* [PATCH] HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown
@ 2026-08-08 15:17 Guangshuo Li
2026-08-08 15:37 ` sashiko-bot
2026-08-10 0:53 ` Xu, Even
0 siblings, 2 replies; 3+ messages in thread
From: Guangshuo Li @ 2026-08-08 15:17 UTC (permalink / raw)
To: Even Xu, Xinpeng Sun, Jiri Kosina, Benjamin Tissoires,
Sakari Ailus, Danny D., Guangshuo Li, Abhishek Tamboli,
Mark Pearson, Srinivas Pandruvada, linux-input, linux-kernel
Cc: stable
quickspi_probe() calls pm_runtime_use_autosuspend(), but
quickspi_remove() does not call the matching
pm_runtime_dont_use_autosuspend() during teardown.
If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without calling pm_runtime_dont_use_autosuspend()
during teardown, this reference is not dropped.
The documentation for pm_runtime_use_autosuspend() also notes that it
is important to undo it with pm_runtime_dont_use_autosuspend() at
driver exit time, unless runtime PM was initially enabled with
devm_pm_runtime_enable().
Add the missing pm_runtime_dont_use_autosuspend() call to the driver
remove path.
This issue was found by manual code inspection.
Fixes: 6912aaf3fd24 ("HID: intel-thc-hid: intel-quickspi: Add PM implementation")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
---
drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c b/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
index 4ae2e1718b30..3c87519aca84 100644
--- a/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
+++ b/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
@@ -713,6 +713,7 @@ static void quickspi_remove(struct pci_dev *pdev)
quickspi_hid_remove(qsdev);
quickspi_dma_deinit(qsdev);
+ pm_runtime_dont_use_autosuspend(qsdev->dev);
pm_runtime_get_noresume(qsdev->dev);
quickspi_dev_deinit(qsdev);
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown
2026-08-08 15:17 [PATCH] HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown Guangshuo Li
@ 2026-08-08 15:37 ` sashiko-bot
2026-08-10 0:53 ` Xu, Even
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-08-08 15:37 UTC (permalink / raw)
To: Guangshuo Li; +Cc: linux-input, dmitry.torokhov
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] The hard IRQ handler accesses MMIO hardware registers without verifying that the device is in an active PM state, risking PCIe errors on spurious interrupts.
- [High] The `quickspi_remove` function destroys the HID device and releases DMA resources before disabling the device interrupts and synchronizing the IRQ handler, leading to a Use-After-Free race condition.
--
--- Patch [1]: [PATCH] HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown ---
commit c65b63d920ef0da607b2572a6bd252126299f2eb
Author: Guangshuo Li <lgs201920130244@gmail.com>
HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown
This commit fixes a runtime PM reference leak during driver removal. It adds a
missing call to pm_runtime_dont_use_autosuspend() in quickspi_remove() to
balance the initialization done during probe.
> diff --git a/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c b/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
> index 4ae2e1718b30c..3c87519aca84a 100644
> --- a/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
> +++ b/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
> @@ -713,6 +713,7 @@ static void quickspi_remove(struct pci_dev *pdev)
> quickspi_hid_remove(qsdev);
> quickspi_dma_deinit(qsdev);
>
> + pm_runtime_dont_use_autosuspend(qsdev->dev);
> pm_runtime_get_noresume(qsdev->dev);
>
> quickspi_dev_deinit(qsdev);
[Severity: High]
This isn't a bug introduced by this patch, but does this teardown sequence
create a use-after-free race condition?
During driver removal, quickspi_remove() calls quickspi_dma_deinit() to free
DMA buffers before disabling hardware interrupts in quickspi_dev_deinit().
Because the IRQ was requested with devm_request_threaded_irq(), it remains
active and is not synchronized or freed until after quickspi_remove() returns.
If an interrupt fires during this window, could the concurrently running
quickspi_irq_thread_handler() invoke thc_rxdma_read() and read from the
already freed DMA memory?
While reviewing this file, I noticed another pre-existing issue in the
interrupt handling code:
drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c:quickspi_irq_quick_handler() {
...
/* Disable THC interrupt before current interrupt be handled */
thc_interrupt_enable(qsdev->thc_hw, false);
...
}
[Severity: High]
This is a pre-existing issue, but does the hard IRQ handler access MMIO
hardware registers without verifying that the device is in an active PM state?
If a spurious or shared interrupt occurs while the device is in the PCI D3hot
(runtime suspended) state, the handler calls thc_interrupt_enable() which
accesses MMIO directly without a pm_runtime_get_if_active() check.
Could this read and write powered-down MMIO registers and generate an
Unsupported Request (UR) on the PCIe bus?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260808151736.2934050-1-lgs201920130244@gmail.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
* RE: [PATCH] HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown
2026-08-08 15:17 [PATCH] HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown Guangshuo Li
2026-08-08 15:37 ` sashiko-bot
@ 2026-08-10 0:53 ` Xu, Even
1 sibling, 0 replies; 3+ messages in thread
From: Xu, Even @ 2026-08-10 0:53 UTC (permalink / raw)
To: Guangshuo Li, Sun, Xinpeng, Jiri Kosina, Benjamin Tissoires,
Sakari Ailus, Danny D., Abhishek Tamboli, Mark Pearson,
Srinivas Pandruvada, linux-input@vger.kernel.org,
linux-kernel@vger.kernel.org
Cc: stable@vger.kernel.org
> -----Original Message-----
> From: Guangshuo Li <lgs201920130244@gmail.com>
> Sent: Saturday, August 8, 2026 11:18 PM
> To: Xu, Even <even.xu@intel.com>; Sun, Xinpeng <xinpeng.sun@intel.com>; Jiri
> Kosina <jikos@kernel.org>; Benjamin Tissoires <bentiss@kernel.org>; Sakari Ailus
> <sakari.ailus@linux.intel.com>; Danny D. <d3z.the.dev@gmail.com>; Guangshuo
> Li <lgs201920130244@gmail.com>; Abhishek Tamboli
> <abhishektamboli9@gmail.com>; Mark Pearson <mpearson-lenovo@squebb.ca>;
> Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>; linux-
> input@vger.kernel.org; linux-kernel@vger.kernel.org
> Cc: stable@vger.kernel.org
> Subject: [PATCH] HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during
> teardown
>
> quickspi_probe() calls pm_runtime_use_autosuspend(), but
> quickspi_remove() does not call the matching
> pm_runtime_dont_use_autosuspend() during teardown.
>
> If the autosuspend delay is set to a negative value while autosuspend is enabled,
> the runtime PM core increments usage_count to prevent runtime suspend.
> Without calling pm_runtime_dont_use_autosuspend() during teardown, this
> reference is not dropped.
>
> The documentation for pm_runtime_use_autosuspend() also notes that it is
> important to undo it with pm_runtime_dont_use_autosuspend() at driver exit
> time, unless runtime PM was initially enabled with devm_pm_runtime_enable().
>
> Add the missing pm_runtime_dont_use_autosuspend() call to the driver remove
> path.
>
> This issue was found by manual code inspection.
>
> Fixes: 6912aaf3fd24 ("HID: intel-thc-hid: intel-quickspi: Add PM implementation")
> Cc: stable@vger.kernel.org
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
> drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
> b/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
> index 4ae2e1718b30..3c87519aca84 100644
> --- a/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
> +++ b/drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
> @@ -713,6 +713,7 @@ static void quickspi_remove(struct pci_dev *pdev)
> quickspi_hid_remove(qsdev);
> quickspi_dma_deinit(qsdev);
>
> + pm_runtime_dont_use_autosuspend(qsdev->dev);
Reviewed-by: Even Xu <even.xu@intel.com>
> pm_runtime_get_noresume(qsdev->dev);
>
> quickspi_dev_deinit(qsdev);
> --
> 2.43.0
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-10 0:53 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-08 15:17 [PATCH] HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown Guangshuo Li
2026-08-08 15:37 ` sashiko-bot
2026-08-10 0:53 ` Xu, Even
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.