893-leds_st1202-Fix-NULL-pointer-access-error.patch 2.4 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970
  1. From e3da313ebcace17f1227566fe1b0d0c3883061f9 Mon Sep 17 00:00:00 2001
  2. From: Manuel Fombuena <[email protected]>
  3. Date: Fri, 17 Jan 2025 12:31:49 +0000
  4. Subject: [PATCH 1/5] leds: leds-st1202: fix NULL pointer access on race
  5. condition
  6. st1202_dt_init() calls devm_led_classdev_register_ext() before the
  7. internal data structures are properly setup, so the leds become visible
  8. to user space while being partially initialized, leading to a window
  9. where trying to access them causes a NULL pointer access.
  10. This change moves devm_led_classdev_register_ext() to the last thing to
  11. happen during initialization to eliminate it.
  12. Signed-off-by: Manuel Fombuena <[email protected]>
  13. ---
  14. drivers/leds/leds-st1202.c | 21 ++++++++++-----------
  15. 1 file changed, 10 insertions(+), 11 deletions(-)
  16. --- a/drivers/leds/leds-st1202.c
  17. +++ b/drivers/leds/leds-st1202.c
  18. @@ -261,8 +261,6 @@ static int st1202_dt_init(struct st1202_
  19. int err, reg;
  20. for_each_available_child_of_node_scoped(dev_of_node(dev), child) {
  21. - struct led_init_data init_data = {};
  22. -
  23. err = of_property_read_u32(child, "reg", &reg);
  24. if (err)
  25. return dev_err_probe(dev, err, "Invalid register\n");
  26. @@ -276,15 +274,6 @@ static int st1202_dt_init(struct st1202_
  27. led->led_cdev.pattern_set = st1202_led_pattern_set;
  28. led->led_cdev.pattern_clear = st1202_led_pattern_clear;
  29. led->led_cdev.default_trigger = "pattern";
  30. -
  31. - init_data.fwnode = led->fwnode;
  32. - init_data.devicename = "st1202";
  33. - init_data.default_label = ":";
  34. -
  35. - err = devm_led_classdev_register_ext(dev, &led->led_cdev, &init_data);
  36. - if (err < 0)
  37. - return dev_err_probe(dev, err, "Failed to register LED class device\n");
  38. -
  39. led->led_cdev.brightness_set = st1202_brightness_set;
  40. led->led_cdev.brightness_get = st1202_brightness_get;
  41. }
  42. @@ -368,6 +357,7 @@ static int st1202_probe(struct i2c_clien
  43. return ret;
  44. for (int i = 0; i < ST1202_MAX_LEDS; i++) {
  45. + struct led_init_data init_data = {};
  46. led = &chip->leds[i];
  47. led->chip = chip;
  48. led->led_num = i;
  49. @@ -384,6 +374,15 @@ static int st1202_probe(struct i2c_clien
  50. if (ret < 0)
  51. return dev_err_probe(&client->dev, ret,
  52. "Failed to clear LED pattern\n");
  53. +
  54. + init_data.fwnode = led->fwnode;
  55. + init_data.devicename = "st1202";
  56. + init_data.default_label = ":";
  57. +
  58. + ret = devm_led_classdev_register_ext(&client->dev, &led->led_cdev, &init_data);
  59. + if (ret < 0)
  60. + return dev_err_probe(&client->dev, ret,
  61. + "Failed to register LED class device\n");
  62. }
  63. return 0;