[PATCH v2 1/2] Input: discard pre-registration events before attaching handlers

From: Karlos Abel

Date: Sat Oct 10 2026 - 15:11:02 EST


input_event() permits drivers to seed switch and absolute-axis state
before registration without delivering those events to input handlers.
After event-buffer allocation moved to input_allocate_device(), such
initialization events can remain queued across input_register_device()
when the buffer does not need resizing.

A later injected LED event followed by SYN_REPORT then delivers the old
switch event to newly attached handlers. This was observed with the
initial SW_RFKILL_ALL event from thinkpad_acpi on a ThinkPad T14 Gen 6:
an LED update replayed the initial radio-switch event after registration.
Registration can also leave a pre-registration timestamp attached to the
first real event packet, including when the event buffer is resized.

Clear the pending event count and monotonic timestamp under event_lock
before attaching handlers. Keep the switch and absolute-axis state that
was seeded by those events. Resetting the monotonic timestamp follows the
existing flush path and lets the next packet obtain a fresh timestamp.

Fixes: 0cd587735205 ("Input: preallocate memory to hold event values")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Karlos Abel <kabel@xxxxxxxxxxxx>
---
drivers/input/input.c | 6 ++++++
1 file changed, 6 insertions(+)

diff --git a/drivers/input/input.c b/drivers/input/input.c
index 01c91fec9..d59d62caa 100644
--- a/drivers/input/input.c
+++ b/drivers/input/input.c
@@ -2445,6 +2445,12 @@ int input_register_device(struct input_dev *dev)

error = -EINTR;
scoped_cond_guard(mutex_intr, goto err_device_del, &input_mutex) {
+ /* Keep seeded state, but do not replay pre-registration events. */
+ scoped_guard(spinlock_irq, &dev->event_lock) {
+ dev->num_vals = 0;
+ dev->timestamp[INPUT_CLK_MONO] = ktime_set(0, 0);
+ }
+
list_add_tail(&dev->node, &input_dev_list);

list_for_each_entry(handler, &input_handler_list, node)