mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Christopher Hoover <ch@murgatroid.com>
To: Jonathan Cameron <jic23@kernel.org>
Cc: "Jiri Kosina" <jikos@kernel.org>,
	"Srinivas Pandruvada" <srinivas.pandruvada@linux.intel.com>,
	"David Lechner" <dlechner@baylibre.com>,
	"Nuno Sá" <nuno.sa@analog.com>,
	"Andy Shevchenko" <andy@kernel.org>,
	linux-iio@vger.kernel.org, linux-input@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	"Christopher Hoover" <ch@murgatroid.com>
Subject: [PATCH 0/2] iio: hid-sensors: fix shared callbacks in temperature and humidity
Date: Wed,  7 Oct 2026 00:23:27 -0700	[thread overview]
Message-ID: <20261007072329.27806-1-ch@murgatroid.com> (raw)

hid-sensor-temperature and hid-sensor-humidity keep a single static
struct hid_sensor_hub_callbacks for all of their instances and
overwrite its pdev on every probe.  The other HID sensor drivers keep
theirs per instance.  With two temperature sensors, input reports for
one are delivered with the other's platform device; once that device
is removed, platform_get_drvdata() returns NULL and
temperature_capture_sample() dereferences it:

  BUG: kernel NULL pointer dereference, address: 00000000000003a8
  RIP: 0010:temperature_capture_sample+0xd/0x50 [hid_sensor_temperature]
  Call Trace:
   sensor_hub_raw_event+0x3fc/0x7a0 [hid_sensor_hub]
   __hid_input_report+0x140/0x230 [hid]
   hid_safe_input_report+0x14/0x30 [hid]
   uhid_char_write+0x1f6/0x340 [uhid]

The oops happens with the hub's spinlock held, so the hub's removal
then hangs until reboot.

I hit this with a userspace daemon that presents a USB thermometer as
a HID temperature sensor through uhid: creating a second uhid sensor
and destroying it while the first keeps sending input reports
reproduced it twice on 7.0. 

The patches move the callbacks into each driver's state, as
hid-sensor-accel-3d does.  Humidity has the same code but I have not
reproduced it there.

Not addressed here: sensor_hub_raw_event() looks up the callback under
dyn_callback_lock and calls it under pdata->lock, while
sensor_hub_remove_callback() takes only dyn_callback_lock, so a
report racing a remove can still reach a callback whose driver is
going away.  That predates this series.

Christopher Hoover (2):
  iio: temperature: hid-sensor-temperature: Use per-instance callbacks
  iio: humidity: hid-sensor-humidity: Use per-instance callbacks

 drivers/iio/humidity/hid-sensor-humidity.c       | 12 +++++-------
 drivers/iio/temperature/hid-sensor-temperature.c | 12 +++++-------
 2 files changed, 10 insertions(+), 14 deletions(-)


base-commit: 9ee8306121495d2a25aa5d1bfd519f2748786b83
-- 
2.43.0


             reply	other threads:[~2026-10-07  7:34 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07  7:23 Christopher Hoover [this message]
2026-10-07  7:23 ` [PATCH 1/2] iio: temperature: hid-sensor-temperature: Use per-instance callbacks Christopher Hoover
2026-10-07  7:23 ` [PATCH 2/2] iio: humidity: hid-sensor-humidity: " Christopher Hoover
2026-10-07 18:44 ` [PATCH v2 0/3] iio: hid-sensors: fix shared callbacks in temperature and humidity Christopher Hoover
2026-10-07 18:44   ` [PATCH v2 1/3] HID: hid-sensor-hub: Synchronize callback removal with raw events Christopher Hoover
2026-10-07 18:44   ` [PATCH v2 2/3] iio: temperature: hid-sensor-temperature: Use per-instance callbacks Christopher Hoover
2026-10-07 18:44   ` [PATCH v2 3/3] iio: humidity: hid-sensor-humidity: " Christopher Hoover

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261007072329.27806-1-ch@murgatroid.com \
    --to=ch@murgatroid.com \
    --cc=andy@kernel.org \
    --cc=dlechner@baylibre.com \
    --cc=jic23@kernel.org \
    --cc=jikos@kernel.org \
    --cc=linux-iio@vger.kernel.org \
    --cc=linux-input@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=nuno.sa@analog.com \
    --cc=srinivas.pandruvada@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®