Re: [PATCH v3 0/2] HID: sensor: custom: Fix fields lifetime issues
From: Jonathan Cameron
Date: Thu Aug 06 2026 - 19:32:41 EST
On Sun, 12 Jul 2026 00:59:06 +0100
Jonathan Cameron <jonathan.cameron@xxxxxxxxxxxxxxxx> wrote:
> On Tue, 7 Jul 2026 15:15:43 +0800
> Haoxiang Li <haoxiang_li2024@xxxxxxx> wrote:
>
> > Hi,
> >
> > This series fixes lifetime issues around sensor_inst->fields and the
> > sysfs attributes that can access it.
> >
> > The first patch creates the field attributes before exposing enable_sensor
> > and removes enable_sensor before freeing the field attributes. This keeps
> > enable_sensor from accessing power_state and report_state pointers after
> > the fields array has been freed.
> >
> > The second patch fixes the original field sysfs group leak on probe
> > failure by unwinding any field groups that were created before a later
> > sysfs_create_group() failure.
> Series applied to the fixes-togreg branch of iio.git
>
Sorry - I wasn't paying attention to what I was picking up.
These should go via Jiri's tree.
Dropping them from the iio-fixes tree.
Jonathan
> Thanks,
>
> Jonathan
>
> >
> > Changes in v3:
> > - Move the enable_sensor registration reorder from patch 2 to patch 1.
> > - Add a comment explaining why enable_sensor is removed before fields.
> > - Add Reported-by and Link tags for the Sashiko review.
> > - Keep patch 2 focused on the field sysfs group cleanup. Tanks, Jonathan!
> >
> > Changes in v2:
> > - Split the fix into two patches.
> > - Unwind already-created field sysfs groups on failure. Thanks, Jiri!
> >
> > Haoxiang Li (2):
> > HID: sensor: custom: Fix use-after-free in enable_sensor
> > HID: sensor: custom: Fix field sysfs group cleanup on failure
> >
> > drivers/hid/hid-sensor-custom.c | 26 +++++++++++++++++---------
> > 1 file changed, 17 insertions(+), 9 deletions(-)
> >
> >
> > base-commit: ef0c9f75a19532d7675384708fc8621e10850104
>
>