From: sashiko-bot@kernel.org
To: "Chris Morgan" <macroalpha82@gmail.com>
Cc: conor+dt@kernel.org, robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH V19 5/9] iio: imu: inv_icm42607: Add PM support for icm42607
Date: Wed, 22 Jul 2026 16:07:42 +0000 [thread overview]
Message-ID: <20260722160743.156C31F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260722153942.144387-6-macroalpha82@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Manual sensor shutdown in `remove` races with devm-managed IIO device unregistration, allowing hardware constraints to be violated.
--
--- Patch [5]: [PATCH V19 5/9] iio: imu: inv_icm42607: Add PM support for icm42607 ---
commit b056ec561cd9320015e132187a3e7a3626b06b64
Author: Chris Morgan <macromorgan@hotmail.com>
iio: imu: inv_icm42607: Add PM support for icm42607
Add power management support for the ICM42607 device driver.
> diff --git a/drivers/iio/imu/inv_icm42607/inv_icm42607_i2c.c b/drivers/iio/imu/inv_icm42607/inv_icm42607_i2c.c
> index f2b9067815b0e..4a8e4f7168038 100644
> --- a/drivers/iio/imu/inv_icm42607/inv_icm42607_i2c.c
> +++ b/drivers/iio/imu/inv_icm42607/inv_icm42607_i2c.c
[ ... ]
> @@ -56,6 +57,13 @@ static int inv_icm42607_probe(struct i2c_client *client)
> return inv_icm42607_core_probe(regmap, hw, inv_icm42607_i2c_bus_setup);
> }
>
> +static void inv_icm42607_i2c_remove(struct i2c_client *client)
> +{
> + struct inv_icm42607_state *st = dev_get_drvdata(&client->dev);
> +
> + inv_icm42607_sensors_off(st);
[Severity: High]
Can this manual shutdown race with devm-managed IIO device unregistration?
Since the IIO devices are registered with devm-managed functions during probe,
the devres release phase will execute after this remove callback returns. This
means the IIO devices remain fully accessible to userspace during this period.
If a concurrent userspace read occurs just after inv_icm42607_sensors_off
finishes but before the devres release phase begins, could it re-acquire the
runtime PM reference via PM_RUNTIME_ACQUIRE_AUTOSUSPEND and turn the sensors
back on?
When the read completes and drops the PM reference, an autosuspend would be
queued. Then, devres runs, unregistering the IIO device and executing
pm_runtime_disable(), which would cancel the pending autosuspend and leave
the hardware permanently on.
Finally, the devm action for inv_icm42607_disable_vddio_reg() would cut power
to the chip while the sensors are still active, bypassing the mandatory 45ms
gyro power-down delay.
> +}
> +
> static const struct i2c_device_id inv_icm42607_id[] = {
[ ... ]
> diff --git a/drivers/iio/imu/inv_icm42607/inv_icm42607_spi.c b/drivers/iio/imu/inv_icm42607/inv_icm42607_spi.c
> index eb04036a6712f..99e112c958a00 100644
> --- a/drivers/iio/imu/inv_icm42607/inv_icm42607_spi.c
> +++ b/drivers/iio/imu/inv_icm42607/inv_icm42607_spi.c
[ ... ]
> @@ -65,6 +66,13 @@ static int inv_icm42607_probe(struct spi_device *spi)
> return inv_icm42607_core_probe(regmap, hw, inv_icm42607_spi_bus_setup);
> }
>
> +static void inv_icm42607_spi_remove(struct spi_device *spi)
> +{
> + struct inv_icm42607_state *st = dev_get_drvdata(&spi->dev);
> +
> + inv_icm42607_sensors_off(st);
[Severity: High]
Does this have the same race condition with devm-managed IIO device
unregistration as the I2C remove function?
> +}
> +
> static const struct spi_device_id inv_icm42607_spi_id_table[] = {
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260722153942.144387-1-macroalpha82@gmail.com?part=5
next prev parent reply other threads:[~2026-07-22 16:07 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 15:39 [PATCH V19 0/9] Add Invensense ICM42607 Chris Morgan
2026-07-22 15:39 ` [PATCH V19 1/9] dt-bindings: iio: imu: icm42600: Add mount-matrix Chris Morgan
2026-07-22 15:39 ` [PATCH V19 2/9] dt-bindings: iio: imu: icm42600: Add icm42607 Chris Morgan
2026-07-22 15:39 ` [PATCH V19 3/9] iio: imu: inv_icm42607: Add inv_icm42607 Core Driver Chris Morgan
2026-07-22 15:53 ` sashiko-bot
2026-07-22 15:39 ` [PATCH V19 4/9] iio: imu: inv_icm42607: Add SPI For icm42607 Chris Morgan
2026-07-22 15:39 ` [PATCH V19 5/9] iio: imu: inv_icm42607: Add PM support for icm42607 Chris Morgan
2026-07-22 16:07 ` sashiko-bot [this message]
2026-07-22 15:39 ` [PATCH V19 6/9] iio: imu: inv_icm42607: Add Accelerometer " Chris Morgan
2026-07-22 16:01 ` sashiko-bot
2026-07-22 15:39 ` [PATCH V19 7/9] iio: imu: inv_icm42607: Add Gyroscope to icm42607 Chris Morgan
2026-07-22 15:39 ` [PATCH V19 8/9] iio: imu: inv_icm42607: Add Temp Support in icm42607 Chris Morgan
2026-07-22 15:39 ` [PATCH V19 9/9] arm64: dts: rockchip: Add icm42607p IMU for RG-DS Chris Morgan
2026-07-22 15:59 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260722160743.156C31F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=macroalpha82@gmail.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox