From nobody Sat Jul 25 23:41:47 2026 Received: from mail-pg1-f181.google.com (mail-pg1-f181.google.com [209.85.215.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8DD12384CCA for ; Sat, 11 Jul 2026 09:21:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783761701; cv=none; b=mLZmfpC4lanuGb2jj0VUu2Gxjp7jzzJMos4KSdAu7gsffdGolVA08B1FOq4gSGIVUYGgjr3JIQpkk5PJyNhD/IveVKO2LT8ySFMKYOpOkzCW40kJskJpOMeS96ua9ePtA9o1K/LcfaWduKOHcqsR6SQwh/skLO8NyDmOKl77KA0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783761701; c=relaxed/simple; bh=wJMAVoV26Wxtc9n53dd5rXmHTRFOtEAhBau0xCJPIic=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=RBrRPxymIP7FjHFs4kz9D0gsgWQVOQIsfmJep46iAhTqs1oI/IeMsG4CKlgLGH6RaWjFizOpo+A8G3jNrNp97QtVvaFGn12UkxqzjfqsAVgfWwXc222LKZobS1rs+E6euYgekcsmDzmeJMc27qJruSCruqDniNQmFNeZthQrDlk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.215.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pg1-f181.google.com with SMTP id 41be03b00d2f7-ca97d139d8dso1062144a12.2 for ; Sat, 11 Jul 2026 02:21:39 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783761699; x=1784366499; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=tlnA7fLt+6hyELPfR2jAqKN6onKfTqXw2YAeru37F4c=; b=BcxUzDWZTMufc7napqmIJCbrIydDUraGxcddVD3kXv2qfsbxN+5Qr8FRdRhGeWhgVt aFaLLZhbO/juXN4+yPTHNQLIJGHdxDRAt70zKetGdHOD028Eek4LtGfzkL3BRisjUNpi nOy6b641Sd7Nb5TDMO1RnHbZoJLa20hrKYP6JzTJRC9Yz/NwHZT75Huc+VeUEtNGSCGm ue/OzJ1KWWwSRU5Y1pHNqXABAZNkgSy5T7WB07bsVWkEZ1ABig9CmA/U8iK9RWM5eeGQ xcIcr7Ci8DM7k9xJU6Z1tMtlOZkA3pDe3l6ebQzUqv/GH94xd/a5xFCX3U02m83o/BdT OLsg== X-Forwarded-Encrypted: i=1; AHgh+RqfJv8PhQKG82FrLRVMacOc1nIpa5k6k+fjj/2CJjz4RDOZUeHhX8CJ9we3qp66FS3SKfiX9wbPREiCP1s=@vger.kernel.org X-Gm-Message-State: AOJu0YyigiyUycD8Zg8FjwGSrzcFpHs1RF2rT6d+lwMkT809UXn2qlaZ IYdZAkM17C8Doaz0WKt8AKYavC7GzjPdJ0JxgHlLkKcoiSlT6X4X6ZU= X-Gm-Gg: AfdE7ckdbXn7YjmgyRA7uf/JbjBeieExVK5YkY2TTbsckuRAhzH0b46dyaqWr1MTYBx TTLPV6i+36zmrZLmV72bG0Eo48UU4TFsMQcevrWgKpMAZGlTha6SvGSFU8KAmQuD0PuCVe0S47S 79W8E7IG8gdzT4nokgJSS04t4MWZKBx9wbfT+dW9TdqDDWOIgcGBFQBsnGPMZjwRE907L6dsRFN AVy5FU6h7bTmGaaYhPj2oEaejFnqfCBNMohqPR/xR9O9UH0JUUPsnrdzaxeIMFA5G+B0AoDYm2l SHWB+EoZgf84ofMF8EN6TjOdAM7kj/SejpFBSLK+S7TvVthZ5cM62jIeG3Rv16HmpEpJi1masfH BCq6Bhytj+xf1uVqLyciOa1qINWeT5lj9VaaBZ4DFUil1VO3pRfIMgzUKUrwFbm2aS6/t9uNCxa JZ9Quzl4q2n4TaDrxG/jL7iW5kIInBbgVYBOlT3QWOXMSodqNgJXlVPjuJMscmwz3pKIyiv7sth 5DEaWNPkF58p8hBUIv6m5hGBQ== X-Received: by 2002:a05:6a00:2441:b0:848:5eae:3695 with SMTP id d2e1a72fcca58-84889883eebmr2183357b3a.78.1783761698716; Sat, 11 Jul 2026 02:21:38 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-847f6dbfd41sm11468726b3a.57.2026.07.11.02.21.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 02:21:38 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v3 1/3] Input: applespi - force PIO mode on MacBook8,1 Date: Sat, 11 Jul 2026 17:20:52 +0800 Message-Id: <20260711092054.13818-2-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711092054.13818-1-fourdollars@debian.org> References: <20260711092054.13818-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" On MacBook8,1 (early 2015 12" MacBook), the LPSS SPI controller's DMA handshake and interrupt routing frequently fail or time out on boot, causing the keyboard and trackpad to become unresponsive. Address this by introducing a DMI quirk and a `force_pio` module parameter. If either is true, override the SPI controller's `can_dma` callback to a helper that always returns false. This forces all SPI transfers to fall back to the reliable PIO mode. To ensure correct timing and architectural safety: 1. Perform the override at the very beginning of applespi_probe() so that all early initialization transfers use PIO. 2. In case of probe failures or module unload (remove), unconditionally restore the original `can_dma` callback (even if it was NULL) to prevent any execute-after-free or dangling pointer vulnerability in the shared host controller. Link: https://bugzilla.kernel.org/show_bug.cgi?id=3D108331 Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 66 +++++++++++++++++++++++++------ 1 file changed, 54 insertions(+), 12 deletions(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index b5ff71cd5a70..79e5cb5001c7 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -46,6 +46,7 @@ #include #include #include +#include #include #include #include @@ -110,6 +111,10 @@ module_param_string(touchpad_dimensions, touchpad_dime= nsions, sizeof(touchpad_dimensions), 0444); MODULE_PARM_DESC(touchpad_dimensions, "The pixel dimensions of the touchpa= d, as XxY+W+H ."); =20 +static bool applespi_force_pio; +module_param_named(force_pio, applespi_force_pio, bool, 0444); +MODULE_PARM_DESC(force_pio, "Force PIO mode (disables DMA) for SPI transfe= rs. ([0] =3D disabled, 1 =3D enabled)"); + /** * struct keyboard_protocol - keyboard message. * message.type =3D 0x0110, message.length =3D 0x000a @@ -431,6 +436,10 @@ struct applespi_data { int tp_dim_max_x; int tp_dim_min_y; int tp_dim_max_y; + + bool (*original_can_dma)(struct spi_controller *controller, + struct spi_device *spi, + struct spi_transfer *xfer); }; =20 static const unsigned char applespi_scancodes[] =3D { @@ -1605,6 +1614,13 @@ static void applespi_save_bl_level(struct applespi_d= ata *applespi, "Error saving backlight level to EFI vars: 0x%lx\n", sts); } =20 +static bool applespi_can_not_dma(struct spi_controller *controller, + struct spi_device *spi, + struct spi_transfer *xfer) +{ + return false; +} + static int applespi_probe(struct spi_device *spi) { struct applespi_data *applespi; @@ -1612,6 +1628,7 @@ static int applespi_probe(struct spi_device *spi) acpi_status acpi_sts; int sts, i; unsigned long long gpe, usb_status; + bool override_dma =3D applespi_force_pio || dmi_match(DMI_PRODUCT_NAME, "= MacBook8,1"); =20 /* check if the USB interface is present and enabled already */ acpi_sts =3D acpi_evaluate_integer(spi_handle, "UIST", NULL, &usb_status); @@ -1628,6 +1645,13 @@ static int applespi_probe(struct spi_device *spi) =20 applespi->spi =3D spi; =20 + /* Save original can_dma and override if requested or needed */ + applespi->original_can_dma =3D spi->controller->can_dma; + if (override_dma) { + dev_info(&spi->dev, "Disabling DMA for SPI to force PIO mode\n"); + spi->controller->can_dma =3D applespi_can_not_dma; + } + INIT_WORK(&applespi->work, applespi_worker); =20 /* store the driver data */ @@ -1645,8 +1669,10 @@ static int applespi_probe(struct spi_device *spi) GFP_KERNEL); =20 if (!applespi->tx_buffer || !applespi->tx_status || - !applespi->rx_buffer || !applespi->msg_buf) - return -ENOMEM; + !applespi->rx_buffer || !applespi->msg_buf) { + sts =3D -ENOMEM; + goto err_restore_dma; + } =20 /* set up our spi messages */ applespi_setup_read_txfrs(applespi); @@ -1658,7 +1684,8 @@ static int applespi_probe(struct spi_device *spi) dev_err(&applespi->spi->dev, "Failed to get SIEN ACPI method handle: %s\n", acpi_format_exception(acpi_sts)); - return -ENODEV; + sts =3D -ENODEV; + goto err_restore_dma; } =20 acpi_sts =3D acpi_get_handle(spi_handle, "SIST", &applespi->sist); @@ -1666,23 +1693,26 @@ static int applespi_probe(struct spi_device *spi) dev_err(&applespi->spi->dev, "Failed to get SIST ACPI method handle: %s\n", acpi_format_exception(acpi_sts)); - return -ENODEV; + sts =3D -ENODEV; + goto err_restore_dma; } =20 /* switch on the SPI interface */ sts =3D applespi_setup_spi(applespi); if (sts) - return sts; + goto err_restore_dma; =20 sts =3D applespi_enable_spi(applespi); if (sts) - return sts; + goto err_restore_dma; =20 /* setup the keyboard input dev */ applespi->keyboard_input_dev =3D devm_input_allocate_device(&spi->dev); =20 - if (!applespi->keyboard_input_dev) - return -ENOMEM; + if (!applespi->keyboard_input_dev) { + sts =3D -ENOMEM; + goto err_restore_dma; + } =20 applespi->keyboard_input_dev->name =3D "Apple SPI Keyboard"; applespi->keyboard_input_dev->phys =3D "applespi/input0"; @@ -1717,7 +1747,7 @@ static int applespi_probe(struct spi_device *spi) if (sts) { dev_err(&applespi->spi->dev, "Unable to register keyboard input device (%d)\n", sts); - return -ENODEV; + goto err_restore_dma; } =20 /* @@ -1729,7 +1759,8 @@ static int applespi_probe(struct spi_device *spi) dev_err(&applespi->spi->dev, "Failed to obtain GPE for SPI slave device: %s\n", acpi_format_exception(acpi_sts)); - return -ENODEV; + sts =3D -ENODEV; + goto err_restore_dma; } applespi->gpe =3D (int)gpe; =20 @@ -1740,7 +1771,8 @@ static int applespi_probe(struct spi_device *spi) dev_err(&applespi->spi->dev, "Failed to install GPE handler for GPE %d: %s\n", applespi->gpe, acpi_format_exception(acpi_sts)); - return -ENODEV; + sts =3D -ENODEV; + goto err_restore_dma; } =20 applespi->suspended =3D false; @@ -1751,7 +1783,8 @@ static int applespi_probe(struct spi_device *spi) "Failed to enable GPE handler for GPE %d: %s\n", applespi->gpe, acpi_format_exception(acpi_sts)); acpi_remove_gpe_handler(NULL, applespi->gpe, applespi_notify); - return -ENODEV; + sts =3D -ENODEV; + goto err_restore_dma; } =20 /* trigger touchpad setup */ @@ -1789,6 +1822,11 @@ static int applespi_probe(struct spi_device *spi) &applespi_tp_dim_fops); =20 return 0; + +err_restore_dma: + if (override_dma) + spi->controller->can_dma =3D applespi->original_can_dma; + return sts; } =20 static void applespi_drain_writes(struct applespi_data *applespi) @@ -1813,6 +1851,7 @@ static void applespi_drain_reads(struct applespi_data= *applespi) static void applespi_remove(struct spi_device *spi) { struct applespi_data *applespi =3D spi_get_drvdata(spi); + bool override_dma =3D applespi_force_pio || dmi_match(DMI_PRODUCT_NAME, "= MacBook8,1"); =20 applespi_drain_writes(applespi); =20 @@ -1822,6 +1861,9 @@ static void applespi_remove(struct spi_device *spi) =20 applespi_drain_reads(applespi); =20 + if (override_dma) + spi->controller->can_dma =3D applespi->original_can_dma; + debugfs_remove_recursive(applespi->debugfs_root); } =20 --=20 2.39.5 From nobody Sat Jul 25 23:41:47 2026 Received: from mail-pf1-f169.google.com (mail-pf1-f169.google.com [209.85.210.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3EE5D384CDE for ; Sat, 11 Jul 2026 09:21:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783761706; cv=none; b=uz4fgn40ex1pPox5BvyBGQ/VRuKj2ZbvCSOTotP6LdHExpCTUIE8WmzoNSw6iuC66UHWxj/7yhsFKfA1JLip6wYs+kFikbDlpMKRi45iczNzyZyPr5VLYotN7gyfCM1lRsRg+SX0IV2DChpkrIF/U6ogJU0uN3Y5igoLu8QVgWo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783761706; c=relaxed/simple; bh=D3DyRDfYmIf0cQl/XuSThu6cyET5FQRA2JO6N/D7FYI=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=bsnm8sl0eCXkeXMglS3AJ3VW6PteGpxL/X7UBoC6Zm6QSdBOu7+sA4TajMwjuv7AqIxLBH80stioJv3ToBUt5CKbNbYM2ItyTg1RTLBbobQGLCj9peQqTmDVMpNdtvbwRY0mUh9UidWF8kORRId/QbyZM3E+2ph3eMznebrASXw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.210.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pf1-f169.google.com with SMTP id d2e1a72fcca58-845c92bc464so1494674b3a.2 for ; Sat, 11 Jul 2026 02:21:42 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783761701; x=1784366501; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=AOzFhkvMsPSUSjbI9YVx5lNGMOZCWdcLEVik8BT/Ayc=; b=EFefrFgJ7xVV0oRRfoeTAi8YBLa31MONj+aychpopsyGp3o9hL31r/dcGSGw+eif93 1Hj89MJgS8CB0/x4k6j99y7bnGc3UE4thBwbl7EZcYtsPMyHmDPcIuMltmntIsW4XQ8L 2wv5TIg4hgbBjfBLM1MHW3BgDNjT45Ahe23HGAKHwaYsY119lBZT1u2Ie2rjmj4GBu0e r9CCLM9DaDXgky+5Nmsu9i3+JrWd0pHGEKiBlI7mqijHU8fgzW5TMNjybApyXRM8C16w kuc2DAUK9Tx+uMIqut8h9g8b43Q4FEef9r9jwGusLZ5fbL5nEhSbqowaBDIiPk1B8Hf7 rsaw== X-Forwarded-Encrypted: i=1; AHgh+RpQL8ZlbpeKI6YaRC2j8Nr4XkwpTNV1mpg/KI4KfQddPJNnWEemXA8X/WRqLk+8XCUDUzeU82UIMhL+EpQ=@vger.kernel.org X-Gm-Message-State: AOJu0YzeUsU9LGrpbOa6K6HFma351QEmbIypCIbG0IAsrFC4MA18U2It UTrSACKMY35VuVfXX7ujzEz/bjDRgWCtKq/PTHsjKcxLsAEtbRkFogU= X-Gm-Gg: AfdE7cnhM4uofXMgB7M3vvB9xQRRScdyYaJr2nGnJHL2FS5Copoa5KszZt4pzgH8RUS 1uTvnXxDOua+zW5VceFbatA2DnDhPLEBqoZbkeZgAaMCILpjSd8hGpe3aGEoOCUPSFrW/vi/2kH agucFyVl8UtT6Z6tWq+9BUcTqF/Bc2Voq/pdoZiWW2KTYCZIVx46A9GjWkZlbOm4u8JMtxMVD5E OpXACq2F5Mjt9e+xLqDLW0hrQJH47GevCU5ZRr2AUmaisORL8CMLptMqyFTlH7SPLXEbFlNUvEr UXxtlHpGFnUcAb27t/Rdbx9N+Hl4n1/HUHmI3ywpKe/aSYygUIH86BE6tPPizvHIeC10UgVmZjm ksStpjnx9Kas7NKf7qM7lX4Seouyh3jnh1DH+Ng2u6Lxl9qdG9NoZry3EGP5TBst72ILs+n0P1u Et/jWuDAC5oCn0oHaqxvOqCX0Fl8T0bkX01DyYbcgKAuFfVmHwluHQGXRVkACbBwLIXJRWna1iv E2zrYsocAofcay+tBbXjR+lAg== X-Received: by 2002:a05:6a00:2303:b0:848:2f74:1d68 with SMTP id d2e1a72fcca58-84889750a60mr2313588b3a.78.1783761700389; Sat, 11 Jul 2026 02:21:40 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-847f6dbfd41sm11468726b3a.57.2026.07.11.02.21.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 02:21:39 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v3 2/3] Input: applespi - cancel pending work on driver remove Date: Sat, 11 Jul 2026 17:20:53 +0800 Message-Id: <20260711092054.13818-3-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711092054.13818-1-fourdollars@debian.org> References: <20260711092054.13818-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" During driver removal in applespi_remove(), the managed private data structure is freed by devres. However, the driver does not cancel the asynchronous work applespi->work, which registers the touchpad input device. This creates a use-after-free (UAF) vulnerability if a pending or running worker thread attempts to access the private data after the remove function returns. Fix this by explicitly calling cancel_work_sync(&applespi->work) in applespi_remove() before cleanups. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index 79e5cb5001c7..fd785dba1174 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -1861,6 +1861,8 @@ static void applespi_remove(struct spi_device *spi) =20 applespi_drain_reads(applespi); =20 + cancel_work_sync(&applespi->work); + if (override_dma) spi->controller->can_dma =3D applespi->original_can_dma; =20 --=20 2.39.5 From nobody Sat Jul 25 23:41:47 2026 Received: from mail-pf1-f174.google.com (mail-pf1-f174.google.com [209.85.210.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E7647381AE0 for ; Sat, 11 Jul 2026 09:21:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.174 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783761706; cv=none; b=Ttl2SO8gRVQmoqxilAoYeuTBlJIcbXppFwRhRbhpBWlKE6RTYk7HQpHlUpxb4BKoAZJ/S6izybVCB4S7BIuOQiJJsLGqUCM0oox/FUHtLxDi4W9wMD3vSLdDBWpWrf7mOYnTdwiXDbCa2llxSPqF9ZI4TSuO1wiK1NOfqlHKMoY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783761706; c=relaxed/simple; bh=uxnE3s+OHBnATD6/J7IwFWikD45wp0+S4wwd8PzleUw=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=s0nGBGujrMFaHgVv8Ucv2CfzwJYEBBYAz2kjokgYaHv72LlporBdsSGH1b0uz5Y0UGwf2ds831Xdo3fa7Qy+5p0DsQBQJvuc8NLhU/vd8wYZEbV4eVZ+aiJsJziunbNwvwQKzlSO1MziEO8sOZM+Nr7RqDvrnSHn3DdgPMCPOKY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.210.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pf1-f174.google.com with SMTP id d2e1a72fcca58-84862b0d5aeso1785296b3a.2 for ; Sat, 11 Jul 2026 02:21:42 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783761702; x=1784366502; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=xWPkjt8pFCGFWg9O7q8pVB8rJD2AVw+GyK5aJ4zTUoQ=; b=j5fwno6OJ8IToIh4C/5ybcu/pU/h2AufgCcGyt+GLlnBfODh0ehX96Vla+3ztqvTN8 BhVwaxzcJbw1HmGtKrEGlIjrIdEUzZIfIrELz5Lbi4OjMibZpqgCRNhzK2gijRbGLy0p jk1Ha35o3P/ZIv42Xhcjnr0XFpMRPWrwiBKcGaYB3izZfebzNZ86GotqI9r/R4To14Ym YnJYMzD/BKJLx/V70gW4sM6tQKMafVhKkk5KdVhb10lv8/LxEmI2dbwsuFoz6hQNkiKR HJMZbqqAf2MHIJC0C7ATgwM5buzsiylOej5LTLn2z0yHEFQhtzIZJOoS7ikwfxVUVip1 /7oQ== X-Forwarded-Encrypted: i=1; AHgh+RrD5YpBrnSNHyM2nrtt3WqqI9jswonM+2H+jq7UaD1RVgfhN2u2bUm3dJNnuM8mc35fzig3VFK93BM6gn8=@vger.kernel.org X-Gm-Message-State: AOJu0YyYdmS2+oTaOti74rRk+RCHNCzcf3d3MaD9A1RKJ4HxdNN3Mw+L Qr23uVcbUEPpqyTzDItKApoPwvcH8q0pDmETDNMHg34ZYfMYSIX5/gc= X-Gm-Gg: AfdE7ckg2z0VU18lzfr1P5ygTx3jF1SkmlIcSUBiBGReT/kDda+c56ZVPpgI2p4QAHy ua96bk6RUfmkiGc+rXkKnz5kpFLPGK5OYC7aVPTJzZhtt9OelCy+31qWQ6BoEUAu20FF+CE5B81 uNzLIgcEiMZDsSC4Pdh3oSbEgkBjFixn/oneeMXOps87rmIwXhNx7wkajrvJ0myRGuUoRgW4Ows Xw9DJrBTovBNwXlpMYvLX7BIRjsi1Mio45/JICwSBB0FAuqHYH2JsoQoehjR+vjSsH7/c3nLHVf 5nQVHSznKXr3s5LMzUSDicAxP68yHkRdFdoEf+I5rMLWLuhajL6DA4QsF61iOqlpL5JjCMr2xkc fXqgOXeAQYZ+NnC4zHnRmuUcFiIaHZ6+jVnw0cqanOtJTNLXYh2PYQiLX4Io1vnOXFJ6yLUqraR O10PFcMTbQszxBF7snDZrZD5XUl4DQcESqoAoNRGK2gsvnboS0DwDspVqTCxTV4PyyH3x/DuIcA 1IX/1r3LIap19mmA1MWqR+azw== X-Received: by 2002:a05:6a00:18a0:b0:847:973b:3cf6 with SMTP id d2e1a72fcca58-848894d37e4mr1992859b3a.0.1783761702040; Sat, 11 Jul 2026 02:21:42 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-847f6dbfd41sm11468726b3a.57.2026.07.11.02.21.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 02:21:41 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v3 3/3] Input: applespi - fix NULL pointer dereference in tp_dim open Date: Sat, 11 Jul 2026 17:20:54 +0800 Message-Id: <20260711092054.13818-4-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711092054.13818-1-fourdollars@debian.org> References: <20260711092054.13818-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The tp_dim debugfs file is registered synchronously during driver probe in applespi_probe(). However, the applespi->touchpad_input_dev is initialized and registered asynchronously in the driver's worker thread. If a userspace process opens the debugfs file before the worker thread has completed initialization, applespi_tp_dim_open() will dereference the NULL applespi->touchpad_input_dev pointer, causing a kernel panic. Fix this by using smp_load_acquire() to safely load touchpad_input_dev and return -ENODEV if it is not yet initialized. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index fd785dba1174..e3e239f430bd 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -972,12 +972,18 @@ static void applespi_debug_update_dimensions(struct a= pplespi_data *applespi, static int applespi_tp_dim_open(struct inode *inode, struct file *file) { struct applespi_data *applespi =3D inode->i_private; + struct input_dev *touchpad; =20 file->private_data =3D applespi; =20 + /* Pairs with smp_store_release in applespi_register_touchpad_device() */ + touchpad =3D smp_load_acquire(&applespi->touchpad_input_dev); + if (!touchpad) + return -ENODEV; + snprintf(applespi->tp_dim_val, sizeof(applespi->tp_dim_val), "0x%.4x %dx%d+%u+%u\n", - applespi->touchpad_input_dev->id.product, + touchpad->id.product, applespi->tp_dim_min_x, applespi->tp_dim_min_y, applespi->tp_dim_max_x - applespi->tp_dim_min_x, applespi->tp_dim_max_y - applespi->tp_dim_min_y); --=20 2.39.5