From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E67843624BF; Wed, 30 Sep 2026 17:47:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790790465; cv=none; b=mVGJF50P1sORSvc9uj9yf/QETrDe6z23q+Q9gsR09hDHgRHMEFef7EWW7GlFA4UUoBxP2utmetHTXjH1H8TFy3adZIJvy8GK4iUatA99YRLUT9ghxzfuhbWDkSvCJxO+RjOZVq43j87HVxH0jgG+DctxwxMntOyaHl9D0al0bLU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790790465; c=relaxed/simple; bh=cLW2qk5Ps+vSVaAqfV1Uv5iSTiIdLhrQLjfOEvejQ78=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fva8fJ5ppUf2qcyw32Zo0jxRinDz/ymkBV6hunpRiE15QaE85D5RKm43rvM48pvFgzY0OcBZaTm7IklkIH5D8G+nLC7CEXM3j9Ii3hU79vhT6Uu57gucKOytADd00E/muKmRmSFgDgCK4ElaXkkFjm9teXjP7giPk4uH7vAb8dk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=LjUjoz0V; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="LjUjoz0V" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0D8E41F000FF; Wed, 30 Sep 2026 17:47:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790790463; bh=HqBoSjZJcbd+lqUFkkbcCsYgAxnK/lmYMfIGtl0KPhM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=LjUjoz0VfK9rBoAkxc5JR6t39DSpGWVo5HWtiM4feFIKnK9yZLmcSh8rmK2RFNsoc gFZz5IYRvXA/5a4iuUrJLVo4Jg5anH1USghtr5neJxvA2Uow/6tkleHmvzK56pKycH STg8joR2O0FtgLMuToLhwt7ek6/4KI3YcqCDEz7k= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Chen Changcheng , Jiri Kosina , Sasha Levin Subject: [PATCH 6.12 839/877] HID: alps: unregister DualPoint Stick input device on remove Date: Wed, 30 Sep 2026 17:29:10 +0200 Message-ID: <20260930152432.841737033@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Chen Changcheng [ Upstream commit aa9dde93e05a837645fdfd577eea71f0733f0694 ] alps_input_configured() allocates a second input device ("DualPoint Stick") with input_allocate_device() and registers it, but the alps_driver struct has no .remove handler and input2 is not tracked in hdev->inputs. The default remove path (hid_hw_stop -> hidinput_disconnect) only iterates hdev->inputs, so input2 is never unregistered and leaks on every device removal. Add a .remove handler that stops the device first (preventing URB callbacks from touching input2 during teardown) and then unregisters input2. Fixes: 2562756dde55 ("HID: add Alps I2C HID Touchpad-Stick support") Cc: stable@vger.kernel.org Signed-off-by: Chen Changcheng Signed-off-by: Jiri Kosina Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- drivers/hid/hid-alps.c | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) --- a/drivers/hid/hid-alps.c +++ b/drivers/hid/hid-alps.c @@ -825,6 +825,24 @@ static int alps_probe(struct hid_device return 0; } +static void alps_remove(struct hid_device *hdev) +{ + struct alps_dev *data = hid_get_drvdata(hdev); + + /* + * input2 ("DualPoint Stick") is allocated separately and is not + * tracked in hdev->inputs, so the default remove path + * (hid_hw_stop -> hidinput_disconnect) does not unregister it. + * + * Stop the device first so that no URB callback can touch input2 + * while it is being unregistered, then drop it explicitly. + */ + hid_hw_stop(hdev); + + if (data->input2) + input_unregister_device(data->input2); +} + static const struct hid_device_id alps_id[] = { { HID_DEVICE(HID_BUS_ANY, HID_GROUP_ANY, USB_VENDOR_ID_ALPS_JP, HID_DEVICE_ID_ALPS_U1_DUAL) }, @@ -847,6 +865,7 @@ static struct hid_driver alps_driver = { .input_configured = alps_input_configured, .resume = pm_ptr(alps_post_resume), .reset_resume = pm_ptr(alps_post_reset), + .remove = alps_remove, }; module_hid_driver(alps_driver);