Re: [PATCH] iio: pressure: dps310: fix NULL pointer dereference on ACPI probe

From: Rupert Zoone

Date: Sun Jul 19 2026 - 08:16:30 EST


On Sun, Jul 19, 2026 at 12:06 PM +0300, Andy Shevchenko wrote:
> As a quick fix this patch is okay, the proper one is to go with chip_info
> structure in the driver_data. where the name will be defined.

Thanks for the review. I'd like to keep this one as the minimal fix so it
backports cleanly (it's Cc: stable). The chip_info/driver_data rework is a
good idea, but I'll do it as follow-up on top rather than fold it into the
stable fix.

> On top of that mutex_init() should be devm_mutex_init(), which is a fix,
> and some cleanups:
> - unused i2c_set_clientdata(); may be dropped
> - C99 initialisers in ACPI ID table
> - IWYU principle for the header inclusions
> - some unneeded GENMASK()s due to use of sign_extend32()
> - perhaps converting to use get_unaligned_xx() where it makes sense
> - use time multipliers in _read_poll_timeout()
> - use fsleep() and time multipliers instead of usleep_range()
> - get rid of min_t(); perhaps replace with clamp() or min()
> - use SI multipliers from units.h

Agreed on all of these, including the devm_mutex_init() change. I'll send
them as a separate cleanup series once this fix and the triggered-buffer
patch are in, so each change stays easy to review on its own.

Thanks,
Rupesh

On Sun, Jul 19, 2026 at 12:06 PM Andy Shevchenko
<andriy.shevchenko@xxxxxxxxx> wrote:
>
> On Sun, Jul 19, 2026 at 03:07:52AM +0300, Rupesh Majhi wrote:
> > When the device is enumerated through its ACPI HID (IFX3100),
> > i2c_client_get_device_id() returns NULL: the ACPI-derived client name
> > does not match the driver's i2c_device_id table. dps310_probe() then
> > dereferences that NULL pointer in "iio->name = id->name" and crashes the
> > kernel during probe.
> >
> > The IIO device name is always "dps310", so set it directly and drop the
> > now-unused device-id lookup.
>
> ...
>
> As a quick fix this patch is okay, the proper one is to go with chip_info
> structure in the driver_data. where the name will be defined.
>
> On top of that mutex_init() should be devm_mutex_init(), which is a fix,
> and some cleanups:
> - unused i2c_set_clientdata(); may be dropped
> - C99 initialisers in ACPI ID table
> - IWYU principle for the header inclusions
> - some unneeded GENMASK()s due to use of sign_extend32()
> - perhaps converting to use get_unaligned_xx() where it makes sense
> - use time multipliers in _read_poll_timeout()
> - use fsleep() and time multipliers instead of usleep_range()
> - get rid of min_t(); perhaps replace with clamp() or min()
> - use SI multipliers from units.h
>
> --
> With Best Regards,
> Andy Shevchenko
>
>