From: sashiko-bot@kernel.org
To: "Rong Zhang" <i@rong.moe>
Cc: lee@kernel.org, linux-leds@vger.kernel.org
Subject: Re: [PATCH v6 06/12] leds: turris-omnia: Implement offloaded() trigger callback and declare hw_control_trigger
Date: Wed, 02 Sep 2026 18:15:54 +0000 [thread overview]
Message-ID: <20260902181555.258DE1F00A3E@smtp.kernel.org> (raw)
In-Reply-To: <20260902-leds-trigger-hw-changed-v6-6-55693cd78877@rong.moe>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] The statically allocated `omnia_hw_trigger` object is registered multiple times via `devm_led_trigger_register()` on probe, causing lock and list corruption if multiple driver instances are bound.
--
commit 836486b7bf6dc3bf19d25d5b547db0edd0d638af
Author: Rong Zhang <i@rong.moe>
leds: turris-omnia: Implement offloaded() trigger callback and declare hw_control_trigger
This commit implements the offloaded() callback for the omnia-mcu hardware
control trigger, returning true to reflect its state. It also declares it as
a hardware control trigger in the class device during registration.
> diff --git a/drivers/leds/leds-turris-omnia.c b/drivers/leds/leds-turris-omnia.c
> index ed6a47bbb44f9..32d40d176d3f1 100644
> --- a/drivers/leds/leds-turris-omnia.c
> +++ b/drivers/leds/leds-turris-omnia.c
[ ... ]
> @@ -195,10 +195,16 @@ static void omnia_hwtrig_deactivate(struct led_classdev *cdev)
> err);
> }
>
> +static bool omnia_hwtrig_offloaded(struct led_classdev *cdev)
> +{
> + return true;
> +}
> +
> static struct led_trigger omnia_hw_trigger = {
> .name = "omnia-mcu",
> .activate = omnia_hwtrig_activate,
> .deactivate = omnia_hwtrig_deactivate,
> + .offloaded = omnia_hwtrig_offloaded,
> .trigger_type = &omnia_hw_trigger_type,
> };
[Severity: High]
This is a pre-existing issue, but does this statically allocated singleton
trigger cause list corruption if multiple driver instances are bound?
If a user manually binds a second device instance to the leds-turris-omnia
driver via the sysfs bind interface (or multiple I2C devices probe),
devm_led_trigger_register() in omnia_leds_probe() will be called again with
this exact same statically allocated omnia_hw_trigger structure pointer.
In drivers/leds/led-triggers.c:led_trigger_register(), the core initializes
the lock and list head before checking for duplicate registrations:
spin_lock_init(&trig->leddev_list_lock);
INIT_LIST_HEAD(&trig->led_cdevs);
Wouldn't this blindly overwrite the active lock and list state of the
trigger, destroying the lock state while another CPU is iterating and
unlinking any already-registered LEDs, leading to a use-after-free?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260902-leds-trigger-hw-changed-v6-0-55693cd78877@rong.moe?part=6
next prev parent reply other threads:[~2026-09-02 18:15 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 18:09 [PATCH v6 00/12] leds: Add support for hardware-initiated hardware control trigger transition Rong Zhang
2026-09-01 18:09 ` [PATCH v6 01/12] leds: class: Always protect brightness_show() with led_access Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 02/12] leds: Move led_trigger_is_hw_controlled() to the right place Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 03/12] leds: class: Remove hardware control trigger when writing brightness Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 04/12] leds: trigger: Add offloaded() callback and provide trigger_may_offload attribute Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-10 15:05 ` Lee Jones
2026-09-10 18:01 ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 05/12] leds: cros_ec: Implement offloaded() trigger callback Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-02 18:45 ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 06/12] leds: turris-omnia: Implement offloaded() trigger callback and declare hw_control_trigger Rong Zhang
2026-09-02 18:15 ` sashiko-bot [this message]
2026-09-02 18:46 ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 07/12] leds: trigger: netdev: Implement offloaded() callback Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-02 18:47 ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 08/12] leds: trigger: Enforce strict checks in led_trigger_is_hw_controlled() Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 09/12] leds: trigger: Add led_trigger_notify_hw_control_changed() interface Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-02 18:56 ` Rong Zhang
2026-09-10 15:45 ` Lee Jones
2026-09-10 18:17 ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 10/12] platform/x86: ideapad-laptop: Serialize keyboard backlight tracking Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 11/12] platform/x86: ideapad-laptop: Decouple hardware & classdev brightness for keyboard backlight Rong Zhang
2026-09-02 18:15 ` sashiko-bot
2026-09-02 19:15 ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 12/12] platform/x86: ideapad-laptop: Fully support auto " Rong Zhang
2026-09-02 18:15 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902181555.258DE1F00A3E@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=i@rong.moe \
--cc=lee@kernel.org \
--cc=linux-leds@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.