From nobody Mon Sep 28 06:38:16 2026 Received: from mail-pg1-f171.google.com (mail-pg1-f171.google.com [209.85.215.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C7B813839B7 for ; Tue, 25 Aug 2026 10:31:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787653901; cv=none; b=L7dLsphOu1yQ73evc9pSYYCZGZHOYqL8LATIp80y+DCvjYDgotd81Ke0UePlhk5VXCHCGB+SOFPdBfdi5WFstG+cuO1H+0Raegb0waxp4m+PD/TeoQNbEC76EsS9bE/1HZ5o3R1F11yJs1vz9LL8gffhc2v3xlh8BRNn4wcmje4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787653901; c=relaxed/simple; bh=6aKXkXmB9UM2GPNzWdjgxSN8+02ddriLlYf0VdTO3UU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=okOOomGZOQiscChSJtdcLsUIgibbDgmvF9yuuO6qD/tQU4ZOl2QKjqe3qLxAd2QZmU2Qz4VoXS1qaLZ5YC7pBGPiphVOR7zUQPUO1niJODP5OwsmUGOz0OnenT7kgYNVmz6vHW2Ts6/lpAjx8XHaEVwvuXi4eiYshWHbvsEyAXk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Rghjj6Qy; arc=none smtp.client-ip=209.85.215.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Rghjj6Qy" Received: by mail-pg1-f171.google.com with SMTP id 41be03b00d2f7-ca12086c06eso3510356a12.0 for ; Tue, 25 Aug 2026 03:31:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787653899; x=1788258699; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=7qtv1Y8lxAp+OLsB54r6tSX8f8bw4F2ktQgQBuN1kCY=; b=Rghjj6QyaH9fG/QkaYJZBA85TpEXGX/9D2aG61XJe1jsUgYFmLPsav+beCWyOoMT+D aLNBzjfMb0B2O6UOzsMlkg1NeoW4aLYe4e0XnNI1pSw/9Z7toN2k/AwdzyijFQ3959zQ Forph8Kk4sxEglmQBl9SiM/MAmrNpDCMqClMmpLgVXPcTvmTizfAMgU9TgZqmsMaKdgs /5ldL5X7j7hukLfQwcJOA54csNsLtaYwbM5xtVywQlfEp1zO9Zq5Ox/qZHWmiXc+qn1W CfErEQ3NexHyMmgL6+YPG9Rm0B/l1aZn6nzHAC65H7YjSfN3Sy/zcpKAlzBv6DA22s3V cQ/w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787653899; x=1788258699; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=7qtv1Y8lxAp+OLsB54r6tSX8f8bw4F2ktQgQBuN1kCY=; b=Ti18MBCJB+vSZhs63Wpgz197QlOx/DQrzRRHImYpSk+vBRRTVJV2p1wpRszwyLwwdK ilnvtwZIFJbM9o5Vy7vB2bNs3TUWvAeUp/la7p2aW/N31TCRLJ3cxbv30q7nNt9GG0h2 auKBbz3WasAcmwXNoB2GrigiJJJ7u+IawNL6FU34ubzVKF7rEvnKYs2bctNoKW1sRw3u 2NYFvdDIug28Bs8dNJ2EctqsB0g892Jj6usb8Tk8Lez620ALePUrjxGWN5PC5Sjy1ERq P3bNsNrjTlS7QzV5JFDWOAsWwp9dSEIIVCIN3fb30PvTDn+7DogyIx8cfpUSZBAFknLM ChWA== X-Forwarded-Encrypted: i=1; AHgh+RqhPwgrd0s9LDUGOe+1wN2V2uigL4zZ7CLayvScLmVuy7vw6fBnn9Y+n4B+bld2lnNogCVVRgq/iaJENqc=@vger.kernel.org X-Gm-Message-State: AFuF++mM79Wy+db1cpnju8wKx8OGafDtkfl7cYslFXrsgHqQv6/S/kQu TENTothI3IVGSKK0M7aoOdqlvrcQz4i7PTOtPwGWcOQQ06JL9JdbyrCf X-Gm-Gg: AR+sD13t9V7YSwsI+RrZu+Q6F08uSv6tjCZWnIdGC+7Zp6jUZHs6SDiiDFfa/Mvwd+w HKcY0rGvLh2NLDyGguJ9wvchuhVYFfbPjveaR9wYNOlgSzxJjYHqVJtkYDK1slCDKKKZsVBySob 1u+Y/shIldNsyCvXVWfCvB4mLTn7ja6vbgRtXP7GL3DD6sokSDSunCkXbOq0N9kpUXhlT+lEa/x IyCbRaE2vcg2b8/CNDQ9Bhdz8iN0yj3uurbtIPQHratLbumIFhRu9atX5SLXB34Oq2LpXLo/xK/ I7qDG2xFalcZCOkhh/Yum/dFcyJ34gyDl2nsOib2s4OiAZp9cIkBVDqCzogwv5Fqzihhkn66zFM EsrmQjrtvqSKmtVg+QVx/D1lMSEHvpkdwIDD8ep7iGe7GyLVuYPRN7Tuu8+LI2bh5+tr2/Xmr33 YvYPk69XV0RKAPyyWaZOe/AncBqenGvQL4WsvmESksa/N/6yCOR8bD5WYjf8+Ak+W4TP4vu6yk+ jFADkr03uaun8Ba4UwoGaDqhJJTY20AlnujsN79BY9prPFHz+f6vgEGpz7uTbEbjrEFb8YFwXfr 84O9Rz1+4OataObIOWBn2Ykz X-Received: by 2002:a17:90b:3b48:b0:393:1cf4:d972 with SMTP id 98e67ed59e1d1-395dee55f7emr43547390a91.3.1787653898935; Tue, 25 Aug 2026 03:31:38 -0700 (PDT) Received: from LAPTOP-UUUVNN1I.localdomain (bb119-74-6-224.singnet.com.sg. [119.74.6.224]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39645b1a54asm3343197a91.1.2026.08.25.03.31.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 03:31:38 -0700 (PDT) From: Wei Jie Law <98lawweijie@gmail.com> To: Dmitry Torokhov Cc: Andrew Duggan , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v2] Input: synaptics-rmi4 - remove the F34 sysfs group when probe fails Date: Tue, 25 Aug 2026 18:31:34 +0800 Message-ID: <20260825103134.12278-1-98lawweijie@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" rmi_driver_probe() creates the F34 firmware attribute group directly on the rmi_device's kobject: retval =3D rmi_f34_create_sysfs(rmi_dev); if (retval) goto err; but rmi_f34_remove_sysfs() is only ever called from rmi_driver_remove(), which does not run when probe fails. Every error path taken after that point -- input_register_device(), rmi_irq_init(), rmi_enable_sensor() -- therefore leaves the group in place on a device that never finished binding. The driver core clears the device's driver data when probe fails, so what is left behind is a set of world-readable attributes whose show() handlers dereference that now-NULL pointer: static ssize_t rmi_driver_bootloader_id_show(struct device *dev, ...) { struct rmi_driver_data *data =3D dev_get_drvdata(dev); struct rmi_function *fn; fn =3D data->f34_container; bootloader_id, configuration_id and update_fw_status are all mode 0444, so any local user can dereference it. Reaching the failure does not need privileges either: a device that simply stops answering a register read makes rmi_enable_sensor() fail, which is past the group creation. An emulated RMI4 touchpad over /dev/uhid that leaves the second read of the F01 interrupt-status register unanswered, on v6.12.105 with CONFIG_KASAN=3Dy: rmi4_physical rmi4-00: Failed to read irqs, code=3D-11 rmi4_physical rmi4-00: probe with driver rmi4_physical failed with error = -11 and then, from an ordinary user: $ cat /sys/bus/rmi4/devices/rmi4-00/bootloader_id Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] PREEMPT SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027] CPU: 0 UID: 1000 PID: 1851 Comm: cat Tainted: G E RIP: 0010:rmi_driver_bootloader_id_show+0x4d/0x1b0 [rmi_core] dev_attr_show+0x46/0xc0 sysfs_kf_seq_show+0x1f1/0x3c0 seq_read_iter+0x2f8/0x1150 vfs_read+0x699/0xa00 one oops per attribute. Add an err_remove_sysfs label that drops the group, and route the error paths below rmi_f34_create_sysfs() through it. rmi_f34_create_sysfs() failing on its own account goes to err_destroy_functions instead, which also repairs a second leak on that path: it used to "goto err" and skip rmi_free_function_list() entirely, leaving the function devices registered on the RMI bus with a parent whose driver data is gone. The resulting order matches rmi_driver_remove(). After this change the same device leaves no attributes behind, the reads fail with -ENOENT, and no oops is reported; a well-behaved device still probes and keeps its F34 group. Fixes: 29fd0ec2bdbe ("Input: synaptics-rmi4 - add support for F34 device re= flash") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Assisted-by: GLM:glm-5.3 Signed-off-by: Wei Jie Law <98lawweijie@gmail.com> --- Changes in v2: - No code change: the diff is identical to v1. Adds the Assisted-by tags required by Documentation/process/coding-assistants.rst. v1: https://lore.kernel.org/linux-input/20260824122751.76415-1-98lawweijie@= gmail.com/ drivers/input/rmi4/rmi_driver.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/drivers/input/rmi4/rmi_driver.c b/drivers/input/rmi4/rmi_drive= r.c index 5d49a9021c7d..144b203e636a 100644 --- a/drivers/input/rmi4/rmi_driver.c +++ b/drivers/input/rmi4/rmi_driver.c @@ -1255,7 +1255,7 @@ static int rmi_driver_probe(struct device *dev) =20 retval =3D rmi_f34_create_sysfs(rmi_dev); if (retval) - goto err; + goto err_destroy_functions; =20 if (data->input) { rmi_driver_set_input_name(rmi_dev, data->input); @@ -1264,14 +1264,14 @@ static int rmi_driver_probe(struct device *dev) if (retval) { dev_err(dev, "%s: Failed to register input device.\n", __func__); - goto err_destroy_functions; + goto err_remove_sysfs; } } } =20 retval =3D rmi_irq_init(rmi_dev); if (retval < 0) - goto err_destroy_functions; + goto err_remove_sysfs; =20 if (data->f01_container->dev.driver) { /* Driver already bound, so enable ATTN now. */ @@ -1284,6 +1284,8 @@ static int rmi_driver_probe(struct device *dev) =20 err_disable_irq: rmi_disable_irq(rmi_dev, false); +err_remove_sysfs: + rmi_f34_remove_sysfs(rmi_dev); err_destroy_functions: rmi_free_function_list(rmi_dev); err: --=20 2.43.0