From nobody Mon Sep 28 13:18:02 2026 Received: from mx.prosyst.ru (m2.prosoftsystems.ru [46.48.77.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8AEA9416102; Fri, 21 Aug 2026 07:54:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=46.48.77.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787298845; cv=none; b=T4h1HwvlHaG3pyoL8AeXOI9BefWw8H+EKnxk7JVd+5g3qqOS3hcSJibYe+uBH8jUbekbHHd7dDpUWQ1w9cm3f4kA7W6qoDZF9TbFn9jnD+ijEVrlPFh4Ckwr+Q9IScAKT4a/eI8dZsa0+taAQnhWvZThggaVZrbXX2bg3RLBw7c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787298845; c=relaxed/simple; bh=REikZi9pApQc2ARh0zVtJvBm/nk2VLJbOUcBU7Yp5aM=; h=Content-Type:From:To:CC:Subject:Date:Message-ID:References: In-Reply-To:MIME-Version; b=OQ84bEhTVPMbFN45WzNRCo5LJOrXPZf0L8AMqX7zafJnSzgOSKOm/0d6KRiH+OvbMlGb/BG6T2RiMR+VmGi7T6Y2v7ZEcF6qSUetreoikdgmGtoidgNaYQjzWCOe52S3aXtx6+qr173wv/y9VpO8d7U2tnJgXwj8+UE/jVYpd7U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=prosoftsystems.ru; spf=pass smtp.mailfrom=prosoftsystems.ru; dkim=pass (2048-bit key) header.d=prosoftsystems.ru header.i=@prosoftsystems.ru header.b=CLrB8vzP; arc=none smtp.client-ip=46.48.77.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=prosoftsystems.ru Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=prosoftsystems.ru Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=prosoftsystems.ru header.i=@prosoftsystems.ru header.b="CLrB8vzP" Content-Language: ru-RU Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; d=prosoftsystems.ru; s=ps; c=relaxed/relaxed; t=1787298837; h=from:to:date:message-id:subject; bh=ToqiBpcLxa4O7isOlNvqkO5oOViLjOPDY5eP115sBvo=; b=CLrB8vzPs37lxh0k651iHUk3jQ1oT5GIHdBDF5tgLcsXhwP7sMYj/CzbZeW/sUyLfK1fVL6VjKR u/CbdC/55TDRrdXw4ZXtyuAiKwYeicWTP9AKcz4mtFEVmi1j4rko0zXp7tXQEv0VG3yxcLyyOK2JM 5HFep1C4qeN1Mj+FJ/0N4zJuxkYlmXcZM5XnXHfldg3Gsy6KjuXuCQfL7hdE/O3YlRxAiMvgDm8GB +ybkKZB3SDzkvenSc5SD9O6ts5azAuYYBNkriuQLcaWCrdvTm6jXPkDMcM3GOqzO7SsKgb4wcz1JG 0WiR/tFrevYQeyL/1qylh9jC1OxE7Gd5viSg== Received: from echo-2.prosoft.ural.ru (172.21.245.22) by mx.prosoftsystems.ru (172.21.240.33) with Microsoft SMTP Server (TLS) id 15.1.396.30; Fri, 21 Aug 2026 12:53:57 +0500 Received: from echo-2.prosoft.ural.ru (172.21.245.22) by echo-2.prosoft.ural.ru (172.21.245.22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1748.39; Fri, 21 Aug 2026 12:53:58 +0500 Received: from echo-2.prosoft.ural.ru ([fe80::8f12:4f85:56d8:13ed]) by echo-2.prosoft.ural.ru ([fe80::8f12:4f85:56d8:13ed%17]) with mapi id 15.02.1748.039; Fri, 21 Aug 2026 12:53:58 +0500 From: =?koi8-r?B?9sHNwsHLycXXIPLBxMnKIPLJy8HSxMnOz9fJ3g==?= To: Aaro Koskinen CC: =?koi8-r?B?9sHNwsHLycXXIPLBxMnKIPLJy8HSxMnOz9fJ3g==?= , Andreas Kemnade , Kevin Hilman , Roger Quadros , "Tony Lindgren" , Lee Jones , Grygorii Strashko , Marcin Niestroj , "linux-omap@vger.kernel.org" , "mfd@lists.linux.dev" , "linux-kernel@vger.kernel.org" , "lvc-project@linuxtesting.org" , "stable@vger.kernel.org" Subject: [PATCH 1/2] mfd: tps65217: Fix NULL pointer dereference on IRQ init failure Thread-Topic: [PATCH 1/2] mfd: tps65217: Fix NULL pointer dereference on IRQ init failure Thread-Index: AQHdMUI4ieVoIMKZ+UiKarSj4WzOxg== Date: Fri, 21 Aug 2026 07:53:58 +0000 Message-ID: <20260821075331.131315-2-r.zhambakiev@prosoftsystems.ru> References: <20260821075331.131315-1-r.zhambakiev@prosoftsystems.ru> In-Reply-To: <20260821075331.131315-1-r.zhambakiev@prosoftsystems.ru> Accept-Language: ru-RU, en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" tps65217_probe() ignores the return value of tps65217_irq_init(), so when the irq domain creation fails the probe still completes and the driver ends up bound with a NULL tps->irq_domain. Unloading the module then makes tps65217_remove() call irq_domain_remove() on the NULL pointer and oops the kernel. On top of that, irq_find_mapping() may fall back to the default irq domain and dispose of mappings that belong to other interrupt controllers. Check the return value and abort the probe on failure so the error is reported and no inconsistent state is left for removal. Fixes: 6556bdacf646fcaa ("mfd: tps65217: Add support for IRQs") Cc: stable@vger.kernel.org Signed-off-by: Radiy Zhambakiev Reviewed-by: Andreas Kemnade --- drivers/mfd/tps65217.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/mfd/tps65217.c b/drivers/mfd/tps65217.c index c240fac0ede7..2d04d9e0ae29 100644 --- a/drivers/mfd/tps65217.c +++ b/drivers/mfd/tps65217.c @@ -333,7 +333,9 @@ static int tps65217_probe(struct i2c_client *client) } =20 if (client->irq) { - tps65217_irq_init(tps, client->irq); + ret =3D tps65217_irq_init(tps, client->irq); + if (ret) + return ret; } else { int i; =20 --=20 2.53.0 From nobody Mon Sep 28 13:18:02 2026 Received: from mx.prosyst.ru (m2.prosoftsystems.ru [46.48.77.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0905D419FBB; Fri, 21 Aug 2026 07:54:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=46.48.77.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787298849; cv=none; b=RNkWm4k0HnloCBxXDBytyMsqLdoRUc6kfUDnzEAYcs2UhevrAxWCKbHPzT7jTPwrptaYA/d1n4N2xkwxej/qlDW/79HnsC9nYQV+z8By2kwybmeUbyxRL4X5tmPSVccf+OQcILxDbsqah0+GO4JPRfaRWnDg/n1QtZ/URrkzS1U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787298849; c=relaxed/simple; bh=v9Uks2YX9bo6AmhoTDp/QPHUwX6o/1CJTfC/Z5FtFt8=; h=Content-Type:From:To:CC:Subject:Date:Message-ID:References: In-Reply-To:MIME-Version; b=JAzEIxkBRWqEgBQai7Mn/akMCLEERk9q+SETp6lBTk2Ay2FC+4pww523ajtmwdWhhTwFdweg0oRrtZ7l9CJkQH9vt7HJZbhW5GxswcCFRJAwqgDV2PbbQgfbxHnhf1aWwk7OALjiwtlNRg9VQpTFyepFpiJTdVFeoCJaMjr9+wc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=prosoftsystems.ru; spf=pass smtp.mailfrom=prosoftsystems.ru; dkim=pass (2048-bit key) header.d=prosoftsystems.ru header.i=@prosoftsystems.ru header.b=ohrtSkRO; arc=none smtp.client-ip=46.48.77.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=prosoftsystems.ru Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=prosoftsystems.ru Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=prosoftsystems.ru header.i=@prosoftsystems.ru header.b="ohrtSkRO" Content-Language: ru-RU Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; d=prosoftsystems.ru; s=ps; c=relaxed/relaxed; t=1787298842; h=from:to:date:message-id:subject; bh=d80hrUiBWS9VMj9C77oH8JPtF3ywVPvFIRx5zJTX2u4=; b=ohrtSkRO3AjfnuG92xRF8lPJsqnSbhKORWGPolUTnWlDj9HrFFc6WgzuNPsGI0U7nFvjGKgWjLx 5TAFJUAxhcoB6LaHMn2YHWFbujli9tyxyg2vSYUg0xnqncmlgmPMcO+13y5y+ih74p6cRQxSa6u11 Lb82DKpr6jEJClSIFsDM7XvQFgbmHeeKGV63V3/eLSrgAnlPxWe19k9ljPDHO1GB02qq1ddjyv1Hz 8szpd2RvO5n+LYw/p0rAbz4mHbPBmAdy5iO30BXDpTOC6xYroKM2GTWWoNSIENjLyAnqq+qAIuCfz bbQYjrsB5nJUdmJmnZydBnuYqiuSnUKCxt8Q== Received: from echo-2.prosoft.ural.ru (172.21.245.22) by mx.prosoftsystems.ru (172.21.240.33) with Microsoft SMTP Server (TLS) id 15.1.396.30; Fri, 21 Aug 2026 12:54:02 +0500 Received: from echo-2.prosoft.ural.ru (172.21.245.22) by echo-2.prosoft.ural.ru (172.21.245.22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1748.39; Fri, 21 Aug 2026 12:54:03 +0500 Received: from echo-2.prosoft.ural.ru ([fe80::8f12:4f85:56d8:13ed]) by echo-2.prosoft.ural.ru ([fe80::8f12:4f85:56d8:13ed%17]) with mapi id 15.02.1748.039; Fri, 21 Aug 2026 12:54:02 +0500 From: =?koi8-r?B?9sHNwsHLycXXIPLBxMnKIPLJy8HSxMnOz9fJ3g==?= To: Aaro Koskinen CC: =?koi8-r?B?9sHNwsHLycXXIPLBxMnKIPLJy8HSxMnOz9fJ3g==?= , Andreas Kemnade , Kevin Hilman , Roger Quadros , "Tony Lindgren" , Lee Jones , Grygorii Strashko , Marcin Niestroj , "linux-omap@vger.kernel.org" , "mfd@lists.linux.dev" , "linux-kernel@vger.kernel.org" , "lvc-project@linuxtesting.org" , "stable@vger.kernel.org" Subject: [PATCH 2/2] mfd: tps65217: Check return value when masking interrupt sources Thread-Topic: [PATCH 2/2] mfd: tps65217: Check return value when masking interrupt sources Thread-Index: AQHdMUI7Rk6iTnyhQ025GACpPton4A== Date: Fri, 21 Aug 2026 07:54:02 +0000 Message-ID: <20260821075331.131315-3-r.zhambakiev@prosoftsystems.ru> References: <20260821075331.131315-1-r.zhambakiev@prosoftsystems.ru> In-Reply-To: <20260821075331.131315-1-r.zhambakiev@prosoftsystems.ru> Accept-Language: ru-RU, en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" tps65217_irq_init() ignores the error returned by tps65217_set_bits() when masking all interrupt sources. A failed register write leaves the driver's software mask out of sync with the hardware and may result in spurious interrupts. Check the return value and propagate the error to the caller. Found by Linux Verification Center (linuxtesting.org) with SVACE. Fixes: 6556bdacf646fcaa ("mfd: tps65217: Add support for IRQs") Cc: stable@vger.kernel.org Signed-off-by: Radiy Zhambakiev Reviewed-by: Andreas Kemnade --- drivers/mfd/tps65217.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/drivers/mfd/tps65217.c b/drivers/mfd/tps65217.c index 2d04d9e0ae29..9a1528456ffc 100644 --- a/drivers/mfd/tps65217.c +++ b/drivers/mfd/tps65217.c @@ -155,8 +155,13 @@ static int tps65217_irq_init(struct tps65217 *tps, int= irq) =20 /* Mask all interrupt sources */ tps->irq_mask =3D TPS65217_INT_MASK; - tps65217_set_bits(tps, TPS65217_REG_INT, TPS65217_INT_MASK, - TPS65217_INT_MASK, TPS65217_PROTECT_NONE); + ret =3D tps65217_set_bits(tps, TPS65217_REG_INT, TPS65217_INT_MASK, + TPS65217_INT_MASK, TPS65217_PROTECT_NONE); + if (ret) { + dev_err(tps->dev, "Failed to mask interrupt sources: %d\n", + ret); + return ret; + } =20 tps->irq_domain =3D irq_domain_create_linear(dev_fwnode(tps->dev), TPS652= 17_NUM_IRQ, &tps65217_irq_domain_ops, tps); --=20 2.53.0