Linux LED subsystem development
 help / color / mirror / Atom feed
From: Rong Zhang <i@rong.moe>
To: sashiko-reviews@lists.linux.dev
Cc: lee@kernel.org, linux-leds@vger.kernel.org
Subject: Re: [PATCH v6 09/12] leds: trigger: Add led_trigger_notify_hw_control_changed() interface
Date: Thu, 03 Sep 2026 02:56:04 +0800	[thread overview]
Message-ID: <0b2f92a242002f22dfabfda546dc14e8df4f1162.camel@rong.moe> (raw)
In-Reply-To: <20260902181556.9BB481F00A3A@smtp.kernel.org>

Hi Lee,

On Wed, 2026-09-02 at 18:15 +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] Uninitialized work_struct leads to NULL pointer dereference

I believe this is an LLM hallucination. See below.

> --
> 
> commit b9b9203cb3b45eb3bbf3490673a89b53a7df12ae
> Author: Rong Zhang <i@rong.moe>
> 
> leds: trigger: Add led_trigger_notify_hw_control_changed() interface
> 
> This commit introduces a new interface to notify the LED core about
> hardware-initiated trigger transitions. It adds a workqueue deferral
> mechanism to safely handle these transitions.
> 
> > diff --git a/drivers/leds/led-class.c b/drivers/leds/led-class.c
> > index 7e571bd1de5b3..3b438d8da5e0c 100644
> > --- a/drivers/leds/led-class.c
> > +++ b/drivers/leds/led-class.c
> 
> [ ... ]
> 
> > @@ -611,6 +611,9 @@ int led_classdev_register_ext(struct device *parent,
> >  	led_trigger_set_default(led_cdev);
> >  #endif
> >  
> > +	if (led_cdev->flags & LED_TRIG_HW_CHANGED)
> > +		led_trigger_init_hw_changed(led_cdev);
> > +
> 
> [Severity: High]
> Is it safe to initialize the work_struct after activating the default
> trigger?
> 
> By the time led_trigger_init_hw_changed() is called,
> led_trigger_set_default() has already run and the device is active. If a
> hardware interrupt or userspace action fires in this small window, it could
> invoke the notification before the work_struct is fully initialized.
> 
> >  	mutex_unlock(&led_cdev->led_access);
> 
> [ ... ]
> 
> > diff --git a/drivers/leds/led-triggers.c b/drivers/leds/led-triggers.c
> > index cb49a02a8b3cf..a9d992a886161 100644
> > --- a/drivers/leds/led-triggers.c
> > +++ b/drivers/leds/led-triggers.c
> 
> [ ... ]
> 
> > +void led_trigger_notify_hw_control_changed(struct led_classdev *led_cdev, bool activate)
> > +{
> > +	/* Restricted to private triggers. */
> > +	if (WARN_ON(!(led_cdev->flags & LED_TRIG_HW_CHANGED) ||
> > +		    !led_cdev->hw_control_trigger || !led_cdev->trigger_type))
> > +		return;
> > +
> > +	WRITE_ONCE(led_cdev->triggers_hw_changed, activate);
> > +
> > +	schedule_work(&led_cdev->triggers_hw_changed_work);
> 
> [Severity: High]
> If this notification is triggered during the registration window mentioned
> above, will this schedule an uninitialized work_struct?

The LED driver apparently cannot call anything on the LED device during
the registration. If the driver lost its sanity and did so, it would
break tons of things, not limited to the "concern" here.

Therefore, this is not a valid concern and should be considered as an LLM
hallucination.

Thanks,
Rong

> 
> Scheduling a zero-initialized work_struct means the function pointer is NULL,
> which will cause a kernel panic when the worker thread attempts to execute it.
> 
> > +}

  reply	other threads:[~2026-09-02 19:01 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-01 18:09 [PATCH v6 00/12] leds: Add support for hardware-initiated hardware control trigger transition Rong Zhang
2026-09-01 18:09 ` [PATCH v6 01/12] leds: class: Always protect brightness_show() with led_access Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 02/12] leds: Move led_trigger_is_hw_controlled() to the right place Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 03/12] leds: class: Remove hardware control trigger when writing brightness Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 04/12] leds: trigger: Add offloaded() callback and provide trigger_may_offload attribute Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 05/12] leds: cros_ec: Implement offloaded() trigger callback Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-02 18:45     ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 06/12] leds: turris-omnia: Implement offloaded() trigger callback and declare hw_control_trigger Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-02 18:46     ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 07/12] leds: trigger: netdev: Implement offloaded() callback Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-02 18:47     ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 08/12] leds: trigger: Enforce strict checks in led_trigger_is_hw_controlled() Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 09/12] leds: trigger: Add led_trigger_notify_hw_control_changed() interface Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-02 18:56     ` Rong Zhang [this message]
2026-09-01 18:09 ` [PATCH v6 10/12] platform/x86: ideapad-laptop: Serialize keyboard backlight tracking Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-01 18:09 ` [PATCH v6 11/12] platform/x86: ideapad-laptop: Decouple hardware & classdev brightness for keyboard backlight Rong Zhang
2026-09-02 18:15   ` sashiko-bot
2026-09-02 19:15     ` Rong Zhang
2026-09-01 18:09 ` [PATCH v6 12/12] platform/x86: ideapad-laptop: Fully support auto " Rong Zhang
2026-09-02 18:15   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=0b2f92a242002f22dfabfda546dc14e8df4f1162.camel@rong.moe \
    --to=i@rong.moe \
    --cc=lee@kernel.org \
    --cc=linux-leds@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox