[PATCH] hwmon: (corsair-cpro) Make wait_input_report_lock IRQ safe
From: Sanan Hasanov
Date: Thu Oct 08 2026 - 16:54:42 EST
From: Sanan Hasanov <sanan.hasanov@xxxxxxx>
ccp_raw_event() is the HID ->raw_event() callback and takes
wait_input_report_lock with a plain spin_lock(). This callback can run
in very different contexts depending on the transport: from process
context (e.g. uhid, via a write() to /dev/uhid) with softirqs and
interrupts enabled, and from URB completion, which is softirq context
for HCDs using HCD_BH and hard interrupt context for HCDs that do not
(e.g. OHCI, UHCI).
Taking the lock from process context with softirqs enabled while the
same lock is also taken from softirq context can deadlock if the
softirq interrupts the lock holder on the same CPU. Lockdep reports:
WARNING: inconsistent lock state
inconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage.
...
spin_lock include/linux/spinlock.h:347 [inline]
ccp_raw_event+0x51/0x110 drivers/hwmon/corsair-cpro.c:161
__hid_input_report+0x41c/0x580 drivers/hid/hid-core.c:2175
hid_irq_in+0x492/0x710 drivers/hid/usbhid/hid-core.c:287
__usb_hcd_giveback_urb+0x378/0x540 drivers/usb/core/hcd.c:1657
dummy_timer+0xa91/0x4cc0 drivers/usb/gadget/udc/dummy_hcd.c:2023
For the same reason, the spin_lock_bh() in send_usb_cmd() is not
sufficient when ccp_raw_event() is called from hard interrupt context.
Use spin_lock_irqsave() in ccp_raw_event(), since it may be called with
interrupts already disabled, and spin_lock_irq() in send_usb_cmd(),
which always runs in process context.
Fixes: d02abd57e794 ("hwmon: (corsair-cpro) Protect ccp->wait_input_report with a spinlock")
Reported-by: syzbot+0f98b0c0bdeaab2dc2fd@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=0f98b0c0bdeaab2dc2fd
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Sanan Hasanov <sanan.hasanov@xxxxxxx>
---
drivers/hwmon/corsair-cpro.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/hwmon/corsair-cpro.c b/drivers/hwmon/corsair-cpro.c
index c09645152..e6d31d367 100644
--- a/drivers/hwmon/corsair-cpro.c
+++ b/drivers/hwmon/corsair-cpro.c
@@ -135,9 +135,9 @@ static int send_usb_cmd(struct ccp_device *ccp, u8 command, u8 byte1, u8 byte2,
* the raw event parsing and marked the ccp->wait_input_report
* completion as done.
*/
- spin_lock_bh(&ccp->wait_input_report_lock);
+ spin_lock_irq(&ccp->wait_input_report_lock);
reinit_completion(&ccp->wait_input_report);
- spin_unlock_bh(&ccp->wait_input_report_lock);
+ spin_unlock_irq(&ccp->wait_input_report_lock);
ret = hid_hw_output_report(ccp->hdev, ccp->cmd_buffer, OUT_BUFFER_SIZE);
if (ret < 0)
@@ -156,15 +156,16 @@ static int send_usb_cmd(struct ccp_device *ccp, u8 command, u8 byte1, u8 byte2,
static int ccp_raw_event(struct hid_device *hdev, struct hid_report *report, u8 *data, int size)
{
struct ccp_device *ccp = hid_get_drvdata(hdev);
+ unsigned long flags;
/* only copy buffer when requested */
- spin_lock(&ccp->wait_input_report_lock);
+ spin_lock_irqsave(&ccp->wait_input_report_lock, flags);
if (!completion_done(&ccp->wait_input_report)) {
memcpy(ccp->buffer, data, min(IN_BUFFER_SIZE, size));
ccp->buffer_recv_size = size;
complete_all(&ccp->wait_input_report);
}
- spin_unlock(&ccp->wait_input_report_lock);
+ spin_unlock_irqrestore(&ccp->wait_input_report_lock, flags);
return 0;
}
base-commit: 6c377d19d4a5116d9bec5203aa3c6c11523e7898
--
2.48.1