Skip to content

Commit 6af713a

Browse files
abdurrahman-nexthopgroeck
authored andcommitted
hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe()
adm1266_probe() calls adm1266_config_nvmem() -- which goes on to devm_nvmem_register() and exposes adm1266_nvmem_read() to userspace -- before pmbus_do_probe() has initialised the per-client PMBus state. Same latent hazard as the gpio_chip one fixed in the previous patch: once the nvmem device is registered, gpiolib's nvmem char-dev / sysfs interface is reachable, and any concurrent read triggers adm1266_nvmem_read() -> adm1266_nvmem_read_blackbox(), which issues PMBus traffic that races pmbus_do_probe()'s own device accesses with no serialisation. Move adm1266_config_nvmem() down past pmbus_do_probe() so the nvmem device isn't reachable from userspace until the PMBus state the nvmem accessors depend on is fully initialised. Fixes: 15609d1 ("hwmon: (pmbus/adm1266) read blackbox") Cc: stable@vger.kernel.org Signed-off-by: Abdurrahman Hussain <abdurrahman@nexthop.ai> Link: https://lore.kernel.org/r/20260518-adm1266-gpio-fixes-v3-5-e425e4f88139@nexthop.ai Signed-off-by: Guenter Roeck <linux@roeck-us.net>
1 parent 491403b commit 6af713a

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

drivers/hwmon/pmbus/adm1266.c

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -477,14 +477,14 @@ static int adm1266_probe(struct i2c_client *client)
477477
if (ret < 0)
478478
return ret;
479479

480-
ret = adm1266_config_nvmem(data);
481-
if (ret < 0)
482-
return ret;
483-
484480
ret = pmbus_do_probe(client, &data->info);
485481
if (ret)
486482
return ret;
487483

484+
ret = adm1266_config_nvmem(data);
485+
if (ret < 0)
486+
return ret;
487+
488488
ret = adm1266_config_gpio(data);
489489
if (ret < 0)
490490
return ret;

0 commit comments

Comments
 (0)