From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f182.google.com (mail-pg1-f182.google.com [209.85.215.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0051F2BEFFE for ; Mon, 20 Jul 2026 10:14:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.182 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542500; cv=none; b=HO3Sx5JnxX9JFIKREh9sxZN2X7Gj1sCPe+Vc6j66S6ej3O9aLz27gLx+MfOp6RMqJ10rKsMtKtYN19sWxSppYk52HxPq020Yavz9poK3Nt/EjVBs4dAk+4ue/MV8zJxvNoIMx8jo77cwS4d5fIwT3jMDVNaTzgOfixiW5uiBdLU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542500; c=relaxed/simple; bh=JXokrE38sgfKHFjs6siu/55oNnmhzpQI+mIVcZk7QiY=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=giEuLOklmQYRBNiHNYEzT0bqOm2dug/mdpVpu0x/RQ2gU0j5AgNKuZd6q23M/6bPrweFFwOKtIxmrjL6mKswI+5NbX85HxU7wVAZ2l3FqyJdzjrqhQBhcxImNX8AgvGd/HSOa8jr3O0rWIa1GAAQ5RswG3Gf2wbcrrkkeIl3Lrg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.215.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pg1-f182.google.com with SMTP id 41be03b00d2f7-ca97d139d5fso6947236a12.0 for ; Mon, 20 Jul 2026 03:14:56 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784542490; x=1785147290; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=RF1ftOMQ+N1bAoeZkI0/wgbxDAI/VKJ5VcqnqJwi0CQ=; b=Rwv9i+BfFsKyUiexyQ+uDGZHyzO9qUc3qpyx23z+1YNPkefyPENzayCFQYcjVgpAbf e7WIHNMEkokycC9XWu2RV+x+cuXou28zbT709vCGx0dFvoEqjjiEzGnm6JfmrklXTLe1 nnsvcDqaiLKF+wvuPBqYILUz4xxN/Wum+wa7BecJ93LCZXtdUYO4oAWjw+4m7J8NaOQe NWU0ECkYtPhnmK8bPyfJ06LZdo8lw8gvpiAATC+q0GKct3iZmHiO2GWrnAK7o+eYyoUL spr+/koxw5sTYiCa0HIchTRh95NeV1iLAY1YpOBtUPRe5t2ZCKjm2HHWK9XiUo1SNDsz 6JLg== X-Forwarded-Encrypted: i=1; AHgh+Rp81f24VIIMc4DDkkRePK9udmJEb4Dhxb6OEG5yabDsywPcZk84i+IduK554FfrwKFxQX+gh84N7gP4P2I=@vger.kernel.org X-Gm-Message-State: AOJu0YzqPL1JYJmK3JIldWDtBcWhlBmAbb5X/zafOPANQyvwIyLnkhXh DkUAbBPDEH25iG32Zpqa5ouMSh8c/B8HORRaoAkyosJ71wT767QE4Q4= X-Gm-Gg: AfdE7cnsWRMjMap6tIvg+8XE6TjAjHp5Eil/X++E/EwcHQAQkfDOrxalW937c5fJmRw O740pP/OKt3jSfvEZHBZR1HOtnX0Od+z/E1dl+SXdilXPzEd5ZjCEW3NX7sRxwQPDHBGnSrsCxa fTt2yRTxssG3V5UvB44+Y3Pdp5/BZ8dBpHqez4yqmOgU6+bT2sUCvzAxiYpXs1mfXUM2YQZ6TEl Yml+DnfccWG4qtkp2VvI096SSl95HbHyV7EzUwhpn4dk1fC2OTZCCOcdKUrMe3DfRtp4Rzdxrgg dEp+ZcyBZm1M96zSkiMGwjncvxoi4W9IJfzwmqnC9sQIUjjkKzxYO97q72On01xDj3qR8SdvT3h uxUgs6UoQlCPW72YH+1EPaKcYzFd5HrstTe+ELDOWRLGr9vTliqzIinSXJ+3g7jTitINxktkdoT 7Y8g/+ZxnHmqvc5GTdum5FLFc4NQsqiGn1xJER3HAulVRoxXAkfOrFHU2ou5/yX96HxmPjvY3eA MHz1YQGThXS/DSp9w== X-Received: by 2002:a05:6a21:9206:b0:3c3:7ac4:dac0 with SMTP id adf61e73a8af0-3c3ad5d4f0fmr15037185637.13.1784542490168; Mon, 20 Jul 2026 03:14:50 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-16-100.dynamic-ip.hinet.net. [61.228.16.100]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cb517f94c31sm4411321a12.13.2026.07.20.03.14.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 03:14:49 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: Mark Brown , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v2 5/5] Input: applespi - fix use-after-free in applespi_remove() Date: Mon, 20 Jul 2026 18:14:35 +0800 Message-Id: <20260720101435.13612-6-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260720101435.13612-1-fourdollars@debian.org> References: <20260720101435.13612-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit applespi_remove() called applespi_drain_writes() to wait for in-flight write transfers, then immediately called acpi_disable_gpe() and acpi_remove_gpe_handler(). However it then called applespi_drain_reads() *after* the GPE handler was removed, which races with any read SPI completion callback that could still reference the applespi struct already being torn down. Moreover, the two drain helpers use separate wait paths that can miss each other: a read completion arriving just after drain_writes() returns but before drain_reads() is called will set read_active, and the subsequent drain_reads() will then wait on a wait_queue that nobody will ever wake because the GPE is already gone. Fix by replacing the two separate drain calls with a single barrier using the existing cancel_spi + wait_event_lock_irq mechanism: - Set cancel_spi = true under the spinlock so that applespi_async() immediately rejects new SPI submissions and wakes the wait queue once all outstanding operations have drained. - Wait for !applespi_async_outstanding() before proceeding with teardown. - Disable the GPE and remove its handler only after all in-flight SPI transfers have completed, eliminating the use-after-free window. Fixes: 0b7a8ac72fc1 ("Input: applespi - add driver for Apple SPI keyboard and touchpad") Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/applespi.c index 95a8f790eaff..088337f060b2 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -1910,15 +1910,22 @@ static void applespi_drain_reads(struct applespi_data *applespi) static void applespi_remove(struct spi_device *spi) { struct applespi_data *applespi = spi_get_drvdata(spi); + unsigned long flags; - applespi_drain_writes(applespi); + /* Prevent any new SPI transfers and wait for outstanding ones */ + spin_lock_irqsave(&applespi->cmd_msg_lock, flags); + applespi->cancel_spi = true; + wait_event_lock_irq_timeout(applespi->wait_queue, + !applespi_async_outstanding(applespi), + applespi->cmd_msg_lock, + msecs_to_jiffies(3000)); + spin_unlock_irqrestore(&applespi->cmd_msg_lock, flags); + /* Disable GPE and remove handler */ acpi_disable_gpe(NULL, applespi->gpe); acpi_remove_gpe_handler(NULL, applespi->gpe, applespi_notify); device_wakeup_disable(&spi->dev); - applespi_drain_reads(applespi); - debugfs_remove_recursive(applespi->debugfs_root); } -- 2.39.5