From: Esben Haabendal <esben@geanix.com>
To: "Jonathan Cameron" <jic23@kernel.org>
Cc: "Lars-Peter Clausen" <lars@metafoo.de>,
"Rob Herring" <robh@kernel.org>,
"Krzysztof Kozlowski" <krzk+dt@kernel.org>,
"Conor Dooley" <conor+dt@kernel.org>,
"Martin Kepplinger" <martink@posteo.de>,
"Sean Nyekjaer" <sean@geanix.com>,
"David Lechner" <dlechner@baylibre.com>,
"Nuno Sá" <nuno.sa@analog.com>,
"Andy Shevchenko" <andy@kernel.org>,
"Martin Kepplinger" <martin.kepplinger@theobroma-systems.com>,
"Christoph Muellner" <christoph.muellner@theobroma-systems.com>,
linux-iio@vger.kernel.org, devicetree@vger.kernel.org,
linux-kernel@vger.kernel.org, stable@vger.kernel.org,
"Joshua Crofts" <joshua.crofts1@gmail.com>
Subject: Re: [PATCH v8 2/9] iio: accel: mma8452: Fix use-after-free bug in error error path
Date: Mon, 14 Sep 2026 08:49:05 +0200 [thread overview]
Message-ID: <877bkoqqe6.fsf@geanix.com> (raw)
In-Reply-To: <20260914000924.165405fc@jic23-hlaptop>
"Jonathan Cameron" <jic23@kernel.org> writes:
> On Mon, 07 Sep 2026 16:50:57 +0200
> Esben Haabendal <esben@geanix.com> wrote:
>
>> If mma8452_probe() fails in iio_device_register() or later, we could end up
>> with runtime suspend callback being called with a now freed device pointer.
>>
>> Fixes: 96c0cb2bbfe0 ("iio: mma8452: add support for runtime power management")
>> Cc: stable@vger.kernel.org
>> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com>
>> Signed-off-by: Esben Haabendal <esben@geanix.com>
>
> Sashiko calls out some preexisting stuff that is worth a look
> https://sashiko.dev/#/patchset/20260907-mma8452-open-drain-v8-0-c17407e22118%40geanix.com
Yes. And I have a follow-up patch series where I try to address
basically everything sashiko-bot has raised concerns for.
Given the rather large number of issues, and the corresponding large
number of changes needed, I am not planning on adding them to this
series.
> Why freefall mode is set after the iio_device_register() is indeed an interesting
> question. Any idea?
I cannot find any good reason for doing it like that. I am moving the
iio_device_register() call to be the last thing done in .probe() in the
follow-up series, so that the device is fully ready before we expose
user-space API for it.
> As far as it goes this patch is fine. I'm not sure about the other sashiko
> comment about making sure the device is suspended. Given pm_runtime_set_active()
> is called I would assume that one of the register sequences has indeed
> turned on the device (maybe the reset?) and we should be turning it off again.
There is quite a number of issues with runtime pm in this driver. I look
forward to getting feedback to the changes I have made to them :)
/Esben
next prev parent reply other threads:[~2026-09-14 6:49 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 14:50 [PATCH v8 0/9] io: accel: mma8452: Allow open drain interrupt pin configuration Esben Haabendal
2026-09-07 14:50 ` [PATCH v8 1/9] dt-bindings: iio: accel: mma8452: Add drive-open-drain Esben Haabendal
2026-09-07 14:50 ` [PATCH v8 2/9] iio: accel: mma8452: Fix use-after-free bug in error error path Esben Haabendal
2026-09-13 23:09 ` Jonathan Cameron
2026-09-14 6:49 ` Esben Haabendal [this message]
2026-09-07 14:50 ` [PATCH v8 3/9] iio: accel: mma8452: Optimize struct mma8452_data member orders Esben Haabendal
2026-09-07 14:50 ` [PATCH v8 4/9] iio: accel: mma8452: Only apply trigger type when not set by firmware Esben Haabendal
2026-09-07 14:51 ` [PATCH v8 5/9] iio: accel: mma8452: Fix unintended comment indent Esben Haabendal
2026-09-07 15:04 ` Joshua Crofts
2026-09-07 14:51 ` [PATCH v8 6/9] iio: accel: mma8452: Add comment block for struct mma8452_data Esben Haabendal
2026-09-07 15:14 ` Joshua Crofts
2026-09-07 16:28 ` Esben Haabendal
2026-09-08 10:36 ` Andy Shevchenko
2026-09-13 23:15 ` Jonathan Cameron
2026-09-14 6:50 ` Esben Haabendal
2026-09-07 14:51 ` [PATCH v8 7/9] iio: accel: mma8452: Allow open drain interrupt pin configuration Esben Haabendal
2026-09-07 14:51 ` [PATCH v8 8/9] iio: accel: mma8452: Use proper error code when missing device model Esben Haabendal
2026-09-07 14:51 ` [PATCH v8 9/9] iio: accel: mma8452: Support interrupt sharing Esben Haabendal
2026-09-07 15:10 ` Joshua Crofts
2026-09-07 16:36 ` Esben Haabendal
2026-09-09 9:21 ` Joshua Crofts
2026-09-13 23:22 ` Jonathan Cameron
2026-09-14 7:15 ` Esben Haabendal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=877bkoqqe6.fsf@geanix.com \
--to=esben@geanix.com \
--cc=andy@kernel.org \
--cc=christoph.muellner@theobroma-systems.com \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dlechner@baylibre.com \
--cc=jic23@kernel.org \
--cc=joshua.crofts1@gmail.com \
--cc=krzk+dt@kernel.org \
--cc=lars@metafoo.de \
--cc=linux-iio@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=martin.kepplinger@theobroma-systems.com \
--cc=martink@posteo.de \
--cc=nuno.sa@analog.com \
--cc=robh@kernel.org \
--cc=sean@geanix.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®