From nobody Sat Jul 25 23:41:46 2026 Received: from mail-pj1-f48.google.com (mail-pj1-f48.google.com [209.85.216.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D806F3C872C for ; Sat, 11 Jul 2026 13:11:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783775510; cv=none; b=g8sRGpowRxzeT7a/n0f9jQBtltul0222WHGD4duf2hSvd4s5rq+Md1tCY6GbWZrzXX05M3CrBiuNEiIYz23uZsDU7alQsiVnEc5kuI79IDV0ZYGx8rPAnd+ss4m0dUqkQXf/YQ9kDJYuSpBXqmm00cmmabVKKwfPPkSenb8womA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783775510; c=relaxed/simple; bh=o2Hiy84rnP/9UMKURCEIhcD7/nHJlcIAPilhOK3M2oU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=La0zmBT/dDiYn0eIQ6D43Vzl3y/b9UGSpTWAJhQW32bsdY8TCrEXO35uCiW7VCtCYfOL4VDtXLLwpGN5p6garlTIBCR13jvfM3YwQk94ASueowqrm4oi7RPMqeJ0H29RHbaWCFGEipHDbn1f0008zmbnoJvXssH1Kg7ajabKxvQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.216.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pj1-f48.google.com with SMTP id 98e67ed59e1d1-381507c9380so1239839a91.0 for ; Sat, 11 Jul 2026 06:11:48 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783775508; x=1784380308; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=kJ53oWqRjCNjVlROCxKHTEOJ8pLHHBllpxRR0nGEHyI=; b=dOYpqABRtptFu90BN6f/Owl/071Qy7aybRu3TH3XI6zwg/Izur89YCXSRAgmlOymFc G9AI6fVA48bKReVAvZz+6PlUzTbBT0iSH9Y2Eg3TFNFyqTeLI5HfwlewMB8CBw4mb5PR D/lQhiDvGCbYDVN4HzdZVlnbeZR8nBtdDT0xUPj4pGkhWxSEI+AA0YjPlipEosc9IQV7 KYj0uA7+U03YfVyDz31Sn98LUMhykSKo3GgYtFonPn5wZ9IkLN0XWoMcn4eymrc5P0Jr wEV/cr01QK7t5BaX0HsPxdQQZGeev2Jp8167m5goEYHFbUhiAM7p/5nRm1DPk5T7tomQ iwtg== X-Forwarded-Encrypted: i=1; AHgh+RpGvuFKm0tEd334SphFl7T7iYzmmba/iYIJvVkTu8do/JiapNierq6/QTCX6RMydZAf7aPYxde+0huc4N0=@vger.kernel.org X-Gm-Message-State: AOJu0YyB70FF8/05N1wC6sDKKjy/uHz7h0YsK4yoXh3QyRbAJit72iVp Q7UqSWEnC8VfcSyFl+LAaMqkaMpxA5dPPTEykRprDmPP6irY/AfcjF8= X-Gm-Gg: AfdE7cnGIvGYq0/LdmV7gVAaEkdw0JNKMoc46tJ7GJlyqlKNb6P3+95Ghi1Gv5VafT6 ShWm2yf2X1IreTqwcPYPBwKnU4meg8Ym7ed8SsXhZxkN9kljeSJE313PPvZ1PvlgPgNnmA4Oyxi 98nTk1DXorrMbvNhEifkse4r9GZcayHlR6n0eiPWtR0PQnpBmdN9EoB2QvYR357lU0emvVPLzZH LKoZikFTlc3DQ2YKYnESEu4LwXBPW9ibAqWPCimEwLMtnKlMIBuVaYRZU2jzVqdjzT9vxPXgNT8 QPn664eQFiODDTR6ToQFKxSkHYziuilYUV7ZXVGb/7LYKeqTY1UFiz/lVutv9nCk3BA78UMlS5P 1UjSG77UwPB4opfMTkOPEdZWjX5WQXSEFgGqyHJGXxmdUMQigwI+Bqce8H6prAPoXryumq4eI9z vR6x4xCRkTlW3Qyz2wg1K55NvcE/XrY1zwXYuOzx8UB0PRlOnFwoX6r9NNT+Txp3BM0diUXhyJw qTySBm1Ik/Y/eDR/g0Jpx0gvg== X-Received: by 2002:a17:90b:224c:b0:381:b64b:5a28 with SMTP id 98e67ed59e1d1-38dc779eb0bmr2445869a91.30.1783775508217; Sat, 11 Jul 2026 06:11:48 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38a55557f25sm4136221a91.5.2026.07.11.06.11.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 06:11:47 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov , Mark Brown Cc: linux-input@vger.kernel.org, linux-spi@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v5 1/3] Input: applespi - cancel pending work on driver remove Date: Sat, 11 Jul 2026 21:11:38 +0800 Message-Id: <20260711131140.18777-2-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711131140.18777-1-fourdollars@debian.org> References: <20260711055247.5412-1-fourdollars@debian.org> <20260711131140.18777-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" During driver removal in applespi_remove(), the managed private data structure is freed by devres. However, the driver does not cancel the asynchronous work applespi->work, which registers the touchpad input device. This creates a use-after-free (UAF) vulnerability if a pending or running worker thread attempts to access the private data after the remove function returns. Fix this by explicitly calling cancel_work_sync(&applespi->work) in applespi_remove() before cleanups. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index b5ff71cd5a70..3bdb9e7cfb8b 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -1822,6 +1822,8 @@ static void applespi_remove(struct spi_device *spi) =20 applespi_drain_reads(applespi); =20 + cancel_work_sync(&applespi->work); + debugfs_remove_recursive(applespi->debugfs_root); } =20 --=20 2.39.5 From nobody Sat Jul 25 23:41:46 2026 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F1FF63C4B82 for ; Sat, 11 Jul 2026 13:11:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783775512; cv=none; b=i7Ssao4TYjvQ1/SWcNhC0pYFmFnRdAfpKxelWNPLyFtmKYScz3I3BHXlYnw9C7IoBr7zfZ68qLMBwqqi4W3siDh7pHt/bph++ecTmNZAGY7rwXLC8QwyLhTCvq+o3l2P2zqAnTZwInU5i+nqS4+0I1wDIiwIk7kRvoUbgrTWPGg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783775512; c=relaxed/simple; bh=16ZCF42qfyfecp4FE6xDMCEwifOTFXd6LvfmvaYgqJU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=dfcouPJr4c0tPAr0CSHiWAFGToDDSGcAy5dFtpH6MWNIhZ5/JeAfUdgupvsk2qn1BCdbNI3GdHWHGdgvWaJ9ZAARyW9texU6UdOV3KOvbywPX71fRoHG+TxZWCPCoAR7htbWR77tcO2bkojZlg0w+2RerAt4DZzwT9XqxhSSKOk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.216.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-37df72c9984so3090209a91.3 for ; Sat, 11 Jul 2026 06:11:50 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783775510; x=1784380310; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Hk5V5J+DbPG/Ee/w/hWVnY1n/ftwZsWJmMFAPAEy6a0=; b=BMXvIveZNL6FY24hmnoq4tgmlF4FwuPBtenufr0Ku9kaKsyiJ85d7DGV0bafpdJF2l kG48XMrSYd/WBsYAHIsdSDR6meAAf3QKxSpVbnYIYyTGx+sJdi9+LDMZST/qpxBwc8rK gHaXbMPRbtyvlePd3H7mb5ucy9XF/2bD6jfA6RUVIyL6U27wdNYEg1XUOopQtSMnwOoN FNuLmKqVaYgWDUe29YozsretpuBKsUx64H5veIAEbyJeubaZJAGuRxsBHyRkhGm2YOjF 4Jyn172fY1+AHuRvvDafBAWcZfRriQyKABli7uY0NizAweSBqFojojRucS3fGzwjWqAb I7Tg== X-Forwarded-Encrypted: i=1; AHgh+RqdFuOy+LiW/DsrdMvzteRruMkgyldA2LuYib0ENyIENGAizPGcryJ42XFHwu1WFTa/MCKS9eQUT2feOZ8=@vger.kernel.org X-Gm-Message-State: AOJu0YyoEF9x7HoQrYvsXZRL59WZrYa1na46vh2sRVph4uhRK/mpQoS3 3MSggtcLA5zD7ygzRsbA93aRvpeI7uNx1bPvKaZSjiBL27EwcldG6Rj850UULzh11D1h X-Gm-Gg: AfdE7clSNDSGAlGAXJH8T82OQSzA77ehoWMcfcJvnKQMj3cszy1wjjHArsmtYOZ5dNp 4jX+1JpPJXF9o/Ycx0lB+n9AWa2DEtYwiDX1pf2D2PLVFI4XtgR9Cro65SQxQM7Rv2x3ari4nTd QvMECBYhtKUW5UnFGA48Oi+ALX7aNts2j0RHDu/KtKTYjs/5ZBHmmOU6vlafUsPG2MZRazIexvu CzvdNxbuZa4zCsd1YBKn2ajZknQsAcipUJBvOskDhJ0SWnORGJhlpT/8wNdjFlNMAwFjB5zeAka sOFXO+8a6BYeHFhoUbKch5k5y7yCmmTpLeKxkW/IezScqzTOq/K1H2IpKj7vcup+luh+NJFvpyA Jf0cCDDsQGvqVQtgH7u/Oztb5swF/pZdz6HqKFgnnP9kPo6xUDCO+3nH5OvW9CV124gFz9KxAqS woxWYkk87Ovp1TVP0FAyjRCjfMcnfzF19fpVQrHNet5mXKBWVAeHSvJiEXWj06k+EvmOE0oBTWj /9PVxCXt5O08FjnV4R0YOrgeg== X-Received: by 2002:a17:90b:5590:b0:381:5ab5:b667 with SMTP id 98e67ed59e1d1-38dc7819dc5mr2677196a91.31.1783775510256; Sat, 11 Jul 2026 06:11:50 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38a55557f25sm4136221a91.5.2026.07.11.06.11.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 06:11:49 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov , Mark Brown Cc: linux-input@vger.kernel.org, linux-spi@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v5 2/3] Input: applespi - fix NULL pointer dereference in tp_dim open Date: Sat, 11 Jul 2026 21:11:39 +0800 Message-Id: <20260711131140.18777-3-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711131140.18777-1-fourdollars@debian.org> References: <20260711055247.5412-1-fourdollars@debian.org> <20260711131140.18777-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The tp_dim debugfs file is registered synchronously during driver probe in applespi_probe(). However, the applespi->touchpad_input_dev is initialized and registered asynchronously in the driver's worker thread. If a userspace process opens the debugfs file before the worker thread has completed initialization, applespi_tp_dim_open() will dereference the NULL applespi->touchpad_input_dev pointer, causing a kernel panic. Fix this by using smp_load_acquire() to safely load touchpad_input_dev and return -ENODEV if it is not yet initialized. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index 3bdb9e7cfb8b..4d339445e9c7 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -963,12 +963,18 @@ static void applespi_debug_update_dimensions(struct a= pplespi_data *applespi, static int applespi_tp_dim_open(struct inode *inode, struct file *file) { struct applespi_data *applespi =3D inode->i_private; + struct input_dev *touchpad; =20 file->private_data =3D applespi; =20 + /* Pairs with smp_store_release in applespi_register_touchpad_device() */ + touchpad =3D smp_load_acquire(&applespi->touchpad_input_dev); + if (!touchpad) + return -ENODEV; + snprintf(applespi->tp_dim_val, sizeof(applespi->tp_dim_val), "0x%.4x %dx%d+%u+%u\n", - applespi->touchpad_input_dev->id.product, + touchpad->id.product, applespi->tp_dim_min_x, applespi->tp_dim_min_y, applespi->tp_dim_max_x - applespi->tp_dim_min_x, applespi->tp_dim_max_y - applespi->tp_dim_min_y); --=20 2.39.5 From nobody Sat Jul 25 23:41:46 2026 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2EE183C1F24 for ; Sat, 11 Jul 2026 13:11:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783775518; cv=none; b=a6PW1qWH1bv4kZhgUttVZiSfXrwxHlxck4BuJwfQrFcdhGUjOVbcaZspory6SjKJsJCfwqHhz/jfPVHSKQBVJ+G+hT5BEBGcJNBZNG0gR+rvDydSNA1grk0YcyXKoG4HzRRZNK5L2APHTjvjf+81TY9Jwxf6DwKpA62DI3fyAgQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783775518; c=relaxed/simple; bh=YRU9k1lERNTxkTc+5YgTqgr3AgfJ0f+mJ5crHfuI4jE=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=UUjMOiSI/opF2t18tcEYI5Y1r/xj+U9iawUO6N9h//gK0Ka4ValHstV1F9yoRdCrni2dL39GgVYLhX75c/qT4gOm15whBQR/5Xs+PRBkg9eoJxSLGquwy8/sQcmwsasRe4yKYWevaDtW5QKI5+50gz7/m8T9rC+KgHp3XIQ5bp0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-3811f512167so2298799a91.3 for ; Sat, 11 Jul 2026 06:11:52 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783775512; x=1784380312; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=kc4/WVQy8fssVht4RAYrhTn5gJQpHPueTRIgj0gLJ/A=; b=RXOsXXeQjfjNM93kmLl4PiBNFWKydWRPkgO4EKfNZs2pDIvnXhQW1dkYgX5obHar8U R7G30yFNFB76lQjpta9JCXWAMYTw2MmyAOkwxq5BGTKXQjti9udIrNwiQZ8LvcinjSWy HK+0Y2DPo4MJ72IlGHK76S/xteCJeN8FH56lwMF3CWrIMRu/EO1pCcQpPgoiZQdXV8En YvKc4JCBxFr2PfMEUBcYGdFUF0TYqr6ZfXtXqN+PoxQCiB/6mmfJrs6A/VyBKiTzS/o0 NxmGwvDPjJ3HFF7kGhuE6UxNEykP8aPZW+a6pkIGQ95HaRluc/Eo5aupuAA40WJSqxBY zDBw== X-Forwarded-Encrypted: i=1; AHgh+RpIyna8eHtMO8jf4gZZ27WEYzZ4EMEp6A1JV6h9jCG9UpH1q5AeX7bPEvDNzP8CUBm0W60t3oaFjBW8yrc=@vger.kernel.org X-Gm-Message-State: AOJu0YyszYQ9UiXoYgGTlZ7xrtx8MHVpFsO08K1UQZTIZLI/dykbqyBo jkt+jtZzAyOHafBE0R+9ev8TuZSF001wtDWnjuSgQEi08KBeRzqGtKo= X-Gm-Gg: AfdE7cnXDgy0uoi6mxXf0qetXyBC8UI/NEXj+caLB0t1SMD6OucFqwuFJjJoup66Bqf QpJHTv5rK4DTnO2OgncTwWIGbt/+UnwwuS55BkD+XFX1jl3/LW6q+CuznYSRDDGUyiET97w3hWJ ttbsjab6TjOqDzcSzykCbNKBsYOp1DBE85hsR2TyE4vj6j+AS82UlBGihPRD4c6wR2hliutPOTh BDRL22/Gv7Wu9NW28E2QPDVd0SRx446L11LqFBZtyLG97xUAc7oQ/QIVOTepf0iioOhpZvo4PDo 0vSYU4D8cx4kkAS1nngNMRBx9Xo4XG7Q9Cd3iiFA2MOet714Z2PogsSK3J3GJGaHx7kctstwhXg JcOVvT9rs+yyKaAn1tiBxbvGGg/Co2jUWyhyGSN9F/Lah/mXAvCBRtialBkKSr2xkgKIjeOcEhU j3uwyjC3llxY3c+V9oO8D40TfqfuXyVcvGxVaPcUgIMwegaM4RHIY5ceeJyisLtmiwm7zWPiy9B hFn+eYGrb0vUxIbeDyZJnjIkA== X-Received: by 2002:a17:90b:4a81:b0:35f:b6a1:8d27 with SMTP id 98e67ed59e1d1-38dc75e184dmr2909302a91.18.1783775512460; Sat, 11 Jul 2026 06:11:52 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38a55557f25sm4136221a91.5.2026.07.11.06.11.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 06:11:51 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov , Mark Brown Cc: linux-input@vger.kernel.org, linux-spi@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v5 3/3] spi: pxa2xx: disable DMA for Apple MacBook8,1 Date: Sat, 11 Jul 2026 21:11:40 +0800 Message-Id: <20260711131140.18777-4-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711131140.18777-1-fourdollars@debian.org> References: <20260711055247.5412-1-fourdollars@debian.org> <20260711131140.18777-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" On MacBook8,1 (early 2015 12" MacBook), the LPSS SPI controller's DMA handshake and interrupt routing frequently fail or time out on boot, causing the keyboard and trackpad to become unresponsive. Avoid this architectural bug by disabling DMA and forcing the SPI controller to use PIO mode. Move this platform/motherboard-level quirk to the SPI host controller driver (spi-pxa2xx-pci.c) where LPSS setup occurs, preventing layering violations, TOCTOU races, or execute-after-free bugs in the client driver. Additionally, introduce a `force_pio` module parameter in the PCI host controller driver to allow other users to force PIO mode for debugging. Link: https://bugzilla.kernel.org/show_bug.cgi?id=3D108331 Signed-off-by: Shih-Yuan Lee --- drivers/spi/spi-pxa2xx-pci.c | 35 +++++++++++++++++++++++++++++++++-- 1 file changed, 33 insertions(+), 2 deletions(-) diff --git a/drivers/spi/spi-pxa2xx-pci.c b/drivers/spi/spi-pxa2xx-pci.c index cae77ac18520..31bdaa096d9e 100644 --- a/drivers/spi/spi-pxa2xx-pci.c +++ b/drivers/spi/spi-pxa2xx-pci.c @@ -18,9 +18,14 @@ =20 #include #include +#include =20 #include "spi-pxa2xx.h" =20 +static bool spi_pxa2xx_force_pio; +module_param_named(force_pio, spi_pxa2xx_force_pio, bool, 0444); +MODULE_PARM_DESC(force_pio, "Force PIO mode (disables DMA) for SPI transfe= rs. ([0] =3D disabled, 1 =3D enabled)"); + #define PCI_DEVICE_ID_INTEL_QUARK_X1000 0x0935 #define PCI_DEVICE_ID_INTEL_BYT 0x0f0e #define PCI_DEVICE_ID_INTEL_MRFLD 0x1194 @@ -93,6 +98,32 @@ static void lpss_dma_put_device(void *dma_dev) pci_dev_put(dma_dev); } =20 +static const struct dmi_system_id pxa2xx_spi_pci_dmi_table[] =3D { + { + .ident =3D "Apple MacBook8,1", + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBook8,1"), + }, + }, + { } +}; + +static bool pxa2xx_spi_pci_can_dma(struct pci_dev *dev) +{ + if (spi_pxa2xx_force_pio) { + pci_info(dev, "Forcing PIO mode (disabling DMA)\n"); + return false; + } + + if (dmi_check_system(pxa2xx_spi_pci_dmi_table)) { + pci_info(dev, "MacBook8,1 detected: disabling DMA to force PIO mode\n"); + return false; + } + + return true; +} + static int lpss_spi_setup(struct pci_dev *dev, struct pxa2xx_spi_controlle= r *c) { struct ssp_device *ssp =3D &c->ssp; @@ -166,7 +197,7 @@ static int lpss_spi_setup(struct pci_dev *dev, struct p= xa2xx_spi_controller *c) =20 c->dma_filter =3D lpss_dma_filter; c->dma_burst_size =3D 1; - c->enable_dma =3D 1; + c->enable_dma =3D pxa2xx_spi_pci_can_dma(dev); return 0; } =20 @@ -238,7 +269,7 @@ static int mrfld_spi_setup(struct pci_dev *dev, struct = pxa2xx_spi_controller *c) =20 c->dma_filter =3D lpss_dma_filter; c->dma_burst_size =3D 8; - c->enable_dma =3D 1; + c->enable_dma =3D pxa2xx_spi_pci_can_dma(dev); return 0; } =20 --=20 2.39.5