From: Esben Haabendal <esben@geanix.com>
To: "Jonathan Cameron" <jic23@kernel.org>
Cc: "Lars-Peter Clausen" <lars@metafoo.de>,
"Rob Herring" <robh@kernel.org>,
"Krzysztof Kozlowski" <krzk+dt@kernel.org>,
"Conor Dooley" <conor+dt@kernel.org>,
"Martin Kepplinger" <martink@posteo.de>,
"Sean Nyekjaer" <sean@geanix.com>,
"David Lechner" <dlechner@baylibre.com>,
"Nuno Sá" <nuno.sa@analog.com>,
"Andy Shevchenko" <andy@kernel.org>,
"Martin Kepplinger" <martin.kepplinger@theobroma-systems.com>,
"Christoph Muellner" <christoph.muellner@theobroma-systems.com>,
linux-iio@vger.kernel.org, devicetree@vger.kernel.org,
linux-kernel@vger.kernel.org, stable@vger.kernel.org,
"Joshua Crofts" <joshua.crofts1@gmail.com>
Subject: Re: [PATCH v8 2/9] iio: accel: mma8452: Fix use-after-free bug in error error path
Date: Mon, 14 Sep 2026 08:49:05 +0200 [thread overview]
Message-ID: <877bkoqqe6.fsf@geanix.com> (raw)
In-Reply-To: <20260914000924.165405fc@jic23-hlaptop>
"Jonathan Cameron" <jic23@kernel.org> writes:
> On Mon, 07 Sep 2026 16:50:57 +0200
> Esben Haabendal <esben@geanix.com> wrote:
>
>> If mma8452_probe() fails in iio_device_register() or later, we could end up
>> with runtime suspend callback being called with a now freed device pointer.
>>
>> Fixes: 96c0cb2bbfe0 ("iio: mma8452: add support for runtime power management")
>> Cc: stable@vger.kernel.org
>> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com>
>> Signed-off-by: Esben Haabendal <esben@geanix.com>
>
> Sashiko calls out some preexisting stuff that is worth a look
> https://sashiko.dev/#/patchset/20260907-mma8452-open-drain-v8-0-c17407e22118%40geanix.com
Yes. And I have a follow-up patch series where I try to address
basically everything sashiko-bot has raised concerns for.
Given the rather large number of issues, and the corresponding large
number of changes needed, I am not planning on adding them to this
series.
> Why freefall mode is set after the iio_device_register() is indeed an interesting
> question. Any idea?
I cannot find any good reason for doing it like that. I am moving the
iio_device_register() call to be the last thing done in .probe() in the
follow-up series, so that the device is fully ready before we expose
user-space API for it.
> As far as it goes this patch is fine. I'm not sure about the other sashiko
> comment about making sure the device is suspended. Given pm_runtime_set_active()
> is called I would assume that one of the register sequences has indeed
> turned on the device (maybe the reset?) and we should be turning it off again.
There is quite a number of issues with runtime pm in this driver. I look
forward to getting feedback to the changes I have made to them :)
/Esben
next prev parent reply other threads:[~2026-09-14 6:49 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 14:50 [PATCH v8 0/9] io: accel: mma8452: Allow open drain interrupt pin configuration Esben Haabendal
2026-09-07 14:50 ` [PATCH v8 1/9] dt-bindings: iio: accel: mma8452: Add drive-open-drain Esben Haabendal
2026-09-07 14:50 ` [PATCH v8 2/9] iio: accel: mma8452: Fix use-after-free bug in error error path Esben Haabendal
2026-09-07 15:04 ` sashiko-bot
2026-09-07 15:08 ` Esben Haabendal
2026-09-13 23:09 ` Jonathan Cameron
2026-09-14 6:49 ` Esben Haabendal [this message]
2026-09-07 14:50 ` [PATCH v8 3/9] iio: accel: mma8452: Optimize struct mma8452_data member orders Esben Haabendal
2026-09-07 14:50 ` [PATCH v8 4/9] iio: accel: mma8452: Only apply trigger type when not set by firmware Esben Haabendal
2026-09-07 15:01 ` sashiko-bot
2026-09-07 14:51 ` [PATCH v8 5/9] iio: accel: mma8452: Fix unintended comment indent Esben Haabendal
2026-09-07 15:04 ` Joshua Crofts
2026-09-07 14:51 ` [PATCH v8 6/9] iio: accel: mma8452: Add comment block for struct mma8452_data Esben Haabendal
2026-09-07 14:58 ` sashiko-bot
2026-09-07 15:07 ` Esben Haabendal
2026-09-07 15:14 ` Joshua Crofts
2026-09-07 16:28 ` Esben Haabendal
2026-09-08 10:36 ` Andy Shevchenko
2026-09-13 23:15 ` Jonathan Cameron
2026-09-14 6:50 ` Esben Haabendal
2026-09-07 14:51 ` [PATCH v8 7/9] iio: accel: mma8452: Allow open drain interrupt pin configuration Esben Haabendal
2026-09-07 15:05 ` sashiko-bot
2026-09-07 15:09 ` Esben Haabendal
2026-09-07 14:51 ` [PATCH v8 8/9] iio: accel: mma8452: Use proper error code when missing device model Esben Haabendal
2026-09-07 14:51 ` [PATCH v8 9/9] iio: accel: mma8452: Support interrupt sharing Esben Haabendal
2026-09-07 15:08 ` sashiko-bot
2026-09-07 15:58 ` Esben Haabendal
2026-09-08 9:15 ` Esben Haabendal
2026-09-07 15:10 ` Joshua Crofts
2026-09-07 16:36 ` Esben Haabendal
2026-09-09 9:21 ` Joshua Crofts
2026-09-13 23:22 ` Jonathan Cameron
2026-09-14 7:15 ` Esben Haabendal
2026-09-15 6:21 ` Esben Haabendal
2026-09-17 2:47 ` Jonathan Cameron
2026-09-17 6:34 ` Esben Haabendal
2026-09-17 2:46 ` Jonathan Cameron
2026-09-17 6:24 ` Esben Haabendal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=877bkoqqe6.fsf@geanix.com \
--to=esben@geanix.com \
--cc=andy@kernel.org \
--cc=christoph.muellner@theobroma-systems.com \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dlechner@baylibre.com \
--cc=jic23@kernel.org \
--cc=joshua.crofts1@gmail.com \
--cc=krzk+dt@kernel.org \
--cc=lars@metafoo.de \
--cc=linux-iio@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=martin.kepplinger@theobroma-systems.com \
--cc=martink@posteo.de \
--cc=nuno.sa@analog.com \
--cc=robh@kernel.org \
--cc=sean@geanix.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.