From: sashiko-bot@kernel.org
To: "Méven Car" <meven29@gmail.com>
Cc: dmitry.torokhov@gmail.com, linux-input@vger.kernel.org
Subject: Re: [PATCH] HID: logitech-headset: add a battery driver for the PRO X 2
Date: Fri, 11 Sep 2026 12:02:58 +0000 [thread overview]
Message-ID: <20260911120258.9C8851F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260911115346.17133-1-meven@kde.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Incorrect teardown sequence in remove callback violates HID subsystem guidelines.
--
commit adb0241c4db099ec7ce91b1ebd7f292627e20d96
Author: Méven Car <meven29@gmail.com>
HID: logitech-headset: add a battery driver for the PRO X 2
This commit introduces a battery driver for the Logitech PRO X 2 LIGHTSPEED
headset. It communicates with the hardware over a vendor collection using a
polling mechanism scheduled via a delayed work queue to report battery status.
[ ... ]
> diff --git a/drivers/hid/hid-logitech-headset.c b/drivers/hid/hid-logitech-headset.c
> new file mode 100644
> index 0000000000000..9081ddf5f42f2
> --- /dev/null
> +++ b/drivers/hid/hid-logitech-headset.c
[ ... ]
> +static void logi_headset_remove(struct hid_device *hdev)
> +{
> + struct logi_headset *headset = hid_get_drvdata(hdev);
> +
> + cancel_delayed_work_sync(&headset->poll);
[Severity: High]
Does this teardown sequence in logi_headset_remove risk a use-after-free?
The HID subsystem guidelines specify that hid_hw_stop must be called before
cancelling asynchronous workers. By executing cancel_delayed_work_sync
before hid_hw_stop, it is theoretically possible for new work to be queued
while the driver is in the process of unbinding.
Calling hid_hw_stop first ensures that no new events or userspace requests
can trigger work to be scheduled during resource reclamation.
> + hid_hw_close(hdev);
> + hid_hw_stop(hdev);
> +}
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260911115346.17133-1-meven@kde.org?part=1
prev parent reply other threads:[~2026-09-11 12:02 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-11 11:53 [PATCH] HID: logitech-headset: add a battery driver for the PRO X 2 Méven Car
2026-09-11 12:02 ` [PATCH v2] " Méven Car
2026-09-11 12:10 ` sashiko-bot
2026-09-11 13:53 ` Méven
2026-09-11 12:02 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260911120258.9C8851F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dmitry.torokhov@gmail.com \
--cc=linux-input@vger.kernel.org \
--cc=meven29@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.