[PATCH] platform/chrome: cros_ec_debugfs: unregister panic notifier
From: Hongyan Xu
Date: Tue Jul 28 2026 - 08:40:36 EST
cros_ec_debugfs_probe() registers debug_info->notifier_panic with the EC
panic notifier chain. The remove path tears down debugfs and cancels the
console log work, but leaves the notifier on the chain. A later panic
notification can call back into a removed driver instance and reschedule
the delayed work.
Unregister the notifier before tearing down debugfs state. Also run the
console-log cleanup in the probe error path.
This issue was found by a static analysis tool.
Signed-off-by: Hongyan Xu <getshell@xxxxxxxxxx>
---
drivers/platform/chrome/cros_ec_debugfs.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/platform/chrome/cros_ec_debugfs.c b/drivers/platform/chrome/cros_ec_debugfs.c
index 92ac9a2f9..6f93aedbd 100644
--- a/drivers/platform/chrome/cros_ec_debugfs.c
+++ b/drivers/platform/chrome/cros_ec_debugfs.c
@@ -534,6 +534,7 @@ static int cros_ec_debugfs_probe(struct platform_device *pd)
return 0;
remove_debugfs:
+ cros_ec_cleanup_console_log(debug_info);
debugfs_remove_recursive(debug_info->dir);
return ret;
}
@@ -542,6 +543,8 @@ static void cros_ec_debugfs_remove(struct platform_device *pd)
{
struct cros_ec_dev *ec = dev_get_drvdata(pd->dev.parent);
+ blocking_notifier_chain_unregister(&ec->ec_dev->panic_notifier,
+ &ec->debug_info->notifier_panic);
debugfs_remove_recursive(ec->debug_info->dir);
cros_ec_cleanup_console_log(ec->debug_info);
}
--
2.50.1.windows.1