From nobody Sat Jul 25 02:43:18 2026 Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B76AF3E0C7E for ; Mon, 20 Jul 2026 10:14:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542492; cv=none; b=Hq6FZKaBALobotyEX5G3ovhO19RRfH/NbNHopO0Hwx+uXxky2+qDSR1yhZuewdAwQvovhMJXjj7tPGuHmVr3FWD5/sKyGpPOS12v6oT6kAXLBwGaqVxNLdTuymZoykKCEIRReKTjLnnJWDo3S8EqgfLPr6t5xHxa5fWwfR622KY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542492; c=relaxed/simple; bh=4olgis/+UK7LivGkbVIiRcuHyl1sNyQgXPWAGbpQwxE=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=BP81oxDfwSl7yMcacivc9o5Vyht3n3BRMwa3UY5yYTWKwMmRyY5FJwJ7Rz4MyiOXgagZTpfNgxvebGYkb5o2IQbO++Rfqtkc964TFvWmOh+EC+YebVQvH1ykWgvubD4/GgQTZlmtB6PbUb2zIS6T91oSh8Vm/EC7w3KDGMj7xzY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.210.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-8485ef63b68so9586698b3a.1 for ; Mon, 20 Jul 2026 03:14:45 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784542483; x=1785147283; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=qUJCDmAKuwvWzvfCdV4S2qqsvo7USEen3xkhjOW/vGU=; b=GKKDrY5A+sfU/mFrHQRUymw3YC1ZjIDIjZ87gZYGMrIHZlczddPmidUQZJAslNfOXH CiPojA4tqXZ6hAhPaLeqLO03cU7r4GmT6GUIj1O8R+nvmA0r9BVDCnYtQwHTRZuBnCV2 9emceLaOkudr92XrKqOd7OWssInQ2jUfk4+gqiKYVdhPmQPthRbJufEjrsr8OHOqGf0D CLh49dJ2DSZcCeg4B+EBDNBsj0FUVdBjZLAVjIMPM+EsUwTY/YMGCaSCRvqfpo+PjpSc t3HZfQgFKNCdFluJaQWrScAZ6sntg0cOTecRjmaqMFp93CGqXTLcZhLUKXHuJkU9zygy S0JQ== X-Forwarded-Encrypted: i=1; AHgh+Rr8gv7JJF2fApFoReyRbnyjycnkk98BFG1THdDCi90mXOm8ycgP/K1T0lEjTixUS5GnDEdR+jUET6iNXtE=@vger.kernel.org X-Gm-Message-State: AOJu0YxwwsvVkrHZ2nG4iSnvUn1nUChTjwkmfV8XhjOJycDNb/EmEQZF pdBvV22mjACE0ajeApNKulwBAjhPIBtbu8EImSzbOuPQdxaLzemwN/Q= X-Gm-Gg: AfdE7ck5jU0gXxN0xiLDrekcxGpsmqObfkEHdLjfyeiwLyyk8bbUn3yo/wyjVTt2kjQ rCmguvburAzwJNe3W+YBJMYOMq5EoReS6HFd33w1EOwTlwTx2HCHn0bYtVZEu3V2emsNC7HVlni RD20OafirIxa597KuGfTXwYpMZ4FGGOogHi6GQGLXaBh/LdgFu2/lRHLZPI2phsltLsUphpiQW5 ATongzdSqcxqzTAUn2tBWgMq3mW4DZ6rtSBvj4ouN4ZtiZ8NslxrEZZMIIbPgKMuBBYi8wBSVjs XXe8yPF/wwc2n6W6w+3OTcsQfFkO3tsD/IlY+JZgU1eolWYfAykmdOvi3DSSPHkggCeoB2JQb5J 20VV+weYwt1M2wlaPwV9SfVSHnqrF2pwKqm60j18gekGQpvRNwNKWMO08s8nvf7mVJtVK6CNWqz OZedQ0m8Y0SrYIqvlLFyaYiVuiDRqoLedslXO7kBkQrT7yQJlFNbsbHGsP0PdRZs4tFASI7Kgz0 mg/HgZN3V7jt+RI6A== X-Received: by 2002:a05:6a00:1f09:b0:845:e440:d0ca with SMTP id d2e1a72fcca58-84c292a0323mr13167391b3a.8.1784542482681; Mon, 20 Jul 2026 03:14:42 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-16-100.dynamic-ip.hinet.net. [61.228.16.100]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cb517f94c31sm4411321a12.13.2026.07.20.03.14.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 03:14:42 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: Mark Brown , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v2 1/5] Input: applespi - use unified wait queue with timeouts for drain Date: Mon, 20 Jul 2026 18:14:31 +0800 Message-Id: <20260720101435.13612-2-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260720101435.13612-1-fourdollars@debian.org> References: <20260720101435.13612-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The driver currently maintains a dedicated wait queue 'drain_complete' specifically to wait for outstanding write requests to complete. Consolidate this with other wait events by renaming it to 'wait_queue' to make resource management cleaner. Furthermore, using wait_event_lock_irq() without a timeout risks blocking the thread indefinitely during driver unbinding (remove) or PM transition phases if the hardware fails to respond or interrupts are missed. Replace wait_event_lock_irq() with wait_event_lock_irq_timeout() in applespi_drain_writes() and applespi_drain_reads() with a 3-second timeout. This ensures the driver can gracefully recover and avoid lockups under unresponsive hardware conditions. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 32 +++++++++++++++++++++---------- 1 file changed, 22 insertions(+), 10 deletions(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index b5ff71cd5a70..64bbeba85ea9 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -417,7 +417,7 @@ struct applespi_data { =20 bool suspended; bool drain; - wait_queue_head_t drain_complete; + wait_queue_head_t wait_queue; bool read_active; bool write_active; =20 @@ -677,7 +677,7 @@ static int applespi_setup_spi(struct applespi_data *app= lespi) return sts; =20 spin_lock_init(&applespi->cmd_msg_lock); - init_waitqueue_head(&applespi->drain_complete); + init_waitqueue_head(&applespi->wait_queue); =20 return 0; } @@ -725,7 +725,7 @@ static void applespi_msg_complete(struct applespi_data = *applespi, applespi->write_active =3D false; =20 if (applespi->drain && !applespi->write_active) - wake_up_all(&applespi->drain_complete); + wake_up_all(&applespi->wait_queue); =20 if (is_write_msg) { applespi->cmd_msg_queued =3D 0; @@ -1415,7 +1415,7 @@ static void applespi_got_data(struct applespi_data *a= pplespi) applespi->read_active =3D false; applespi->write_active =3D false; =20 - wake_up_all(&applespi->drain_complete); + wake_up_all(&applespi->wait_queue); } =20 return; @@ -1793,21 +1793,33 @@ static int applespi_probe(struct spi_device *spi) =20 static void applespi_drain_writes(struct applespi_data *applespi) { - guard(spinlock_irqsave)(&applespi->cmd_msg_lock); + unsigned long flags; + + spin_lock_irqsave(&applespi->cmd_msg_lock, flags); =20 applespi->drain =3D true; - wait_event_lock_irq(applespi->drain_complete, !applespi->write_active, - applespi->cmd_msg_lock); + wait_event_lock_irq_timeout(applespi->wait_queue, + !applespi->write_active, + applespi->cmd_msg_lock, + msecs_to_jiffies(3000)); + + spin_unlock_irqrestore(&applespi->cmd_msg_lock, flags); } =20 static void applespi_drain_reads(struct applespi_data *applespi) { - guard(spinlock_irqsave)(&applespi->cmd_msg_lock); + unsigned long flags; + + spin_lock_irqsave(&applespi->cmd_msg_lock, flags); =20 - wait_event_lock_irq(applespi->drain_complete, !applespi->read_active, - applespi->cmd_msg_lock); + wait_event_lock_irq_timeout(applespi->wait_queue, + !applespi->read_active, + applespi->cmd_msg_lock, + msecs_to_jiffies(3000)); =20 applespi->suspended =3D true; + + spin_unlock_irqrestore(&applespi->cmd_msg_lock, flags); } =20 static void applespi_remove(struct spi_device *spi) --=20 2.39.5 From nobody Sat Jul 25 02:43:18 2026 Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1167F3C8C48 for ; Mon, 20 Jul 2026 10:14:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542496; cv=none; b=AMI9v7mM/49/wqjohtIm2ctIQ+lBgejOCP1xrZCtDaXV9XJJaF/3CkPxuKZ66ylMXhazoqFcVvHBhjwIXjlalmRlKjbKUZA2HV5piwNvRi6Wtqit4RT6+AeJ3xA/OqbCQ6+rpcJzwj9OXVkPbVeDB2etlqG5BD86shtrmnh1c4g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542496; c=relaxed/simple; bh=0aiI1f6vHsTeiGWLu/hog9EOHsxEKlYzD2ZIFajrF80=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=WTf1fbyqoYy06vh/p2LL6OhxpegzoNWRVucMSg0BT6nkd8bbRPkxJPx8mv40T34rtkeH1/arDguRq+vcQKIEJm1zqKj9MEhcqvkM5XwNkIVNz0EUzkWe/sZyo1S/1tvmD//kLUzZIGHKXPTXLViPulf6/0zYYz8FdgY/fibDskg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.216.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-38dc69c74b8so7610135a91.0 for ; Mon, 20 Jul 2026 03:14:48 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784542485; x=1785147285; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+KR23a5utjuBAUGcUFKPLl7/miZdWqDcdDLPWy8Jfvk=; b=bueGdt9eWgYGusp6HijH+GpvWzPC9wHAQMzWlu1ngrXbdgXRbL1FXge6Rmk405dyEq aoH4x3Y4Ts2Vb30lyYaqQngaFI7jlyaVSuQftl8JauUgmHYHj9HXE/klobb3t+EfhYsC qX5WppeIXjbGVFQcHMxMihA+63GvMVApIfPPoP9AmM6oIp8B79E7gEhyRnkICY6KbQih UpYQgVZ31tnQDSoRejWrqNOLG/WAAoGbRTclhee4sXRAGbwiqvEXTsAI8pzl1Qx4kxBE Un7GzeXCanI1xHEzkzAK9ap8QYeIeOUZBaMT+G57MQTqbIUgTHvMbLS+VRNbuAICvvTl kdjw== X-Forwarded-Encrypted: i=1; AHgh+RosgmSQaTAIDD0symUcxlfYHtm66yd8gKuBOhirTbRKpgDwmVLFMMrwANT8Br6f8SUTWBds+f+G0dru1fg=@vger.kernel.org X-Gm-Message-State: AOJu0YwGJ4I1hWkFK3X4eAW/lV6zq5uBawtZ+DyUGAX/1B2a4XchNrYT qGgchPKZXduwW6o2y9XMPU6fMeVJbMykXMG4Gj5PeZ3vnqZciwWzkJvNwRdmhcDBXg== X-Gm-Gg: AfdE7cmKOuCP2U41KUEokjpTTMRMo9PXLxJlHAi5YmfzUVyyCreZGzLcv0DOEH2QgRv zU2D9OiO1ghx0oe+27unnc+AGKoTBpNrzCU7f2a7bKaWmgGhBebIgiTtP2ZjsCoRbXrqPH0UXXN WYvWiTEx9uFw4dnSHCa56gvf1ZO2hctvuyCl1ygMPKkLg1pLpnZ3S2WffT8+l51oujq+nmXtcg7 nTYszdX1bpFpTHpYkZO7QJO4g/aCkbNyf0W39z+oxiNaTbDke8xFllu7yibH4J5VMY+btsBauqP +B0RfqpoIx7CiQ9lGx2v2GEQiDm+BUVOaPRY35kq8jzxLOSb0cN30ccjcC7XSZSN+ICkcVm5jyi IFxY8MD0MCso5rNRc0h2972KzjDTJFVwSZAgbXCkdzQ7edf2V7KxUOcrVQGX+XBnAkmYIDJ06cp Ne5jy8YKKzebHTue7hqUGLBgy4M/U4Jlcgwz7gjB7F//y/ueb3x89OLHr5/uAecenSFmEQAzVPh /gjuyfSqby8c0kICQ== X-Received: by 2002:a05:6a20:244c:b0:3c3:7fff:ba77 with SMTP id adf61e73a8af0-3c3ad973f68mr13774806637.42.1784542484649; Mon, 20 Jul 2026 03:14:44 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-16-100.dynamic-ip.hinet.net. [61.228.16.100]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cb517f94c31sm4411321a12.13.2026.07.20.03.14.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 03:14:44 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: Mark Brown , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v2 2/5] Input: applespi - track asynchronous SPI transfers in flight Date: Mon, 20 Jul 2026 18:14:32 +0800 Message-Id: <20260720101435.13612-3-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260720101435.13612-1-fourdollars@debian.org> References: <20260720101435.13612-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The driver queues read and write packets asynchronously. When shutting down, removing, or suspending, the driver must guarantee that no asynchronous transfers remain in flight to prevent memory corruption or use-after-free conditions. Introduce a 'spi_complete' slot tracking array in struct applespi_data to represent the two concurrent transfers (one for reads, one for writes). Implement applespi_async_outstanding() and applespi_async_complete() to track transfers under cmd_msg_lock. Modify applespi_async() to allocate a completion slot and assert that the caller holds the required cmd_msg_lock. This ensures robust and lock-safe tracking of all asynchronous SPI transactions. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 70 +++++++++++++++++++++++++++++-- 1 file changed, 67 insertions(+), 3 deletions(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index 64bbeba85ea9..a8f8d5370e95 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -421,6 +421,12 @@ struct applespi_data { bool read_active; bool write_active; =20 + struct applespi_complete_info { + void (*complete)(void *context); + struct applespi_data *applespi; + } spi_complete[2]; + bool cancel_spi; + struct work_struct work; struct touchpad_info_protocol rcvd_tp_info; =20 @@ -607,13 +613,71 @@ static void applespi_setup_write_txfrs(struct applesp= i_data *applespi) spi_message_add_tail(st_t, msg); } =20 +static bool applespi_async_outstanding(struct applespi_data *applespi) +{ + return applespi->spi_complete[0].complete || + applespi->spi_complete[1].complete; +} + +static void applespi_async_complete(void *context) +{ + struct applespi_complete_info *info =3D context; + struct applespi_data *applespi =3D info->applespi; + void (*complete)(void *context); + unsigned long flags; + + spin_lock_irqsave(&applespi->cmd_msg_lock, flags); + + complete =3D info->complete; + info->complete =3D NULL; + + if (applespi->cancel_spi && !applespi_async_outstanding(applespi)) + wake_up_all(&applespi->wait_queue); + + spin_unlock_irqrestore(&applespi->cmd_msg_lock, flags); + + if (complete) + complete(applespi); +} + static int applespi_async(struct applespi_data *applespi, struct spi_message *message, void (*complete)(void *)) { - message->complete =3D complete; - message->context =3D applespi; + struct applespi_complete_info *info; + int sts; + + assert_spin_locked(&applespi->cmd_msg_lock); + + if (applespi->cancel_spi) { + if (!applespi_async_outstanding(applespi)) + wake_up_all(&applespi->wait_queue); + return -ESHUTDOWN; + } + + /* + * There can only be at most 2 spi requests in flight, one for "reads" + * and one for "writes". + */ + if (!applespi->spi_complete[0].complete) + info =3D &applespi->spi_complete[0]; + else if (!applespi->spi_complete[1].complete) + info =3D &applespi->spi_complete[1]; + else { + dev_warn(&applespi->spi->dev, "Both SPI async slots in use\n"); + return -EBUSY; + } + + info->complete =3D complete; + info->applespi =3D applespi; + + message->complete =3D applespi_async_complete; + message->context =3D info; + + sts =3D spi_async(applespi->spi, message); + if (sts) + info->complete =3D NULL; =20 - return spi_async(applespi->spi, message); + return sts; } =20 static inline bool applespi_check_write_status(struct applespi_data *apple= spi, --=20 2.39.5 From nobody Sat Jul 25 02:43:18 2026 Received: from mail-pg1-f173.google.com (mail-pg1-f173.google.com [209.85.215.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4063739E197 for ; Mon, 20 Jul 2026 10:14:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542493; cv=none; b=C0lHfllctqnlHKqA+2x9ELTlCdjzJfW7zQFGJDj3mg4S9eGbBnvDEUZwKmytBFL/uj3AJ25b+o6MmxxPe5HcRL7OJDZry68yU0DXEY3cdtEsF1AG/RVhNP7e5GyrsA0aNPi+dzf5RNZUMq9TGHsuHTnNu7W4NECntFsoM6QClaU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542493; c=relaxed/simple; bh=zBFAtScCtJz6J3LkuunkpMbvy3Vysw16nLyJL24kSuA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=WxuAQtORD4VE8Q+Hlw+GT38WvvkiV4g3M2Qc0FZ/QE6gUiYV7PPJOOF9qIJvlKjUwAH6TOnGLnxRNkRRRrjo1Jac0Ifxf+QWLGTClSfsGvr6PRzzJ5U8Q6KC4wCaKF1lsRYfYvxZU4Wm6qH+Afi2ilWLMYU5ucuP7mEkqegqTDQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.215.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pg1-f173.google.com with SMTP id 41be03b00d2f7-ca80d708489so2389398a12.1 for ; Mon, 20 Jul 2026 03:14:48 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784542487; x=1785147287; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=1BlyvrkmFv1hwh49RhEdK1f4LtTECBvTt9R0UVOVdkA=; b=GQH7Fp24WY8W3GKaVlcdbZwKX7vp8JG2DszrbagB5eefRDiby3Z8tqbczo1808AXaL N++25FTqaQ+lYZ5DGjHI74gnB0MXllEMmOPNSxuyqTl4+uK8et97NyGhFCAuf3s2nf9D efJfz6o6Jqa9kUjUfgWTNo4v9FDDv7tSggcx1y8osOJ6UQNFj3MdG809fhv/j7MFYn8G rBkEzCVjxExPHxE0UT7VtN/5FFicv+JiwCBC3w0Rjf4+2ZvFxbtoVXM5xcrOlYy9t+Rg Sth+a3Hwa5riYKg1VeoRPCzPuGopdZ7wZUZFzjaBuBWWpzZI8XG6JFVx0IBurA8JifP5 y6JQ== X-Forwarded-Encrypted: i=1; AHgh+RqYTAdb2dYb44viuKyk2dx3qT5CYWrh5zCRbN73TdgH874d3fLx8/0gDUFecvxop1yg+J5lFbQo1PWLmz8=@vger.kernel.org X-Gm-Message-State: AOJu0YwWmE4Z7F36SAmKKlc85l9Ll5E3hRIXk8ooNbu4MD9tN9cpQHg4 NiX6PMQkSzfGRUYxYS/E342G0BJW08yCWFvNkb4SBKWSr1z0Umbp6nX72L1+KAmUFA== X-Gm-Gg: AfdE7cnq53IGkjmMj0k11JrtnPerz5EqjoD7XbnMV98lDvZNHTiqwtNdPOiteTCEpPq pFQ9AM85Xl1UZHGn83Q7iMEC34qUZcHx+DzjBA8pzln2ocs72EImUWJQ1AmYi8Ow74mum8t6jje W57BHjVhsIL308rMH3IZrUQx/XcEul6F6zkStyUai1kiR11eHLNsx9S4ZWnbnYlNibDrCFp0DpY Ehw4UV3S9kdU4Wk5g8/pycCkOiuJEFmyS4ImNC8+zfV+t7YaLDsrDYeCiUV8wUlzvkJMa+qgZJo WpdTx6+6ROxz9WWedIfSXvoCp0NHlFO+3YrWpl9CTY8WxGyIBbKkzHijHGU2MYZnwVsDwxALpBM 2BXw1YvMJBQkLXl+uKNjUHxT+Bpd5X8rQ0rLrid2uyI6qCGaweI+VZvV82HWXts5a+osJlwpUbF 0wSRalmwJd+RE6u2gxVGUvAaZZb8Tu9kIqukkiLRED017t/XSS8pG7OdDGlSUtdcs11iW9xrQPs To8Upxk1q84vL2kvw== X-Received: by 2002:a05:6a20:258a:b0:3bf:aa54:4cbc with SMTP id adf61e73a8af0-3c38dbb8287mr19933105637.26.1784542486563; Mon, 20 Jul 2026 03:14:46 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-16-100.dynamic-ip.hinet.net. [61.228.16.100]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cb517f94c31sm4411321a12.13.2026.07.20.03.14.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 03:14:46 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: Mark Brown , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v2 3/5] Input: applespi - register touchpad synchronously in probe Date: Mon, 20 Jul 2026 18:14:33 +0800 Message-Id: <20260720101435.13612-4-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260720101435.13612-1-fourdollars@debian.org> References: <20260720101435.13612-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Touchpad registration is currently deferred to an asynchronous worker applespi_worker(). This asynchronous registration introduces race conditions if debugfs or other properties are accessed before the worker completes, or if the driver is unbound while the worker is active. Remove the workqueue and the asynchronous worker. Perform touchpad registration synchronously during driver probe. Wait up to 3 seconds for the touchpad information command packet response using wait_event_timeout(). If the response times out, log a warning and fallback to keyboard-only mode. If registration fails, gracefully unwind GPE handlers and wait for outstanding SPI transactions to complete. To prevent data races between the interrupt handler and the probe thread, protect the 'have_tp_info' flag and 'rcvd_tp_info' structure under the cmd_msg_lock in applespi_handle_cmd_response(). Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 52 +++++++++++++++++++++---------- 1 file changed, 36 insertions(+), 16 deletions(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index a8f8d5370e95..42b7f87ef2cd 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -427,7 +427,7 @@ struct applespi_data { } spi_complete[2]; bool cancel_spi; =20 - struct work_struct work; + bool have_tp_info; struct touchpad_info_protocol rcvd_tp_info; =20 struct dentry *debugfs_root; @@ -1388,26 +1388,20 @@ applespi_register_touchpad_device(struct applespi_d= ata *applespi, return 0; } =20 -static void applespi_worker(struct work_struct *work) -{ - struct applespi_data *applespi =3D - container_of(work, struct applespi_data, work); - - applespi_register_touchpad_device(applespi, &applespi->rcvd_tp_info); -} - static void applespi_handle_cmd_response(struct applespi_data *applespi, struct spi_packet *packet, struct message *message) { + unsigned long flags; + if (packet->device =3D=3D PACKET_DEV_INFO && le16_to_cpu(message->type) =3D=3D 0x1020) { - /* - * We're not allowed to sleep here, but registering an input - * device can sleep. - */ + spin_lock_irqsave(&applespi->cmd_msg_lock, flags); applespi->rcvd_tp_info =3D message->tp_info; - schedule_work(&applespi->work); + applespi->have_tp_info =3D true; + spin_unlock_irqrestore(&applespi->cmd_msg_lock, flags); + + wake_up_all(&applespi->wait_queue); return; } =20 @@ -1675,6 +1669,7 @@ static int applespi_probe(struct spi_device *spi) acpi_handle spi_handle =3D ACPI_HANDLE(&spi->dev); acpi_status acpi_sts; int sts, i; + unsigned long flags; unsigned long long gpe, usb_status; =20 /* check if the USB interface is present and enabled already */ @@ -1692,8 +1687,6 @@ static int applespi_probe(struct spi_device *spi) =20 applespi->spi =3D spi; =20 - INIT_WORK(&applespi->work, applespi_worker); - /* store the driver data */ spi_set_drvdata(spi, applespi); =20 @@ -1821,6 +1814,20 @@ static int applespi_probe(struct spi_device *spi) /* trigger touchpad setup */ applespi_init(applespi, false); =20 + /* set up the touchpad as a separate input device if info is received */ + sts =3D wait_event_timeout(applespi->wait_queue, + READ_ONCE(applespi->have_tp_info), + msecs_to_jiffies(3000)); + if (!sts) { + dev_warn(&applespi->spi->dev, + "Timed out waiting for touchpad info, continuing keyboard-only\n"); + } else { + sts =3D applespi_register_touchpad_device(applespi, + &applespi->rcvd_tp_info); + if (sts) + goto cancel_spi; + } + /* * By default this device is not enabled for wakeup; but USB keyboards * generally are, so the expectation is that by default the keyboard @@ -1853,6 +1860,19 @@ static int applespi_probe(struct spi_device *spi) &applespi_tp_dim_fops); =20 return 0; + +cancel_spi: + acpi_disable_gpe(NULL, applespi->gpe); + acpi_remove_gpe_handler(NULL, applespi->gpe, applespi_notify); + + spin_lock_irqsave(&applespi->cmd_msg_lock, flags); + applespi->cancel_spi =3D true; + wait_event_lock_irq(applespi->wait_queue, + !applespi_async_outstanding(applespi), + applespi->cmd_msg_lock); + spin_unlock_irqrestore(&applespi->cmd_msg_lock, flags); + + return sts; } =20 static void applespi_drain_writes(struct applespi_data *applespi) --=20 2.39.5 From nobody Sat Jul 25 02:43:18 2026 Received: from mail-pl1-f180.google.com (mail-pl1-f180.google.com [209.85.214.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E4F3539D6F6 for ; Mon, 20 Jul 2026 10:14:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542502; cv=none; b=O1AZd+NLwHiksixp/fizSkO15Z6ZxMEq5Lm/KfJf6jUuhHyz722ZD8A49eD6k5AkvnyVKiKyzeeeVYJvVuV/u5ctvJD6asLbQE32g6KkC3rZKm8Ds37JBHbPZaGtdW54KXaa8knzOAEdRZfhRtNxYP3zsiR6VpCr2Z+tKc2uVmk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542502; c=relaxed/simple; bh=NhumDAPtVfA/+OxCt91N4vf3hIjURO6jz1ij/AUKMFs=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=PpKsjLC6XZmc7eG1Ha6IXZXgQXVpHezEfYTCBL7vbhKADoTx+xk90S+wTu8Fd+qbK2SWQ9D/xKjgd7zTsOr7Dpz0xHZ8bRinOHwuyGjs+6Kok4jLYpxFOclRvpEeKh2UhQutiatsiFq0TDlGxqThjErp+TQNNFnc78Md8ZyozCM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.214.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f180.google.com with SMTP id d9443c01a7336-2ce87c7e3bbso111270825ad.1 for ; Mon, 20 Jul 2026 03:14:53 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784542488; x=1785147288; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TnC4sF8YJwzUoevHGn/VBk+2Onx+uhb+pGRw5Dnqm7g=; b=KpWDXUOBIWm/Bd2ByhdIcuQKZnb2pU81F53ELuAGmHTClItVMRpgzXMRkvMJYu6oqN u/Cf+9p2XUgTBFDEtL5pWgfMXY5U6XWAcHDJOawjVEIZKm7bxspths/mXrx0qnY86YQV Z3kJnP3L+FhvRgSncVT42bdqBJd1c8qKiPURrXv1lUrs2f5Dn9FuL1QYZfV/SgmzBj87 Y4hFFkHVzGnNwBOIXijhQZ8KjkSnnxLzdOrPMycxb0PHqF7HnCdEQZgrkQGePg2pMWER 9TyiHE8Xgsm77CPyPRLQHMjpyt88KYHd0ipwSzGtFoOeQA3hz0F/I0gzHdxBxEPS4Tu1 vYHg== X-Forwarded-Encrypted: i=1; AHgh+RoD+BfiMXadw967NtB6JBXfBGVA1IxfQJjH/JAP0xf+OJ24CoOzDYcFCFKR53HzQZYg6unxM9CltMI+6MA=@vger.kernel.org X-Gm-Message-State: AOJu0YxNOqTm3UeDQA5nVm9+2ZxZmAEqBXxIMhU+/Tn3le3leOWshrDK QvgN9iM0dwbPtQ5E5GYzutHpBEwEG/Oij+ITsDkhnLyG2ajj0ySLp00= X-Gm-Gg: AfdE7cmlJHyvRNKSFlMatI/XB0nRy7HLPoJnh098mJ0w0XkA+nwFVz+I2iyqDKF/oBv kkTFr8u5r5es/SjAfXgoabZQ+389ea8G1bphWxQrqfJ938qmNN/QNEbgxnYQwkRgSq2qJWfd/ov ApfVkC3Tf2xm2cWq1P0DnCEKv8az298riXOd7rduM8UX3+0Yw++024sr62D7WR472QJUQGSVO6X StAoqVp2hTNEYmTkxOrXa16QC3JZgpdhAtq+ihCSWNpKjNDCGCMJCGCB+/EXlZpWUrzIdBDFcPJ A/dnXIcQRlOI4D0rdiidaiAkXPptPm8iH2PdD0Ex7m+ZaanR4PS5Ou/fTUW+UdgoHQKjcCWY1IJ VjcNbWsokD+E8D8osh5KNz1yafu2Svrh4IxFKiCnq4ZcA//maS76xEjg19yZEcViMDk7UkKJnU9 /ocaKOBEh1gBuo2oIS6ymYIEO7sN88oBWI98a9cGIZNPEX9KDmJkDWkoid/TL2ekwyLwGHW/pgg OMw2hv/W5fOuAhCpw== X-Received: by 2002:a05:6a20:a103:b0:3c0:9c1a:8941 with SMTP id adf61e73a8af0-3c3ada59cd5mr13875315637.73.1784542488359; Mon, 20 Jul 2026 03:14:48 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-16-100.dynamic-ip.hinet.net. [61.228.16.100]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cb517f94c31sm4411321a12.13.2026.07.20.03.14.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 03:14:47 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: Mark Brown , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v2 4/5] Input: applespi - prefer asynchronous driver probing Date: Mon, 20 Jul 2026 18:14:34 +0800 Message-Id: <20260720101435.13612-5-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260720101435.13612-1-fourdollars@debian.org> References: <20260720101435.13612-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Set probe_type to PROBE_PREFER_ASYNCHRONOUS to allow the driver core to run applespi_probe() asynchronously. This improves system boot speeds by avoiding blocking the main kernel thread during the 3-second touchpad detection wait. Additionally, clean up applespi_tp_dim_open() by simplifying product ID retrieval and avoiding dereferencing touchpad_input_dev without a helper variable. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index 42b7f87ef2cd..95a8f790eaff 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -1027,12 +1027,13 @@ static void applespi_debug_update_dimensions(struct= applespi_data *applespi, static int applespi_tp_dim_open(struct inode *inode, struct file *file) { struct applespi_data *applespi =3D inode->i_private; + struct input_dev *touchpad =3D applespi->touchpad_input_dev; =20 file->private_data =3D applespi; =20 snprintf(applespi->tp_dim_val, sizeof(applespi->tp_dim_val), "0x%.4x %dx%d+%u+%u\n", - applespi->touchpad_input_dev->id.product, + touchpad->id.product, applespi->tp_dim_min_x, applespi->tp_dim_min_y, applespi->tp_dim_max_x - applespi->tp_dim_min_x, applespi->tp_dim_max_y - applespi->tp_dim_min_y); @@ -2015,6 +2016,7 @@ static struct spi_driver applespi_driver =3D { .name =3D "applespi", .acpi_match_table =3D applespi_acpi_match, .pm =3D pm_sleep_ptr(&applespi_pm_ops), + .probe_type =3D PROBE_PREFER_ASYNCHRONOUS, }, .probe =3D applespi_probe, .remove =3D applespi_remove, --=20 2.39.5 From nobody Sat Jul 25 02:43:18 2026 Received: from mail-pg1-f182.google.com (mail-pg1-f182.google.com [209.85.215.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0051F2BEFFE for ; Mon, 20 Jul 2026 10:14:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542500; cv=none; b=HO3Sx5JnxX9JFIKREh9sxZN2X7Gj1sCPe+Vc6j66S6ej3O9aLz27gLx+MfOp6RMqJ10rKsMtKtYN19sWxSppYk52HxPq020Yavz9poK3Nt/EjVBs4dAk+4ue/MV8zJxvNoIMx8jo77cwS4d5fIwT3jMDVNaTzgOfixiW5uiBdLU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784542500; c=relaxed/simple; bh=JXokrE38sgfKHFjs6siu/55oNnmhzpQI+mIVcZk7QiY=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=giEuLOklmQYRBNiHNYEzT0bqOm2dug/mdpVpu0x/RQ2gU0j5AgNKuZd6q23M/6bPrweFFwOKtIxmrjL6mKswI+5NbX85HxU7wVAZ2l3FqyJdzjrqhQBhcxImNX8AgvGd/HSOa8jr3O0rWIa1GAAQ5RswG3Gf2wbcrrkkeIl3Lrg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.215.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pg1-f182.google.com with SMTP id 41be03b00d2f7-ca97d139d5fso6947236a12.0 for ; Mon, 20 Jul 2026 03:14:56 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784542490; x=1785147290; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=RF1ftOMQ+N1bAoeZkI0/wgbxDAI/VKJ5VcqnqJwi0CQ=; b=Rwv9i+BfFsKyUiexyQ+uDGZHyzO9qUc3qpyx23z+1YNPkefyPENzayCFQYcjVgpAbf e7WIHNMEkokycC9XWu2RV+x+cuXou28zbT709vCGx0dFvoEqjjiEzGnm6JfmrklXTLe1 nnsvcDqaiLKF+wvuPBqYILUz4xxN/Wum+wa7BecJ93LCZXtdUYO4oAWjw+4m7J8NaOQe NWU0ECkYtPhnmK8bPyfJ06LZdo8lw8gvpiAATC+q0GKct3iZmHiO2GWrnAK7o+eYyoUL spr+/koxw5sTYiCa0HIchTRh95NeV1iLAY1YpOBtUPRe5t2ZCKjm2HHWK9XiUo1SNDsz 6JLg== X-Forwarded-Encrypted: i=1; AHgh+Rp81f24VIIMc4DDkkRePK9udmJEb4Dhxb6OEG5yabDsywPcZk84i+IduK554FfrwKFxQX+gh84N7gP4P2I=@vger.kernel.org X-Gm-Message-State: AOJu0YzqPL1JYJmK3JIldWDtBcWhlBmAbb5X/zafOPANQyvwIyLnkhXh DkUAbBPDEH25iG32Zpqa5ouMSh8c/B8HORRaoAkyosJ71wT767QE4Q4= X-Gm-Gg: AfdE7cnsWRMjMap6tIvg+8XE6TjAjHp5Eil/X++E/EwcHQAQkfDOrxalW937c5fJmRw O740pP/OKt3jSfvEZHBZR1HOtnX0Od+z/E1dl+SXdilXPzEd5ZjCEW3NX7sRxwQPDHBGnSrsCxa fTt2yRTxssG3V5UvB44+Y3Pdp5/BZ8dBpHqez4yqmOgU6+bT2sUCvzAxiYpXs1mfXUM2YQZ6TEl Yml+DnfccWG4qtkp2VvI096SSl95HbHyV7EzUwhpn4dk1fC2OTZCCOcdKUrMe3DfRtp4Rzdxrgg dEp+ZcyBZm1M96zSkiMGwjncvxoi4W9IJfzwmqnC9sQIUjjkKzxYO97q72On01xDj3qR8SdvT3h uxUgs6UoQlCPW72YH+1EPaKcYzFd5HrstTe+ELDOWRLGr9vTliqzIinSXJ+3g7jTitINxktkdoT 7Y8g/+ZxnHmqvc5GTdum5FLFc4NQsqiGn1xJER3HAulVRoxXAkfOrFHU2ou5/yX96HxmPjvY3eA MHz1YQGThXS/DSp9w== X-Received: by 2002:a05:6a21:9206:b0:3c3:7ac4:dac0 with SMTP id adf61e73a8af0-3c3ad5d4f0fmr15037185637.13.1784542490168; Mon, 20 Jul 2026 03:14:50 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-16-100.dynamic-ip.hinet.net. [61.228.16.100]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cb517f94c31sm4411321a12.13.2026.07.20.03.14.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 03:14:49 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: Mark Brown , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v2 5/5] Input: applespi - fix use-after-free in applespi_remove() Date: Mon, 20 Jul 2026 18:14:35 +0800 Message-Id: <20260720101435.13612-6-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260720101435.13612-1-fourdollars@debian.org> References: <20260720101435.13612-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" applespi_remove() called applespi_drain_writes() to wait for in-flight write transfers, then immediately called acpi_disable_gpe() and acpi_remove_gpe_handler(). However it then called applespi_drain_reads() *after* the GPE handler was removed, which races with any read SPI completion callback that could still reference the applespi struct already being torn down. Moreover, the two drain helpers use separate wait paths that can miss each other: a read completion arriving just after drain_writes() returns but before drain_reads() is called will set read_active, and the subsequent drain_reads() will then wait on a wait_queue that nobody will ever wake because the GPE is already gone. Fix by replacing the two separate drain calls with a single barrier using the existing cancel_spi + wait_event_lock_irq mechanism: - Set cancel_spi =3D true under the spinlock so that applespi_async() immediately rejects new SPI submissions and wakes the wait queue once all outstanding operations have drained. - Wait for !applespi_async_outstanding() before proceeding with teardown. - Disable the GPE and remove its handler only after all in-flight SPI transfers have completed, eliminating the use-after-free window. Fixes: 0b7a8ac72fc1 ("Input: applespi - add driver for Apple SPI keyboard a= nd touchpad") Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/app= lespi.c index 95a8f790eaff..088337f060b2 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -1910,15 +1910,22 @@ static void applespi_drain_reads(struct applespi_da= ta *applespi) static void applespi_remove(struct spi_device *spi) { struct applespi_data *applespi =3D spi_get_drvdata(spi); + unsigned long flags; =20 - applespi_drain_writes(applespi); + /* Prevent any new SPI transfers and wait for outstanding ones */ + spin_lock_irqsave(&applespi->cmd_msg_lock, flags); + applespi->cancel_spi =3D true; + wait_event_lock_irq_timeout(applespi->wait_queue, + !applespi_async_outstanding(applespi), + applespi->cmd_msg_lock, + msecs_to_jiffies(3000)); + spin_unlock_irqrestore(&applespi->cmd_msg_lock, flags); =20 + /* Disable GPE and remove handler */ acpi_disable_gpe(NULL, applespi->gpe); acpi_remove_gpe_handler(NULL, applespi->gpe, applespi_notify); device_wakeup_disable(&spi->dev); =20 - applespi_drain_reads(applespi); - debugfs_remove_recursive(applespi->debugfs_root); } =20 --=20 2.39.5