Re: [PATCH 0/7] iio: validate SPI match data before use
From: Andy Shevchenko
Date: Mon Sep 28 2026 - 04:21:11 EST
On Sun, Sep 27, 2026 at 06:20:01PM +0100, Jonathan Cameron wrote:
> On Sat, 26 Sep 2026 08:13:13 +0200
> Uwe Kleine-König (The Capable Hub) <u.kleine-koenig@xxxxxxxxxxxx> wrote:
> > On Sat, Sep 26, 2026 at 02:11:43AM +0100, Jonathan Cameron wrote:
> > > On Fri, 25 Sep 2026 21:17:29 +0800
> > > Jiale Yao <yaojiale02@xxxxxxx> wrote:
> > >
> > > > SPI driver_override can bind a device without a matching entry in the
> > > > driver's ID tables. spi_get_device_match_data() then returns NULL.
> > > >
> > > > These seven IIO drivers use that result without checking it, causing a
> > > > NULL pointer dereference during probe. Add the missing checks before
> > > > the match data is used.
> > >
> > > I was hoping we'd close this finally by adding a flag to the
> > > drivers to say they should fail a match if driver_override is set.
> > > Given I thought maybe that would happen when Andy looked into this
> > > a while back I've been sitting on this problem for a while.
Sorry, I have had no time to continue...
> > >
> > > Unfortunately seems we have to carry on papering over it in the
> > > drivers for now :(
> >
> > Note there is another effort:
> > https://lore.kernel.org/lkml/20260922-driver-override-opt-out-v1-0-58c35ded3b83@xxxxxxxxxx/
...but I like this effort, it looks great!
> Nice. I look forward to ripping all these checks out again
> if that lands. Obviously we won't backport doing that given the checks
> will remain harmless.
--
With Best Regards,
Andy Shevchenko