From patchwork Tue May 19 00:52:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Abdurrahman Hussain X-Patchwork-Id: 2240140 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=nexthop.ai header.i=@nexthop.ai header.a=rsa-sha256 header.s=google header.b=KDQrKJOq; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c15:e001:75::12fc:5321; helo=sin.lore.kernel.org; envelope-from=linux-gpio+bounces-37095-incoming=patchwork.ozlabs.org@vger.kernel.org; receiver=patchwork.ozlabs.org) Received: from sin.lore.kernel.org (sin.lore.kernel.org [IPv6:2600:3c15:e001:75::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gKGP36lF9z1yFD for ; Tue, 19 May 2026 10:52:55 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sin.lore.kernel.org (Postfix) with ESMTP id 3874A3014A09 for ; Tue, 19 May 2026 00:52:40 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id AECD028468E; Tue, 19 May 2026 00:52:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="KDQrKJOq" X-Original-To: linux-gpio@vger.kernel.org Received: from mail-dy1-f177.google.com (mail-dy1-f177.google.com [74.125.82.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0D39326A08F for ; Tue, 19 May 2026 00:52:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.177 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151953; cv=none; b=IDFCvaE5CcBeLE5ofBgm2j2yWAa3LZxfqPc+eoI4yO0upUExLgkpyW/w9Y2Sh9FM4ECN8sZwyYxJEajpYDESOV+Yjlxi7xfy7auqMmtZTvLTJ3d72ET24srDtA0Y/I3YmUHg39bQGgomkBMmUGFEoSkR5/M5+E1o6BU8JAIVPy4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151953; c=relaxed/simple; bh=UKwTxR23bo/8190Ma3oEAswzHLxiNKOJzcKPyM3XidY=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=qWFdR61gLjLTxqbEh43MMWQSoVEgcLzP80qDUOEL/w+QzU2qDLIDhCoMBZEauMyKy1VY7r5oM7YUK4CGcHrdAw2UKu2PDJEE1zBdtuY24qBIJ2e7IcgcbvLFc4OmQeg2vz/7Wca1/rFOjM0kyFApexFfil/IGTtS2D3kJrJYo4s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=KDQrKJOq; arc=none smtp.client-ip=74.125.82.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Received: by mail-dy1-f177.google.com with SMTP id 5a478bee46e88-2f33ae12f97so10401346eec.1 for ; Mon, 18 May 2026 17:52:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1779151951; x=1779756751; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=ewneUiTeW4FFURX4JgSEmHD5g9yyYbAjzLEjC7sMhRw=; b=KDQrKJOqDWANIBBqazkc/7Tn+rqj42Ln0vZTvIf3QMUiswXR4TAbNW1YZ4rIJOIESv p3Tbw6e9tHRKbgfzvmXlMs9Vru6V1YY8vzVtSMd2AYE4PEBpeGgucIzSo43ZkMrVyQn+ C/z0/JSQTw3dWykRwUpqlhFEc4/CLEVGr+wXjj1Qg6a4bV52zonueb3Mhd5XIEOE7If4 IbkAnPyuEEn7ruNPQwcjd+jd86JipRALBX3Yxu3BWD3/siULZxHtddtKHkrP+Ss7R356 MXJj1dZHCrMh6luFHMFFhFGtBcYC1emEEOPfeC9cNMFo6/dA27qlpcgzSsmB3fcSb4w7 j0TQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779151951; x=1779756751; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=ewneUiTeW4FFURX4JgSEmHD5g9yyYbAjzLEjC7sMhRw=; b=XqUPHZj+zfBM6xM2tnNj4gsPuk2+WRdYKr7VVxmESw2TkK2jpFYZVAKTFlyvFSE138 nHluWzG7UQxP8rcNBJg5A5A9wkFWD4l/CQBkLVdVVN0GB8bwxf7oKaARBU4jCz5gEE5O /FqK2nupWQb8N6jj7miEVlH7no/wqGIuOi1pYDvKmctGVsyc7BWfJcmS4WvOrZeCUc3+ 99UhFxFWgAvD4TWkhe547/noMGUJtLISpQjMNzcIr60Zop2rVdyzPYIZfY7otYAeoW6J CrPAUqiDfNlpe728FUGRhFI2B4ULlXuWdjslurl9V5RmhhCbpKzOE9/Tb3dTvqaSMbRl b2mQ== X-Forwarded-Encrypted: i=1; AFNElJ8yjOuxQ1Kmfb2qz+y9IbGarhh3+4G0wheQgQkB/XwEDuTMcz83SwaWK3U6xTi7NlMMbGa6fvxHB/76@vger.kernel.org X-Gm-Message-State: AOJu0YyZuEg5X7HKcX4Enq0q6XgcQ668NfxtSyKx7U9V4gFhqeF17X2V gicUqyRiwm1v1Ewsc69NVlRXsUbyL2l61vcJqsNz9erXeZG1u++qkhLi6WWZ8iROV+IsdEsFqdj W6HVtSiU= X-Gm-Gg: Acq92OEJ/I4lZsb5itDjQL6LHI9gmvQJrwTqDtdB51SEzHgDgFS3F0ob3xlU43qOBB3 5WydvjvwFAZuUf1ifxR1CfLW1MktORBHtBoMam+2UrjQ0IsUMyggRkgeafPU6TJC05/qr/E0GPz 2+1PWxjcNjJrFEUrp9sr3GI3qLUFP+T/67kyFhz8te+7s7VVdJXixo8jiwQ4XW0P4fgFmWDZMyZ edI2EQ5ZggmsAZImVbe7BHugCXjTRnBT2lq4SDQy3jj7BGAgyLjSRP1tVjEv7ma7rp1JmJLquQr hQN+NtdnHwOJi9XAf98psD1nIowAKfjLmFKpU/Cfui0bw2cfwehSKtB/fJzCrxpNmddUMYuCSzG sXUIfIcHVzfiSRN/2HR0FT0xeNqa0qJiBK4nKiiUqWNjM0lkxhX2TvuRHrtvEs8vPhfAR66x0vJ EuVXT9IeJ03V7Vjhwoi4IPrpkcSQ== X-Received: by 2002:a05:7022:4183:b0:132:1e01:8737 with SMTP id a92af1059eb24-1350542e5a3mr8640606c88.26.1779151950688; Mon, 18 May 2026 17:52:30 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-134cbcb93f3sm22546633c88.3.2026.05.18.17.52.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 17:52:30 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 18 May 2026 17:52:25 -0700 Subject: [PATCH v3 1/8] hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR Precedence: bulk X-Mailing-List: linux-gpio@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-Id: <20260518-adm1266-gpio-fixes-v3-1-e425e4f88139@nexthop.ai> References: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> In-Reply-To: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> To: Guenter Roeck , Alexandru Tachici , Linus Walleij , Bartosz Golaszewski Cc: linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, linux-gpio@vger.kernel.org, Abdurrahman Hussain , Bartosz Golaszewski X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1779151949; l=1909; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=UKwTxR23bo/8190Ma3oEAswzHLxiNKOJzcKPyM3XidY=; b=xMhWNO55f7uVRzwHl8EIoXja68oza75rFM5LQtWDh61+3xx1p6acSL1AwhpH5fIuFDmlUhGJr K1cQHsXlSqTCoTjX5iLRkRb3K+kf+lgwi4Bd8npwGK39ZvPlUm6AqK9 X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= adm1266_gpio_get_multiple() iterates the PDIO portion of the caller-supplied mask using for_each_set_bit_from(gpio_nr, mask, ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) { ... } where ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233), not the number of PDIO pins. The intended upper bound is ADM1266_GPIO_NR + ADM1266_PDIO_NR = 25. gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip), so the iteration walks find_next_bit() up to 242, reading up to 217 extra bits (a handful of unsigned-long words: four on 64-bit, seven on 32-bit) of whatever lives past the end of the mask in the caller's stack. Any incidental set bit in that range then drives a set_bit(gpio_nr, bits) call that writes past the end of the caller-supplied bits array too -- both out-of-bounds. Substitute ADM1266_PDIO_NR for the constant so the scan stops at the last real PDIO bit. Fixes: d98dfad35c38 ("hwmon: (pmbus/adm1266) Add support for GPIOs") Cc: stable@vger.kernel.org Signed-off-by: Abdurrahman Hussain Reviewed-by: Bartosz Golaszewski Reviewed-by: Linus Walleij --- drivers/hwmon/pmbus/adm1266.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/hwmon/pmbus/adm1266.c b/drivers/hwmon/pmbus/adm1266.c index d90f8f80be8e..11f9a44f4361 100644 --- a/drivers/hwmon/pmbus/adm1266.c +++ b/drivers/hwmon/pmbus/adm1266.c @@ -211,7 +211,7 @@ static int adm1266_gpio_get_multiple(struct gpio_chip *chip, unsigned long *mask status = read_buf[0] + (read_buf[1] << 8); *bits = 0; - for_each_set_bit_from(gpio_nr, mask, ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) { + for_each_set_bit_from(gpio_nr, mask, ADM1266_GPIO_NR + ADM1266_PDIO_NR) { if (test_bit(gpio_nr - ADM1266_GPIO_NR, &status)) set_bit(gpio_nr, bits); } From patchwork Tue May 19 00:52:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Abdurrahman Hussain X-Patchwork-Id: 2240141 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=nexthop.ai header.i=@nexthop.ai header.a=rsa-sha256 header.s=google header.b=FQgGJ4kO; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org; envelope-from=linux-gpio+bounces-37096-incoming=patchwork.ozlabs.org@vger.kernel.org; receiver=patchwork.ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [IPv6:2600:3c04:e001:36c::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gKGPJ3flrz1yFD for ; Tue, 19 May 2026 10:53:08 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 82B33303EBBF for ; Tue, 19 May 2026 00:52:43 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 81789296BD3; Tue, 19 May 2026 00:52:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="FQgGJ4kO" X-Original-To: linux-gpio@vger.kernel.org Received: from mail-dy1-f180.google.com (mail-dy1-f180.google.com [74.125.82.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9F2242749ED for ; Tue, 19 May 2026 00:52:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151954; cv=none; b=bMf2txUJuzQ7ehj14Cirr4pv/gNzzdlZSwpcpLZtuTq0YA0UWAOeOutxYbHYgLbQTbdmKRo0BOQ8MHuWGseUnG3lM6eT9qsx5ugGlOIPPKZIclYywlrwPRUQoJJbKxmaLGRb4BfHRbwTFfvNFc7uXet2mjg7L5DoXw1C18xlTDo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151954; c=relaxed/simple; bh=7oeVwKpqCxGqOnMbjsP+k2FBysBipybyK2sSj3BSta0=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=TevTZDcnX/gfS2bB5hhzL0oASZ3KcoH6HWh7egnnHwylFKxjV6xnVlwOq8NcC6+1MqdxrUbCkC9LapdLFPmYpnNFFpusli4MFUFCCeQsX1MK3lF7zVC2d5VEfVC1Pu9S/FqTca+Rx4N4QOOXOAdKv4sRmrDwDLZu4nkP1IKMfjQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=FQgGJ4kO; arc=none smtp.client-ip=74.125.82.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Received: by mail-dy1-f180.google.com with SMTP id 5a478bee46e88-2f00a567cfaso2059639eec.0 for ; Mon, 18 May 2026 17:52:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1779151951; x=1779756751; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=PonswPhkAzDBi/+Jp4z7N6H9Ghz98afuWr/1QrXWWfU=; b=FQgGJ4kO77jKY8q6xhwk6HsxZOwX3rJWBa3v+NJx4m0MrakbxCRAamMStUDjYYHjPe n7WXoMre5w7wxYSFx0pXDvph4r7/N62U7wgc7ydrtOwyj3dKHYtqaUa9mvq+KBJfv96L QLZg7Ny+gHyYI5qIghKkp6WuQMHYwbHwY5+a5Ry+nMte2caSB5834Rb8Y3czXspxEYJM KUxBW5RIqQsn/o3X49QfE0y6Ms+SV8hGSvkzu3Su8oVcp5PEzjpRsT1JfQf3npfXLxTF fSC6SBJB1JR+PeY8J6fjxB3CPMM9YFo+ilKuWlo3BXqpnhe/YXMobz3+3Bnv+95s4zkF Qp3Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779151951; x=1779756751; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=PonswPhkAzDBi/+Jp4z7N6H9Ghz98afuWr/1QrXWWfU=; b=BKvjt6Pp0wAHFimmtUMZwe1sY1XCo+P76ZHywu7RIPBCDvU96adMcz7XkhRQR6zuo1 5IyNovSEZw2BGxsYnn0jCCfSFpd855ALGOvLJKAJXTMr6GL+3Rdj8JMFYg/6/9Ay99t+ cMT68ExZK+vMWhx7oJpKzswKYTSpOOw6hzTaEiT9yP67V1nrf1dKPh2ISdwi2FJDm089 Zmbfxa5oizrfNk3puHpV06F3NXeQtO5LzSMRPEUyhpwCyJQjCdKhUUzcKNzTnWdzvtb2 uHaim/lfHwGV2tZT+X3ZSGlB1Ulku5dfxWfk4xg7lHT+W7IZKe5MBq5k0RyoFIOPy3dj HMJg== X-Forwarded-Encrypted: i=1; AFNElJ81EHVR2cNlA8JeSXRsi99MavWWyFfVCE/fvQyDck+PJKWkRbsjXDoQax1/iNyxUrdEbVj8tWsxkBgY@vger.kernel.org X-Gm-Message-State: AOJu0Ywxz61E/QKgL/gLKn4VRcyKKgjRFEIV2Zj0CzKxsJ85BusdSlVi RYnjBqsOOj8QaOLBQFUWpFx8lJDJFRSp3XpaXSQq9c5vQu9OIVkxnvfBq3ZWFGHSVY9bvnwxnkr 0aInV5lo= X-Gm-Gg: Acq92OFjyzkjtzQkoZXAljDOQG6lfxfV+7sm34zJohD/6DFlz2lK2jyhKZhCRX0HVVJ md0HtmqRpGjW98ydINmRiNv/EFVH+xhMi6GHIN/xTkdtzt8wMUgIg73hgfoitMSEqaI0kQJBcWc SRMSp21wfeDG19y6yPdcAtWZS9NIP0RM/DzDQUsdBBb2SggMH2F3F5l8SSexhLZrSLGSelaOTO+ XZ3r1zLV23VBsrRUYLKPrEJeDll6o8XVSGRt3Nz0sxrV6DKP9J2adlBxb2NFXCunwOqGO77hIeY AoDssfACYYu4jCWx3vsM+MCvUqLdDblcnJqJqxPbhUQZG2DC2a1ZArD5lUKHarKjLLxWIEgAC6i 2OBa6FI/+0xKOFhBXNFBVYsf9YOq5E6OLLl3ZYCxtL25Nmo3byQgLI4iRK5z+naxZp4619th/3E T0QK3Aov1VJP3xN4bY2V8tuqB0AQ== X-Received: by 2002:a05:7022:238f:b0:135:60db:3412 with SMTP id a92af1059eb24-13560db354bmr3638913c88.10.1779151951380; Mon, 18 May 2026 17:52:31 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-134cbcb93f3sm22546633c88.3.2026.05.18.17.52.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 17:52:31 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 18 May 2026 17:52:26 -0700 Subject: [PATCH v3 2/8] hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple Precedence: bulk X-Mailing-List: linux-gpio@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-Id: <20260518-adm1266-gpio-fixes-v3-2-e425e4f88139@nexthop.ai> References: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> In-Reply-To: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> To: Guenter Roeck , Alexandru Tachici , Linus Walleij , Bartosz Golaszewski Cc: linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, linux-gpio@vger.kernel.org, Abdurrahman Hussain , Bartosz Golaszewski X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1779151949; l=1613; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=7oeVwKpqCxGqOnMbjsP+k2FBysBipybyK2sSj3BSta0=; b=xDW5l49mtttRT+LsIzPeEnV6ZnDcneJeKt08CuJu2RFwl+Iq9V4lOY6NCS2cJYZMS5TA1QJKL ALlOlTCDXjfAMwewAaxc+gY2de79j3fiY4570urPmwMWQqgOTr/ZOQs X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= adm1266_gpio_get_multiple() zeroes *bits before the GPIO_STATUS loop and then a second time before the PDIO_STATUS loop: *bits = 0; for_each_set_bit(gpio_nr, mask, ADM1266_GPIO_NR) { ... set_bit(gpio_nr, bits); } ret = i2c_smbus_read_block_data(data->client, ADM1266_PDIO_STATUS, ...); ... *bits = 0; for_each_set_bit_from(gpio_nr, mask, ADM1266_GPIO_NR + ADM1266_PDIO_NR) { ... set_bit(gpio_nr, bits); } The second *bits = 0 throws away every GPIO bit the first loop just populated, so callers asking for any combination of GPIO and PDIO pins always see the GPIO portion of the returned bits as zero. Drop the redundant second assignment so both halves of the result survive. Fixes: d98dfad35c38 ("hwmon: (pmbus/adm1266) Add support for GPIOs") Cc: stable@vger.kernel.org Signed-off-by: Abdurrahman Hussain Reviewed-by: Bartosz Golaszewski Reviewed-by: Linus Walleij --- drivers/hwmon/pmbus/adm1266.c | 1 - 1 file changed, 1 deletion(-) diff --git a/drivers/hwmon/pmbus/adm1266.c b/drivers/hwmon/pmbus/adm1266.c index 11f9a44f4361..4dd67c02b412 100644 --- a/drivers/hwmon/pmbus/adm1266.c +++ b/drivers/hwmon/pmbus/adm1266.c @@ -210,7 +210,6 @@ static int adm1266_gpio_get_multiple(struct gpio_chip *chip, unsigned long *mask status = read_buf[0] + (read_buf[1] << 8); - *bits = 0; for_each_set_bit_from(gpio_nr, mask, ADM1266_GPIO_NR + ADM1266_PDIO_NR) { if (test_bit(gpio_nr - ADM1266_GPIO_NR, &status)) set_bit(gpio_nr, bits); From patchwork Tue May 19 00:52:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Abdurrahman Hussain X-Patchwork-Id: 2240143 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=nexthop.ai header.i=@nexthop.ai header.a=rsa-sha256 header.s=google header.b=VWxg1iaI; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=104.64.211.4; helo=sin.lore.kernel.org; envelope-from=linux-gpio+bounces-37097-incoming=patchwork.ozlabs.org@vger.kernel.org; receiver=patchwork.ozlabs.org) Received: from sin.lore.kernel.org (sin.lore.kernel.org [104.64.211.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gKGPg6V7qz1yFD for ; Tue, 19 May 2026 10:53:27 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sin.lore.kernel.org (Postfix) with ESMTP id DAA50300B292 for ; Tue, 19 May 2026 00:52:47 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 7240D2D5432; Tue, 19 May 2026 00:52:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="VWxg1iaI" X-Original-To: linux-gpio@vger.kernel.org Received: from mail-dl1-f45.google.com (mail-dl1-f45.google.com [74.125.82.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 87B6226738B for ; Tue, 19 May 2026 00:52:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151955; cv=none; b=pBDACgz6jRwCoX/+OiFT1jY+uyKMwrexcna8esk2aqkRMyKJgjPOr3Xw5uCLqLPf6apsdUf70HTn1T30c/4AS1s7/vfas6ogUdIrZbXtSSoDex/fjGueqfKeuNX8xri75c3NKbqJLt6tu0Fjt4ojGVTaSTiw2FHxOmJ3kgPsOUI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151955; c=relaxed/simple; bh=rSPUXzgLQKI1wwnUPptEwKPDreTpZONWfB9dTDbQyy8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=GkotMsfmd6s4I5wc1lhDJrQz5bImCjR9g25sGbYNwyOKkIqTQjtHqgHkLlg5XF3GaCyQfgmzPZHHULfsO+m1FmzSOQvB6h9yMHM/CNYKsXFWqce9wsUrb+RjrFZ0sYd/X+1JmIuZgrkI9XVYfQiKnSzriP0lOGhVzBK6eHbRrL4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=VWxg1iaI; arc=none smtp.client-ip=74.125.82.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Received: by mail-dl1-f45.google.com with SMTP id a92af1059eb24-12c88e5f4aeso1342178c88.0 for ; Mon, 18 May 2026 17:52:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1779151952; x=1779756752; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=xkSDV/hGDItXdWtxgXI29OZTMaQsdY9kIYFJD3n6x/c=; b=VWxg1iaIkmllm7/M3RQVrTAAgreJ7Od1e5XdYmpfcPojzc+9pf78AIX9wNB4viH3pB i7ntaBmNGjQq3nPBLvpIay2n6NbEwwEhp0SW2/DOxhPkQBN24ZfA9Uw/aQrrZzo3XDwt kBkcmEdy8U+Hat7WkZCZzAvDIkuFAWz9HKuq1zoX3T1yd0Ffz+s4iaaWKY0X2myde96m oNLnBhpCQkBWiB+MyFUP4Pcqaqits7QW3AH1G7ZowoBL09622c1aXMkgVggot7gZqN0O 4u7LfLr2PZtwh6Y9JHaOoNHCiRs39/JlvJOTqNM78OAdgqOaR/zMPd/gEonJNEswD7TL iGkA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779151952; x=1779756752; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=xkSDV/hGDItXdWtxgXI29OZTMaQsdY9kIYFJD3n6x/c=; b=D6RuNCb+dAbGFxW++RAwSJhoMsJ7KmIuMAraEN22RR0MHYcn6rWUXfapEbiFh8KBkd txM7YgGwrOlgyoSlVVp89pLWm+PK7S8VAg+A0wkzRPOH9s+7Pue7MU4Vpy3fzJl3h+0N gWOwBKgcTOf8PDIUf5XchL+4wKG17qy81KP6wVNZktUnq/fyOX9yoG1tni6Fh0hY0sim FSTksTjFqrdzfzFy9aFpqvE4RBFxVr4AYAYXynIeeodkQgo4Xa0hyv4961p9hp1yWfBV YlkutpgLgciad0UGK4aMRD4l+X047M3DSKjW66v/2RhqypEpzinIHagQeUin0OBm9Ua8 C8fg== X-Forwarded-Encrypted: i=1; AFNElJ8hQo18LV8VAo4L/oucnu3EHotCcYMKTBhs9N/G/w6pDKPVruwAv+twFEy4YZsepO8vEToRPW4hLNcA@vger.kernel.org X-Gm-Message-State: AOJu0YzacEIylX2URHv5pUw+vHwtYsCh/+TK6+BITH3hAgcWj7y4S3hI 6IbWdm867ndt8sr81rrhX/kh1r/jKubvJNH5P/yNIxBZcY+2KKVgQadCHOXBFz7HumpsrBJr6+D +MS25oaU= X-Gm-Gg: Acq92OGVIObAyutHCga1RsLNaYanr/mK6NBke2M2a4Rv/is3vydo1ULZ1XOo6tSaSAq aRlVAmrswqGHNpTgTuExyo54gWXD6XZhBgv2uw664WihqGi3+wBw3YkLB1GOu3GewHtLHLbJBzb ROmBz1pRy30DNGK8cUoRSpRXCDnLFBdBpBxNl/lYleT2t1lNQ9RH+VjrTJ7Vj7+ApcC97W7PtVh sO18QL02IS+PoQt6oTKMdHolJZOB+5jhUVMwPmHt7YCNIlIlwx/nQ9643S8UQGP9aYmijo50N6Q i02WZpxGMu6fkSUa9H8d6OlM8F8VFPI8ivp2DDZs6meuFGx9Axvdz4LWIdsgeb5ZztAW7625K80 LQEQe0df0Id8L/HekhVR215KeacnL5zhC+3MXHtvWEvHQ7tNMGkSeRzFpC3CfmeGh+sG/rTGdJP D4R3s+RF1IlGw78lrOwQveChv5Zg== X-Received: by 2002:a05:7022:250b:b0:12c:6dd8:623b with SMTP id a92af1059eb24-134ff500f38mr6567069c88.0.1779151952355; Mon, 18 May 2026 17:52:32 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-134cbcb93f3sm22546633c88.3.2026.05.18.17.52.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 17:52:31 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 18 May 2026 17:52:27 -0700 Subject: [PATCH v3 3/8] hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors Precedence: bulk X-Mailing-List: linux-gpio@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-Id: <20260518-adm1266-gpio-fixes-v3-3-e425e4f88139@nexthop.ai> References: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> In-Reply-To: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> To: Guenter Roeck , Alexandru Tachici , Linus Walleij , Bartosz Golaszewski Cc: linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, linux-gpio@vger.kernel.org, Abdurrahman Hussain , Bartosz Golaszewski X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1779151949; l=2394; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=rSPUXzgLQKI1wwnUPptEwKPDreTpZONWfB9dTDbQyy8=; b=K+8bHGXkf6oBwMcxqjzXElyXNeXhFer71lr5CRjozh8Jex49aLDFwWIl2SefX8JKqfza6NZJ8 n502WXx0f+KDep2/9UWQR4xrP0ALQwNNexLE2viY6t1it/tkxDIBXGA X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= adm1266_gpio_get() and adm1266_gpio_get_multiple() both compose the pin-status word as pins_status = read_buf[0] + (read_buf[1] << 8); right after i2c_smbus_read_block_data(), guarding only against an error return. A well-behaved device returns 2 bytes for GPIO_STATUS/PDIO_STATUS, but the helper happily reports a 0- or 1-byte response too. If the device returns 0 bytes, both read_buf slots are uninitialized stack memory; if it returns 1 byte, read_buf[1] is. The composed value then flows through set_bit() into the caller's *bits in adm1266_gpio_get_multiple(), or into the return value of adm1266_gpio_get(), and ends up in userspace via gpiolib (sysfs and the char-dev ioctls). That leaks a few bits of kernel stack per request on any device whose firmware glitch, bus error, or hostile slave produces a short block-read response. Add the missing length check to both call sites and surface a short response as -EIO. Fixes: d98dfad35c38 ("hwmon: (pmbus/adm1266) Add support for GPIOs") Cc: stable@vger.kernel.org Signed-off-by: Abdurrahman Hussain Reviewed-by: Bartosz Golaszewski --- drivers/hwmon/pmbus/adm1266.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/hwmon/pmbus/adm1266.c b/drivers/hwmon/pmbus/adm1266.c index 4dd67c02b412..57cb7d302cdd 100644 --- a/drivers/hwmon/pmbus/adm1266.c +++ b/drivers/hwmon/pmbus/adm1266.c @@ -175,6 +175,8 @@ static int adm1266_gpio_get(struct gpio_chip *chip, unsigned int offset) ret = i2c_smbus_read_block_data(data->client, pmbus_cmd, read_buf); if (ret < 0) return ret; + if (ret < 2) + return -EIO; pins_status = read_buf[0] + (read_buf[1] << 8); if (offset < ADM1266_GPIO_NR) @@ -195,6 +197,8 @@ static int adm1266_gpio_get_multiple(struct gpio_chip *chip, unsigned long *mask ret = i2c_smbus_read_block_data(data->client, ADM1266_GPIO_STATUS, read_buf); if (ret < 0) return ret; + if (ret < 2) + return -EIO; status = read_buf[0] + (read_buf[1] << 8); @@ -207,6 +211,8 @@ static int adm1266_gpio_get_multiple(struct gpio_chip *chip, unsigned long *mask ret = i2c_smbus_read_block_data(data->client, ADM1266_PDIO_STATUS, read_buf); if (ret < 0) return ret; + if (ret < 2) + return -EIO; status = read_buf[0] + (read_buf[1] << 8); From patchwork Tue May 19 00:52:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Abdurrahman Hussain X-Patchwork-Id: 2240144 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=nexthop.ai header.i=@nexthop.ai header.a=rsa-sha256 header.s=google header.b=BHDlrNtW; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org; envelope-from=linux-gpio+bounces-37098-incoming=patchwork.ozlabs.org@vger.kernel.org; receiver=patchwork.ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [IPv6:2600:3c04:e001:36c::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gKGQX2c8nz1yFD for ; Tue, 19 May 2026 10:54:12 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 2F8EC305F55C for ; Tue, 19 May 2026 00:52:56 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id D3FE822B8AB; Tue, 19 May 2026 00:52:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="BHDlrNtW" X-Original-To: linux-gpio@vger.kernel.org Received: from mail-dl1-f54.google.com (mail-dl1-f54.google.com [74.125.82.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 80A8F26982C for ; Tue, 19 May 2026 00:52:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.54 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151956; cv=none; b=YdmwnhDTpPo8gwb9VMgE2pfXZZ+xFi43yZUvPjIgpVe5DUs7JYjtFcXULhFsfudvuKJ3L8cBmFkIo5ZxaiV2XIvh228RXsQw8nap1v6DsVe3cPv9WbKhk61yh6H+/w8h0+F184+g47Fv4SWCvDAFPtuxXGa5HdWCVyrUeKEdylM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151956; c=relaxed/simple; bh=1JG+/zkIS+GEXFeDqZ4D4F9Ctl/p/94MPO/ij8zaqjI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=ByQhJb48p+17dEqHzc2soYWOegQqSZiG835T9bBSJYG1oBoA85d9TL8oA6V8ULM8tp5pQJCo6zZnrQlYdXESemIOrdLBzmrBiqEzmFwlOGz4eFtKs/byJUBMPNGLGnx5NJDfcY7OO0HdEMI6FuzjCz/ySY8qSIsUJNL/hHjv0J4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=BHDlrNtW; arc=none smtp.client-ip=74.125.82.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Received: by mail-dl1-f54.google.com with SMTP id a92af1059eb24-135200bc7d2so8050426c88.0 for ; Mon, 18 May 2026 17:52:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1779151953; x=1779756753; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=Zlzk3IweM6/T1gjXkni5pH832MnF1gtDJTKqsEsOXm8=; b=BHDlrNtWFcjsv4sNRVfNpmf2mpHdjuAbMov+K+YfBX8DJx5FKlJ2vVGbawleEYJInO nawHYFADCL48EgoxKTIaHrx9wAgtvmv44RswJDZED7VbfshZmj3Yal2vxSSthkaOIj4l bOpMGZJgCTFvHx7HrOZm+5LrIhxsPkRhSevzIfoLzmb5g3JUBJ4Q+z5XQzf9CULKoQff 4ZH0a63aVxaIwAUJOc/79XdjD/SzSAe2OIUMldil0Gx/iSKkqs+prrEnEFKpcrqRddMv +t+ceypaYPMDMqYJwb2pNLd+WQEMbArKxjGKQBzViBtkvQ640Rpe3hQixj+JZpCDR3U5 tOsg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779151953; x=1779756753; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=Zlzk3IweM6/T1gjXkni5pH832MnF1gtDJTKqsEsOXm8=; b=Vcm79LCSgNIzB85lhUrp6FEsiqDQa/heylhCnVQe66mlszfkmhof9o+wzIp9IvjEw+ S565cgCqcgaxm0w4lEyOdq5QRMc6o67+J6F9WG1sh8yDnFBIJ/ekDOXGhk1kgy3a8f4M 6S64qCa36xoEgsOO9l0kMtpe2fRS7B77jOzi6bLI28ELTGHKAAl/LuFSNMVgkAO/0t1j XQO1R5gtCnWQ6nzljlTPr2NtTKlTkP27qBAu8VQm4glMzdgUjWEiaJ6lawpoca44uAXm c5wzPYbjvOdaOiuS8yP38lRIAKsWY4EYwxi52SUW0xwALDAhl9N6L13d9kY0Fu8S8/OM 9Ycg== X-Forwarded-Encrypted: i=1; AFNElJ8CTJsxqa/E7VooqCPTI93CdUVOKkmn4LE+9X5f7gUwBYyzm3eK+eVsfRy58gOiKiCUeobamBacd6DI@vger.kernel.org X-Gm-Message-State: AOJu0YxVZ8WBmLLgc4hloElxE+ssne3841RUdsFV2SlzPNEwbSedFxoz 2giuv0yvmyvII3ThLh3w6Sijc2FMRcP9QPeird4Ft3cqGTVKOxRMzJ9onhjSBUYNqQzDhOh9iuq 3D908FT8= X-Gm-Gg: Acq92OH6Yiq8/4Q7nYQGOqGAiCADEyCIAqX+iz0iyuV1TCqNtSl9lVdMSO7sx0GLbHb DoWK8CBDeDZYQl1Frkm1gPgvHZs1wT2WTYlPYV72qvfDdVqEVDnhXIxGLnvDkgAQdKqjKaZFwYD G9B1NbfM4rZj/uvQwpxDMl4lTyRaMRGVgu314BUYMdmZLGW9LTTNh5NML4WSWu+L92kSle4Hf17 nUldIIXlpBuMPfs8bjYDsj8NyB5nTodROTrAeKr3ZnAIGIMRexmVgk2QEecCWabJR+NRntY5+x7 4YUORu86ZDRxmi7dg8QH8cgdkuMVBWfzAiT2MJ8vC02QljD+Ymgq1eGOTNCVs50eIJ8N2V9CA/E 6uX0Y91bJFG45p/4IeC/uXP5D2wgH5htgGinYp8qhTXljMIECtsXoNKTUJD/VQy7vaT++p/zQfo gDyd2LYUh5vzTetaPJzmmUVBxe/Q== X-Received: by 2002:a05:7022:7a2:b0:12d:c9b6:bbdc with SMTP id a92af1059eb24-1350494e473mr8550867c88.30.1779151953289; Mon, 18 May 2026 17:52:33 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-134cbcb93f3sm22546633c88.3.2026.05.18.17.52.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 17:52:32 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 18 May 2026 17:52:28 -0700 Subject: [PATCH v3 4/8] hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() Precedence: bulk X-Mailing-List: linux-gpio@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-Id: <20260518-adm1266-gpio-fixes-v3-4-e425e4f88139@nexthop.ai> References: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> In-Reply-To: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> To: Guenter Roeck , Alexandru Tachici , Linus Walleij , Bartosz Golaszewski Cc: linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, linux-gpio@vger.kernel.org, Abdurrahman Hussain , Bartosz Golaszewski X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1779151949; l=1812; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=1JG+/zkIS+GEXFeDqZ4D4F9Ctl/p/94MPO/ij8zaqjI=; b=eDz6CtV+xk55DonqDrs1pNdpplss0Fqb6RErODkJAylZJrzDENIty2KbtoJC91N9SDjbi5UCS sbEujihg8YUC0+CRw+cQAghEQIkGIUQUkYd3V4fLbB9hMDwRxFEPzB2 X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= adm1266_probe() calls adm1266_config_gpio() -- which goes on to devm_gpiochip_add_data() and exposes the gpio_chip callbacks to gpiolib -- before pmbus_do_probe() has initialised the per-client PMBus state (notably the pmbus_lock mutex the core hands out via pmbus_get_data()). That ordering is already a latent hazard: any GPIO access that lands between adm1266_config_gpio() and the end of pmbus_do_probe() (for example a sysfs read from a user space agent that opens the gpiochip the instant gpiolib advertises it) races pmbus_do_probe()'s own device accesses with no serialisation. Move adm1266_config_gpio() down past pmbus_do_probe() so the chip isn't reachable from userspace until the PMBus state it depends on is fully initialised. Fixes: d98dfad35c38 ("hwmon: (pmbus/adm1266) Add support for GPIOs") Cc: stable@vger.kernel.org Signed-off-by: Abdurrahman Hussain Reviewed-by: Bartosz Golaszewski --- drivers/hwmon/pmbus/adm1266.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/drivers/hwmon/pmbus/adm1266.c b/drivers/hwmon/pmbus/adm1266.c index 57cb7d302cdd..b91dcf067fa6 100644 --- a/drivers/hwmon/pmbus/adm1266.c +++ b/drivers/hwmon/pmbus/adm1266.c @@ -467,10 +467,6 @@ static int adm1266_probe(struct i2c_client *client) crc8_populate_msb(pmbus_crc_table, 0x7); mutex_init(&data->buf_mutex); - ret = adm1266_config_gpio(data); - if (ret < 0) - return ret; - ret = adm1266_set_rtc(data); if (ret < 0) return ret; @@ -483,6 +479,10 @@ static int adm1266_probe(struct i2c_client *client) if (ret) return ret; + ret = adm1266_config_gpio(data); + if (ret < 0) + return ret; + adm1266_init_debugfs(data); return 0; From patchwork Tue May 19 00:52:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Abdurrahman Hussain X-Patchwork-Id: 2240145 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=nexthop.ai header.i=@nexthop.ai header.a=rsa-sha256 header.s=google header.b=QoX5yKYw; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-gpio+bounces-37099-incoming=patchwork.ozlabs.org@vger.kernel.org; receiver=patchwork.ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gKGQk5PRWz1yFD for ; Tue, 19 May 2026 10:54:22 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 7C0D530623F1 for ; Tue, 19 May 2026 00:52:58 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id F109F2F5A13; Tue, 19 May 2026 00:52:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="QoX5yKYw" X-Original-To: linux-gpio@vger.kernel.org Received: from mail-dl1-f53.google.com (mail-dl1-f53.google.com [74.125.82.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 71F022D47FF for ; Tue, 19 May 2026 00:52:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151957; cv=none; b=k7j9y+xfpP7JUeCOiB0U1eOn9qbb6V/9HSwCFAkY/H6qthUBiVyLAwDC1L45YHyMIVHDlJLvb7IlR4S6HM/hB0mKqTjcuDfURWswrP8j92YgiCq0TTyj8mfPUWB3PuzhmE3ps+EIi4ncSBD/DGirR4HLgjYLdIeIjDZdmQ3Un4A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151957; c=relaxed/simple; bh=iQxdf1yuFfxkq4dVmlhtA1OD3Mg8u9x0iWEOejR0KI0=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=J4vX0UuFTpEcXwPZWqhHWixgLxZNaeToLTbL1F+JfFi0St+2NOmgk2el8+m6WjwHx5rzEPLjO7iM0OrU7fiTGLWeWpuNsZD1bllfJeblEkUHJXn0nA9JqDYf3XTh4NpQDBXILiUn63ynvo8wyHKn4puKjCAkxidcv6VN2lE4sCU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=QoX5yKYw; arc=none smtp.client-ip=74.125.82.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Received: by mail-dl1-f53.google.com with SMTP id a92af1059eb24-130c9dcbd25so2527870c88.1 for ; Mon, 18 May 2026 17:52:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1779151954; x=1779756754; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=y2P8AA+VKiT9we9opdJjInDAt+Givsn990e3P/EhFhw=; b=QoX5yKYw9dzTwxSdddXoeYY5y/bVNsZ0pGp6Lo0U6U0HNxtv+Qdz5AIftI6ji4eR1r 3M7kt4AcLBD/Q7RlXTR1Wvn4lBXM/U918fFrifzLlPjFusPZLHdo5uUDkUcbZdT2Ub2U 0LkuIlk/x2/RTsNPNYeTNuO/GxHMnY4lZHxE6DF0Y+LrkfVi/Gd+Q/pRVLzkL2Af4/6y aXkxL2h048IsfN65fCv7/k9q6VZB5CC4y8dg2UDnHjoqGGF7oHom+12jPkIVHbEVtSjr e7GWYORoFUflbUjAG0Iboi71j/cQWC7mK63roxpqYv/NxVKatksru6I1lkLlGIOj1ZOM h0LA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779151954; x=1779756754; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=y2P8AA+VKiT9we9opdJjInDAt+Givsn990e3P/EhFhw=; b=DoANllDhLIy4DMhkp5xjJOFMzZyqnGxnQS4uI2D6eC3rRyV42V4XxvaGUDdzaOaqKs RbDOR9lPBHefhBvlAQEvhosUyGkTrRt/Bed7kxa/VoaZEjFlv01ZULsLHhCfMPiB4PQe gDt5Fwrv/abqY9iAY3p5RAjqGaATp127vhnC9JHdsnsukQ+vCEMZhixiK61uxOdF+Ayz JaC6Q1wNIDckPlP9XamsosT40uAt3cL8VQw37aKDKo2dEH4nh4vAoDm2KNGCOtN0eJrO NpKTwJxu6fYJFvNa3RKRiMb8sFpWdr8fQ8vzcONnqd4M/KGuTOypiArRw/YTOEhrl8mT 39tA== X-Forwarded-Encrypted: i=1; AFNElJ/3IU/ZrVJ+FLJ11kg9dHmIuRR2JYdJtrJM6gdiI7tJ9umHJe9UyVwrpWltmK29zYspCvWMatkaNZqz@vger.kernel.org X-Gm-Message-State: AOJu0Yx7RjgWbhH3akVLxwcXLVOqhzcXwsSub8gXIOsu0xEzPz3vL+cQ PdX+WmllSt1DUZmuQxx8RrrgXEe6JThIbmQ4DXtKsX09EfJye5yPYgX2LK8zx2K7Ttd2ENxhMXU 9VepUbAo= X-Gm-Gg: Acq92OFV1rEdpwaXoMtylFP49UF6JWgdun5vK3rmbdHaXJ1Ks47OlWp/HyYhax5L0ij 3zoonneB0sKCJlsUwn+Z4Jti1oScZ3rrmowAQG14u49vYjWTrv2aU6k9SD3hK4eIDDi/27jeE2j rb8NgHBkCAorXn9FdJLGF23x4LKSvO3BNhRoZLg4MjnMwmsBLaHXGawHxneIOUc7oi3tnXo6kIU 6xcHQMHzAAjc5780oCknn73B7xuQ7yXVq1Gfb6DgwiwwQ8tjHZZZO01sF76PpDw01x9QuWj+Qy9 DTFBvgvkRUTFTE0BnHOm1V7jsqp8MG3lcQEdiRtQGVL3R8j8RwNXypEHqoNVImZctMmtctKiCL1 ZGG3WSgAqy5KJTJM3D53GyVRgkKJlkpmsbz/oR1gKpCM7HrryOyoHp/37bE8+PRBLAjvscwi8OX twfhd4cbS8aNYg4ZbhuKNGlrAl6w== X-Received: by 2002:a05:7022:45a2:b0:12d:c3d8:1f95 with SMTP id a92af1059eb24-134c880b6bemr8010416c88.4.1779151954194; Mon, 18 May 2026 17:52:34 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-134cbcb93f3sm22546633c88.3.2026.05.18.17.52.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 17:52:33 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 18 May 2026 17:52:29 -0700 Subject: [PATCH v3 5/8] hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() Precedence: bulk X-Mailing-List: linux-gpio@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-Id: <20260518-adm1266-gpio-fixes-v3-5-e425e4f88139@nexthop.ai> References: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> In-Reply-To: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> To: Guenter Roeck , Alexandru Tachici , Linus Walleij , Bartosz Golaszewski Cc: linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, linux-gpio@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1779151949; l=1611; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=iQxdf1yuFfxkq4dVmlhtA1OD3Mg8u9x0iWEOejR0KI0=; b=TcrBIRWgrteBYTVwtpzSU+2Wm3eg5LmBx6FfTh0fYto/+XZGoCtTnc6S6Pu63qnTE8+oW3o5t lXy2qBOOeXWAvofdMd9M+EiP8hmV2QzMP4JS+jPrPk+hvk+oDWwCO9U X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= adm1266_probe() calls adm1266_config_nvmem() -- which goes on to devm_nvmem_register() and exposes adm1266_nvmem_read() to userspace -- before pmbus_do_probe() has initialised the per-client PMBus state. Same latent hazard as the gpio_chip one fixed in the previous patch: once the nvmem device is registered, gpiolib's nvmem char-dev / sysfs interface is reachable, and any concurrent read triggers adm1266_nvmem_read() -> adm1266_nvmem_read_blackbox(), which issues PMBus traffic that races pmbus_do_probe()'s own device accesses with no serialisation. Move adm1266_config_nvmem() down past pmbus_do_probe() so the nvmem device isn't reachable from userspace until the PMBus state the nvmem accessors depend on is fully initialised. Fixes: 15609d189302 ("hwmon: (pmbus/adm1266) read blackbox") Cc: stable@vger.kernel.org Signed-off-by: Abdurrahman Hussain --- drivers/hwmon/pmbus/adm1266.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/drivers/hwmon/pmbus/adm1266.c b/drivers/hwmon/pmbus/adm1266.c index b91dcf067fa6..8b9fbb99a4bd 100644 --- a/drivers/hwmon/pmbus/adm1266.c +++ b/drivers/hwmon/pmbus/adm1266.c @@ -471,14 +471,14 @@ static int adm1266_probe(struct i2c_client *client) if (ret < 0) return ret; - ret = adm1266_config_nvmem(data); - if (ret < 0) - return ret; - ret = pmbus_do_probe(client, &data->info); if (ret) return ret; + ret = adm1266_config_nvmem(data); + if (ret < 0) + return ret; + ret = adm1266_config_gpio(data); if (ret < 0) return ret; From patchwork Tue May 19 00:52:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Abdurrahman Hussain X-Patchwork-Id: 2240142 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=nexthop.ai header.i=@nexthop.ai header.a=rsa-sha256 header.s=google header.b=kWvDZK8o; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.232.135.74; helo=sto.lore.kernel.org; envelope-from=linux-gpio+bounces-37100-incoming=patchwork.ozlabs.org@vger.kernel.org; receiver=patchwork.ozlabs.org) Received: from sto.lore.kernel.org (sto.lore.kernel.org [172.232.135.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gKGPX04ktz1yFD for ; Tue, 19 May 2026 10:53:20 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sto.lore.kernel.org (Postfix) with ESMTP id D4A4D3022BBB for ; Tue, 19 May 2026 00:53:03 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 5F179282F09; Tue, 19 May 2026 00:52:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="kWvDZK8o" X-Original-To: linux-gpio@vger.kernel.org Received: from mail-dl1-f45.google.com (mail-dl1-f45.google.com [74.125.82.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D9062EAD1C for ; Tue, 19 May 2026 00:52:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151959; cv=none; b=M1AMruALdgmhxn0eVyRr+RbnZxFiG2lKvUHEzp1ibFQsFyvznl8wcJ/decOd4iJAtLwfty969nbKEEdRkJcJb5gv48VaSY4MvLH6f6HdCrd6kOUewikEZ15h4OMS72YC/mK7upAx61hoKWquILp6WCSJF+nDC6G9HsJ4g0EELG8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151959; c=relaxed/simple; bh=kGAUxCtbDfmt+7K9n1CVIf/I9Exjw2mL1Khe/Uk924I=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=U9sYTKntBIGny+ctrlw8mH1I36wI52t2DHoqgGTNz6Y7B/+TgsqQztS1vZI/nW0zW8kbnFBY1oYY72hGvHqs3Vo3mn1ZNTJ1lmHUqvWo0IuF3Zqfxstisd7rRFtT7XJHu+QpyLV46CcBAFBmHmXrmMd37m/nyVzLZryz9ssKocw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=kWvDZK8o; arc=none smtp.client-ip=74.125.82.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Received: by mail-dl1-f45.google.com with SMTP id a92af1059eb24-1331e851faaso1492680c88.1 for ; Mon, 18 May 2026 17:52:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1779151955; x=1779756755; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=sYDly6dzMfBVk+bP7Sp71lgzYnskpjHG63z/xSSPQ2M=; b=kWvDZK8o10adgbx/UbTu/EBWNCyeZi/m4r/9Tomh0M1hP7u7esNQrv3MRtNUbmTXSP s1kv1LnfvzXxf8VbHAeFgVosX9gofJeUrYYHA4/66AThgeX7WKfaQt1AAq7Ydrq5fcQc +pPwJJsEZaL2VNHJthiFNuVN+zYm9tJ/QyJA4501qLOXvnGvqEKvchs9BuOrxVA51aaL mxqXW5K/NcQ+Pp46OzFQv8IYRN2OEbWdTKzF72odMrRZy8/9NrrHPdFPuBpNDwxbp0Cv ISF0Ag6Ocr5+eAJpq3ebQ0BMTLr1Lt7FgsWDwzAz+QNHL8R3Ghm83A41ry8m7nJT3pzB BX6g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779151955; x=1779756755; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=sYDly6dzMfBVk+bP7Sp71lgzYnskpjHG63z/xSSPQ2M=; b=CY9GE3VOGAz6Ib1Znq4V/W0oaaPFd8ZjfEQUyBzVrrBAkofxeuc9QVUXXLQT2jbkw2 b6whcoqXoRo5/4iIvrg8HzZBZxSuSOv8bUkmvbkdA39KKhj5SRWdB01jNlrxgOlVMQy3 QWtPod1sIIqaJ/N2dEVgLky7eDsy5AM3+boAHlH9g55+Io7W2BPobuoBrxCs+lJFSEU5 gHBwsduKbzHgI7saXeqkZrZswI6ClCHOyto8N9ljMaMrET5hN7cbTh/OXD9j3DSLGyOK nHgnZB4o86E/6WGqEBsbS0xjoXPg1tmbUpn65y67z+qKsUVOHChhKa0vBSSN9IG0097M yz+g== X-Forwarded-Encrypted: i=1; AFNElJ+vaFprJOoE/UbdL1S5JY7eTDQd4Wrz+mRBPP++2m3AWGqURt/9TjpxzQ5VUUQ9YIEBj1XY9jPQzkJK@vger.kernel.org X-Gm-Message-State: AOJu0Ywhd3tok7hbz7o/1lVjujebDzVDiSNodGl953YIHPeK/6qXCccI XKQFU8Bhg1X1UzO7mcE/YojKQzdFj6jNxIim7JAylw0tBqMHvjRqSFstUJbXyEdjYoBr4osRCq8 +vYKt5gc= X-Gm-Gg: Acq92OF0tjREug0rilzMXWCSnMOT2Zrb2pyXYKhrYEraoS9dUP6R/WG74yhvneNO231 XDbOFg9bzKdEAobleCvz1Vy5JjiRUNbHqaCooaZU3xGA7gh2aFvhdnvWRtO4MPUoIEYYmn7Hliz r3k0/QjcR742AElwQ1COWmJLRBNj9jBDj7+Sw/Ew5lI9sY+1MIcGeqXRlu97aD5vDciLnzyoaLn AxCn13rTVLW1z0pMSTCF9VoyxB5TO2YBZXpbjWGH4JVeQSEhUhdjpP+gS4l2ZBDSeMQemA2aaHT d74aKda+ZRAb0wQRRLixyBO44JmU2JcUXxOhiARMmX7zvCvsfy1X2lQoBbjz/+N70z6y763yKgF eTi7XetBAgvzTKrvVMxf3P4K4VYI2DfJJZoOuMJu0zkKvoK2Cks5qyCGMgnkTDx+kFjfI6/arBB 4Kd2fY+ufMZgjxnbf0iVv3umTDsg== X-Received: by 2002:a05:7022:f508:b0:135:40b2:ede2 with SMTP id a92af1059eb24-13540b2ef7fmr2486006c88.3.1779151955117; Mon, 18 May 2026 17:52:35 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-134cbcb93f3sm22546633c88.3.2026.05.18.17.52.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 17:52:34 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 18 May 2026 17:52:30 -0700 Subject: [PATCH v3 6/8] hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock Precedence: bulk X-Mailing-List: linux-gpio@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-Id: <20260518-adm1266-gpio-fixes-v3-6-e425e4f88139@nexthop.ai> References: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> In-Reply-To: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> To: Guenter Roeck , Alexandru Tachici , Linus Walleij , Bartosz Golaszewski Cc: linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, linux-gpio@vger.kernel.org, Abdurrahman Hussain , Bartosz Golaszewski X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1779151949; l=2124; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=kGAUxCtbDfmt+7K9n1CVIf/I9Exjw2mL1Khe/Uk924I=; b=9vVVO+CcgVRiqRirJmI1dL8zn8m7wPIIrw7ytI1DhMCMynB3bEERLXVdkm14ZxySs9eWEYO0i r5IYC90CXlxDB9B4gVoLnDeylPugQhUkW+RZ3r6FrpP0bsHQg+c1XSR X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= adm1266_gpio_get(), adm1266_gpio_get_multiple(), and adm1266_gpio_dbg_show() all issue PMBus reads against the device but none of them take pmbus_lock. The pmbus_core framework holds pmbus_lock around its own multi-transaction sequences (notably the "set PAGE, then read paged register" pattern used by hwmon attributes), so an unlocked GPIO accessor can land between a PAGE write and the subsequent paged read in another thread and corrupt either side's view of the device state machine. Take pmbus_lock at the top of each of the three accessors via the scope-based guard(). The lock is uncontended in the common case and adds only a single mutex round-trip per call. Fixes: d98dfad35c38 ("hwmon: (pmbus/adm1266) Add support for GPIOs") Cc: stable@vger.kernel.org Signed-off-by: Abdurrahman Hussain Reviewed-by: Bartosz Golaszewski --- drivers/hwmon/pmbus/adm1266.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/hwmon/pmbus/adm1266.c b/drivers/hwmon/pmbus/adm1266.c index 8b9fbb99a4bd..a80fb2ea73bd 100644 --- a/drivers/hwmon/pmbus/adm1266.c +++ b/drivers/hwmon/pmbus/adm1266.c @@ -172,6 +172,8 @@ static int adm1266_gpio_get(struct gpio_chip *chip, unsigned int offset) else pmbus_cmd = ADM1266_PDIO_STATUS; + guard(pmbus_lock)(data->client); + ret = i2c_smbus_read_block_data(data->client, pmbus_cmd, read_buf); if (ret < 0) return ret; @@ -194,6 +196,8 @@ static int adm1266_gpio_get_multiple(struct gpio_chip *chip, unsigned long *mask unsigned int gpio_nr; int ret; + guard(pmbus_lock)(data->client); + ret = i2c_smbus_read_block_data(data->client, ADM1266_GPIO_STATUS, read_buf); if (ret < 0) return ret; @@ -235,6 +239,8 @@ static void adm1266_gpio_dbg_show(struct seq_file *s, struct gpio_chip *chip) int ret; int i; + guard(pmbus_lock)(data->client); + for (i = 0; i < ADM1266_GPIO_NR; i++) { write_cmd = adm1266_gpio_mapping[i][1]; ret = adm1266_pmbus_block_xfer(data, ADM1266_GPIO_CONFIG, 1, &write_cmd, read_buf); From patchwork Tue May 19 00:52:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Abdurrahman Hussain X-Patchwork-Id: 2240146 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=nexthop.ai header.i=@nexthop.ai header.a=rsa-sha256 header.s=google header.b=FokCYGVf; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-gpio+bounces-37101-incoming=patchwork.ozlabs.org@vger.kernel.org; receiver=patchwork.ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gKGRd2q6Rz1y5N for ; Tue, 19 May 2026 10:55:09 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 345883071845 for ; Tue, 19 May 2026 00:53:09 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 1EC38282F25; Tue, 19 May 2026 00:52:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="FokCYGVf" X-Original-To: linux-gpio@vger.kernel.org Received: from mail-dl1-f53.google.com (mail-dl1-f53.google.com [74.125.82.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8092F2F5498 for ; Tue, 19 May 2026 00:52:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151959; cv=none; b=D1IIutdD6Z0QtYzks+a21AZx7emyZ2Dtsqxz24Tpke/n2/Ya9qTaOa5Z2fFq4OQqovNIuHMmNxmksEr8zkkrOFIClJNppt0aSP6+I3Yf/C23NZW2D+6yeF2ISQRgGDA1TtYaA1zyrl1ek1934PHkfw6c+a6h49XlojEIg2yjuAE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151959; c=relaxed/simple; bh=FDObNUWMvwjjzrN2IkV6Cgo3wEKZLI2a8RqN+knZ8DY=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=JXcAqp5iyMSgCV4VV3/HSMQI0pf+IEgY6JW9M4o+oROtC2I8kE/sPUOVTXHQgia6IhyP5MYmOvvPOH0fqB7o7hZLBZBvqyq7qqMdKldD0zqjHOqz6YxCcllrG/OkbC/x2QlkyNl1GCUbR43KXVPsKLUUQKorvSlnPCcNbBdq5WI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=FokCYGVf; arc=none smtp.client-ip=74.125.82.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Received: by mail-dl1-f53.google.com with SMTP id a92af1059eb24-12c1a170a50so3668520c88.0 for ; Mon, 18 May 2026 17:52:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1779151956; x=1779756756; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=k/5ooRxhmqvebnRUuOuBr2iP+EihWYORWSHfWOHXOBo=; b=FokCYGVfbUh3NyYoQHX98CPim+tFdcPD3ttErufWDJtZIqPQbdnPeRsCt/cv+gInSR BAdSdvFMUROPobIGUgaWJUaodkTLlj0Lizu3cM0FW1Pq8CzEj6O8W7liMNbEpVBbXxeG v6vRGyj+YiNdB/sJYyCCbA/9da4qzUi5uTnFINwKDTPQA8qUOk8oqfbYwyk7cIF1eW0s u+Sgofk85lc1fhVYTPG9ZKi4wwkehkoyx1YCKxf+ZvcodoAO3O2wzaKPMSfgxK2UhEj3 b+ny1xDjhaEVM0qBav3u1kA3jdlJFQlgpvwYTL3YWOTIeMHW1k+PJFbjvMmTTn91b+eS ev3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779151956; x=1779756756; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=k/5ooRxhmqvebnRUuOuBr2iP+EihWYORWSHfWOHXOBo=; b=mBLaxT/mCevB5kwiEd1wtfHyJcSoVV35EgbAqhaLUOXilHjnorPX7h3mCb/jvrFucw ME3TQtUkRun53Dr9F+FqCN6NDZYjnQDTjG01vMcWXinO2NAmZz9+TJwnODk4YhcH2HeC 9ApZBoPM2aczlMlZHkqqAkTxUbCaTY8iORGn0MEyykleKvBPUPzmzs5wJVFgHsftFbbS Fff7z7MQLeMciq9uEaeETrRDnpiFsdC1ccumpy9Yrkd9lEOlu8aEu8giQza1dByxd+Uy l2W0ZokoltdMtCc/YKQlGmlkkROW3RingncQKfIfagc7GRkwDv6Imt6heZpjYzba1Moc 7fbg== X-Forwarded-Encrypted: i=1; AFNElJ9Gp25UqIsFcLs/i4zZHtKRazn5kjTKFHImucbMmFI+DzbDIibeIK/cB1/JSeZm9ArZ3EmX9I//DXla@vger.kernel.org X-Gm-Message-State: AOJu0YwEqNHCqkul9l+6v+KMYsizRJueRrGt+DU30Y4fh7AsmjchOgid ilAucAnz04BE9MjU3PQYojk+488Gz5OVpG0N0TSvx65kS9BxHXk1vCORBwt4BLZyxGy/MNCFDNg 6FPShxpg= X-Gm-Gg: Acq92OEcaT6icNl+bJI0pvakNJCGCGWo9cn0J9O2920I4h+TY33iESkJ7dKlbpmap2I Ma8TQsNwVPMBlFed+cNdEoPTAac4r8kL/c2QlABiWjMAd7t1jDwXdNXYWrIi2w6Ql2JMU1nS9l7 6zLoiPSBSuKyAzCe4zAXnyFa8YZ4nGseCdsGdwU/Ur7Ubnkfy0PARMOfovIPJUUG5IEobkjuo08 2SYzreG7OG9+fTE5WfT3KPAHXTl9p4beemQj8W79onfxM9VaPNM7D+Y/KA+6sxBZ7QmTL9szDrX 4knyv0g4VYrUl0WGKI4huPwV87w6s4quwj1fokBcqZxnc0gupNEYFxSh3XTtvasHm5qKleuPnq9 wKIjYcvbNoJwBZo10BSCmoCkpz2n30/wQoHnEb4n7yJ8tl14i2/1IHpXkuCDvoDHm4lithZsr/4 SrnTjmlwWJXp/EoYoqod2QcYGNCg== X-Received: by 2002:a05:7022:f88:b0:12c:2dd7:9099 with SMTP id a92af1059eb24-13504945cc6mr6484019c88.30.1779151956046; Mon, 18 May 2026 17:52:36 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-134cbcb93f3sm22546633c88.3.2026.05.18.17.52.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 17:52:35 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 18 May 2026 17:52:31 -0700 Subject: [PATCH v3 7/8] hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock Precedence: bulk X-Mailing-List: linux-gpio@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-Id: <20260518-adm1266-gpio-fixes-v3-7-e425e4f88139@nexthop.ai> References: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> In-Reply-To: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> To: Guenter Roeck , Alexandru Tachici , Linus Walleij , Bartosz Golaszewski Cc: linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, linux-gpio@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1779151949; l=2029; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=FDObNUWMvwjjzrN2IkV6Cgo3wEKZLI2a8RqN+knZ8DY=; b=o4T0vpm7vwd7nU4PKFq3LRjfSe8OC/WKKKQElG1ohtEyZMkibITfRtuoo4iMw2HUrWZ5T/jQj fdKq75w5UTrA8wEIqtvyvFpSdRLwy/IkjcE+xsu56FiOHl5FTYfOXj8 X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= adm1266_nvmem_read() is the reg_read callback the NVMEM core invokes when userspace reads /sys/bus/nvmem/devices/.../nvmem on this chip. On the first byte of every read it does a memset of data->dev_mem, walks the device blackbox through adm1266_nvmem_read_blackbox() (which issues a chain of PMBus block transactions), and then memcpys the refreshed buffer out to userspace. None of that runs under pmbus_lock today. Two consequences: - The PMBus traffic the refresh issues is not serialised against pmbus_core's own multi-step PAGE+register sequences. A paged hwmon attribute read from another thread can land between a PAGE write and the paged read in either direction and corrupt one side's view of the device state machine. - The NVMEM core does not serialise concurrent reg_read calls, so two userspace readers racing at offset 0 can interleave the memset of data->dev_mem with another reader's adm1266_nvmem_read_blackbox() refill or memcpy out, returning torn data to userspace. Take pmbus_lock at the top of adm1266_nvmem_read() via the scope-based guard(). Patch 5 of this series moves adm1266_config_nvmem() past pmbus_do_probe() so the lock is guaranteed to be live before the callback is reachable from userspace. Fixes: 15609d189302 ("hwmon: (pmbus/adm1266) read blackbox") Cc: stable@vger.kernel.org Signed-off-by: Abdurrahman Hussain --- drivers/hwmon/pmbus/adm1266.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/hwmon/pmbus/adm1266.c b/drivers/hwmon/pmbus/adm1266.c index a80fb2ea73bd..051f4f188ec5 100644 --- a/drivers/hwmon/pmbus/adm1266.c +++ b/drivers/hwmon/pmbus/adm1266.c @@ -394,6 +394,8 @@ static int adm1266_nvmem_read(void *priv, unsigned int offset, void *val, size_t if (offset + bytes > data->nvmem_config.size) return -EINVAL; + guard(pmbus_lock)(data->client); + if (offset == 0) { memset(data->dev_mem, 0, data->nvmem_config.size); From patchwork Tue May 19 00:52:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Abdurrahman Hussain X-Patchwork-Id: 2240147 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=nexthop.ai header.i=@nexthop.ai header.a=rsa-sha256 header.s=google header.b=HLBhpNFK; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org; envelope-from=linux-gpio+bounces-37102-incoming=patchwork.ozlabs.org@vger.kernel.org; receiver=patchwork.ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [IPv6:2600:3c04:e001:36c::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gKGS66zD1z1y5N for ; Tue, 19 May 2026 10:55:34 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id BA965307829C for ; Tue, 19 May 2026 00:53:14 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id B8DA73090E8; Tue, 19 May 2026 00:52:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="HLBhpNFK" X-Original-To: linux-gpio@vger.kernel.org Received: from mail-dy1-f169.google.com (mail-dy1-f169.google.com [74.125.82.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A6F052D7D3A for ; Tue, 19 May 2026 00:52:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151960; cv=none; b=tNXNUNV5fDQMr6ypfjj/iex80WMkuqu4noyTdToMKLJioPiXjYSn9NG6OLThb6D2z2QDvf6FgqNcveiaplpbNCzzRwbrXrwxMQKtQBt9l/orn2WWMM5QLbqSIp1vLyqz01mZsC+ZZeEAMdn2NfYR9d72yRCKWGARS7sBEygiALE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779151960; c=relaxed/simple; bh=MbcEhPfilDl5djs8OwiISgXUAGJH031p6hDtDP0Q1lw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=LtT7RGUcrsb1yisU0erxBc9B7WHniz8AeUaEhEOEabSWsctbS+TAXZfwGN7vAd0UoRKg0vufEa4lvVQi8RHVPuds9YlL5d9EASNy4AqlAZCVQNuU2H9wE/SPHKvsc8M30bv///6Bx1e3ZswTXoM/KUjnXf0CjDNKBaZktxEqniQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=HLBhpNFK; arc=none smtp.client-ip=74.125.82.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Received: by mail-dy1-f169.google.com with SMTP id 5a478bee46e88-2ef2a1cc06dso1997125eec.0 for ; Mon, 18 May 2026 17:52:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1779151957; x=1779756757; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=jWewpsuFbzTqoRaVPbiB62v6E+GOY+1kwxAn2d+qoXs=; b=HLBhpNFKhHmcW89rtStr/gT2BTY9pEKaCzvShRGGfeaTMbrtbKv83n4BKV+OIJcfV+ nDheqI9UjvqzcntyDsPWPkMNj2k8BEVVV9MPP1+cXrXUfjnmJPTjsL08fH/uzmLu5fxJ mAJxqRHqbABchNgCc32T/1/v8XgNzpL8U9fVVWwJWl7wye6fVgVdvCJBuGvPR/2Wu7/V GhHSr1SRrn4geRzsniihVyEOItBFmMG/V7ZgX3vDbgrlocMvnpSnt6v/hKhU6idYDfCI Qxb+NpSGkKhZnkmfRrlnQ/8OoFlI2jpCe3z7VuGLV2PKqWWmHfdOPWmQrfr27SmJK9PD 2KTw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779151957; x=1779756757; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=jWewpsuFbzTqoRaVPbiB62v6E+GOY+1kwxAn2d+qoXs=; b=WgwXIP8gbb5ef67SPO3GgDerkUCwjOU6BqDrOtRHQkr8nNw8CmxN4tHdg9IDgY8cBK /P52FTePbA5LV4CH34yLuCepH6ZT0KvAXktNzzLUmqsQEc3R3XCJxKnJ6mrXjsC3g0Rw YEmRvsaCsbIteIx2vntpfHlh+vhmL+KK+B//SUh8OWq/UaNatTYb2Rd9HkuxgGOEFSm4 /QJOBZp8vxA5LAm8BKdwoNODCpYuJc6z6XdRFZT4MEShkG4LW93+ZtwKEk8lW9KOhA3Z QvD8SB02anUyJ0vu8mPtmq2kIBXcupgL+sEjyTtJF/NSEoCVQ6jn/Mrt/Ob/lIFDy3o0 5LgQ== X-Forwarded-Encrypted: i=1; AFNElJ+4MfeTo9bpGXlmNybx8BVbkTNYS8SJuvrNa9spBU/9p9C+3ZXxaIEk/v7ftA+adWK8QKAW6vU1wWJY@vger.kernel.org X-Gm-Message-State: AOJu0YyWUaCjjCC5kUj3KNWwTIVoSRzsy4nl1yLH66XLZ95F1rUhet0o 5xIog2ShyTkuHNWwezk/R7kd6ThIg3PVqCuM7Msb2XUeD05NEAMkGQAxiL9PPSm7dBqxsxhk8fD s7JepAZU= X-Gm-Gg: Acq92OE+54j1j4u3mT0eaAKfINIVZ9ggCxxBpbWWbXOy2HBl671s5JnIb5bNVSqGEJ2 4ZxadelkmGZ3doEtabY/fYK2NeVoM8qZRP/SCVtcS007fgy3e+egv67lIQ8/Mj/Fh9UI5RGLy5E dX/f54gIXwO0wGDw2JNPXH+ramZby5bkIYS+WVydhEU5eGsr5PxqmUaAIq/OTRflC7eWztc2r4l c5VnS/eXoL7mG5XacuLrT+N4z+8pZDuxX1kucD1TnewKNiXfQC179I5G5udm2HCUJci5f3Iab9U a23/XjVKgK3tSRG3qAqQffqFJFJ+nu+oFzDOA8X/CyYIHwA5TfXCS7fCmeOFVkhb/MdE5DN4MDT wCtjpliT1yWHXXXcxtejNFv24Q37P3Oshfo/5v/evrj9IGXPeGBBeEzl5nKcAjBlpp8TYMsc4am 4zAVaQh+6KuQxIuYCrjEfUAIFX7A== X-Received: by 2002:a05:7022:2201:b0:128:bae0:e03c with SMTP id a92af1059eb24-13504948b9cmr7313101c88.30.1779151956831; Mon, 18 May 2026 17:52:36 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-134cbcb93f3sm22546633c88.3.2026.05.18.17.52.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 17:52:36 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 18 May 2026 17:52:32 -0700 Subject: [PATCH v3 8/8] hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock Precedence: bulk X-Mailing-List: linux-gpio@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-Id: <20260518-adm1266-gpio-fixes-v3-8-e425e4f88139@nexthop.ai> References: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> In-Reply-To: <20260518-adm1266-gpio-fixes-v3-0-e425e4f88139@nexthop.ai> To: Guenter Roeck , Alexandru Tachici , Linus Walleij , Bartosz Golaszewski Cc: linux-hwmon@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, linux-gpio@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1779151949; l=1513; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=MbcEhPfilDl5djs8OwiISgXUAGJH031p6hDtDP0Q1lw=; b=tZbataWxursToK6TwLtzAmcuF1Y17nbY6u7cTpaJYyj/zzPSkodk7mxZZH1JHVU1DnAEfVJlV wM8DBAZHWeaDlPp97HVGOW3fr13+66tWHGwfFTqkXPbMbpgV5W2XWyX X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= adm1266_state_read() backs the sequencer_state debugfs entry and issues an i2c_smbus_read_word_data(client, ADM1266_READ_STATE) against the device without taking pmbus_lock. pmbus_core holds pmbus_lock around its own multi-transaction sequences (notably the "set PAGE, then read paged register" pattern used by hwmon attributes), so an unlocked debugfs reader can land between a PAGE write and the subsequent paged read in another thread. READ_STATE itself is not paged, so it cannot corrupt PAGE in flight, but the same defensive serialisation that applies to the GPIO accessors applies here: any direct device access from outside pmbus_core should be ordered with respect to pmbus_core's own. Take pmbus_lock at the top of adm1266_state_read() via the scope-based guard(). Fixes: ed1ff457e187 ("hwmon: (pmbus/adm1266) add debugfs for states") Cc: stable@vger.kernel.org Signed-off-by: Abdurrahman Hussain --- drivers/hwmon/pmbus/adm1266.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/hwmon/pmbus/adm1266.c b/drivers/hwmon/pmbus/adm1266.c index 051f4f188ec5..605db086236c 100644 --- a/drivers/hwmon/pmbus/adm1266.c +++ b/drivers/hwmon/pmbus/adm1266.c @@ -333,6 +333,7 @@ static int adm1266_state_read(struct seq_file *s, void *pdata) struct i2c_client *client = to_i2c_client(dev); int ret; + guard(pmbus_lock)(client); ret = i2c_smbus_read_word_data(client, ADM1266_READ_STATE); if (ret < 0) return ret;