From nobody Sat Feb 7 19:45:39 2026 Received: from mail-pf1-f172.google.com (mail-pf1-f172.google.com [209.85.210.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B93EE32E690 for ; Tue, 3 Feb 2026 12:16:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770120972; cv=none; b=twZtChLSl/3Jq/PsZtiknEgmDSNMlPguBQouWeSljTDdOfmkoLO8SB37swcUBjDAL52nUCTJ0XalrBSMK4+LZV4qgP8k1uqsLQKIEQVn3ga+sknuy8mYEkwTbJa03V2o8UcTNxTYpI098KCSLsmDydtiJbUVcJkZHz8qVUdm9YI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770120972; c=relaxed/simple; bh=oBNlv8tpYIAfycUufaW2kqcNJPt0+IY20m9BXQcCGbE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=H3YFD/z/8QVk1X3uoisjcHjGmTORyRN0++Mm0in19XS9/qWSk4qnwEDkN9z+C1oYBy1xBcClKSZrGeFuL640MlyG4vMyv5WCvRd3SDUIh4feupxMpkDjmgpVqhgN26Fd3QZT+locUJru+wJ7CeeRj+y5gm4KIBbZ2hz7RsnHIeY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=QmXap9PL; arc=none smtp.client-ip=209.85.210.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="QmXap9PL" Received: by mail-pf1-f172.google.com with SMTP id d2e1a72fcca58-81f4c0e2b42so3261155b3a.1 for ; Tue, 03 Feb 2026 04:16:09 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1770120969; x=1770725769; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=ibRrXpgw1lU51ODUe8Kbvxi0SMmu3MLTIurVFgESCMQ=; b=QmXap9PLs4e9k2Ck8cvMq/l+QVIdgig/sfrpTF05+SKiJq0/kOCfLjp0yFnV5NO2jn 2T0O0C3wrQVYKah+5qLf5JkbAdWWVWlUepvhxW2lIcN7N7NkVjC3BtFbMUrmaX7A+YBt T3GrlnVWscAtFnUS3nfkEPD43doQ4kxcEeP6kpBWp/n7TVG9SLL8JYRik8sujwRKYi++ YQx/DinXD4AUOTq13LMYQVx4UIShP6uO5VS5TVFZwU3u/jfNZd0w0gmNETK6gPi4/Ulm 4P8ooZLcyk3WuY0hdAdeJHodROOUSjP/6Ti2nCnWLEDH/eYz1qWm1VuRKtB5vbAqLsu/ u8qA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770120969; x=1770725769; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=ibRrXpgw1lU51ODUe8Kbvxi0SMmu3MLTIurVFgESCMQ=; b=LPNF+Bshd5lIx1YendgNdYqsoOFf8FQACcv5awpX1gogTcblsEXmQCYCSsqws3oC9J ofNighYv3hXZjKMg3zGzVIS6L17T/UdO53VwFAj7seM1MVl3GFUHULKK2Vgx7ICzD82N TOqU+OuWQukyvnlLbnQ8fUPH5JXS5CnEKiGeipk0P9vl26fw5jm+1kNC0pLxLJZ6kk1C mJh4XpXBEmCAugA2y2PYQavIPc4gd6A3X9HKcyHQD9zFOCHxvMtuWFfXdqPbPc+7PCch cUxGY7bTClNWtRJ5XZLSrxYIAhw097zMW88MLkBXaJM9pSvUc2wcB/pRJKBF4yh77rM1 8EnQ== X-Forwarded-Encrypted: i=1; AJvYcCUz4sEVLFIyPN6saBwzFSUBhr0sPI8F2J+9yolWibbiTF96Bfuy6mf6OpxxoFOvb+Wmx4uxO0EWflAylUk=@vger.kernel.org X-Gm-Message-State: AOJu0Yy/K8oo03UCG2ydEtMA983TaQpDIj4dKRECOJC6BoZFvTDzHbCr aZyX7XRjdGW1tw3/65BLA1j0YGYhvXLqDVR/L6Tx+ygAP/zDaZBMdj55 X-Gm-Gg: AZuq6aIycK9CSo6AjbzGOhIUS7wDemeGWD12s3Ky05/7yl6Gr53Pmqo0c0BrO+ifh0p TVz1ftVtd4WeuJcFwql/VGtNofI0aRBOhmP+H8YO2H1tqNTp5gTFVcZJnseATPPLCx4Auo09fUz 3DZm5mnwLANMvQC3/s50/4ZFk2ddbZoGkFmqcFM3IGXfeB/mVdqiLEgc1Y7XX86XpRKVdzT0u7i re4Mfp6Qs8vHTcY28X+hpYl/1KbB0xdOBRDNpQ+87sCkK+K9yGGrOf31VKd4v7DohqhLArttNM7 H8Ue+WKKClL2zpVBCnQjMxNZ/R3oJ8aB5gB4US9Qp+KR0qH/wC5rIwkyXOd4b5vbgF+zuWCzhqP m6fgRZU+RDJxSp8GBEQ/hM3AAA3eAfDZ69Kl2QCLYu+yKmMwKUw7J0A+4ofj4DWI1SusPR+ogcG T/5HOTa9V3nE/I4vZM6+65eMU4bcPBFfsFF5FvAWmxjrcAVslMJSbmctXPN5g9QW151Ue4P35g4 RN9kazvMYlnH/pK0YdHeMWMN0BOdDMdrNR6RVBxlCJV5Mv7ITf/UZ+sDBRwXXRsDXSY X-Received: by 2002:aa7:9064:0:b0:81f:50b1:51f2 with SMTP id d2e1a72fcca58-823aa71118cmr12594872b3a.41.1770120968901; Tue, 03 Feb 2026 04:16:08 -0800 (PST) Received: from 2045D.localdomain (120.sub-75-226-39.myvzw.com. [75.226.39.120]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-82379bfb924sm19339481b3a.34.2026.02.03.04.16.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 03 Feb 2026 04:16:08 -0800 (PST) From: Gui-Dong Han To: linux@roeck-us.net Cc: linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, baijiaju1990@gmail.com, Gui-Dong Han , Ben Hutchings , stable@vger.kernel.org Subject: [PATCH] hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization induced race Date: Tue, 3 Feb 2026 20:14:43 +0800 Message-ID: <20260203121443.5482-1-hanguidong02@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Simply copying shared data to a local variable cannot prevent data races. The compiler is allowed to optimize away the local copy and re-read the shared memory, causing a Time-of-Check Time-of-Use (TOCTOU) issue if the data changes between the check and the usage. To enforce the use of the local variable, use READ_ONCE() when reading the shared data and WRITE_ONCE() when updating it. Apply these macros to the three identified locations (curr_sense, adc, and fault) where local variables are used for error validation, ensuring the value remains consistent. Reported-by: Ben Hutchings Closes: https://lore.kernel.org/all/6fe17868327207e8b850cf9f88b7dc58b2021f7= 3.camel@decadent.org.uk/ Fixes: f5bae2642e3d ("hwmon: Driver for MAX16065 System Manager and compati= bles") Fixes: b8d5acdcf525 ("hwmon: (max16065) Use local variable to avoid TOCTOU") Cc: stable@vger.kernel.org Signed-off-by: Gui-Dong Han --- drivers/hwmon/max16065.c | 26 +++++++++++++------------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/drivers/hwmon/max16065.c b/drivers/hwmon/max16065.c index 4c9e7892a73c..43fbb9b26b10 100644 --- a/drivers/hwmon/max16065.c +++ b/drivers/hwmon/max16065.c @@ -151,27 +151,27 @@ static struct max16065_data *max16065_update_device(s= truct device *dev) int i; =20 for (i =3D 0; i < data->num_adc; i++) - data->adc[i] - =3D max16065_read_adc(client, MAX16065_ADC(i)); + WRITE_ONCE(data->adc[i], + max16065_read_adc(client, MAX16065_ADC(i))); =20 if (data->have_current) { - data->adc[MAX16065_NUM_ADC] - =3D max16065_read_adc(client, MAX16065_CSP_ADC); - data->curr_sense - =3D i2c_smbus_read_byte_data(client, - MAX16065_CURR_SENSE); + WRITE_ONCE(data->adc[MAX16065_NUM_ADC], + max16065_read_adc(client, MAX16065_CSP_ADC)); + WRITE_ONCE(data->curr_sense, + i2c_smbus_read_byte_data(client, MAX16065_CURR_SENSE)); } =20 for (i =3D 0; i < 2; i++) - data->fault[i] - =3D i2c_smbus_read_byte_data(client, MAX16065_FAULT(i)); + WRITE_ONCE(data->fault[i], + i2c_smbus_read_byte_data(client, MAX16065_FAULT(i))); =20 /* * MAX16067 and MAX16068 have separate undervoltage and * overvoltage alarm bits. Squash them together. */ if (data->chip =3D=3D max16067 || data->chip =3D=3D max16068) - data->fault[0] |=3D data->fault[1]; + WRITE_ONCE(data->fault[0], + data->fault[0] | data->fault[1]); =20 data->last_updated =3D jiffies; data->valid =3D true; @@ -185,7 +185,7 @@ static ssize_t max16065_alarm_show(struct device *dev, { struct sensor_device_attribute_2 *attr2 =3D to_sensor_dev_attr_2(da); struct max16065_data *data =3D max16065_update_device(dev); - int val =3D data->fault[attr2->nr]; + int val =3D READ_ONCE(data->fault[attr2->nr]); =20 if (val < 0) return val; @@ -203,7 +203,7 @@ static ssize_t max16065_input_show(struct device *dev, { struct sensor_device_attribute *attr =3D to_sensor_dev_attr(da); struct max16065_data *data =3D max16065_update_device(dev); - int adc =3D data->adc[attr->index]; + int adc =3D READ_ONCE(data->adc[attr->index]); =20 if (unlikely(adc < 0)) return adc; @@ -216,7 +216,7 @@ static ssize_t max16065_current_show(struct device *dev, struct device_attribute *da, char *buf) { struct max16065_data *data =3D max16065_update_device(dev); - int curr_sense =3D data->curr_sense; + int curr_sense =3D READ_ONCE(data->curr_sense); =20 if (unlikely(curr_sense < 0)) return curr_sense; --=20 2.43.0