mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 1/4] Input: da7280 - fix input device parent assignment
@ 2026-10-08  9:47 Dmitry Torokhov
  2026-10-08  9:47 ` [PATCH 2/4] Input: drv2665 " Dmitry Torokhov
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Dmitry Torokhov @ 2026-10-08  9:47 UTC (permalink / raw)
  To: linux-input
  Cc: Support Opensource, Roy Im, Dan Murphy, Yegor Yefremov, linux-kernel

Assigning the I2C bus controller (client->dev.parent) instead of the
I2C client (&client->dev) as the parent device after
devm_input_allocate_device() causes input_register_device() to attach
the devm unregistration action to the parent controller device rather
than the client device. This leaves the input device registered on
driver unbind, leading to use-after-free.

devm_input_allocate_device() already sets input_dev->dev.parent to
&client->dev. Drop the redundant and erroneous assignment.

Fixes: cd3f609823a5 ("Input: new da7280 haptic driver")
Assisted-by: LLM
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
---
 drivers/input/misc/da7280.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/input/misc/da7280.c b/drivers/input/misc/da7280.c
index 77fcf868dca2..e607836efb50 100644
--- a/drivers/input/misc/da7280.c
+++ b/drivers/input/misc/da7280.c
@@ -1218,7 +1218,6 @@ static int da7280_probe(struct i2c_client *client)
 	}
 
 	input_dev->name = "da7280-haptic";
-	input_dev->dev.parent = client->dev.parent;
 	input_dev->open = da7280_haptic_open;
 	input_dev->close = da7280_haptic_close;
 	input_set_drvdata(input_dev, haptics);
-- 
2.56.0.385.gd3acb90ef8-goog


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH 2/4] Input: drv2665 - fix input device parent assignment
  2026-10-08  9:47 [PATCH 1/4] Input: da7280 - fix input device parent assignment Dmitry Torokhov
@ 2026-10-08  9:47 ` Dmitry Torokhov
  2026-10-08  9:47 ` [PATCH 3/4] Input: drv2667 " Dmitry Torokhov
  2026-10-08  9:47 ` [PATCH 4/4] Input: tps6507x-ts " Dmitry Torokhov
  2 siblings, 0 replies; 4+ messages in thread
From: Dmitry Torokhov @ 2026-10-08  9:47 UTC (permalink / raw)
  To: linux-input
  Cc: Support Opensource, Roy Im, Dan Murphy, Yegor Yefremov, linux-kernel

Assigning the I2C bus controller (client->dev.parent) instead of the
I2C client (&client->dev) as the parent device after
devm_input_allocate_device() causes input_register_device() to attach
the devm unregistration action to the parent controller device rather
than the client device. This leaves the input device registered on
driver unbind, leading to use-after-free.

devm_input_allocate_device() already sets input_dev->dev.parent to
&client->dev. Drop the redundant and erroneous assignment.

Fixes: 4d10da13467e ("Input: add TI drv2665 haptics driver")
Assisted-by: LLM
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
---
 drivers/input/misc/drv2665.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/input/misc/drv2665.c b/drivers/input/misc/drv2665.c
index 4f8c1f69aa63..134d65fdcf2d 100644
--- a/drivers/input/misc/drv2665.c
+++ b/drivers/input/misc/drv2665.c
@@ -180,7 +180,6 @@ static int drv2665_probe(struct i2c_client *client)
 	}
 
 	haptics->input_dev->name = "drv2665:haptics";
-	haptics->input_dev->dev.parent = client->dev.parent;
 	haptics->input_dev->close = drv2665_close;
 	input_set_drvdata(haptics->input_dev, haptics);
 	input_set_capability(haptics->input_dev, EV_FF, FF_RUMBLE);
-- 
2.56.0.385.gd3acb90ef8-goog


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH 3/4] Input: drv2667 - fix input device parent assignment
  2026-10-08  9:47 [PATCH 1/4] Input: da7280 - fix input device parent assignment Dmitry Torokhov
  2026-10-08  9:47 ` [PATCH 2/4] Input: drv2665 " Dmitry Torokhov
@ 2026-10-08  9:47 ` Dmitry Torokhov
  2026-10-08  9:47 ` [PATCH 4/4] Input: tps6507x-ts " Dmitry Torokhov
  2 siblings, 0 replies; 4+ messages in thread
From: Dmitry Torokhov @ 2026-10-08  9:47 UTC (permalink / raw)
  To: linux-input
  Cc: Support Opensource, Roy Im, Dan Murphy, Yegor Yefremov, linux-kernel

Assigning the I2C bus controller (client->dev.parent) instead of the
I2C client (&client->dev) as the parent device after
devm_input_allocate_device() causes input_register_device() to attach
the devm unregistration action to the parent controller device rather
than the client device. This leaves the input device registered on
driver unbind, leading to use-after-free.

devm_input_allocate_device() already sets input_dev->dev.parent to
&client->dev. Drop the redundant and erroneous assignment.

Fixes: 1c24622572d6 ("Input: add support for the DRV2667 haptic driver")
Assisted-by: LLM
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
---
 drivers/input/misc/drv2667.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/input/misc/drv2667.c b/drivers/input/misc/drv2667.c
index 97309984fa7c..bbda7b4cbdcb 100644
--- a/drivers/input/misc/drv2667.c
+++ b/drivers/input/misc/drv2667.c
@@ -357,7 +357,6 @@ static int drv2667_probe(struct i2c_client *client)
 	}
 
 	haptics->input_dev->name = "drv2667:haptics";
-	haptics->input_dev->dev.parent = client->dev.parent;
 	haptics->input_dev->close = drv2667_close;
 	input_set_drvdata(haptics->input_dev, haptics);
 	input_set_capability(haptics->input_dev, EV_FF, FF_RUMBLE);
-- 
2.56.0.385.gd3acb90ef8-goog


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH 4/4] Input: tps6507x-ts - fix input device parent assignment
  2026-10-08  9:47 [PATCH 1/4] Input: da7280 - fix input device parent assignment Dmitry Torokhov
  2026-10-08  9:47 ` [PATCH 2/4] Input: drv2665 " Dmitry Torokhov
  2026-10-08  9:47 ` [PATCH 3/4] Input: drv2667 " Dmitry Torokhov
@ 2026-10-08  9:47 ` Dmitry Torokhov
  2 siblings, 0 replies; 4+ messages in thread
From: Dmitry Torokhov @ 2026-10-08  9:47 UTC (permalink / raw)
  To: linux-input
  Cc: Support Opensource, Roy Im, Dan Murphy, Yegor Yefremov, linux-kernel

Assigning the MFD parent device (tsc->dev) instead of the platform
device (&pdev->dev) as the parent device after
devm_input_allocate_device(&pdev->dev) splits devres management across
two devices. As a result, input_register_device() attaches the devm
unregistration action to the MFD parent device rather than the platform
device, leaving the input device registered when the platform driver
unbinds.

devm_input_allocate_device(&pdev->dev) already sets
input_dev->dev.parent to &pdev->dev. Drop the redundant and erroneous
assignment.

Fixes: 2e2a0db8c88d ("Input: tps6507x-ts - update to devm_* API")
Assisted-by: LLM
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
---
 drivers/input/touchscreen/tps6507x-ts.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/input/touchscreen/tps6507x-ts.c b/drivers/input/touchscreen/tps6507x-ts.c
index f48871767763..e84dc3ea1fcb 100644
--- a/drivers/input/touchscreen/tps6507x-ts.c
+++ b/drivers/input/touchscreen/tps6507x-ts.c
@@ -251,7 +251,6 @@ static int tps6507x_ts_probe(struct platform_device *pdev)
 
 	input_dev->name = "TPS6507x Touchscreen";
 	input_dev->phys = tsc->phys;
-	input_dev->dev.parent = tsc->dev;
 	input_dev->id.bustype = BUS_I2C;
 	if (init_data) {
 		input_dev->id.vendor = init_data->vendor;
-- 
2.56.0.385.gd3acb90ef8-goog


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-08  9:47 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08  9:47 [PATCH 1/4] Input: da7280 - fix input device parent assignment Dmitry Torokhov
2026-10-08  9:47 ` [PATCH 2/4] Input: drv2665 " Dmitry Torokhov
2026-10-08  9:47 ` [PATCH 3/4] Input: drv2667 " Dmitry Torokhov
2026-10-08  9:47 ` [PATCH 4/4] Input: tps6507x-ts " Dmitry Torokhov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®