From: Shang En Sim <sim@shangen.org>
To: "Hans de Goede" <hansg@kernel.org>,
"Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>
Cc: "Krishna Chomal" <krishna.chomal108@gmail.com>,
"Suryansh Singh" <technosfan14@gmail.com>,
"Emre Cecanpunar" <emreleno@gmail.com>,
"Radhey Kalra" <radheykalra901@gmail.com>,
"Kürşat Abaylı" <hello@kursatabayli.dev>,
"Alain Cousinie" <alain.cousinie@laposte.net>,
platform-driver-x86@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v2 1/2] platform/x86: hp-wmi: Fix hwmon keep-alive teardown
Date: Wed, 30 Sep 2026 22:10:11 -0500 [thread overview]
Message-ID: <20261001031012.48473-2-sim@shangen.org> (raw)
In-Reply-To: <20261001031012.48473-1-sim@shangen.org>
hp_wmi_hwmon_init() initialises keep_alive_dwork with INIT_DELAYED_WORK()
and relies on hp_wmi_bios_remove() to cancel it. Nothing cancels the work
if probe fails after hp_wmi_hwmon_init() has run, so the devm-managed
priv can be freed while the work is still pending.
The ordering is also wrong on both ends. The work is initialised only
after the hwmon device is registered, so a sysfs write to pwm1_enable
can schedule an uninitialised work item. On removal, the work is
cancelled in .remove(), before devres unregisters the hwmon device, so a
sysfs write can requeue it after the cancel.
Use devm_delayed_work_autocancel() and set it up before registering the
hwmon device. devres then cancels the work on every teardown path, after
the hwmon sysfs interface has been removed and before priv and its mutex
are released. Drop the now-unneeded cancel in hp_wmi_bios_remove() and
the platform drvdata that was only used for it.
Fixes: c203c59fb5de ("platform/x86: hp-wmi: implement fan keep-alive")
Suggested-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Shang En Sim <sim@shangen.org>
---
drivers/platform/x86/hp/hp-wmi.c | 19 ++++++++++++-------
1 file changed, 12 insertions(+), 7 deletions(-)
diff --git a/drivers/platform/x86/hp/hp-wmi.c b/drivers/platform/x86/hp/hp-wmi.c
index 7ab81ce5f8d4..2bf0bb04dcec 100644
--- a/drivers/platform/x86/hp/hp-wmi.c
+++ b/drivers/platform/x86/hp/hp-wmi.c
@@ -18,6 +18,7 @@
#include <linux/bits.h>
#include <linux/cleanup.h>
#include <linux/compiler_attributes.h>
+#include <linux/devm-helpers.h>
#include <linux/dmi.h>
#include <linux/fixp-arith.h>
#include <linux/hwmon.h>
@@ -2571,7 +2572,6 @@ static int __init hp_wmi_bios_setup(struct platform_device *device)
static void __exit hp_wmi_bios_remove(struct platform_device *device)
{
int i;
- struct hp_wmi_hwmon_priv *priv;
for (i = 0; i < rfkill2_count; i++) {
rfkill_unregister(rfkill2[i].rfkill);
@@ -2590,10 +2590,6 @@ static void __exit hp_wmi_bios_remove(struct platform_device *device)
rfkill_unregister(wwan_rfkill);
rfkill_destroy(wwan_rfkill);
}
-
- priv = platform_get_drvdata(device);
- if (priv)
- cancel_delayed_work_sync(&priv->keep_alive_dwork);
}
static int hp_wmi_resume_handler(struct device *device)
@@ -2941,6 +2937,17 @@ static int hp_wmi_hwmon_init(void)
ret = hp_wmi_setup_fan_settings(priv);
if (ret)
return ret;
+
+ /*
+ * Set up the work before registering hwmon so that, on teardown,
+ * it is cancelled only after the sysfs writers that schedule it
+ * are gone.
+ */
+ ret = devm_delayed_work_autocancel(dev, &priv->keep_alive_dwork,
+ hp_wmi_hwmon_keep_alive_handler);
+ if (ret)
+ return ret;
+
hwmon = devm_hwmon_device_register_with_info(dev, "hp", priv,
&chip_info, NULL);
@@ -2949,8 +2956,6 @@ static int hp_wmi_hwmon_init(void)
return PTR_ERR(hwmon);
}
- INIT_DELAYED_WORK(&priv->keep_alive_dwork, hp_wmi_hwmon_keep_alive_handler);
- platform_set_drvdata(hp_wmi_platform_dev, priv);
ret = hp_wmi_apply_fan_settings(priv);
if (ret)
dev_warn(dev, "Failed to apply initial fan settings: %d\n", ret);
--
2.56.0
next prev parent reply other threads:[~2026-10-01 3:25 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 3:10 [PATCH v2 0/2] platform/x86: hp-wmi: Spectre charge behaviour Shang En Sim
2026-10-01 3:10 ` Shang En Sim [this message]
2026-10-01 3:10 ` [PATCH v2 2/2] platform/x86: hp-wmi: add charge_behaviour support for Spectre 8C15/8C17 Shang En Sim
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001031012.48473-2-sim@shangen.org \
--to=sim@shangen.org \
--cc=alain.cousinie@laposte.net \
--cc=emreleno@gmail.com \
--cc=hansg@kernel.org \
--cc=hello@kursatabayli.dev \
--cc=ilpo.jarvinen@linux.intel.com \
--cc=krishna.chomal108@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=platform-driver-x86@vger.kernel.org \
--cc=radheykalra901@gmail.com \
--cc=technosfan14@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®