Re: [PATCH 6/8] watchdog: core: Cancel timer if cdev_device_add() fails
From: Tzung-Bi Shih
Date: Wed Sep 30 2026 - 08:06:08 EST
On Tue, Sep 29, 2026 at 06:46:33AM -0700, Guenter Roeck wrote:
> If misc_register() exposed the device to userspace before cdev_device_add()
> is called, a concurrent watchdog_open() could start the watchdog and arm
> wd_data->timer as well as the pretimeout timer. Also, if the hardware
> watchdog was already running, watchdog_open() expects the device and module
> references to have been acquired prior to opening.
>
> If cdev_device_add() then fails, the error path drops the device reference
> but fails to stop the watchdog, cancel the timers, and stop the worker,
> leaving the watchdog active and timers armed that can later fire and
> dereference freed memory. Furthermore, if a concurrent watchdog_open() saw
> hw_running == true before cdev_device_add() was called, it skipped taking
> its own device reference, allowing put_device() on the error path to free
> wd_data while the file descriptor is still open. Similarly, when
> unregistering a running watchdog that is not currently open, the extra
> hw_running module and device references were never released.
>
> Fix the problem by initializing wd_data and taking the running-watchdog
> references before exposing the device via misc_register(), stopping the
> watchdog and canceling both the heartbeat and pretimeout timers and
> stopping the worker on registration failure, and releasing unclaimed
> running-watchdog references on registration failure and unregistration.
>
> Fixes: ee142889e32f ("watchdog: Introduce WDOG_HW_RUNNING flag")
> Assisted-by: LLM
> Signed-off-by: Guenter Roeck <linux@xxxxxxxxxxxx>
Reviewed-by: Tzung-Bi Shih <tzungbi@xxxxxxxxxx>