Re: [PATCH v3] tty: serial: max3100: shut down timer before freeing port

From: Greg KH

Date: Wed Sep 23 2026 - 06:02:18 EST


On Wed, Aug 05, 2026 at 12:40:39AM +0000, Fan Wu wrote:
> max3100_shutdown() stops the polling timer but returns early during
> system suspend. If the SPI device is unbound before resume, the serial
> core does not call max3100_shutdown() again, so max3100_remove() frees
> the port while the timer remains armed. max3100_timeout() may then
> access the freed port and re-arm the timer.
>
> Add final timer teardown to max3100_remove() and use
> timer_shutdown_sync() to prevent a racing callback from re-arming it.
> Also free the IRQ and destroy the workqueue there before freeing the
> port. Keep timer_delete_sync() in max3100_shutdown() so that a
> subsequent open() can re-arm the timer.
>
> The workqueue is created before request_irq() and destroyed on both
> request_irq() failure and normal shutdown. Its presence at remove thus
> identifies the IRQ left registered when suspend bypasses shutdown.
>
> This issue was found by an in-house static analysis tool.

There are still issues:
https://sashiko.dev/#/patchset/20260805004039.382698-1-fanwu01@xxxxxxxxxx