241107114712.538976-2-heiko@sntech.de
Signed-off-by: Lee Jones <lee@kernel.org>

authored by

Heiko Stuebner and committed by
Lee Jones
8a5b38c3 40384c84

+14 -7
+14 -7
drivers/hid/hid-sensor-hub.c
··· 730 730 return ret; 731 731 } 732 732 733 + static int sensor_hub_finalize_pending_fn(struct device *dev, void *data) 734 + { 735 + struct hid_sensor_hub_device *hsdev = dev->platform_data; 736 + 737 + if (hsdev->pending.status) 738 + complete(&hsdev->pending.ready); 739 + 740 + return 0; 741 + } 742 + 733 743 static void sensor_hub_remove(struct hid_device *hdev) 734 744 { 735 745 struct sensor_hub_data *data = hid_get_drvdata(hdev); 736 746 unsigned long flags; 737 - int i; 738 747 739 748 hid_dbg(hdev, " hardware removed\n"); 740 749 hid_hw_close(hdev); 741 750 hid_hw_stop(hdev); 751 + 742 752 spin_lock_irqsave(&data->lock, flags); 743 - for (i = 0; i < data->hid_sensor_client_cnt; ++i) { 744 - struct hid_sensor_hub_device *hsdev = 745 - data->hid_sensor_hub_client_devs[i].platform_data; 746 - if (hsdev->pending.status) 747 - complete(&hsdev->pending.ready); 748 - } 753 + device_for_each_child(&hdev->dev, NULL, 754 + sensor_hub_finalize_pending_fn); 749 755 spin_unlock_irqrestore(&data->lock, flags); 756 + 750 757 mfd_remove_devices(&hdev->dev); 751 758 mutex_destroy(&data->mutex); 752 759 }