From nobody Sat Jul 25 23:41:42 2026 Received: from mail-pj1-f49.google.com (mail-pj1-f49.google.com [209.85.216.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AB9943C2785 for ; Sat, 11 Jul 2026 11:50:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783770603; cv=none; b=QpYA2PC7iPDuxoD3ULFHUHC6swhbF7L+iLl3w5gMSr+/vTPKDhxVsYqPuptA5eGtCdvs1b1Fl+HVf2DtobcQwvlrT93iDpYaj43TCLxyySz2pGCsAcVTY3rwG9ngXrzwMZaRchSfAmCK9U0dRiS0m0+OlbfMMc1SERumfTvOVf8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783770603; c=relaxed/simple; bh=o2Hiy84rnP/9UMKURCEIhcD7/nHJlcIAPilhOK3M2oU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=EI/hI5vWS/7swyOtS6ok/pqRI3eTuv0IUc7JTm4/a5JR2VQMNDA7FE/OpXpUXRTD5JL3sKHsutpg6LKVTii5EXJzOR98OUVCemfkhSgzmeeUDLrrSJfsZJyQRmIiaEu1uErAD3dBg6XMYnN5zn/XVIaUiZs8vEFvPLOXdTXrfvM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.216.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pj1-f49.google.com with SMTP id 98e67ed59e1d1-37ff8e0ad0fso2136129a91.2 for ; Sat, 11 Jul 2026 04:50:01 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783770601; x=1784375401; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=kJ53oWqRjCNjVlROCxKHTEOJ8pLHHBllpxRR0nGEHyI=; b=AwBx0TWH4R9GzXRwtgNv6RBD5CvFhzLDJlbs21+UBThFrSx4BQQR0//dCpaZvfMdaw zV4qO/t6GM3aDa7EBtg22nZJf5B2XZwLvSFF/6WneGwvjLdYd5+R/qy6scUYdcPN6nA8 sdk26DIylmjEsczZWDrqpJK2CIJ89rmMQkQKUGuLR1Ds+ofH4vWhQyVbdCZsJ7p3RApT Cr1n0owErHKXy4j1aIFcD9VEPW8ZmmIinh2Eio87ogDLtGCfdTbDvS8mD9SQPzbzUZ34 mNd+4MwCdf+10ryY6NMBCIaUI2S5U3XUqJgzc8f8UJlGUbRMtZvV8cu6YK18JcDljrbB JcQw== X-Forwarded-Encrypted: i=1; AHgh+Rp1aYDoyATTpG8ZukTkfjbo6O4i77u72ztOKbJ3uCIraiYDOX4NFXoWRUBoVVpIPrjZEkLCbANi7iGE8gg=@vger.kernel.org X-Gm-Message-State: AOJu0YxTWzuUlkfyvIdW7C6d42gC74K66pI94aSyYdLSo40MD/x/I3Sb Z2DiQYrBCN27sGh5KEpjzg1Fj5NYhIMEDhSbfFx3GItwAzwnqRwPA5o= X-Gm-Gg: AfdE7clAJk00ZImSSP/dytY7tH7PT5m5xd0F0Mcrg2aR8zmMjnWUj5/rMzpx02B0l+7 Bk0AmB7yfiuAT39zXNP9Iedkj4nER9B5qlV+79DZgS1CtCYr0IzINBzWLwIPgcWsZb5Bo0he5Zn RaNDknM6S1amtgVh7QmXAs9SxmrYbW+TJKGJ032DUgvMwz9TVhOlsWFvI9fFldtJWrm70CrIj5U chxJC4PMiS1LWs0dy28l2FRBXWS+emRCTJhOuUuZ2wN96SNLPM011EwXvA66HmnnV+mLDCE3SS8 tutizixdeVKBRcUhnUu4N8QgfQMMrvoMBpI9A4iZ1CYdCE2GOF0Me583/CvvtVC6ZvcBSRnvnre 1ymF74QKS4rnN9IdgDIz5qxrWx1KZQ8qhj3/b5MOREIntesVQByOcEb5Bn5UBH+rYVBeKmmKCR1 /Ve53hY3wWt/B4nCyKFqGMPpfEi82paAX++ZaZWQ9uYenA/8vNsellkL3vGGse9dEprCfEDhAM1 qVGgauW0e+l1/rDMq5cIuKbUA== X-Received: by 2002:a17:90b:5344:b0:381:1b66:4734 with SMTP id 98e67ed59e1d1-38dc75d0b31mr2658787a91.6.1783770601104; Sat, 11 Jul 2026 04:50:01 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38a5506b48bsm3957570a91.1.2026.07.11.04.49.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 04:50:00 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov , Mark Brown Cc: Daniel Mack , Haojian Zhuang , Robert Jarzmik , Shih-Yuan Lee , linux-input@vger.kernel.org, linux-spi@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org Subject: [PATCH v4 1/3] Input: applespi - cancel pending work on driver remove Date: Sat, 11 Jul 2026 19:49:35 +0800 Message-Id: <20260711114937.16670-2-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711114937.16670-1-fourdollars@debian.org> References: <20260711055247.5412-1-fourdollars@debian.org> <20260711114937.16670-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" During driver removal in applespi_remove(), the managed private data structure is freed by devres. However, the driver does not cancel the asynchronous work applespi->work, which registers the touchpad input device. This creates a use-after-free (UAF) vulnerability if a pending or running worker thread attempts to access the private data after the remove function returns. Fix this by explicitly calling cancel_work_sync(&applespi->work) in applespi_remove() before cleanups. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index b5ff71cd5a70..3bdb9e7cfb8b 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -1822,6 +1822,8 @@ static void applespi_remove(struct spi_device *spi) =20 applespi_drain_reads(applespi); =20 + cancel_work_sync(&applespi->work); + debugfs_remove_recursive(applespi->debugfs_root); } =20 --=20 2.39.5 From nobody Sat Jul 25 23:41:42 2026 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5D6063A4505 for ; Sat, 11 Jul 2026 11:50:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783770608; cv=none; b=reH67RNSLuRlDD8q2XXv0cUnuJaZpKfeAsX4ULG4Gj3Igg1LCaPEnG+mumG0/O2tI27pvwjtlqZMzwjxMjfrvFNwqaftDq9KLLGyjIXOmlRCv4KUL2dbkuAr6Lqv8k5djWj5w/Ix+sao1y/Azi1daoYXpkJoPNEUzzcxhT0qwR8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783770608; c=relaxed/simple; bh=16ZCF42qfyfecp4FE6xDMCEwifOTFXd6LvfmvaYgqJU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=S1CzInoyrfjYsk76G6ckur9ieW7yFbFnox0aZCecfpOJBh4h6n6D4Zh1GCJYkXr8lBLbFfFO+dgFL8LFNzqCauFGA2Za7oDmcBCIhTCBns9RnLqbxzeCb5SocUdGP3tQ9AzJkt0FbMokvciM+E4xGnvN3FqXHRmQ6F9BsYZoC7Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.216.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-384c94c9414so1732506a91.3 for ; Sat, 11 Jul 2026 04:50:04 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783770604; x=1784375404; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Hk5V5J+DbPG/Ee/w/hWVnY1n/ftwZsWJmMFAPAEy6a0=; b=diYUPl8isRQAOD9v0emw62bxB09JM5u3KyZCQTAn3tKqcjiJgdHdeOVcs+3h8Vihmb RT+Cl6kA5YT8bEi443OciplJcwjkspo4u5vlwW5NEDSiWUd4SiaeQH6ddc7q7OK/V8ba 8f6FOqSIKBiktzQuJpALmt2ra18eZ2vpMbuZ+0TorB09qF4Q6WyR2/TJzmBwuoGiD98l VOcZ7gH5WLfUck+Rm+r4HzbkS7dsnrqWSAPuphUjxYey+nolBxee4J+yLaHkABCUWjLA C2S2BK9KOhDRsfAvbzQE6XK85f6D7Ohs6VgVWsQVRCFaAi8EDL816+A7MDNzx2LCZlEN uvJQ== X-Forwarded-Encrypted: i=1; AHgh+Rr9ma7Zkn6XosVAmxWXnVWvnIVNWmYNzhfIbuUeWhjqw9szUiirLo/CdJCXCedZ3fETbF8rWDE03Ehsrdw=@vger.kernel.org X-Gm-Message-State: AOJu0YxtMfMutwp/ixg1hTmUNACNZMTKveRxsxwnnvY9aFqQ2fDe3G/n Tm3BeU+QIDicXXgTtDFx7bNWFGYhzqvl7Fc0pGBvTEcOi0pgI1eWiQY= X-Gm-Gg: AfdE7cldrpjQwqwjtCDZbJmNwdmbf8Q/hpK/l+pRiUklurClUjQifAObpgZRkXXjuJP SXAAtT2xLDLTh88W4ryIZjKuRwuwqUF8Jxen27lpknj6i8jM2rK15xCBuugbl3GzLrVnlspZ9wC Y/owh28HPZLz8st/Je0TMwTzI5ITocdmkoGEVIgnTqzgGmu3jvDU8cZrPkdzhNahmV3CK0L4FEe DXjpBzS099eled6miAkpvu0rNNRlziDmMUwxQav4d3zljXjfU+XkwH2tvA6hmVFFTLrxFiCYz1Y ravAfVXwa/CKhRVwbp/4DIieJm5fCfjnE/y92b3KLBnd390PtTdCkoQmXulV7AkEC4gjw2lmZ5b sfmdYhfoRsxl/XJ/p7wsgjTb6UynjkZyvIyzZTeBYKDqAbohx41ux0yTxtyjfeUvwrspzbYKkLQ +NuAShBzAvoeCb2+KyOSj8crNTYLAOezSE/yoKCtTvO68557NDjONmQyIiY+4vYPrWPRXeOxq8L XBrdljOTqucasPLxGSXmMTA6Q== X-Received: by 2002:a17:90b:58f0:b0:387:e0db:bc23 with SMTP id 98e67ed59e1d1-38dc77b82bemr2604555a91.35.1783770603661; Sat, 11 Jul 2026 04:50:03 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38a5506b48bsm3957570a91.1.2026.07.11.04.50.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 04:50:03 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov , Mark Brown Cc: Daniel Mack , Haojian Zhuang , Robert Jarzmik , Shih-Yuan Lee , linux-input@vger.kernel.org, linux-spi@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org Subject: [PATCH v4 2/3] Input: applespi - fix NULL pointer dereference in tp_dim open Date: Sat, 11 Jul 2026 19:49:36 +0800 Message-Id: <20260711114937.16670-3-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711114937.16670-1-fourdollars@debian.org> References: <20260711055247.5412-1-fourdollars@debian.org> <20260711114937.16670-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The tp_dim debugfs file is registered synchronously during driver probe in applespi_probe(). However, the applespi->touchpad_input_dev is initialized and registered asynchronously in the driver's worker thread. If a userspace process opens the debugfs file before the worker thread has completed initialization, applespi_tp_dim_open() will dereference the NULL applespi->touchpad_input_dev pointer, causing a kernel panic. Fix this by using smp_load_acquire() to safely load touchpad_input_dev and return -ENODEV if it is not yet initialized. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index 3bdb9e7cfb8b..4d339445e9c7 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -963,12 +963,18 @@ static void applespi_debug_update_dimensions(struct a= pplespi_data *applespi, static int applespi_tp_dim_open(struct inode *inode, struct file *file) { struct applespi_data *applespi =3D inode->i_private; + struct input_dev *touchpad; =20 file->private_data =3D applespi; =20 + /* Pairs with smp_store_release in applespi_register_touchpad_device() */ + touchpad =3D smp_load_acquire(&applespi->touchpad_input_dev); + if (!touchpad) + return -ENODEV; + snprintf(applespi->tp_dim_val, sizeof(applespi->tp_dim_val), "0x%.4x %dx%d+%u+%u\n", - applespi->touchpad_input_dev->id.product, + touchpad->id.product, applespi->tp_dim_min_x, applespi->tp_dim_min_y, applespi->tp_dim_max_x - applespi->tp_dim_min_x, applespi->tp_dim_max_y - applespi->tp_dim_min_y); --=20 2.39.5 From nobody Sat Jul 25 23:41:42 2026 Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F10193C1966 for ; Sat, 11 Jul 2026 11:50:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783770608; cv=none; b=IKa4VbFznEH3c5567RrtuLhUYa7CGmfLq3oNLLnxBWKpVPWzmE6KDMRKW2/DvrsVxjHw6E3jPv5LJ3gFJCo8im0ciCxbTVwyRKgsKWGbX6z1ILrWfIAS4y9OEfugvLNkpOPlkh26+SNId5aO76/XS1a7Z2z1abdMaM4qaQWtIog= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783770608; c=relaxed/simple; bh=FImt+bsSj++vXBt8dl06uq7wyPYDWF8eV3nAHecKHCA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Riqmlesfq7J0TiJFmslTrmXJcYbwrYFyLnthogOirGX7DTm7KYl2QC9vId+m7MdEuUI/TEzDOkX6F3N7ZcWpkj6tMBIriycmpcy5D09inc4k59DihuqB4/o03UAjMPPR1p9h7i51bnGx3H6Id7zJtLZPLhV4O0g1y+DXeK+pOX0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.216.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-384930ca5e2so2054217a91.3 for ; Sat, 11 Jul 2026 04:50:06 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783770606; x=1784375406; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=HRFub8kSA/fS8InEMuVJNmE6mYQvQVfDODAvVSAOiMA=; b=ep69Ktql5lRngGwapCRgBhkkf6358x0oW1Y4S8ReCsphk41dy9Sc6TxkWqaboPdba3 Fw4BW/+aW4/D9E+zwFniKiVYCrPD7THynFeVkD/vd9AA/ApCadezPgom7PLpH834nMqV mjLvvd/W8dD1z16fVmNUW+KUw76c2oPr8pprjuQzaRGCUvhCS0n1+opNs9Tw0BnpxKcj pJXAFyq/jxJ7Gt73QCqgW8su/rz+0g6lOoc4zlzJLZ2YOXJjnh/9U9BlDdavLNmupyPe Z/NzpOO5zJeoj1Sb1NU9pOO75wMv8hNvtw88WEF/m4Id8RR8hTUEMiFLCNH/+JoD7l8U 1R5g== X-Forwarded-Encrypted: i=1; AHgh+RqSVs5C4A7yfhAEhnJoeG8MdTbDjey5O1qkHyZmDvIF8s3e4we5FvHA2MBZKW9s99exBuv5MeqozisR3+8=@vger.kernel.org X-Gm-Message-State: AOJu0YysVgTXZkmxAeFwqZ8QTMzHHKxtKZwKFD/Aet5UIeH9A8cJtD8J mm9n9ajitFq25EXFtTAi20XejtI2/xnqBASxFYJXUfIlShAjKA23OrRZgL8b+NKHtqnz X-Gm-Gg: AfdE7cloWvK0QexigE+70W+OuP9XNr0J9E3wKnI0wKOldRzriQVLv0eXvVbuFdaPA0Z NNCngmeuDck6BtHIyuOu3/CmEKeaOQOSNVnCPsDs844523Y61Hu2bFpZvU0BWmyHzwJjYcwdD0r IgB2y434ZYmyXL/ODT52t49g3EzahL524vD8lZRSwMbZsmd/HPV1XJUls/AP5J45XVDtORF/1eg Gqwv9lcpGEDursWJfV8Gdj1WumCTQ5EBUsts3+5lDgCOkfRhW4AVvS87c3GR3ojXxpEuAffsF1o ijkyBAJ5fn72RDRn+31B6+PR2/vMwxdPeAQjdB0HBmFmRILBBS8a5I1WgfiDdUZy9DYEkhPzxR6 DH9uY8sCvy1t4pkxt+jcSSpvSk1ROSSa1TUuT/CDikpDB+gcZfP0pZG0BgYp8zcdinMfw6fNjgV 0woJ4MU+hC8fRuHOmg+qifErmUlJ7oJcGA7AwwvvVPrgPJ0/VIIfcVmpCBrlJt6O+TOw+/M0Fz/ kbbSSlBlPWaQgyAGhFGpcHTBw== X-Received: by 2002:a17:90b:3806:b0:384:5dbc:cba5 with SMTP id 98e67ed59e1d1-38dc777c6d4mr2735418a91.26.1783770606205; Sat, 11 Jul 2026 04:50:06 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38a5506b48bsm3957570a91.1.2026.07.11.04.50.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 04:50:05 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov , Mark Brown Cc: Daniel Mack , Haojian Zhuang , Robert Jarzmik , Shih-Yuan Lee , linux-input@vger.kernel.org, linux-spi@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org Subject: [PATCH v4 3/3] spi: pxa2xx: disable DMA for Apple MacBook8,1 Date: Sat, 11 Jul 2026 19:49:37 +0800 Message-Id: <20260711114937.16670-4-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711114937.16670-1-fourdollars@debian.org> References: <20260711055247.5412-1-fourdollars@debian.org> <20260711114937.16670-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" On MacBook8,1 (early 2015 12" MacBook), the LPSS SPI controller's DMA handshake and interrupt routing frequently fail or time out on boot, causing the keyboard and trackpad to become unresponsive. Avoid this architectural bug by disabling DMA and forcing the SPI controller to use PIO mode. Move this platform/motherboard-level quirk to the SPI host controller driver (spi-pxa2xx-pci.c) where LPSS setup occurs, preventing layering violations, TOCTOU races, or execute-after-free bugs in the client driver. Additionally, introduce a `force_pio` module parameter in the PCI host controller driver to allow other users to force PIO mode for debugging. Link: https://bugzilla.kernel.org/show_bug.cgi?id=3D108331 Signed-off-by: Shih-Yuan Lee --- drivers/spi/spi-pxa2xx-pci.c | 33 ++++++++++++++++++++++++++++++++- 1 file changed, 32 insertions(+), 1 deletion(-) diff --git a/drivers/spi/spi-pxa2xx-pci.c b/drivers/spi/spi-pxa2xx-pci.c index cae77ac18520..96bbc7a7c381 100644 --- a/drivers/spi/spi-pxa2xx-pci.c +++ b/drivers/spi/spi-pxa2xx-pci.c @@ -18,9 +18,14 @@ =20 #include #include +#include =20 #include "spi-pxa2xx.h" =20 +static bool spi_pxa2xx_force_pio; +module_param_named(force_pio, spi_pxa2xx_force_pio, bool, 0444); +MODULE_PARM_DESC(force_pio, "Force PIO mode (disables DMA) for SPI transfe= rs. ([0] =3D disabled, 1 =3D enabled)"); + #define PCI_DEVICE_ID_INTEL_QUARK_X1000 0x0935 #define PCI_DEVICE_ID_INTEL_BYT 0x0f0e #define PCI_DEVICE_ID_INTEL_MRFLD 0x1194 @@ -93,6 +98,32 @@ static void lpss_dma_put_device(void *dma_dev) pci_dev_put(dma_dev); } =20 +static const struct dmi_system_id pxa2xx_spi_pci_dmi_table[] =3D { + { + .ident =3D "Apple MacBook8,1", + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBook8,1"), + }, + }, + { } +}; + +static bool pxa2xx_spi_pci_can_dma(struct pci_dev *dev) +{ + if (spi_pxa2xx_force_pio) { + pci_info(dev, "Forcing PIO mode (disabling DMA)\n"); + return false; + } + + if (dmi_check_system(pxa2xx_spi_pci_dmi_table)) { + pci_info(dev, "MacBook8,1 detected: disabling DMA to force PIO mode\n"); + return false; + } + + return true; +} + static int lpss_spi_setup(struct pci_dev *dev, struct pxa2xx_spi_controlle= r *c) { struct ssp_device *ssp =3D &c->ssp; @@ -166,7 +197,7 @@ static int lpss_spi_setup(struct pci_dev *dev, struct p= xa2xx_spi_controller *c) =20 c->dma_filter =3D lpss_dma_filter; c->dma_burst_size =3D 1; - c->enable_dma =3D 1; + c->enable_dma =3D pxa2xx_spi_pci_can_dma(dev); return 0; } =20 --=20 2.39.5