[PATCH v2 0/2] wifi: carl9170: revert broken devres conversions for input and hwrng

From: Dmitry Torokhov

Date: Thu Oct 08 2026 - 05:40:57 EST


Commits 23de0fa0d2a0 ("carl9170: devres-ing hwrng_register usage") and
87ddb2fc29f1 ("carl9170: devres-ing input_allocate_device") converted
the HWRNG and WPS button input device registrations in carl9170 to
devres attached to the parent struct usb_device (&ar->udev->dev) and
removed explicit unregistration from carl9170_unregister().

In carl9170_usb_disconnect(), the driver calls carl9170_unregister()
followed immediately by carl9170_free(), which frees struct ar9170
inside the interface .disconnect() callback before devres_release_all()
runs. Furthermore, devres on &ar->udev->dev is not released on
interface unbind or registration failure in carl9170_register().
As a result, both the WPS input device (whose input->name and
input->phys point into freed memory) and the embedded struct hwrng
remain registered after struct ar9170 has been freed, leading to
use-after-free bugs.

Revert both commits to restore explicit lifecycle management in
carl9170_unregister().

Signed-off-by: Dmitry Torokhov <dmitry.torokhov@xxxxxxxxx>
---
Changes in v2:
- Clarify commit messages to focus on the teardown order in
carl9170_usb_disconnect() and the error path in carl9170_register()
rather than request_firmware_nowait().
- Link to v1: https://patch.msgid.link/20260930-carl9170-reverts-v1-0-7033b5716c14@xxxxxxxxx

---
Dmitry Torokhov (2):
wifi: carl9170: Revert "carl9170: devres-ing input_allocate_device"
wifi: carl9170: Revert "carl9170: devres-ing hwrng_register usage"

drivers/net/wireless/ath/carl9170/carl9170.h | 1 +
drivers/net/wireless/ath/carl9170/main.c | 42 ++++++++++++++++++++++++----
2 files changed, 38 insertions(+), 5 deletions(-)
---
base-commit: 6474fa070f2b8013b4b87350b775b8c3be6e8aac
change-id: 20260930-carl9170-reverts-bc4b3b6a1a25

Thanks.

--
Dmitry