From: sashiko-bot@kernel.org
To: "Myeonghun Pak" <mhun512@gmail.com>
Cc: linux-hwmon@vger.kernel.org
Subject: Re: [PATCH] hwmon: (corsair-psu) Close HID device on probe errors
Date: Fri, 24 Apr 2026 14:21:02 +0000 [thread overview]
Message-ID: <20260424142103.6D83BC2BCB2@smtp.kernel.org> (raw)
In-Reply-To: <20260424135107.13720-1-mhun512@gmail.com>
Sashiko AI review found 1 potential issue(s):
- [High] Missing required locking for debugfs attributes and shared command buffer.
--
commit f516eb8cbe20556b89a6e098a982bbc4318175c6
Author: Myeonghun Pak <mhun512@gmail.com>
hwmon: (corsair-psu) Close HID device on probe errors
This commit modifies the error handling path in corsairpsu_probe() to
properly balance the open count. It adds a new fail_and_close label so
the HID hardware is closed before stopping when initialization or firmware
queries fail.
> diff --git a/drivers/hwmon/corsair-psu.c b/drivers/hwmon/corsair-psu.c
> index dddbd2463f8da7..76f3e1da68d09e 100644
> --- a/drivers/hwmon/corsair-psu.c
> +++ b/drivers/hwmon/corsair-psu.c
> @@ -796,13 +796,13 @@ static int corsairpsu_probe(struct hid_device *hdev, const struct hid_device_id
> ret = corsairpsu_init(priv);
This isn't a bug introduced by this patch, but does the driver lack
required locking for the shared priv->cmd_buffer and priv->wait_completion
when accessed concurrently?
The hwmon guidelines state that drivers must implement locking for attributes
registered outside the core (like debugfs) and should use hwmon_lock() and
hwmon_unlock().
Since corsairpsu_debugfs_init() registers attributes that eventually call
corsairpsu_usb_cmd(), these debugfs reads can execute concurrently with
standard sysfs reads. Inside corsairpsu_usb_cmd(), the driver uses a single
shared buffer:
Thread A:
memset(priv->cmd_buffer, 0, CMD_BUFFER_SIZE);
reinit_completion(&priv->wait_completion);
hid_hw_output_report(...);
Thread B (before Thread A's reply arrives):
memset(priv->cmd_buffer, 0, CMD_BUFFER_SIZE);
reinit_completion(&priv->wait_completion);
When the device reply arrives, corsairpsu_raw_event() overwrites
cmd_buffer and calls complete(), which would wake only one waiter.
Can this concurrent access lead to corrupted device communication, missed
wakeups, or returning values for the wrong command?
> if (ret < 0) {
> dev_err(&hdev->dev, "unable to initialize device (%d)\n", ret);
> - goto fail_and_stop;
> + goto fail_and_close;
> }
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260424135107.13720-1-mhun512@gmail.com?part=1
next prev parent reply other threads:[~2026-04-24 14:21 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-04-24 13:50 [PATCH] hwmon: (corsair-psu) Close HID device on probe errors Myeonghun Pak
2026-04-24 14:21 ` sashiko-bot [this message]
2026-04-24 15:37 ` Wilken Gottwalt
2026-04-30 18:20 ` Guenter Roeck
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260424142103.6D83BC2BCB2@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-hwmon@vger.kernel.org \
--cc=mhun512@gmail.com \
--cc=sashiko@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.