Re: [PATCH] thermal/drivers/ti-soc-thermal: Cancel pending alert work on remove
From: Daniel Lezcano
Date: Tue Sep 29 2026 - 03:15:34 EST
On 9/26/26 14:49, Weigang He wrote:
On a threshold crossing, the talert IRQ handler callsSounds correct to me, so if nobody is against this change I'll apply it
ti_thermal_report_sensor_temperature(), which queues the work embedded
in the sensor's ti_thermal_data on the system workqueue. Nothing ever
cancels or flushes that work.
ti_bandgap_remove() frees the talert IRQ last. free_irq() waits for a
running handler, but not for the work the handler has queued. When
remove returns, devres unregisters and frees the thermal zones and then
frees the devm-allocated ti_thermal_data, so a work item that is still
pending runs ti_thermal_work() on freed memory:
ti_thermal_work()
data = container_of(work, struct ti_thermal_data, thermal_wq);
thermal_zone_device_update(data->ti_thermal, ...);
Free the talert IRQ before removing the sensors, so that no new work
can be queued, and cancel the work in ti_thermal_remove_sensor().
This needs an OMAP4460/4470 or OMAP5 SoC (DRA7 has TALERT but no
->report_temperature, so it never queues the work), a threshold crossing
just before the driver is unbound or unloaded, and the work still
pending when devres frees the data.
Found by static analysis tool CodeQL.
Fixes: 445eaf871bf9 ("staging: omap-thermal: common code to expose driver to thermal framework")
Assisted-by: LLM codeql
Signed-off-by: Weigang He <geoffreyhe2@xxxxxxxxx>
---
Thanks