Re: [PATCH v2 0/3] iio: hid-sensors: fix shared callbacks in temperature and humidity

From: Joshua Crofts

Date: Thu Oct 08 2026 - 04:02:25 EST


On Wed, 7 Oct 2026 11:44:20 -0700
Christopher Hoover <ch@xxxxxxxxxxxxxx> wrote:

> hid-sensor-temperature and hid-sensor-humidity share one static
> struct hid_sensor_hub_callbacks across instances and overwrite its pdev
> on every probe. With two temperature sensors, reports for one go to
> the other's pdev; once that device is removed,
> temperature_capture_sample() dereferences NULL. I hit this on 7.0
> with two uhid-created sensors.
>
> Patches 2-3 make the callbacks per instance, as the other HID sensor
> drivers do. Patch 1 makes sensor_hub_remove_callback() take
> pdata->lock, as sensor_hub_raw_event() does, so a report racing an
> unbind cannot call through the freed callbacks.
>
> Changes in v2:
> - New patch 1, for the use-after-free on unbind found by the Sashiko
> review of v1.
>
> Christopher Hoover (3):
> HID: hid-sensor-hub: Synchronize callback removal with raw events
> iio: temperature: hid-sensor-temperature: Use per-instance callbacks
> iio: humidity: hid-sensor-humidity: Use per-instance callbacks
>
> drivers/hid/hid-sensor-hub.c | 12 ++++++++++--
> drivers/iio/humidity/hid-sensor-humidity.c | 12 +++++-------
> drivers/iio/temperature/hid-sensor-temperature.c | 12 +++++-------
> 3 files changed, 20 insertions(+), 16 deletions(-)
>
>
> base-commit: 9ee8306121495d2a25aa5d1bfd519f2748786b83

Reviewed-by: Joshua Crofts <joshua.crofts1@xxxxxxxxx>

--
Kind regards,
Joshua Crofts