All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jorijn van der Graaf" <jorijnvdgraaf@catcrafts.net>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v3 5/5] iio: light: stk3310: support the Sensortek STK36C61
Date: Tue, 01 Sep 2026 01:04:52 +0000	[thread overview]
Message-ID: <20260901010452.C2FDE1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260901005114.203062-6-jorijnvdgraaf@catcrafts.net>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Possible Use-After-Free of IIO event interface (ev_int) during probe failure due to asymmetric IRQ lifecycle.
--

commit b4e1397431b4f12cb9a540f222673e8512090f40
Author: Jorijn van der Graaf <jorijnvdgraaf@catcrafts.net>
Subject: iio: light: stk3310: support the Sensortek STK36C61

The Sensortek STK36C61 is a 3-in-1 ambient light / proximity / RGB
colour sensor. This patch adds its chip ID to the known-ID list and
device table entries, exposing the colour channels alongside ALS and
proximity.

> diff --git a/drivers/iio/light/stk3310.c b/drivers/iio/light/stk3310.c
> index f5782a1e19bbc..0a16e326e9390 100644
> --- a/drivers/iio/light/stk3310.c
> +++ b/drivers/iio/light/stk3310.c
[ ... ]
> @@ -866,6 +866,7 @@ static const struct i2c_device_id stk3310_i2c_id[] = {
>  	{ .name = "stk3310", .driver_data = (kernel_ulong_t)&stk3310_chip_info },
>  	{ .name = "stk3311", .driver_data = (kernel_ulong_t)&stk3310_chip_info },
>  	{ .name = "stk3335", .driver_data = (kernel_ulong_t)&stk3310_chip_info },
> +	{ .name = "stk36c61", .driver_data = (kernel_ulong_t)&stk36c61_chip_info },

[Severity: High]
This isn't a bug introduced by this patch, but is it possible for the
pre-existing IRQ setup in stk3310_probe() (drivers/iio/light/stk3310.c,
around line 766) to trigger a use-after-free if probe fails?

Looking at stk3310_probe(), the IRQ handler is registered before the IIO
device:

	if (client->irq > 0) {
		ret = devm_request_threaded_irq(&client->dev, client->irq,
						stk3310_irq_handler,
						stk3310_irq_event_handler,
						IRQF_TRIGGER_FALLING |
						IRQF_ONESHOT,
						"stk3310_event", indio_dev);
		if (ret)
			goto err_standby;
	}

	ret = iio_device_register(indio_dev);
	if (ret < 0) {
		dev_err(&client->dev, "device_register failed\n");
		goto err_standby;
	}

If iio_device_register() fails late in its execution, it cleans up its
partial state and frees the ev_int structure via kfree(). Because the IRQ
is managed by devres, it remains active until stk3310_probe() returns and
the devres unwinding phase disables it.

If a hardware interrupt fires during this window, stk3310_irq_event_handler()
(around line 714) will execute:

	event = IIO_UNMOD_EVENT_CODE(IIO_PROXIMITY, 1,
				     IIO_EV_TYPE_THRESH,
				     (dir ? IIO_EV_DIR_FALLING :
					    IIO_EV_DIR_RISING));
	iio_push_event(indio_dev, event, data->timestamp);

Can iio_push_event() dereference the freed ev_int structure here since there
is no synchronization with the iio_device_unregister_eventset() cleanup?

>  	{ }
>  };

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260901005114.203062-1-jorijnvdgraaf@catcrafts.net?part=5

  reply	other threads:[~2026-09-01  1:04 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-01  0:51 [PATCH v3 0/5] iio: light: stk3310: per-chip match data and STK36C61 support Jorijn van der Graaf
2026-09-01  0:51 ` [PATCH v3 1/5] iio: light: stk3310: lower-case the i2c device ID names Jorijn van der Graaf
2026-09-01  0:51 ` [PATCH v3 2/5] dt-bindings: iio: light: stk33xx: document the Sensortek STK36C61 Jorijn van der Graaf
2026-09-01  0:51 ` [PATCH v3 3/5] iio: light: stk3310: move the data registers into the channel address Jorijn van der Graaf
2026-09-01  0:51 ` [PATCH v3 4/5] iio: light: stk3310: add per-chip match data Jorijn van der Graaf
2026-09-01  0:51 ` [PATCH v3 5/5] iio: light: stk3310: support the Sensortek STK36C61 Jorijn van der Graaf
2026-09-01  1:04   ` sashiko-bot [this message]
2026-09-05  0:50   ` Jonathan Cameron
2026-09-05  0:51 ` [PATCH v3 0/5] iio: light: stk3310: per-chip match data and STK36C61 support Jonathan Cameron

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260901010452.C2FDE1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=jorijnvdgraaf@catcrafts.net \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.