Re: [PATCH v2 0/2] wifi: carl9170: revert broken devres conversions for input and hwrng

From: Christian Lamparter

Date: Fri Oct 09 2026 - 15:48:13 EST


On 10/8/26 11:39 AM, Dmitry Torokhov wrote:
Commits 23de0fa0d2a0 ("carl9170: devres-ing hwrng_register usage") and
87ddb2fc29f1 ("carl9170: devres-ing input_allocate_device") converted
the HWRNG and WPS button input device registrations in carl9170 to
devres attached to the parent struct usb_device (&ar->udev->dev) and
removed explicit unregistration from carl9170_unregister().

In carl9170_usb_disconnect(), the driver calls carl9170_unregister()
followed immediately by carl9170_free(), which frees struct ar9170
inside the interface .disconnect() callback before devres_release_all()
runs. Furthermore, devres on &ar->udev->dev is not released on
interface unbind or registration failure in carl9170_register().
As a result, both the WPS input device (whose input->name and
input->phys point into freed memory) and the embedded struct hwrng
remain registered after struct ar9170 has been freed, leading to
use-after-free bugs.

Ok, so you just reworded your patch? Sight...

looking at the WPS input


| snprintf(ar->wps.name, sizeof(ar->wps.name), "%s WPS Button",
| wiphy_name(ar->hw->wiphy));
|
| snprintf(ar->wps.phys, sizeof(ar->wps.phys),
| "ieee80211/%s/input0", wiphy_name(ar->hw->wiphy));
|
| input->name = ar->wps.name;
| input->phys = ar->wps.phys;
| input->id.bustype = BUS_USB;
| input->dev.parent = &ar->hw->wiphy->dev;
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

the input's dev.parent is set to ar->hw->wiphy->dev and not ar->udev->dev, right?
Does this do anything at all? If not, why? The wiphy gets shutdown by
ieee80211_unregister() and having the "freeing" stick around after the USB device
is gone should not hurt, right?

As for the hwrng, wouldn't it make sense to use the wiphy dev there as well?
So the whole reverting can be sidestepped by simply going with wiphy dev.

Cheers,
Christian