From patchwork Tue Jan 31 13:08:45 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Pietro Borrello X-Patchwork-Id: 649046 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id E6658C636D4 for ; Tue, 31 Jan 2023 13:09:09 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232048AbjAaNJH (ORCPT ); Tue, 31 Jan 2023 08:09:07 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44690 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231473AbjAaNJF (ORCPT ); Tue, 31 Jan 2023 08:09:05 -0500 Received: from mail-ej1-x62d.google.com (mail-ej1-x62d.google.com [IPv6:2a00:1450:4864:20::62d]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 0FD51222F4 for ; Tue, 31 Jan 2023 05:09:03 -0800 (PST) Received: by mail-ej1-x62d.google.com with SMTP id bk15so41388290ejb.9 for ; Tue, 31 Jan 2023 05:09:02 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=uOYadJvP8u49K2x2oSYl+EYqiXssZ4idBGq/e4Tz9NY=; b=KDEKy6z9clzZ/yt+Ugm+vcRRWzEj90+XlSFk9eYXi6IC5nH1Ekl2y3Hm9QX1/VOyg6 KoU6Bt2QbVi12p9NEJGHVLQti9laMQw3q0XhRpn8RudSITu6ZnOGgKHs7nTwUuFy4XOk N1Lq/Rl18bZd0+9UEdChBzxmYVa5FEhjARYR8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=uOYadJvP8u49K2x2oSYl+EYqiXssZ4idBGq/e4Tz9NY=; b=2bpsXL/CoO/INlMlG62gDBmcFEI/6RWt+1AuAjfVCwO5wHISF75JIIKz3dwIVqToBQ dNhfn1ZIIw1yoxziqOdSQCwHJ4LF7pI9Z1m5q8T9A/aYJ9+FhjAjKBoiGQwFv/kR0goS 64Dg1/jXo4cHiMzw7BxzN2IyGBr4x+PbE6LLyARCX6LW9PwMxfh4dCp/NhhUsYlloV+G /sxd9TPPvnubF4IIXVuLcOppj3KvV0pOAwEFlkLggG45ydCx4EXwueDjJuhhusp0OveX +4apYC8jyQfv+b/dnFBfwWHLZGLZn2AzKqiuavRUwSIBUBwsszGIS637FWqWIdivHf5L 89FQ== X-Gm-Message-State: AO0yUKUcpJUPfri8AZ2aNq6zx73MSSss+FNrhRSMM8BmQ8wUN32rYlL8 3Ax+52V3K1Ktjwokfj4gbcQqxQ== X-Google-Smtp-Source: AK7set+TLo90zN/rggXs78IMqKvdRPq3UMM97//YKxvo/gz4hPVpUrCvA/s+uzGixpW4LfOqI22Pzg== X-Received: by 2002:a17:907:da1:b0:888:7ce4:1dc1 with SMTP id go33-20020a1709070da100b008887ce41dc1mr10015780ejc.26.1675170541590; Tue, 31 Jan 2023 05:09:01 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:01 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:45 +0000 Subject: [PATCH v2 1/5] HID: bigben_remove: manually unregister leds MIME-Version: 1.0 Message-Id: <20230125-hid-unregister-leds-v2-1-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=1037; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=wlU1zbXd7qFTSbVqYvqS9BOVrqglVS3eHD1ePCtISHc=; b=1S4dFJ6YtEJ88InQZSjBIJqgxbqXt+T9JIgkqoLWq0NtwsubGN/Fl9VW6G07oKHBAzx9ClO/JaNt v2JlPGwtCuiFqrHoLk9QBHzG1Seo6N4LHcIZ7c4vooOoJ+dx5t6/ X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-input@vger.kernel.org Unregister the LED controllers before device removal, as bigben_set_led() may schedule bigben->worker after the structure has been freed, causing a use-after-free. Fixes: 4eb1b01de5b9 ("HID: hid-bigbenff: fix race condition for scheduled work during removal") Signed-off-by: Pietro Borrello --- drivers/hid/hid-bigbenff.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/hid/hid-bigbenff.c b/drivers/hid/hid-bigbenff.c index e8b16665860d..d3201b755595 100644 --- a/drivers/hid/hid-bigbenff.c +++ b/drivers/hid/hid-bigbenff.c @@ -306,9 +306,14 @@ static enum led_brightness bigben_get_led(struct led_classdev *led) static void bigben_remove(struct hid_device *hid) { + int n; struct bigben_device *bigben = hid_get_drvdata(hid); bigben->removed = true; + for (n = 0; n < NUM_LEDS; n++) { + if (bigben->leds[n]) + devm_led_classdev_unregister(&hid->dev, bigben->leds[n]); + } cancel_work_sync(&bigben->worker); hid_hw_stop(hid); } From patchwork Tue Jan 31 13:08:46 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Pietro Borrello X-Patchwork-Id: 649457 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 94AFCC6379F for ; Tue, 31 Jan 2023 13:09:10 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231473AbjAaNJI (ORCPT ); Tue, 31 Jan 2023 08:09:08 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44738 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232043AbjAaNJG (ORCPT ); Tue, 31 Jan 2023 08:09:06 -0500 Received: from mail-ej1-x62a.google.com (mail-ej1-x62a.google.com [IPv6:2a00:1450:4864:20::62a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id CF02223C69 for ; Tue, 31 Jan 2023 05:09:03 -0800 (PST) Received: by mail-ej1-x62a.google.com with SMTP id ud5so41449369ejc.4 for ; Tue, 31 Jan 2023 05:09:03 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=OtVGZ8lsHwJ47yfcKnn1bRe6oeChLHMzfzZSc6Gf3Bk=; b=pA5e7TMvW7cwu+TT7l2Hls+dk56ZZZU4LdW2+MDQ1rJPyNuoyoaIIbboW9W2vfpw1x 5kNnqcCF5WcbT8fBUpvhAIq51qswfLSi6U1lqV9+SYOI3lJkdxs2B0me5bZCn6L47cx3 TPTHTQIUwNYyT2tDWfyXmMowMwebJsuaFs+h8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=OtVGZ8lsHwJ47yfcKnn1bRe6oeChLHMzfzZSc6Gf3Bk=; b=F8mfqHf+v6HMBpTxBfbcwflsbkVW7aHYFF9tmjKdfA/DbBHBrrclqWXDxBPYEHLUcy 6BDW+0mjA0+azyGldtMnXG03bO7DmxL1Lg/7SdF2R1wUc7+mL5ULms2gn8y7yHGpQ7xC K87klUn2+UTUSOUuivssw2i6vUPy58HrqI+T7ZG2nzxGH/HNyhTEbVxBn/JzwFucQiX3 IgMaOZCy0SkHzpC4tV2OIrh1YVi8Wk5N1drXllcWE7r1tzYaP0QRErdYBcolHr56fZ+/ cFgzf90BdpouJ3XX06RtzYvd4Yqp1TFjKI5MZW8iwfiI3JTGHoQRCdHCzei7v7EZ91eo s9RA== X-Gm-Message-State: AO0yUKVI0PkF1+9E7/n/B5CGGTVpsg+AIFalWOQdvHa5ZeS6v/S3zYHf Ka93wpxPmXO2ZELysk1M9IjNFg== X-Google-Smtp-Source: AK7set/Cksul47Eq5LwKVVTkjIXAKGTG73njw/C2kmdOuQ3OLYqxIfQjR7bGvW2NKfHw496llf5C4w== X-Received: by 2002:a17:907:20b0:b0:87b:d376:b850 with SMTP id pw16-20020a17090720b000b0087bd376b850mr15363396ejb.10.1675170542167; Tue, 31 Jan 2023 05:09:02 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:01 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:46 +0000 Subject: [PATCH v2 2/5] HID: asus_remove: manually unregister led MIME-Version: 1.0 Message-Id: <20230125-hid-unregister-leds-v2-2-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=841; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=6oFA70DnzD6hxYzPyFU4oYw2osDEjulwpyTezPO1v4g=; b=LzdPeS7nVFRpo8VU64kao203h0vMfO08dDdS4pMuCfp8K26oNi2WN4aYBXEv1EMMlBBQasjjEP2T c2hJTcoeAT73y7sOHiri1/kUbKWKBhOqOKL2ZerGBDgo+vBVjtga X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-input@vger.kernel.org Unregister the LED controller before device removal, as asus_kbd_backlight_set() may schedule led->work after the structure has been freed, causing a use-after-free. Fixes: af22a610bc38 ("HID: asus: support backlight on USB keyboards") Signed-off-by: Pietro Borrello --- drivers/hid/hid-asus.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/hid/hid-asus.c b/drivers/hid/hid-asus.c index f99752b998f3..0f274c8d1bef 100644 --- a/drivers/hid/hid-asus.c +++ b/drivers/hid/hid-asus.c @@ -1122,6 +1122,7 @@ static void asus_remove(struct hid_device *hdev) if (drvdata->kbd_backlight) { drvdata->kbd_backlight->removed = true; + devm_led_classdev_unregister(&hdev->dev, &drvdata->kbd_backlight->cdev); cancel_work_sync(&drvdata->kbd_backlight->work); } From patchwork Tue Jan 31 13:08:47 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Pietro Borrello X-Patchwork-Id: 649045 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id F24A6C636D3 for ; Tue, 31 Jan 2023 13:09:13 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232043AbjAaNJK (ORCPT ); Tue, 31 Jan 2023 08:09:10 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44732 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232038AbjAaNJH (ORCPT ); Tue, 31 Jan 2023 08:09:07 -0500 Received: from mail-ej1-x62c.google.com (mail-ej1-x62c.google.com [IPv6:2a00:1450:4864:20::62c]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 3FD3DE061 for ; Tue, 31 Jan 2023 05:09:04 -0800 (PST) Received: by mail-ej1-x62c.google.com with SMTP id qw12so25514926ejc.2 for ; Tue, 31 Jan 2023 05:09:04 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=eVbivV8EGu+km89gAq7ikjZD9Nt9wLtDAtt21fJbyIE=; b=pJVMbn/vZRNaPQe0/Pfzxri/P1+RByqeFUJ9/umN+VsPxL3e3/bBzc6h668t114S/u sW0RQ1vPA/6lSs5n+Rn3J70dvTRtFZbVX8QiMjDTuDt7ZIOIuevWut63gXisf4/2autT pzVkokK1srC+UOM9kbemm2181pRPbr+c1pDBU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=eVbivV8EGu+km89gAq7ikjZD9Nt9wLtDAtt21fJbyIE=; b=aqSZhmpfD02Z9Gka4e0QMwIEzL+fCCyVegDhJgtPf2APWGLV8jq0rl+yYPi0PLiwB9 A/tpjsXiMMfAeB9gHTeYBEVgVgXxmNOYw4Jt/+95Fgt0TPV0AT3KIpMjyZGDduYqF7KS 5wjHQ9qIkYwxNX+745KR1M77IaiPJ1JN8vDzmBlzVq3f5U6TJC1XlKzMrZN0eUdyenSI sJdUYHESAp6wjYg3vleyU8uYvW5jhh6y6KFJTEDSLvtiKHR2HX704lehYomFEJLMk7jp XT9I5Hyu129iM4/CYvvhmWx6BfhCdBo1TMyqMi4Tv84mCkCb8PPK2CSS8Z+Y8RE6yxRm nBIg== X-Gm-Message-State: AO0yUKVrfO2UdVqrSGiykGFRBa8r7mn6aKRQcKruFAXoDtrBvarlhBOo o6YOOSM5xGPLBOMsa8j/eCV48g== X-Google-Smtp-Source: AK7set8/dsb0DwLaEBtLxuVxd2bPqNpGLBTx6byaW3iLpH0RJzEEdVF24gASNLKt0q4ByhBIplGh5g== X-Received: by 2002:a17:906:208b:b0:885:d02f:d4ad with SMTP id 11-20020a170906208b00b00885d02fd4admr12778878ejq.43.1675170542716; Tue, 31 Jan 2023 05:09:02 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:02 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:47 +0000 Subject: [PATCH v2 3/5] HID: dualsense_remove: manually unregister leds MIME-Version: 1.0 Message-Id: <20230125-hid-unregister-leds-v2-3-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=1556; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=I/aK9DcIPRri1R7+BoQmPFot08oQLGwMbJpqlNV1B8M=; b=5sp2HxZcrnV1R0s9GQ65lRPDmAjbbTrzRLu2QOtJ2rZ+CPXfd6lM34SYzoZQTTz5wcKpPq3+C4Rz xTnnHicND5nqprX0be6N1UIrfJQbhy+wplZo58FC2enoRBiPpDC4 X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-input@vger.kernel.org Unregister the LED controllers before device removal, to prevent unnecessary runs of dualsense_player_led_set_brightness(). Fixes: 8c0ab553b072 ("HID: playstation: expose DualSense player LEDs through LED class.") Signed-off-by: Pietro Borrello --- Contrary to the other patches in this series, failing to unregister the led controller does not results into a use-after-free thanks to the output_worker_initialized variable and the spinlock checks. Changes in v2: - Unregister multicolor led controller - Clarify UAF - Link to v1: https://lore.kernel.org/all/20230125-hid-unregister-leds-v1-3-9a5192dcef16@diag.uniroma1.it/ --- drivers/hid/hid-playstation.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/hid/hid-playstation.c b/drivers/hid/hid-playstation.c index 27c40894acab..f23186ca2d76 100644 --- a/drivers/hid/hid-playstation.c +++ b/drivers/hid/hid-playstation.c @@ -1503,11 +1503,17 @@ static void dualsense_remove(struct ps_device *ps_dev) { struct dualsense *ds = container_of(ps_dev, struct dualsense, base); unsigned long flags; + int i; spin_lock_irqsave(&ds->base.lock, flags); ds->output_worker_initialized = false; spin_unlock_irqrestore(&ds->base.lock, flags); + for (i = 0; i < ARRAY_SIZE(ds->player_leds); i++) + devm_led_classdev_unregister(&ps_dev->hdev->dev, &ds->player_leds[i]); + + devm_led_classdev_multicolor_unregister(&ps_dev->hdev->dev, &ds->lightbar); + cancel_work_sync(&ds->output_worker); } From patchwork Tue Jan 31 13:08:48 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Pietro Borrello X-Patchwork-Id: 649456 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 932D7C636CC for ; Tue, 31 Jan 2023 13:09:28 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232110AbjAaNJ1 (ORCPT ); Tue, 31 Jan 2023 08:09:27 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44902 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232067AbjAaNJK (ORCPT ); Tue, 31 Jan 2023 08:09:10 -0500 Received: from mail-ed1-x533.google.com (mail-ed1-x533.google.com [IPv6:2a00:1450:4864:20::533]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id BD01A4F34A for ; Tue, 31 Jan 2023 05:09:04 -0800 (PST) Received: by mail-ed1-x533.google.com with SMTP id m8so5115172edd.10 for ; Tue, 31 Jan 2023 05:09:04 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=Q79upilYUaTabLjtO3bZo14lYpmZpgLc63/mP4eG9WA=; b=Jiv6RUxvmV3Ufd8uoYWmd1situOGY4NhVV6W3e8iX/gSnI5hNoydnRNmL6pvCh8dSp 8eGfWvxqWz8zd3of7EcGBXL41UT07GSlYrxg5SjhiHyP+oXMvTPrRuVAlouhz4+y9We6 18ytUHl0u33LcDQGVwMctqXQbHTO04YiVQkmc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=Q79upilYUaTabLjtO3bZo14lYpmZpgLc63/mP4eG9WA=; b=3a6IpZLSbGHtJlyh8nRF9iEOEUD81uoDgh/Q1jsF5tjjJ4l/zB1udQAhxxMO1HWzEK 1RRxmxmqvX1/PsCgHs86nxL7XAWRxEluPVP1lD7eH330ARFnNUO8CHNaoOD0jznKs9kb 5fv/7mJTfrmDzrPNT9cocV4l4G6SUYjVFDtoh8gZjJR+cPx1/4KaAf8Ty33jzgoYGL3n HFmC7a2wq3xaeNSSp0O4M5jyxuCVYx98Rehh6Lr7bn96A15yRhsjrYCdptxf2mIdAeEB AJ7kA0qJzYYXwO/0m6pPy37QmY48CPT3DHwQp+DUIWTBSep2yj8x5KFbZwHSQOz8VCVR aMbA== X-Gm-Message-State: AFqh2kr6nlDubcUxDriAF5Fyru1LQkjREtV1XHKP5ExgKbQ07ne5DOkY 8ij1L5sp+d5EHrsKD0uU+JcTpg== X-Google-Smtp-Source: AMrXdXtiGqkeWKlRDAoIO4sROri5jyb0nQOOYcVpEPXewNUDAsDU6bDYl4l7r4L+LJVAOmVrweQMoA== X-Received: by 2002:aa7:c052:0:b0:475:dddc:374a with SMTP id k18-20020aa7c052000000b00475dddc374amr56004206edo.18.1675170543237; Tue, 31 Jan 2023 05:09:03 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:02 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:48 +0000 Subject: [PATCH v2 4/5] HID: dualshock4_remove: manually unregister leds MIME-Version: 1.0 Message-Id: <20230125-hid-unregister-leds-v2-4-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=1491; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=VPrVVBqqogjSwkjTCQxGFur+jXJWf031MbQaC/naVuk=; b=a5Fi08feBch0WK2QkEw6jb2k0YeWIxIy0TOvIlH4YFQDjzx5YCPMMBiXJ+X1wwE3U5mdz9JHAVyg S53Yt4moDbGRX18ytJbn1h1YkW4eu7pgIyCWWt7/3d1Y4VCSvbfP X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-input@vger.kernel.org Unregister the LED controllers before device removal, to prevent unnecessary runs of dualshock4_led_set_brightness(). Fixes: 4521109a8f40 ("HID: playstation: support DualShock4 lightbar.") Signed-off-by: Pietro Borrello --- Contrary to the other patches in this series, failing to unregister the led controller does not results into a use-after-free thanks to the output_worker_initialized variable and the spinlock checks. Changes in v2: - Clarify UAF - Link to v1: https://lore.kernel.org/all/20230125-hid-unregister-leds-v1-4-9a5192dcef16@diag.uniroma1.it/ --- drivers/hid/hid-playstation.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/hid/hid-playstation.c b/drivers/hid/hid-playstation.c index f23186ca2d76..b41657842e26 100644 --- a/drivers/hid/hid-playstation.c +++ b/drivers/hid/hid-playstation.c @@ -2434,11 +2434,15 @@ static void dualshock4_remove(struct ps_device *ps_dev) { struct dualshock4 *ds4 = container_of(ps_dev, struct dualshock4, base); unsigned long flags; + int i; spin_lock_irqsave(&ds4->base.lock, flags); ds4->output_worker_initialized = false; spin_unlock_irqrestore(&ds4->base.lock, flags); + for (i = 0; i < ARRAY_SIZE(ds4->lightbar_leds); i++) + devm_led_classdev_unregister(&ps_dev->hdev->dev, &ds4->lightbar_leds[i]); + cancel_work_sync(&ds4->output_worker); if (ps_dev->hdev->product == USB_DEVICE_ID_SONY_PS4_CONTROLLER_DONGLE) From patchwork Tue Jan 31 13:08:49 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Pietro Borrello X-Patchwork-Id: 649044 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1CFDDC636D7 for ; Tue, 31 Jan 2023 13:09:30 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232063AbjAaNJ3 (ORCPT ); Tue, 31 Jan 2023 08:09:29 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44730 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232097AbjAaNJ0 (ORCPT ); Tue, 31 Jan 2023 08:09:26 -0500 Received: from mail-ej1-x635.google.com (mail-ej1-x635.google.com [IPv6:2a00:1450:4864:20::635]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 59EC211145 for ; Tue, 31 Jan 2023 05:09:05 -0800 (PST) Received: by mail-ej1-x635.google.com with SMTP id ud5so41449558ejc.4 for ; Tue, 31 Jan 2023 05:09:05 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=nSLU5NXnF595gyXxeWDSi1UUOJiT0ePoBW3kFPldqJg=; b=TgjBsUPIIAq4tN9feRGWSXFsbMEDj58nrNmhPLcm8UYtMOHOp4/0TGiQxOfrEr5e1R IjpmRHyrmvjbBOn01c4NOZnltIE5kHzrr4/H5ipgdZvT1HfDziI25QxWLil3DqTlYXbc SUELTdzKzqxqmohf9wyt67/3HN3HQX2YnoJUs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=nSLU5NXnF595gyXxeWDSi1UUOJiT0ePoBW3kFPldqJg=; b=i226ejG+oN4Y6s4YnOzQTJvLSsd0wn7vneIS9iaEVnu6ns/DiUPF/G4cqIY0RTD9h8 F/g/BEKCyEBcO7s+pNWCSMD/Mfj0gufvjH3HhxsQtlswqrAd/V4Ne6cqtaF0mPeykyMb HRa5OaB/J54G55KGJGUYxE56oP6oQOAcPaCBYfyleKpt2l2DGegXiaz3uXtKInCtdvNW 0qXVRF+NLEZvW0DmCL+5lyVEgITqSQcxaHb9wzMe5Veie1/pMtGYpY5oNYbTUXUsfy9w DsgkPulDSGRmAJK2SOaG5ixKED9Uqj1RPBJmrug+FgKHfgcd/7IL+Hm5DLNPkfdWxe1X fyXA== X-Gm-Message-State: AFqh2kq8+9Fg8mrD8wWacJ6gjGNb558eRpNT/wGMzc0sQJs9NIZlfQta g+ALXZi7hj74iqhy25B3nEpddA== X-Google-Smtp-Source: AMrXdXuJ9cWrU1GrTo9lhXJQpnCgMCNtO38vDPa2itSyQ5DYq1ObFWX83kJ8A2Kg/awK6/VUMpmpYg== X-Received: by 2002:a17:906:6846:b0:84d:2fdf:a41b with SMTP id a6-20020a170906684600b0084d2fdfa41bmr54522936ejs.50.1675170543813; Tue, 31 Jan 2023 05:09:03 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:03 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:49 +0000 Subject: [PATCH v2 5/5] HID: sony_remove: manually unregister leds MIME-Version: 1.0 Message-Id: <20230125-hid-unregister-leds-v2-5-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=1360; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=229FyOXnrqPun6wciRAitLA27itC/9x6aEmACwn1+hs=; b=8Ck9ho6y0MkvQj3h5QlnwTwQENcRw2KZSkxXIkbaRHd+HTbXacBdbpF7ABf3bbxtN28DrLjQFpZW TSYqKYoFCrzdxPZgCRpFzFuRuSjrIes+qSrrPtSh6ehgPH3grT0O X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-input@vger.kernel.org Unregister the LED controller before device removal, as sony_led_set_brightness() may schedule sc->state_worker after the structure has been freed, causing a use-after-free. Fixes: 0a286ef27852 ("HID: sony: Add LED support for Sixaxis/Dualshock3 USB") Signed-off-by: Pietro Borrello Reviewed-by: Sven Eckelmann --- drivers/hid/hid-sony.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/drivers/hid/hid-sony.c b/drivers/hid/hid-sony.c index 13125997ab5e..146677c8319c 100644 --- a/drivers/hid/hid-sony.c +++ b/drivers/hid/hid-sony.c @@ -3083,6 +3083,7 @@ static int sony_probe(struct hid_device *hdev, const struct hid_device_id *id) static void sony_remove(struct hid_device *hdev) { struct sony_sc *sc = hid_get_drvdata(hdev); + int n; if (sc->quirks & (GHL_GUITAR_PS3WIIU | GHL_GUITAR_PS4)) { del_timer_sync(&sc->ghl_poke_timer); @@ -3100,6 +3101,13 @@ static void sony_remove(struct hid_device *hdev) if (sc->hw_version_created) device_remove_file(&sc->hdev->dev, &dev_attr_hardware_version); + if (sc->quirks & SONY_LED_SUPPORT) { + for (n = 0; n < sc->led_count; n++) { + if (sc->leds[n]) + devm_led_classdev_unregister(&hdev->dev, sc->leds[n]); + } + } + sony_cancel_work_sync(sc); sony_remove_dev_list(sc);