From: sashiko-bot@kernel.org
To: "Dmitry Torokhov" <dmitry.torokhov@gmail.com>
Cc: linux-input@vger.kernel.org, dmitry.torokhov@gmail.com
Subject: Re: [PATCH] Input: synaptics-rmi4 - fix input device name lifetime with hid-rmi
Date: Thu, 01 Oct 2026 06:39:52 +0000 [thread overview]
Message-ID: <20261001063953.4FC581F000FF@smtp.kernel.org> (raw)
In-Reply-To: <ar38b7ToAe8iGU5v@google.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] mm: devm memory leak of input device name on rmi_driver probe failure or unbind
--
commit cb8d75744bf1ae82958b47feab42ec5de7126321
Author: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: synaptics-rmi4 - fix input device name lifetime with hid-rmi
This commit changes the input device name allocation to use the parent device
instead of the child device. This addresses a use-after-free issue when the
input device is supplied by a transport driver such as hid-rmi.
> diff --git a/drivers/input/rmi4/rmi_driver.c b/drivers/input/rmi4/rmi_driver.c
> index 5d49a9021c7d0..5b104b2b8e19a 100644
> --- a/drivers/input/rmi4/rmi_driver.c
> +++ b/drivers/input/rmi4/rmi_driver.c
> @@ -361,7 +361,14 @@ static void rmi_driver_set_input_name(struct rmi_device *rmi_dev,
> const char *device_name = rmi_f01_get_product_ID(data->f01_container);
> char *name;
>
> - name = devm_kasprintf(&rmi_dev->dev, GFP_KERNEL,
> + /*
> + * Allocate the name string on the input device's parent rather than
> + * rmi_dev->dev so that when the input device is supplied by a
> + * transport driver (such as hid-rmi), the name string is not freed
> + * when rmi_dev is torn down before the transport unregisters its
> + * input device.
> + */
> + name = devm_kasprintf(input->dev.parent, GFP_KERNEL,
[Severity: Medium]
Does tying this devm allocation to the parent transport device (e.g., hdev->dev
when using hid-rmi) cause a memory leak when the child device fails to probe
or is unbound/rebound?
If the RMI driver probe fails subsequently, or if the RMI driver is manually
unbound via sysfs and rebound, the devres group for the parent HID device is
not cleaned up. Each probe attempt allocates a new string on the parent's
devres list, leaking the previous allocations until the parent HID device
is eventually unbound.
> "Synaptics %s", device_name);
> if (!name)
> return;
--
Sashiko AI review · https://sashiko.dev/#/patchset/ar38b7ToAe8iGU5v@google.com?part=1
prev parent reply other threads:[~2026-10-01 6:39 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 6:26 [PATCH] Input: synaptics-rmi4 - fix input device name lifetime with hid-rmi Dmitry Torokhov
2026-10-01 6:39 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001063953.4FC581F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dmitry.torokhov@gmail.com \
--cc=linux-input@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox