RE: [PATCH] thermal/drivers/ti-soc-thermal: Cancel pending alert work on remove
From: J, KEERTHY
Date: Tue Sep 29 2026 - 04:17:47 EST
-----Original Message-----
From: Daniel Lezcano <daniel.lezcano@xxxxxxxxxxxxxxxx>
Sent: Tuesday, September 29, 2026 12:45 PM
To: Weigang He <geoffreyhe2@xxxxxxxxx>; Daniel Lezcano <daniel.lezcano@xxxxxxxxxx>; Rafael J . Wysocki <rafael@xxxxxxxxxx>; Eduardo Valentin <edubezval@xxxxxxxxx>; J, KEERTHY <j-keerthy@xxxxxx>
Cc: Zhang Rui <rui.zhang@xxxxxxxxx>; Lukasz Luba <lukasz.luba@xxxxxxx>; linux-pm@xxxxxxxxxxxxxxx; linux-omap@xxxxxxxxxxxxxxx; linux-kernel@xxxxxxxxxxxxxxx
Subject: Re: [PATCH] thermal/drivers/ti-soc-thermal: Cancel pending alert work on remove
On 9/26/26 14:49, Weigang He wrote:
> On a threshold crossing, the talert IRQ handler calls
> ti_thermal_report_sensor_temperature(), which queues the work embedded
> in the sensor's ti_thermal_data on the system workqueue. Nothing ever
> cancels or flushes that work.
>
> ti_bandgap_remove() frees the talert IRQ last. free_irq() waits for a
> running handler, but not for the work the handler has queued. When
> remove returns, devres unregisters and frees the thermal zones and
> then frees the devm-allocated ti_thermal_data, so a work item that is
> still pending runs ti_thermal_work() on freed memory:
>
> ti_thermal_work()
> data = container_of(work, struct ti_thermal_data, thermal_wq);
> thermal_zone_device_update(data->ti_thermal, ...);
>
> Free the talert IRQ before removing the sensors, so that no new work
> can be queued, and cancel the work in ti_thermal_remove_sensor().
>
> This needs an OMAP4460/4470 or OMAP5 SoC (DRA7 has TALERT but no
> ->report_temperature, so it never queues the work), a threshold
> ->crossing
> just before the driver is unbound or unloaded, and the work still
> pending when devres frees the data.
>
> Found by static analysis tool CodeQL.
>
> Fixes: 445eaf871bf9 ("staging: omap-thermal: common code to expose
> driver to thermal framework")
> Assisted-by: LLM codeql
> Signed-off-by: Weigang He <geoffreyhe2@xxxxxxxxx>
> ---
Sounds correct to me, so if nobody is against this change I'll apply it
> FWIW: Acked-by: Keerthy <j-keerthy@xxxxxx>
Thanks