From nobody Sat Jul 25 23:41:23 2026 Received: from mail-pl1-f180.google.com (mail-pl1-f180.google.com [209.85.214.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E113033A9E2 for ; Sat, 11 Jul 2026 06:54:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783752884; cv=none; b=R907cH02za5VeGVNvano/OmGSUPxkS58Z+NSe3QZlK51Hd0gV1/djdWEFeJP6OV2Sb3gy44USGo7papHZfhbxKBmQzNsV8t/wY7YeKu6niydTO1K0ugpPCd2J+XO5JtFqXKQIx9Iz2shKknkA3uGTRLOtWMaAiE+WeE2Dw5QkxM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783752884; c=relaxed/simple; bh=r8zVy/hy4V0/8I+I9cgXPbXLAFAu3TqXTM7jHRDzT5U=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=mzS8tCRN/gBfN62BoyJ3lFjQ4f7stY1w1ju5ZNP90SIFHiCezB4XyqYSyl2BdGd4zj86YmlNHpGGvxL9HjAcq0kP2sFFxN6PQjcG91NKI4lzianXLbALk4/d228OEk9AiixihCUKVg8bPCAyyYETNOiKrkLtQIKh8z9SXRAjV6M= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.214.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f180.google.com with SMTP id d9443c01a7336-2c7c61b5292so29326665ad.0 for ; Fri, 10 Jul 2026 23:54:42 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783752882; x=1784357682; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=LnDtSBfU0+MIPTjDEiJMV7jjCz5ET5nDw4xwWOKlpbE=; b=L5w4xgNY/W+jBe0sS+TTG4jxX6SaUTfIYY9TRnbvNfiwj6WVAD4BGfD5Tp3ckMtVcP cSar5ZlGtffW5VnMA+DsJzg5MsIHEYMl+5H0lokFc4hkWwzFYg4viaDGp3fnbAKiKKpd HT3AiSygRZleYSgjeAlHQmdU4SbKvMWZjo3WWYVFJL1N+FprH3ZvvYxrJoFZ0UI+17FN /atkGFNZvWECr5kqQquGpkhveESNfbdVVq3rLO5HRYHPLPTPJYzIyMEAMudy1V8ECmdD N1V6ZGyiayxRawEkWxLIY2Meyhi+Yk/F5EXRJxdTJWMPENFAxQ9u+ME1pCyClYPNl/R+ vq/Q== X-Forwarded-Encrypted: i=1; AHgh+RpW+BYBbULRVKjvcQaz4bS32CfJVzElExBjSS6udAPz7J9UVD3I5ulOmK/zMH45TQHOl4X5hhyhj5XmTZg=@vger.kernel.org X-Gm-Message-State: AOJu0YyduTTrv4G4bAiN4zQFPuOIOVfzOqnosDICKRHP/CSc2bcDdnip ud/cIGVPSVJveB950RFiYT8amhmWwrv0JKYsckRsHtFVoFqfvF0/FN4= X-Gm-Gg: AfdE7cnygSfBp7OukNfalGhOkLrLqfzpcbhCJoHTiIDVjbLdDrsWQ7VK3rH0CR5QGB5 72ZylPgnNhWaagdTyPuK2s7+G5qcGsD+59A0Bw2UfFmCC3KEROSH0Tngjh+UUeltXuXNzxlgw4S rK9ULxvHGwrSDDSeNA4plzGWPTk0UdZdgN7wALA2vs2B5kUfl+ISTjfR5cwRjF5pPz5WoRiScUM 4s6A0M0sqImskJa9UdJLoFnhRiUkJ9xcc2DJ/tk7MPsKh49IkZ5FTk5Fyfk8p7hj/8MGlQnzNkk 0UdfLr8l+8hjr506s8/crVkMvbrFXaTNdyV4S/x9qqLS/WB5yqnddHrZC4SWS/hpoaIhaewEMUS x/v/UjnW6UOAxLkNEMAEAtSuOkziPw88qdDYyoJttia0KSrvJEKFSsuBrePNvIJuU8A4i8YvqCo XWkuDzTYRhhOgz47dI3wll1MbiS7n/MJ38rCP8PBUy5ocvUIzr6unQbtyM+LRgTBwBYj/aTzzuB 8fWHZ0VDklAXOHtKFi77exlylVwfZAKvnVl X-Received: by 2002:a17:903:2f90:b0:2ca:4cfd:a6ea with SMTP id d9443c01a7336-2ce9e7b0335mr19692175ad.16.1783752882319; Fri, 10 Jul 2026 23:54:42 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ce8f5183b9sm18272535ad.5.2026.07.10.23.54.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 10 Jul 2026 23:54:41 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v2 1/3] Input: applespi - force PIO mode on MacBook8,1 Date: Sat, 11 Jul 2026 14:54:13 +0800 Message-Id: <20260711065415.7396-2-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711065415.7396-1-fourdollars@debian.org> References: <20260711055247.5412-1-fourdollars@debian.org> <20260711065415.7396-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" On MacBook8,1 (early 2015 12" MacBook), the LPSS SPI controller's DMA handshake and interrupt routing frequently fail or time out after warm reboots, causing the keyboard and trackpad to become unresponsive and spamming "SPI transfer timed out" (-110) errors to dmesg. Address this by introducing a DMI quirk inside the probe function that detects the MacBook8,1 model and overrides the controller's can_dma callback to a custom helper that always returns false. This forces the host controller to fall back to the rock-solid PIO mode. Since we overwrite the shared host controller's can_dma callback, save the original callback pointer during probe and restore it in the unbind (remove) path to prevent an execute-after-free vulnerability when the applespi driver is unloaded. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index b5ff71cd5a70..07a910cb8459 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -45,6 +45,7 @@ #include #include #include +#include #include #include #include @@ -431,6 +432,10 @@ struct applespi_data { int tp_dim_max_x; int tp_dim_min_y; int tp_dim_max_y; + + bool (*original_can_dma)(struct spi_controller *controller, + struct spi_device *spi, + struct spi_transfer *xfer); }; =20 static const unsigned char applespi_scancodes[] =3D { @@ -1605,6 +1610,13 @@ static void applespi_save_bl_level(struct applespi_d= ata *applespi, "Error saving backlight level to EFI vars: 0x%lx\n", sts); } =20 +static bool applespi_can_not_dma(struct spi_controller *controller, + struct spi_device *spi, + struct spi_transfer *xfer) +{ + return false; +} + static int applespi_probe(struct spi_device *spi) { struct applespi_data *applespi; @@ -1788,6 +1800,19 @@ static int applespi_probe(struct spi_device *spi) debugfs_create_file("tp_dim", 0400, applespi->debugfs_root, applespi, &applespi_tp_dim_fops); =20 + /* + * MacBook8,1's SPI host controller DMA is broken (timeout errors). + * Force PIO mode by overriding the controller's can_dma callback. + * + * Since we modify the shared controller's callback, we save the + * original pointer and restore it in applespi_remove(). + */ + applespi->original_can_dma =3D spi->controller->can_dma; + if (dmi_match(DMI_PRODUCT_NAME, "MacBook8,1")) { + dev_info(&spi->dev, "Disabling DMA for MacBook8,1 SPI to force PIO mode\= n"); + spi->controller->can_dma =3D applespi_can_not_dma; + } + return 0; } =20 @@ -1822,6 +1847,9 @@ static void applespi_remove(struct spi_device *spi) =20 applespi_drain_reads(applespi); =20 + if (applespi->original_can_dma) + spi->controller->can_dma =3D applespi->original_can_dma; + debugfs_remove_recursive(applespi->debugfs_root); } =20 --=20 2.39.5 From nobody Sat Jul 25 23:41:23 2026 Received: from mail-pl1-f172.google.com (mail-pl1-f172.google.com [209.85.214.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BD8212FB97D for ; Sat, 11 Jul 2026 06:54:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783752886; cv=none; b=uwCxcnzIcOZK0nTWfkOk1bVpSBpQzWyunRZzZlB2qrgEvAvtSD5QwonPLlDNQlPBmCk6EnAr6Hy/BAB20KNpk4tsXofpAoPKvscLZhiDPS3L6XFAdrBKfjkBqi2JIL8h/z8RfrVBTIm732q+6P56gR5EIXe6yhi7yfOcoj63+R8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783752886; c=relaxed/simple; bh=hGG1QqmsXO8DZa/raxRUemdtxRcLvOuVWVFaisUeLkI=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=k/Rz4MYYxPjqdlzAJA6HIp4LKbq6lDFAw7N9FTtCuGW1gcYuTFqwy7AAtCBDivFIQ8dRx7Sk3o/bTkuyB95biQLCMddJEa/MiqDyey9MrQ5n6RHBO/zivtztY0du3yojaP1Z2bK8J2IeFmUlaF2CafqLtL7T0AiEVuVJr4SZDmI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.214.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f172.google.com with SMTP id d9443c01a7336-2cca0c5799eso15936445ad.0 for ; Fri, 10 Jul 2026 23:54:44 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783752884; x=1784357684; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=elcaEIBrAdy5k816lVEGPLULCsTSJKI/r6Pi3p4N1Is=; b=qMpa4WcJsxxEI8nS5aIK42InbOzAJ4F45/yXc19KFf4cHcsTKT7MXEg9dqYWcUVsKb LwpSI5Dh7Dm85pNG+fsiD3jyyySC1E6qPQwpIw9ZivPeaS2nCChl9oh7uexVE7BCJBwX azFGlsrDvnQL0qLp6n/H0Ez9moeTfdFhcKJ814paJXmIe/vIQZHvlDD8EJzoEuYcfgbt MA3v59a0CbJilP4ccWrHotLqp6IjpyxJ6wqbDnWzOGYeVGwl2VTK9RXKv3yK6uPYIh1J pPxyPsK20v+mXGUHo6+lIC01nP9R3hSVSqN+24fgPilaT6Afq0xTbzFr/tJn3U4fZY91 3ZIQ== X-Forwarded-Encrypted: i=1; AHgh+RoVCuGaPdAFxW4B1MwZUSU55lLrHTUNDylO7bsrWZ/YU3nZNCAwtrvf7ZeSgk4AJm+UOXDgiBpOdKq2SRc=@vger.kernel.org X-Gm-Message-State: AOJu0YwHcTFa0tL9QQo2Iz7xXPCIWBkjdSnt3yoilCmV6+BGCy7fiyqS aZvHs+SZbaGAMnXucyLKZNjk3hnWzKn8Nch8h4eFIGgz2B1Nb2X2+On1t/1Cd14tMBbS X-Gm-Gg: AfdE7cnIm1pdBpzu7PagjvtG98ZhBp7FTFgxwhU9sETNV4spguWFGrua+dAuS57cBnL aAsTUs+flxF7BCcw0K6l7C56WKD8y6OD4gPbNHqc7vzCWa1SUUzaQw4oA6dG9f2cu/T1Jfcz1nO Dlx9pvj8EleGCD9M/MehIBvmCPzc/Gei2YkqpNLRuusPw4mqMZBImpRe7W6prsNLMnDRUczDGhC qCLjpNPq61zoP4aizNccpVTfQCYifNGOAOMikWVuoSrLie9NjEGvT9IUOm+YZMHSPlQ5z/+rjnW 01Y+Ii+ycAHVezUr+Es9Ah7KJDTgij6CJ/jIDIf0ch6ANiLEoqtJmm+uFTnhRseYgcrego9AbXJ EWxY5HIJuzY1GQWQHmBwSphsiUQjPqhvmE+wOT52JJ5MZopeGaaJI8jnFqDqk/5Bn6vMXw1gQ+3 A0lNGl8dUT4aSFeNY4W/BOLVakjAKwKc90BoH4CzC0my/Iw4sp1680k0EhFNysNLwWue3FFt4r4 d2xiwHb1An39cmqfCWjlGUxSDeGMn9a9jmD X-Received: by 2002:a17:902:ffcf:b0:2ca:d873:3b34 with SMTP id d9443c01a7336-2ce9f3b3933mr22477795ad.36.1783752884190; Fri, 10 Jul 2026 23:54:44 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ce8f5183b9sm18272535ad.5.2026.07.10.23.54.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 10 Jul 2026 23:54:43 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v2 2/3] Input: applespi - cancel pending work on driver remove Date: Sat, 11 Jul 2026 14:54:14 +0800 Message-Id: <20260711065415.7396-3-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711065415.7396-1-fourdollars@debian.org> References: <20260711055247.5412-1-fourdollars@debian.org> <20260711065415.7396-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" During driver removal in applespi_remove(), the managed private data structure is freed by devres. However, the driver does not cancel the asynchronous work applespi->work, which registers the touchpad input device. This creates a use-after-free (UAF) vulnerability if a pending or running worker thread attempts to access the private data after the remove function returns. Fix this by explicitly calling cancel_work_sync(&applespi->work) in applespi_remove() before cleanups. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index 07a910cb8459..b6b4d258d0dd 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -1847,6 +1847,8 @@ static void applespi_remove(struct spi_device *spi) =20 applespi_drain_reads(applespi); =20 + cancel_work_sync(&applespi->work); + if (applespi->original_can_dma) spi->controller->can_dma =3D applespi->original_can_dma; =20 --=20 2.39.5 From nobody Sat Jul 25 23:41:23 2026 Received: from mail-pl1-f170.google.com (mail-pl1-f170.google.com [209.85.214.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 83F5D3403E1 for ; Sat, 11 Jul 2026 06:54:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783752890; cv=none; b=UmYMIDoWP6f7lefbzevR4CsgyXZ+VPkMbsOov3oIGb535oKXJoGep4hr3rCdRI6zsfl3BdejDSTypQmY0ih19X/RQmSOq30DcK64RVfSzgmzuDoqzZFIj8Xi2luhrqe9yNu7v6C/3ZJMT+8CG2/vB7IxhQ1mWsFTR5Xs6DJrmdk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783752890; c=relaxed/simple; bh=8fT0Gg/8Igu9jt6gZKh1bW7ODGFpVtDQrf69dpWU9zE=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=V25Z4rToZmkBM+z141DxT+2ocAKjqFsOqfNAJDQ1muyXUH29FVV4ueLepoEIhNAeWQdGf/yFSAKLNFmvFkvggywQRAPD2rc9ALN0c/v5PxO8iERPd5jBOeSAQysQukn3JiQ39js77obD3YNNEDO3+Z2YEMivdPbSl3Bp1ufy21U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.214.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f170.google.com with SMTP id d9443c01a7336-2cc97653887so18091165ad.1 for ; Fri, 10 Jul 2026 23:54:46 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783752886; x=1784357686; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=DNuv1LlOXCQ1HK6vbtUi5c2rok5gLYfCN2rAKCK3bnw=; b=ERN0P86ySyExhTr+t39BHAD0y1p6kD/iNu0uhhZ/QW7rcFHlSt3KnoXgp7QLggAXhc n1VWSzEfs1xGAI4NOTMc3wXtCH81y8dwwsHAx1s+oYwe1vR6ZLldoJJ1fa9iUJY1Ys9h zujDRouDs7Y77bSpp5DvFwmWjEkDjtv6L6I/VOys0fnDeexzYZBniUPd0/8bjLqacD8f mpzkOWHosMQ1njhqqkl1VVs4XKgndWs4/I1hSzT8YmyaH/D5Ihb0A2/roM0kljDJHqwu Yj7wX2hKaGbS9UKGUcZx3kIQC9KIIwT7RdTa0yKE3IN/5joilf967A+7/P4YF5KU4pmy lSTA== X-Forwarded-Encrypted: i=1; AHgh+RrJd5MiJ9rgwHfyHzLE231bHACrYNEqyueH6BPapkzNE2E8VxkdV1xdOTybftxJsRfOdZIA0wgH2GSQjAM=@vger.kernel.org X-Gm-Message-State: AOJu0YxKlRBhSUQiiBHidT9fGJd3+yU0xmhQJcy4MBcWzDTZdcxCgzFK 73/CVhOxEi6+2NKkqfdRwmNVp1Dukozr+NtO9MEJ7qSIcVvsuzEYEI8= X-Gm-Gg: AfdE7ckIKJOCEAZ561LiX74/bD3DAwSGNP2Hh5s0VSu+OZEwMa9txCSza/z0HO6Twwe rFxOFO3AMAOjC/pnPE46I/EZEr92ufOmvWhKnuc7Yh5TMoeY8+mPdwdvUaRez2vCDL8CIGAQHvX aIRfmKxRB5ImfALIlv1oW7q3FcDONuXYjRK+356qnprnMDKyAZmFZI24K565PVbl8MMJ1/q177Y i6WiduM4tnXZKZyvtTo0Wm8QuiaCMihNfGxU9UlJ2WmBq6tZE33VXtQtQQQYnNDI2koOPU8M6t+ f4cFp3Z7dgOxkAelkf2ZMSyXgXZUlAE0qRGY5sMphiqeU0ZFVk38QRe1dIX5Eogw4oSXT+dfXBd fQOPxW4DTAYT5oDHB9AeRbjWOheGiYnj8fT83FsfRhLlzEGFO2vyISjiofF4jx9SeIWEBTaR8bQ 0mRX3QcJgEZoYF59roi93Tpa66oui1/oTrJMtKvwSrOweS4fTtegm4T8Tn/q2PnRANYLIjlj0Yp 4nC7WDkhpYMeaCg7tGnDOj+wwR8E9h/U4Uf X-Received: by 2002:a17:902:d987:b0:2c9:df1b:e948 with SMTP id d9443c01a7336-2ce9e9a7128mr24297395ad.4.1783752885868; Fri, 10 Jul 2026 23:54:45 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ce8f5183b9sm18272535ad.5.2026.07.10.23.54.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 10 Jul 2026 23:54:45 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v2 3/3] Input: applespi - fix NULL pointer dereference in tp_dim open Date: Sat, 11 Jul 2026 14:54:15 +0800 Message-Id: <20260711065415.7396-4-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711065415.7396-1-fourdollars@debian.org> References: <20260711055247.5412-1-fourdollars@debian.org> <20260711065415.7396-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The tp_dim debugfs file is registered synchronously during driver probe in applespi_probe(). However, the applespi->touchpad_input_dev is initialized and registered asynchronously in the driver's worker thread. If a userspace process opens the debugfs file before the worker thread has completed initialization, applespi_tp_dim_open() will dereference the NULL applespi->touchpad_input_dev pointer, causing a kernel panic. Fix this by using smp_load_acquire() to safely load touchpad_input_dev and return -ENODEV if it is not yet initialized. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index b6b4d258d0dd..1f8e4ae90285 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -968,12 +968,18 @@ static void applespi_debug_update_dimensions(struct a= pplespi_data *applespi, static int applespi_tp_dim_open(struct inode *inode, struct file *file) { struct applespi_data *applespi =3D inode->i_private; + struct input_dev *touchpad; =20 file->private_data =3D applespi; =20 + /* Pairs with smp_store_release in applespi_register_touchpad_device() */ + touchpad =3D smp_load_acquire(&applespi->touchpad_input_dev); + if (!touchpad) + return -ENODEV; + snprintf(applespi->tp_dim_val, sizeof(applespi->tp_dim_val), "0x%.4x %dx%d+%u+%u\n", - applespi->touchpad_input_dev->id.product, + touchpad->id.product, applespi->tp_dim_min_x, applespi->tp_dim_min_y, applespi->tp_dim_max_x - applespi->tp_dim_min_x, applespi->tp_dim_max_y - applespi->tp_dim_min_y); --=20 2.39.5