From: sashiko-bot@kernel.org
To: "Yibo Tan" <lhfff@tju.edu.cn>
Cc: linux-hwmon@vger.kernel.org
Subject: Re: [PATCH v1] hwmon: (pwm-fan) Stop RPM timer before freeing tach data
Date: Fri, 11 Sep 2026 07:30:22 +0000 [thread overview]
Message-ID: <20260911073022.AFF991F00898@smtp.kernel.org> (raw)
In-Reply-To: <20260911071809.130151-1-lhfff@tju.edu.cn>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing lock in pwm_fan_cleanup leads to data race and potential memory/HW state corruption during system shutdown.
--
commit 7dfed1a79b0f4d06cbff416478ab737ce3920c29
Author: Yibo Tan <lhfff@tju.edu.cn>
hwmon: (pwm-fan) Stop RPM timer before freeing tach data
This commit fixes a use-after-free bug where driver detach can free timer
backing arrays before the timer is shut down. It does this by splitting the
timer retirement from power cleanup and registering its devres action after
the timer backing data is installed.
> diff --git a/drivers/hwmon/pwm-fan.c b/drivers/hwmon/pwm-fan.c
> index 3b87f65bae058..c633d7f6464c7 100644
> --- a/drivers/hwmon/pwm-fan.c
> +++ b/drivers/hwmon/pwm-fan.c
[ ... ]
> @@ -700,6 +710,7 @@ static void pwm_fan_shutdown(struct platform_device *pdev)
> {
> struct pwm_fan_ctx *ctx = platform_get_drvdata(pdev);
>
> + pwm_fan_timer_cleanup(ctx);
> pwm_fan_cleanup(ctx);
[Severity: High]
This is a pre-existing issue, but does this unlocked call to
pwm_fan_cleanup() create a data race with the thermal subsystem?
During system shutdown, pwm_fan_shutdown() invokes pwm_fan_cleanup()
without holding ctx->lock. At the same time, if the kernel's thermal
governor triggers a temperature update, it can follow this path:
pwm_fan_set_cur_state()
set_pwm()
__set_pwm()
The thermal path acquires ctx->lock, but because pwm_fan_cleanup() modifies
ctx->enable_mode and ctx->pwm_state locklessly, these operations can race.
Could this result in invalid configurations being passed to the PWM driver
during shutdown, potentially causing a crash or malfunction?
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260911071809.130151-1-lhfff@tju.edu.cn?part=1
next prev parent reply other threads:[~2026-09-11 7:30 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-11 7:18 [PATCH v1] hwmon: (pwm-fan) Stop RPM timer before freeing tach data Yibo Tan
2026-09-11 7:30 ` sashiko-bot [this message]
2026-09-11 14:50 ` Guenter Roeck
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260911073022.AFF991F00898@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=lhfff@tju.edu.cn \
--cc=linux-hwmon@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.