summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorPengpeng Hou <pengpeng@iscas.ac.cn>2026-06-15 14:31:05 +0800
committerSebastian Reichel <sebastian.reichel@collabora.com>2026-07-21 22:28:10 +0200
commit631adfa03595c63b2a621cdc62db60bb1ce5f91c (patch)
tree260666def9133aa1c05f2cb7a33a25a59afdd6ad
parent402684c39cb911bc772ffc13bfee95ab57cdd2f1 (diff)
power: supply: cros_pchg: unregister EC notifier
cros_pchg_probe() registers an EC event notifier whose callback uses the devm-allocated charger_data via container_of(). The driver has no remove callback and does not unregister the notifier, so the notifier chain can retain a pointer to freed driver state after unbind or probe cleanup. Register a devm cleanup action immediately after the notifier is installed so the notifier is unregistered before the driver state is released. Also fail probe if the notifier cannot be registered, instead of leaving a charger device that cannot receive EC events. Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn> Reviewed-by: Tzung-Bi Shih <tzungbi@kernel.org> Link: https://patch.msgid.link/20260615063105.39152-1-pengpeng@iscas.ac.cn Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
-rw-r--r--drivers/power/supply/cros_peripheral_charger.c13
1 files changed, 11 insertions, 2 deletions
diff --git a/drivers/power/supply/cros_peripheral_charger.c b/drivers/power/supply/cros_peripheral_charger.c
index 9f67a6dbd94e..0f4e34710b46 100644
--- a/drivers/power/supply/cros_peripheral_charger.c
+++ b/drivers/power/supply/cros_peripheral_charger.c
@@ -259,6 +259,14 @@ static int cros_ec_notify(struct notifier_block *nb,
return cros_pchg_event(charger);
}
+static void cros_pchg_unregister_notifier(void *data)
+{
+ struct charger_data *charger = data;
+
+ blocking_notifier_chain_unregister(&charger->ec_device->event_notifier,
+ &charger->notifier);
+}
+
static int cros_pchg_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
@@ -346,9 +354,10 @@ static int cros_pchg_probe(struct platform_device *pdev)
ret = blocking_notifier_chain_register(&ec_dev->ec_dev->event_notifier,
nb);
if (ret < 0)
- dev_err(dev, "Failed to register notifier (err:%d)\n", ret);
+ return dev_err_probe(dev, ret, "Failed to register notifier\n");
- return 0;
+ return devm_add_action_or_reset(dev, cros_pchg_unregister_notifier,
+ charger);
}
#ifdef CONFIG_PM_SLEEP