[PATCH] hwmon: (sht4x) Fix torn read of heating_complete in heater_enable_show()
From: Tom Verdonck
Date: Mon Sep 28 2026 - 02:27:22 EST
Commit 61406e9cac69 ("hwmon: (sht4x) Fix jiffies wraparound in
heater-ready check") widened ->heating_complete from unsigned long to
u64. On 32-bit architectures a u64 is no longer loaded and stored
atomically, so heater_enable_show(), which reads ->heating_complete
without any locking, can race heater_enable_store() and observe a torn
value, reporting a wrong heater state.
Take the hwmon lock in heater_enable_show(), as heater_enable_store()
already does when it updates ->heating_complete. The other reader,
sht4x_read_values(), is only reached through the hwmon read callback,
which the hwmon core already serializes with the same lock.
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Closes: https://sashiko.dev/#/patchset/cover.1790358356.git.tom.verdonck@xxxxxxxxxxx?part=3
Fixes: 61406e9cac69 ("hwmon: (sht4x) Fix jiffies wraparound in heater-ready check")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Tom Verdonck <tom.verdonck@xxxxxxxxxxx>
---
Guenter, if the hwmon branch has not gone to Linus yet, feel free to
squash this into commit 61406e9cac69 ("hwmon: (sht4x) Fix jiffies
wraparound in heater-ready check") instead.
drivers/hwmon/sht4x.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/hwmon/sht4x.c b/drivers/hwmon/sht4x.c
index da2b6130fca7..27fddff70354 100644
--- a/drivers/hwmon/sht4x.c
+++ b/drivers/hwmon/sht4x.c
@@ -237,6 +237,8 @@ static ssize_t heater_enable_show(struct device *dev,
{
struct sht4x_data *data = dev_get_drvdata(dev);
+ guard(hwmon_lock)(dev);
+
return sysfs_emit(buf, "%u\n", time_before64(get_jiffies_64(), data->heating_complete));
}
--
2.53.0