From nobody Sat Jul 25 23:41:40 2026 Received: from mail-pl1-f174.google.com (mail-pl1-f174.google.com [209.85.214.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 08C82381EB3 for ; Sat, 11 Jul 2026 07:58:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.174 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783756684; cv=none; b=R2/wmA0Y0h2+KSTa/627fL1D37PUmtJ3NPXOdblLxsRSJax/4cBPTsja/1549vHHx3wQA7aOJaYYlik0eRVmR/+o9+db10NlVGPwSs+uGvJTG4eSj+4iMtmuK03p8kImjAWz3Vn8SxkGS4tinbDjUlQwyPWxeIQ21gmkdcE2/BI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783756684; c=relaxed/simple; bh=TFMbF+6YpQE5zKhsi92k+6lG3+v7THpi7mqTMKsa1tE=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=JeRyJVfS/WBja862MkXwOpu4Lq+6Gg0unt/Lhck8IC4UMIKMH0UGKKqS5K3NqqlT3QNRGR+Q1Lx4z4K58ag1JaRMqEFd45o8rC/DDVR2hj4METe7PJYErdsZ4m2zkXIF/UFmbo++hRFkYA059o0/S+2yHiz1GA1bx6owQ4Tb4Gw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.214.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f174.google.com with SMTP id d9443c01a7336-2ccdb73f0e1so14084035ad.3 for ; Sat, 11 Jul 2026 00:58:02 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783756682; x=1784361482; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=fCVs3YON/pS66KjufLTdz6MFzQkosWnFvToVGu3OBSs=; b=XrH7pO9HFaRb1KhJVK1vU8scbXzUNAJT04btfcnf1CBHCgVQf/rFjwo1JtI1Lz+cM8 NQ1stS7WBCqOSAlchHmC9KBojIfkdfOh4eW3zgLPcQnEY2/SYMQ4VPnRGeYQRJHSOW8H CBriX6GamWnNM3BIwRRaM69Cz0dJjQZkMUK23h/x2V0/UQEi6FozXoTmvXFOAq//gQnV d4zqr0I4mAkUkmJGcnE0SQ/2qn5+4nG5l70HKUQ/0ZR0wguW38SWkxUIKMfepp+d2TS7 R0banbYhxMWWmJ/HLOx2GH5ChWAt8ZSWEFfaxNJhTV8675ROJHCeKVwegp6Upef48FIL Nj4g== X-Forwarded-Encrypted: i=1; AHgh+RolXcD1rJx/eMnqDGJ03QXkeaityIkP3VYM6kzbMCNGyxpBC38znUy0XuBgG+WbffxUUWaY/oISzvNZsBQ=@vger.kernel.org X-Gm-Message-State: AOJu0Yw1CxK7iruhigNpl5C6nQ+qMimDM9u4e3a0Mt4QwaiU7QhWez9+ dgs825uc7TaQQtLKjMLHy7CdSRCcrq5X+4gDEbGG3q2sMo52LZo9bvM= X-Gm-Gg: AfdE7cnoUIUzQF/yDbe4CZC+GTtvDc74Rs+l2d2LKsQ1yqgB98NaY1hDHfeL2NCMA5V Nhx/cSgaX0wEAgGKFw3MAPBjc0Z7tiBgfJtk6zYKuuLoHZrwKNp8hjEcHzUqZcQ4PjCDWe9/iFp 1HaWW5nbmhyR5dd36Moquat3p+wuC8nRIk1IZ347ukWLv7Xayn9GiyoSJMn4eB+CVZXBaOqlDxt WF2EYuT4qmol4rCdQwZY/oJNIT9Ml8kj52guzRVJYcypuIF1tDyt4Zz4Mm/IPBSTe72dPLPm9Lp BdcSK4r8lSbvVQxLv4Y8mbGzU98hV6Rs5puzJTU476mTBUX5W2KtO3ipHN30FOFWnpMdd30dfez /TA0coJe5Fzg0ue++c8xM7PRHXjdguvE+19WbCpIirKdEjVGjiuvWhcEEMNiOvpPtReii0HQEOQ 6eusJTtZXNeXDMFIHvFwD3Tv0mgKIgcFR02PZLm5y6tK0dWrDVDn5FOAeLZajsAv0eVhOtiCr/i lu3Axq7N/LvW87emmnPrzzsWw== X-Received: by 2002:a17:902:f651:b0:2ca:1594:451e with SMTP id d9443c01a7336-2ce9f286f13mr24254365ad.31.1783756682253; Sat, 11 Jul 2026 00:58:02 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ccc9d1e279sm71130285ad.45.2026.07.11.00.58.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 00:58:01 -0700 (PDT) From: Shih-Yuan Lee To: Henrik Rydberg , Guenter Roeck Cc: Armin Wolf , linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v5 1/3] hwmon: (applesmc) Cache fan positions during register initialization Date: Sat, 11 Jul 2026 15:57:52 +0800 Message-Id: <20260711075754.11358-2-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711075754.11358-1-fourdollars@debian.org> References: <20260710123236.10508-1-fourdollars@debian.org> <20260711075754.11358-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" To support the read_string callback for fan labels in the modern HWMON API, load and cache the fan position names in smcreg.fan_positions during register initialization. Pre-pad fallback labels with four spaces to match the "+ 4" pointer arithmetic offset used by all fan labels in the read_string callback. Signed-off-by: Shih-Yuan Lee --- drivers/hwmon/applesmc.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/drivers/hwmon/applesmc.c b/drivers/hwmon/applesmc.c index 90a14a7f2c4c..9b2d9ecb20c0 100644 --- a/drivers/hwmon/applesmc.c +++ b/drivers/hwmon/applesmc.c @@ -133,6 +133,7 @@ static struct applesmc_registers { bool init_complete; /* true when fully initialized */ struct applesmc_entry *cache; /* cached key entries */ const char **index; /* temperature key index */ + char fan_positions[10][17]; /* cached fan position labels */ } smcreg =3D { .mutex =3D __MUTEX_INITIALIZER(smcreg.mutex), }; @@ -566,7 +567,7 @@ static int applesmc_init_smcreg_try(void) { struct applesmc_registers *s =3D &smcreg; bool left_light_sensor =3D false, right_light_sensor =3D false; - unsigned int count; + unsigned int count, i; u8 tmp[1]; int ret; =20 @@ -597,6 +598,16 @@ static int applesmc_init_smcreg_try(void) if (s->fan_count > 10) s->fan_count =3D 10; =20 + for (i =3D 0; i < s->fan_count; i++) { + char newkey[5]; + + scnprintf(newkey, sizeof(newkey), FAN_ID_FMT, i); + ret =3D applesmc_read_key(newkey, s->fan_positions[i], 16); + s->fan_positions[i][16] =3D 0; + if (ret) + scnprintf(s->fan_positions[i], 17, " Fan %d", i); + } + ret =3D applesmc_get_lower_bound(&s->temp_begin, "T"); if (ret) return ret; --=20 2.39.5 From nobody Sat Jul 25 23:41:40 2026 Received: from mail-pl1-f182.google.com (mail-pl1-f182.google.com [209.85.214.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B1EB0381E8E for ; Sat, 11 Jul 2026 07:58:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783756687; cv=none; b=TlLg09TrTcnxg8Y8JvhGpEXYmmJ0sWHK+fHLBenND9TaeoFIP8gcbxv00KQ+OhqWkuRTi/Bsou9KvPBvJm6wfRnpkAHB79LEMk08wy3gVY6OXuQ2vTkxRAQy7fpHEfRdKvyHU8x0Id4ar5G+m7boj/g0lsUS99el153Q1FVyxvc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783756687; c=relaxed/simple; bh=PvyDEtDG8TdjDcuAHzeqmpHFrdL1tyXkP2WE36J/VYo=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=iJipdRaFKTLEc4uijaxRvCJ+wFTmQMv6GKb0EvnkvipOyjfDzv8wFFjnIM73h9HdQerA/ePr21ZUP24ad7lTxvxLB992rIP6Vm5z4S/pFiA8lx8J3Aa5ltHGI0GYVytYdLcdlVwChSAB42KnlwI/04buktDTHtGbHI6uDC4U4xs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.214.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f182.google.com with SMTP id d9443c01a7336-2cc7ef7ec27so17990265ad.1 for ; Sat, 11 Jul 2026 00:58:04 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783756684; x=1784361484; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Tf+wqnGQpAYU6cY0CxfR0PNyYQLqysQQrgD50QiJkT0=; b=NLq/J/D8IMrA0CYNQSNl2naKw1DTKBqrbopVe2qAXSlI2UgEIHlEynpoVBFYn39h3c YvhO1siJ2E45+GjcFC2amucsUyVdriz/2Pm+0DRTtJzsnRM5snq0ohfNj8Z0bIlMtEux JT0i+xgiyyM1mAx9lcACwTryQPNiIFrgT7wjl05uF//eRfOjiUZYJCCsqJzrwQyrKvMA CkoNkPNLpe93g+IMQXOYCsyMehGzk5kWb+kOWkZutEZKxRKZUkf9YtGdnvQPeMm2c5zW hqdNjRp5x9ZYy8EHY7jlT8d4ailNVtj4yaTvsZkbJoACmPSKIZpoHGklAHxRZ8zVOChu zIgQ== X-Forwarded-Encrypted: i=1; AHgh+RrBCxVn72vaK53GYWkRevPi84cK6BrgB8J02zz89ILSDdUFYuTeBv3V0ujEpWXcPWACVavHk0jQ5yglp2I=@vger.kernel.org X-Gm-Message-State: AOJu0YyZJpyLA3itI2RvX4+/Mr/dn3LodI856ln0xT3Zo51gOLtds/xQ GWx46tmvW7/4DyGVMhxIzlehpJkf1e5IqO5fXmxSTVMS8rxYxUhSTIY= X-Gm-Gg: AfdE7ckNpEF/cEddsaPfuV3q5on4fhh5ep1WrgpP9XSeSYzYToAq7S76kdHJvE2E+nN WH+1cIdLOMRh+D8e1HbgnGxl5HyDAdQ1LImwxHcMiSXDpKTKC9OV34Hxl7qXR9TkZ/r3Q63Cz/w ozuI2J+FyKzppoeLpH0n8Hq8qXYDZVvMg4Q4ZksL3MuieIvQEvGXTnFEGi6VJrz8fwyvU7HWmix 2/7gWQh3ORtHOYMXpoZLRDg4CBm5xtYXw9qevQYr8bd61iVv3wluju1/cAnSrYFEzAlLnmqH5tU bUcWw3P9T9AuvuoOriHUQfNVkmGsbOuUadkRBhPa91RKAsuQyXdBEbBQOq0UD7WrtblZelLS1jt UFSsVsvk2xaKMfQ2+FH91oCjW84N11JB8KSzVQZgsLdK7DiHReJKetAahrgfmfK9Y+Ji2P/vjuk BCksL785U5cTMIMnkcAJTeuN+967HXuJ2HBRpj6LtVhhaFuatQfdc/bEcJNjFlKgsouj5UEH4pI jmwCcTx1ix/Cuf7+cjw6PbiIg== X-Received: by 2002:a17:903:2a88:b0:2cc:6018:f030 with SMTP id d9443c01a7336-2ce9e9b2507mr22689155ad.14.1783756684085; Sat, 11 Jul 2026 00:58:04 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ccc9d1e279sm71130285ad.45.2026.07.11.00.58.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 00:58:03 -0700 (PDT) From: Shih-Yuan Lee To: Henrik Rydberg , Guenter Roeck Cc: Armin Wolf , linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v5 2/3] hwmon: (applesmc) Fix lockless cache validation data race Date: Sat, 11 Jul 2026 15:57:53 +0800 Message-Id: <20260711075754.11358-3-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711075754.11358-1-fourdollars@debian.org> References: <20260710123236.10508-1-fourdollars@debian.org> <20260711075754.11358-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In applesmc_get_entry_by_index(), the cache->valid flag is checked locklessly, but setting it to true lacks memory barriers. This can lead to a data race (TOCTOU) where another thread sees cache->valid as true before the actual cache contents (cache->key, cache->len, cache->type, etc.) are fully committed and visible to that CPU, potentially causing it to read uninitialized data and send incorrect keys to the Apple SMC hardware. Introduce memory barriers (smp_load_acquire and smp_store_release) with explanatory comments to ensure cache synchronization is thread-safe and fully visible across all CPUs. Signed-off-by: Shih-Yuan Lee --- drivers/hwmon/applesmc.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/hwmon/applesmc.c b/drivers/hwmon/applesmc.c index 9b2d9ecb20c0..317135fc4b73 100644 --- a/drivers/hwmon/applesmc.c +++ b/drivers/hwmon/applesmc.c @@ -33,6 +33,7 @@ #include #include #include +#include =20 /* data port used by Apple SMC */ #define APPLESMC_DATA_PORT 0x300 @@ -373,7 +374,8 @@ static const struct applesmc_entry *applesmc_get_entry_= by_index(int index) __be32 be; int ret =3D 0; =20 - if (cache->valid) + /* Pairs with smp_store_release() to ensure cache contents are visible */ + if (smp_load_acquire(&cache->valid)) return cache; =20 mutex_lock(&smcreg.mutex); @@ -392,7 +394,8 @@ static const struct applesmc_entry *applesmc_get_entry_= by_index(int index) cache->len =3D info[0]; memcpy(cache->type, &info[1], 4); cache->flags =3D info[5]; - cache->valid =3D true; + /* Pairs with smp_load_acquire() to commit cache contents before setting = valid */ + smp_store_release(&cache->valid, true); =20 out: mutex_unlock(&smcreg.mutex); --=20 2.39.5 From nobody Sat Jul 25 23:41:40 2026 Received: from mail-pl1-f174.google.com (mail-pl1-f174.google.com [209.85.214.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F328237C922 for ; Sat, 11 Jul 2026 07:58:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.174 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783756690; cv=none; b=T3g4VWHzuB3JLTw5InCW8aGE346jGET/pVNff9KadYRKUhPXIFQ6TBqs1uwIQllVHTgO02RClzO6nrvaS4PCBMrfHWKrKBpuSVgHSmWlpvmQNhHWdekvJzGy/uWW+oeJCfG/3TQBTCQgdqEXYs/C40BRWz8ps24VAog7J73oBX8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783756690; c=relaxed/simple; bh=hNw87PqzlkJNrhIIKSmJAnF91g6aT9u65DKBlsFgaOM=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=iOY6i7EpyoHhXJ560REl9Mev7c/mV1jh1qAgK3+LrVvZg4q+pYalAmu9xGBWw1Pe2bzlL6jNK5fl5mvyhDS3VHCHpYQvlTOCx6UGhZSsNT2DuVmgb/V/cIq67f7cLD5mlS46UF6doOksqNna1TxgO9db+mO9efAilOEtTM5/fdE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.214.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f174.google.com with SMTP id d9443c01a7336-2ceaf8a1265so367695ad.2 for ; Sat, 11 Jul 2026 00:58:06 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783756686; x=1784361486; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=otUYxNlQRmM0TTQbpF3S5WfU++sJBtSuggopWwJsZxU=; b=EPqWT/u5BzBVE7dbXaMhiPP7uHzqAHjUTu+NYt5ZqNsU3Sj7QyLeklcAM+rDOYhWF5 6ZNL6bUxHzkLNvDcDQUjFBWvTJ2ekdf7MDRtOsawcz2KMg6653Vr/tQea66J6XhxvEAH /i718D1jFk7XLdIbtAfkRZX7fjeX2RcwumDFD88MDopYCvRfGW8g3hN46fnduS8uWr+w ujC8AwCYYn4X2yyliYuGdlF7MX3T/JXge7YmICxHhX/E9Poy4kxw0GYu1hx9yutL0bnC rGdDkRKsp09vjOSbPQAiwXAZIPSwGio4Ex+UFTQr0IkkdrBj9eC719juPrzit2q/cu1C bifQ== X-Forwarded-Encrypted: i=1; AHgh+RoRMNL71Fy5fEYjBw5eSqGSFe0QjBFnIAKclV/4T3lEYdDcjO9uwc+FGSISFk7PdtopjLpNiLuOdQ+R/OM=@vger.kernel.org X-Gm-Message-State: AOJu0YyWPtgK4f6e3j2WAPYyTatZBNBQQJNfuzGl89fNXeLf0LntFusF c055csKoNi//lGPQoZhUixAu7oiR2cd3ZEZ41H9eYIY+KUfHURRHbfc= X-Gm-Gg: AfdE7cmYnhoIX2iyUxaba+Vsdjt6TVku7HhoE+Cg571RJVGmfFcSZK02lD6ZYwprvjf eItpBdRb7dWjFl5A/yZUEti/oMtJjc/kAmSx+u2BZEP5GwY6/g7lc6mLNqVOgH8YtxebCBmSCg1 wpc0Dyh4LgYnF4wPm78/7rza1op2luM50iYLU6PAaoOVGw92jYTc2SZaZyaBuZ6N/ibhOmxnlY5 jTzDggs1vM50+cCk2i1m52mvDUa+aE3p5kbAPsZ4I2l58Wu71fChmMCzvqCRfDpwclSbF7nG3DX tqJZynD1+GZ6muE1ROi57qSAguo0Dm3Q5A0G11xH6YQjlp068lTtn7Uvzju9FjPOmEdrIyRUG2w KeGHkSjcUVSSC7OIX1ndHt7PoR/AqGSQmuJgLWfWRv38+LW5gIYkfNyRa9IkEpUy7gaizD9adgV a5rnJrMHwfvivLYmHFbTbFrhHQVfale3RMi/UPobQYYX2OITodSlFHskqN7B2fpfSY9THVNPZoW cjajt3Fa+WcDGYGUksZm2oX/w== X-Received: by 2002:a17:903:458f:b0:2cb:3f5b:6663 with SMTP id d9443c01a7336-2ce9e9b4534mr21244925ad.11.1783756686247; Sat, 11 Jul 2026 00:58:06 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ccc9d1e279sm71130285ad.45.2026.07.11.00.58.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 00:58:05 -0700 (PDT) From: Shih-Yuan Lee To: Henrik Rydberg , Guenter Roeck Cc: Armin Wolf , linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v5 3/3] hwmon: (applesmc) Convert to hwmon_device_register_with_info Date: Sat, 11 Jul 2026 15:57:54 +0800 Message-Id: <20260711075754.11358-4-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711075754.11358-1-fourdollars@debian.org> References: <20260710123236.10508-1-fourdollars@debian.org> <20260711075754.11358-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The legacy hwmon_device_register() function is deprecated and triggers warnings in dmesg. Convert the driver to the modern hwmon_device_register_with_info() API. This conversion does the following: - Dynamically allocates standard HWMON temp, fan, and pwm channels. - Configures HWMON ops callbacks (.is_visible, .read, .read_string, .write). - Standardizes attribute naming to match the HWMON ABI: - fanX_output -> fanX_target (HWMON_F_TARGET) - fanX_manual -> pwmX_enable (HWMON_PWM_ENABLE) - Dynamically registers non-standard fanX_safe attributes under the HWMON class directory via extra_groups. - Cleans up legacy sysfs nodes, groups, and unused show/store static functi= ons to avoid unused symbol compiler warnings. - Avoids recursive mutex deadlocks when writing to pwmX_enable by locklessly resolving the entry and invoking the underlying raw SMC read/write calls. - Avoids UAF race condition on module exit by using unmanaged registration = and explicitly calling hwmon_device_unregister() as the first step of applesm= c_exit(), guaranteeing that HWMON nodes are destroyed before static structures are = freed. Signed-off-by: Shih-Yuan Lee --- drivers/hwmon/applesmc.c | 470 ++++++++++++++++++++++++++------------- 1 file changed, 321 insertions(+), 149 deletions(-) diff --git a/drivers/hwmon/applesmc.c b/drivers/hwmon/applesmc.c index 317135fc4b73..bec9e9e98896 100644 --- a/drivers/hwmon/applesmc.c +++ b/drivers/hwmon/applesmc.c @@ -145,8 +145,8 @@ static s16 rest_x; static s16 rest_y; static u8 backlight_state[2]; =20 -static struct device *hwmon_dev; static struct input_dev *applesmc_idev; +static struct device *hwmon_dev; =20 /* * Last index written to key_at_index sysfs file, and value to use for all= other @@ -822,33 +822,6 @@ static ssize_t applesmc_light_show(struct device *dev, return sysfs_emit(sysfsbuf, "(%d,%d)\n", left, right); } =20 -/* Displays sensor key as label */ -static ssize_t applesmc_show_sensor_label(struct device *dev, - struct device_attribute *devattr, char *sysfsbuf) -{ - const char *key =3D smcreg.index[to_index(devattr)]; - - return sysfs_emit(sysfsbuf, "%s\n", key); -} - -/* Displays degree Celsius * 1000 */ -static ssize_t applesmc_show_temperature(struct device *dev, - struct device_attribute *devattr, char *sysfsbuf) -{ - const char *key =3D smcreg.index[to_index(devattr)]; - int ret; - s16 value; - int temp; - - ret =3D applesmc_read_s16(key, &value); - if (ret) - return ret; - - temp =3D 250 * (value >> 6); - - return sysfs_emit(sysfsbuf, "%d\n", temp); -} - static ssize_t applesmc_show_fan_speed(struct device *dev, struct device_attribute *attr, char *sysfsbuf) { @@ -868,99 +841,6 @@ static ssize_t applesmc_show_fan_speed(struct device *= dev, return sysfs_emit(sysfsbuf, "%u\n", speed); } =20 -static ssize_t applesmc_store_fan_speed(struct device *dev, - struct device_attribute *attr, - const char *sysfsbuf, size_t count) -{ - int ret; - unsigned long speed; - char newkey[5]; - u8 buffer[2]; - - if (kstrtoul(sysfsbuf, 10, &speed) < 0 || speed >=3D 0x4000) - return -EINVAL; /* Bigger than a 14-bit value */ - - scnprintf(newkey, sizeof(newkey), fan_speed_fmt[to_option(attr)], - to_index(attr)); - - buffer[0] =3D (speed >> 6) & 0xff; - buffer[1] =3D (speed << 2) & 0xff; - ret =3D applesmc_write_key(newkey, buffer, 2); - - if (ret) - return ret; - else - return count; -} - -static ssize_t applesmc_show_fan_manual(struct device *dev, - struct device_attribute *attr, char *sysfsbuf) -{ - int ret; - u16 manual =3D 0; - u8 buffer[2]; - - ret =3D applesmc_read_key(FANS_MANUAL, buffer, 2); - if (ret) - return ret; - - manual =3D ((buffer[0] << 8 | buffer[1]) >> to_index(attr)) & 0x01; - return sysfs_emit(sysfsbuf, "%d\n", manual); -} - -static ssize_t applesmc_store_fan_manual(struct device *dev, - struct device_attribute *attr, - const char *sysfsbuf, size_t count) -{ - int ret; - u8 buffer[2]; - unsigned long input; - u16 val; - - if (kstrtoul(sysfsbuf, 10, &input) < 0) - return -EINVAL; - - ret =3D applesmc_read_key(FANS_MANUAL, buffer, 2); - if (ret) - goto out; - - val =3D (buffer[0] << 8 | buffer[1]); - - if (input) - val =3D val | (0x01 << to_index(attr)); - else - val =3D val & ~(0x01 << to_index(attr)); - - buffer[0] =3D (val >> 8) & 0xFF; - buffer[1] =3D val & 0xFF; - - ret =3D applesmc_write_key(FANS_MANUAL, buffer, 2); - -out: - if (ret) - return ret; - else - return count; -} - -static ssize_t applesmc_show_fan_position(struct device *dev, - struct device_attribute *attr, char *sysfsbuf) -{ - int ret; - char newkey[5]; - u8 buffer[17]; - - scnprintf(newkey, sizeof(newkey), FAN_ID_FMT, to_index(attr)); - - ret =3D applesmc_read_key(newkey, buffer, 16); - buffer[16] =3D 0; - - if (ret) - return ret; - - return sysfs_emit(sysfsbuf, "%s\n", buffer + 4); -} - static ssize_t applesmc_calibrate_show(struct device *dev, struct device_attribute *attr, char *sysfsbuf) { @@ -1108,22 +988,7 @@ static struct applesmc_node_group light_sensor_group[= ] =3D { { } }; =20 -static struct applesmc_node_group fan_group[] =3D { - { "fan%d_label", applesmc_show_fan_position }, - { "fan%d_input", applesmc_show_fan_speed, NULL, 0 }, - { "fan%d_min", applesmc_show_fan_speed, applesmc_store_fan_speed, 1 }, - { "fan%d_max", applesmc_show_fan_speed, NULL, 2 }, - { "fan%d_safe", applesmc_show_fan_speed, NULL, 3 }, - { "fan%d_output", applesmc_show_fan_speed, applesmc_store_fan_speed, 4 }, - { "fan%d_manual", applesmc_show_fan_manual, applesmc_store_fan_manual }, - { } -}; =20 -static struct applesmc_node_group temp_group[] =3D { - { "temp%d_label", applesmc_show_sensor_label }, - { "temp%d_input", applesmc_show_temperature }, - { } -}; =20 /* Module stuff */ =20 @@ -1321,8 +1186,238 @@ static const struct dmi_system_id applesmc_whitelis= t[] __initconst =3D { }; MODULE_DEVICE_TABLE(dmi, applesmc_whitelist); =20 +static struct applesmc_dev_attr *fan_safe_attrs; +static struct attribute **fan_safe_attr_list; +static struct attribute_group fan_safe_group; +static const struct attribute_group *applesmc_extra_groups[2]; + +static u32 *applesmc_temp_config; +static u32 *applesmc_fan_config; +static u32 *applesmc_pwm_config; +static struct hwmon_channel_info *applesmc_info_temp; +static struct hwmon_channel_info *applesmc_info_fan; +static struct hwmon_channel_info *applesmc_info_pwm; +static const struct hwmon_channel_info **applesmc_info_arr; +static struct hwmon_chip_info *applesmc_chip; + +static void applesmc_free_hwmon(void) +{ + kfree(applesmc_temp_config); + kfree(applesmc_fan_config); + kfree(applesmc_pwm_config); + kfree(applesmc_info_temp); + kfree(applesmc_info_fan); + kfree(applesmc_info_pwm); + kfree(applesmc_info_arr); + kfree(applesmc_chip); + kfree(fan_safe_attrs); + kfree(fan_safe_attr_list); +} + +static umode_t applesmc_hwmon_is_visible(const void *drvdata, enum hwmon_s= ensor_types type, + u32 attr, int channel) +{ + switch (type) { + case hwmon_temp: + if (attr =3D=3D hwmon_temp_input || attr =3D=3D hwmon_temp_label) + return 0444; + break; + case hwmon_fan: + switch (attr) { + case hwmon_fan_input: + case hwmon_fan_label: + case hwmon_fan_max: + return 0444; + case hwmon_fan_min: + case hwmon_fan_target: + return 0644; + default: + break; + } + break; + case hwmon_pwm: + if (attr =3D=3D hwmon_pwm_enable) + return 0644; + break; + default: + break; + } + return 0; +} + +static int applesmc_hwmon_read(struct device *dev, enum hwmon_sensor_types= type, + u32 attr, int channel, long *val) +{ + int ret; + + switch (type) { + case hwmon_temp: + if (attr =3D=3D hwmon_temp_input) { + const char *key =3D smcreg.index[channel]; + s16 value; + + ret =3D applesmc_read_s16(key, &value); + if (ret) + return ret; + *val =3D 250 * (value >> 6); + return 0; + } + break; + case hwmon_fan: + switch (attr) { + case hwmon_fan_input: { + char key[5]; + u8 buffer[2]; + + scnprintf(key, sizeof(key), "F%dAc", channel); + ret =3D applesmc_read_key(key, buffer, 2); + if (ret) + return ret; + *val =3D ((buffer[0] << 8 | buffer[1]) >> 2); + return 0; + } + case hwmon_fan_min: { + char key[5]; + u8 buffer[2]; + + scnprintf(key, sizeof(key), "F%dMn", channel); + ret =3D applesmc_read_key(key, buffer, 2); + if (ret) + return ret; + *val =3D ((buffer[0] << 8 | buffer[1]) >> 2); + return 0; + } + case hwmon_fan_max: { + char key[5]; + u8 buffer[2]; + + scnprintf(key, sizeof(key), "F%dMx", channel); + ret =3D applesmc_read_key(key, buffer, 2); + if (ret) + return ret; + *val =3D ((buffer[0] << 8 | buffer[1]) >> 2); + return 0; + } + case hwmon_fan_target: { + char key[5]; + u8 buffer[2]; + + scnprintf(key, sizeof(key), "F%dTg", channel); + ret =3D applesmc_read_key(key, buffer, 2); + if (ret) + return ret; + *val =3D ((buffer[0] << 8 | buffer[1]) >> 2); + return 0; + } + default: + break; + } + break; + case hwmon_pwm: + if (attr =3D=3D hwmon_pwm_enable) { + u8 buffer[2]; + + ret =3D applesmc_read_key(FANS_MANUAL, buffer, 2); + if (ret) + return ret; + *val =3D ((buffer[0] << 8 | buffer[1]) >> channel) & 0x01; + return 0; + } + break; + default: + break; + } + return -EOPNOTSUPP; +} + +static int applesmc_hwmon_write(struct device *dev, enum hwmon_sensor_type= s type, + u32 attr, int channel, long val) +{ + int ret; + + switch (type) { + case hwmon_fan: + if (attr =3D=3D hwmon_fan_min || attr =3D=3D hwmon_fan_target) { + char key[5]; + u8 buffer[2]; + const char *fmt =3D (attr =3D=3D hwmon_fan_min) ? "F%dMn" : "F%dTg"; + + if (val < 0 || val >=3D 0x4000) + return -EINVAL; + scnprintf(key, sizeof(key), fmt, channel); + buffer[0] =3D (val >> 6) & 0xff; + buffer[1] =3D (val << 2) & 0xff; + return applesmc_write_key(key, buffer, 2); + } + break; + case hwmon_pwm: + if (attr =3D=3D hwmon_pwm_enable) { + u8 buffer[2]; + u16 manual_val; + const struct applesmc_entry *entry; + + if (val !=3D 0 && val !=3D 1) + return -EINVAL; + + entry =3D applesmc_get_entry_by_key(FANS_MANUAL); + if (IS_ERR(entry)) + return PTR_ERR(entry); + + mutex_lock(&smcreg.mutex); + ret =3D read_smc(APPLESMC_READ_CMD, entry->key, buffer, 2); + if (ret) + goto out_unlock; + manual_val =3D (buffer[0] << 8 | buffer[1]); + if (val) + manual_val |=3D (0x01 << channel); + else + manual_val &=3D ~(0x01 << channel); + buffer[0] =3D (manual_val >> 8) & 0xff; + buffer[1] =3D manual_val & 0xff; + ret =3D write_smc(APPLESMC_WRITE_CMD, entry->key, buffer, 2); +out_unlock: + mutex_unlock(&smcreg.mutex); + return ret; + } + break; + default: + break; + } + return -EOPNOTSUPP; +} + +static int applesmc_hwmon_read_string(struct device *dev, enum hwmon_senso= r_types type, + u32 attr, int channel, const char **str) +{ + switch (type) { + case hwmon_temp: + if (attr =3D=3D hwmon_temp_label) { + *str =3D smcreg.index[channel]; + return 0; + } + break; + case hwmon_fan: + if (attr =3D=3D hwmon_fan_label) { + *str =3D smcreg.fan_positions[channel] + 4; + return 0; + } + break; + default: + break; + } + return -EOPNOTSUPP; +} + +static const struct hwmon_ops applesmc_hwmon_ops =3D { + .is_visible =3D applesmc_hwmon_is_visible, + .read =3D applesmc_hwmon_read, + .write =3D applesmc_hwmon_write, + .read_string =3D applesmc_hwmon_read_string, +}; + static int __init applesmc_init(void) { + int i; int ret; =20 if (!dmi_check_system(applesmc_whitelist)) { @@ -1357,17 +1452,97 @@ static int __init applesmc_init(void) if (ret) goto out_smcreg; =20 - ret =3D applesmc_create_nodes(fan_group, smcreg.fan_count); - if (ret) + /* allocate hwmon channel configs */ + applesmc_temp_config =3D kcalloc(smcreg.index_count + 1, + sizeof(*applesmc_temp_config), GFP_KERNEL); + applesmc_fan_config =3D kcalloc(smcreg.fan_count + 1, + sizeof(*applesmc_fan_config), GFP_KERNEL); + applesmc_pwm_config =3D kcalloc(smcreg.fan_count + 1, + sizeof(*applesmc_pwm_config), GFP_KERNEL); + if (!applesmc_temp_config || !applesmc_fan_config || !applesmc_pwm_config= ) { + ret =3D -ENOMEM; goto out_info; + } =20 - ret =3D applesmc_create_nodes(temp_group, smcreg.index_count); - if (ret) - goto out_fans; + for (i =3D 0; i < smcreg.index_count; i++) + applesmc_temp_config[i] =3D HWMON_T_INPUT | HWMON_T_LABEL; + applesmc_temp_config[smcreg.index_count] =3D 0; + + for (i =3D 0; i < smcreg.fan_count; i++) { + applesmc_fan_config[i] =3D HWMON_F_INPUT | HWMON_F_LABEL | HWMON_F_MIN | + HWMON_F_MAX | HWMON_F_TARGET; + applesmc_pwm_config[i] =3D HWMON_PWM_ENABLE; + } + applesmc_fan_config[smcreg.fan_count] =3D 0; + applesmc_pwm_config[smcreg.fan_count] =3D 0; + + applesmc_info_temp =3D kzalloc_obj(*applesmc_info_temp, GFP_KERNEL); + applesmc_info_fan =3D kzalloc_obj(*applesmc_info_fan, GFP_KERNEL); + applesmc_info_pwm =3D kzalloc_obj(*applesmc_info_pwm, GFP_KERNEL); + if (!applesmc_info_temp || !applesmc_info_fan || !applesmc_info_pwm) { + ret =3D -ENOMEM; + goto out_info; + } + + applesmc_info_temp->type =3D hwmon_temp; + applesmc_info_temp->config =3D applesmc_temp_config; + + applesmc_info_fan->type =3D hwmon_fan; + applesmc_info_fan->config =3D applesmc_fan_config; + + applesmc_info_pwm->type =3D hwmon_pwm; + applesmc_info_pwm->config =3D applesmc_pwm_config; + + applesmc_info_arr =3D kcalloc(4, sizeof(*applesmc_info_arr), GFP_KERNEL); + if (!applesmc_info_arr) { + ret =3D -ENOMEM; + goto out_info; + } + + applesmc_info_arr[0] =3D applesmc_info_temp; + applesmc_info_arr[1] =3D applesmc_info_fan; + applesmc_info_arr[2] =3D applesmc_info_pwm; + applesmc_info_arr[3] =3D NULL; + + applesmc_chip =3D kzalloc_obj(*applesmc_chip, GFP_KERNEL); + if (!applesmc_chip) { + ret =3D -ENOMEM; + goto out_info; + } + + applesmc_chip->ops =3D &applesmc_hwmon_ops; + applesmc_chip->info =3D applesmc_info_arr; + + /* Create non-standard fanX_safe attributes group */ + fan_safe_attrs =3D kcalloc(smcreg.fan_count, + sizeof(*fan_safe_attrs), GFP_KERNEL); + fan_safe_attr_list =3D kcalloc(smcreg.fan_count + 1, + sizeof(*fan_safe_attr_list), GFP_KERNEL); + if (!fan_safe_attrs || !fan_safe_attr_list) { + ret =3D -ENOMEM; + goto out_info; + } + + for (i =3D 0; i < smcreg.fan_count; i++) { + struct applesmc_dev_attr *node =3D &fan_safe_attrs[i]; + + scnprintf(node->name, sizeof(node->name), "fan%d_safe", i + 1); + node->sda.index =3D (3 << 16) | (i & 0xffff); /* Option 3 (safe speed) */ + node->sda.dev_attr.show =3D applesmc_show_fan_speed; + node->sda.dev_attr.store =3D NULL; + sysfs_attr_init(&node->sda.dev_attr.attr); + node->sda.dev_attr.attr.name =3D node->name; + node->sda.dev_attr.attr.mode =3D 0444; + fan_safe_attr_list[i] =3D &node->sda.dev_attr.attr; + } + fan_safe_attr_list[smcreg.fan_count] =3D NULL; + fan_safe_group.attrs =3D fan_safe_attr_list; + applesmc_extra_groups[0] =3D &fan_safe_group; + applesmc_extra_groups[1] =3D NULL; =20 ret =3D applesmc_create_accelerometer(); if (ret) - goto out_temperature; + goto out_info; =20 ret =3D applesmc_create_light_sensor(); if (ret) @@ -1377,7 +1552,8 @@ static int __init applesmc_init(void) if (ret) goto out_light_sysfs; =20 - hwmon_dev =3D hwmon_device_register(&pdev->dev); + hwmon_dev =3D hwmon_device_register_with_info(&pdev->dev, "applesmc", NUL= L, + applesmc_chip, applesmc_extra_groups); if (IS_ERR(hwmon_dev)) { ret =3D PTR_ERR(hwmon_dev); goto out_light_ledclass; @@ -1391,11 +1567,8 @@ static int __init applesmc_init(void) applesmc_release_light_sensor(); out_accelerometer: applesmc_release_accelerometer(); -out_temperature: - applesmc_destroy_nodes(temp_group); -out_fans: - applesmc_destroy_nodes(fan_group); out_info: + applesmc_free_hwmon(); applesmc_destroy_nodes(info_group); out_smcreg: applesmc_destroy_smcreg(); @@ -1416,13 +1589,12 @@ static void __exit applesmc_exit(void) applesmc_release_key_backlight(); applesmc_release_light_sensor(); applesmc_release_accelerometer(); - applesmc_destroy_nodes(temp_group); - applesmc_destroy_nodes(fan_group); applesmc_destroy_nodes(info_group); applesmc_destroy_smcreg(); platform_device_unregister(pdev); platform_driver_unregister(&applesmc_driver); release_region(APPLESMC_DATA_PORT, APPLESMC_NR_PORTS); + applesmc_free_hwmon(); } =20 module_init(applesmc_init); --=20 2.39.5