* [PATCH 1/4] iio: accel: adxl313: reject devices without match data
2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
@ 2026-09-25 12:43 ` Jiale Yao
2026-09-25 12:43 ` [PATCH 2/4] iio: accel: adxl372: " Jiale Yao
` (3 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Jiale Yao @ 2026-09-25 12:43 UTC (permalink / raw)
To: Lucas Stankus, Nuno Sá,
Michael Hennerich, Jonathan Cameron, David Lechner,
Andy Shevchenko, Krzysztof Kozlowski, linux, linux-iio,
linux-kernel
Cc: Jiale Yao, stable
SPI driver_override allows a device to bind to this driver without
matching either the OF or SPI device ID table. In that case,
spi_get_device_match_data() returns NULL.
adxl313_spi_probe() dereferences chip_data to select the regmap
configuration, causing a NULL pointer dereference.
Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match
data") fixed the same driver_override issue in another SPI driver.
Reject devices without match data before selecting the configuration.
Fixes: d6e3ee74d16f ("iio: accel: adxl313: simplify with spi_get_device_match_data()")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/iio/accel/adxl313_spi.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/iio/accel/adxl313_spi.c b/drivers/iio/accel/adxl313_spi.c
index a61295de104f..0f0da44461f7 100644
--- a/drivers/iio/accel/adxl313_spi.c
+++ b/drivers/iio/accel/adxl313_spi.c
@@ -79,6 +79,8 @@ static int adxl313_spi_probe(struct spi_device *spi)
return ret;
chip_data = spi_get_device_match_data(spi);
+ if (!chip_data)
+ return -ENODATA;
regmap = devm_regmap_init_spi(spi,
&adxl31x_spi_regmap_config[chip_data->type]);
--
2.34.1
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH 2/4] iio: accel: adxl372: reject devices without match data
2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
2026-09-25 12:43 ` [PATCH 1/4] iio: accel: adxl313: reject " Jiale Yao
@ 2026-09-25 12:43 ` Jiale Yao
2026-09-25 12:43 ` [PATCH 3/4] iio: accel: adxl380: " Jiale Yao
` (2 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Jiale Yao @ 2026-09-25 12:43 UTC (permalink / raw)
To: Nuno Sá,
Michael Hennerich, Marcelo Schmitt, Antoniu Miclaus,
Jonathan Cameron, David Lechner, Andy Shevchenko, linux,
linux-iio, linux-kernel
Cc: Jiale Yao, stable
SPI driver_override allows a device to bind to this driver without
matching either the OF or SPI device ID table. In that case,
spi_get_device_match_data() returns NULL.
adxl372_spi_probe() passes the result to adxl372_probe(), which
dereferences chip_info to set the IIO device name and capabilities,
causing a NULL pointer dereference.
Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match
data") fixed the same driver_override issue in another SPI driver.
Reject devices without match data in the SPI frontend.
Fixes: 23d742859a2d ("iio: accel: adxl372: introduce chip_info structure")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/iio/accel/adxl372_spi.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/iio/accel/adxl372_spi.c b/drivers/iio/accel/adxl372_spi.c
index 128e148c4e96..d54544d6df6f 100644
--- a/drivers/iio/accel/adxl372_spi.c
+++ b/drivers/iio/accel/adxl372_spi.c
@@ -25,6 +25,8 @@ static int adxl372_spi_probe(struct spi_device *spi)
struct regmap *regmap;
chip_info = spi_get_device_match_data(spi);
+ if (!chip_info)
+ return -ENODATA;
regmap = devm_regmap_init_spi(spi, &adxl372_spi_regmap_config);
if (IS_ERR(regmap))
--
2.34.1
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH 3/4] iio: accel: adxl380: reject devices without match data
2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
2026-09-25 12:43 ` [PATCH 1/4] iio: accel: adxl313: reject " Jiale Yao
2026-09-25 12:43 ` [PATCH 2/4] iio: accel: adxl372: " Jiale Yao
@ 2026-09-25 12:43 ` Jiale Yao
2026-09-25 12:43 ` [PATCH 4/4] iio: accel: sca3000: " Jiale Yao
2026-09-27 17:51 ` [PATCH 0/4] iio: accel: reject SPI " Jonathan Cameron
4 siblings, 0 replies; 6+ messages in thread
From: Jiale Yao @ 2026-09-25 12:43 UTC (permalink / raw)
To: Nuno Sá,
Michael Hennerich, Ramona Gradinariu, Antoniu Miclaus,
Jonathan Cameron, David Lechner, Andy Shevchenko, linux,
linux-iio, linux-kernel
Cc: Jiale Yao, stable
SPI driver_override allows a device to bind to this driver without
matching either the OF or SPI device ID table. In that case,
spi_get_device_match_data() returns NULL.
adxl380_spi_probe() passes the result to adxl380_probe(), which
dereferences chip_info to set the IIO device name and operations,
causing a NULL pointer dereference.
Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match
data") fixed the same driver_override issue in another SPI driver.
Reject devices without match data in the SPI frontend.
Fixes: df36de13677a ("iio: accel: add ADXL380 driver")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/iio/accel/adxl380_spi.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/iio/accel/adxl380_spi.c b/drivers/iio/accel/adxl380_spi.c
index ae8467f4e6c0..8ffb3a8690a6 100644
--- a/drivers/iio/accel/adxl380_spi.c
+++ b/drivers/iio/accel/adxl380_spi.c
@@ -25,6 +25,8 @@ static int adxl380_spi_probe(struct spi_device *spi)
struct regmap *regmap;
chip_data = spi_get_device_match_data(spi);
+ if (!chip_data)
+ return -ENODATA;
regmap = devm_regmap_init_spi(spi, &adxl380_spi_regmap_config);
if (IS_ERR(regmap))
--
2.34.1
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH 4/4] iio: accel: sca3000: reject devices without match data
2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
` (2 preceding siblings ...)
2026-09-25 12:43 ` [PATCH 3/4] iio: accel: adxl380: " Jiale Yao
@ 2026-09-25 12:43 ` Jiale Yao
2026-09-27 17:51 ` [PATCH 0/4] iio: accel: reject SPI " Jonathan Cameron
4 siblings, 0 replies; 6+ messages in thread
From: Jiale Yao @ 2026-09-25 12:43 UTC (permalink / raw)
To: Jonathan Cameron, David Lechner, Nuno Sá,
Andy Shevchenko, Harshit Mogalapalli,
Uwe Kleine-König (The Capable Hub),
Antoniu Miclaus, linux-iio, linux-kernel
Cc: Jiale Yao, stable
SPI driver_override allows a device to bind to this driver without
matching either the OF or SPI device ID table. In that case,
spi_get_device_match_data() returns NULL.
sca3000_probe() immediately dereferences the returned chip information
to set the IIO device name and channel layout, causing a NULL pointer
dereference.
Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match
data") fixed the same driver_override issue in another SPI driver.
Reject devices without match data before using the chip information.
Fixes: d6ae9f202f61 ("iio: sca3000: simplify with spi_get_device_match_data()")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/iio/accel/sca3000.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/iio/accel/sca3000.c b/drivers/iio/accel/sca3000.c
index a92a563f6a4b..0d5ed244a663 100644
--- a/drivers/iio/accel/sca3000.c
+++ b/drivers/iio/accel/sca3000.c
@@ -1462,6 +1462,8 @@ static int sca3000_probe(struct spi_device *spi)
st->us = spi;
mutex_init(&st->lock);
st->info = spi_get_device_match_data(spi);
+ if (!st->info)
+ return -ENODATA;
indio_dev->name = st->info->name;
indio_dev->info = &sca3000_info;
--
2.34.1
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH 0/4] iio: accel: reject SPI devices without match data
2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
` (3 preceding siblings ...)
2026-09-25 12:43 ` [PATCH 4/4] iio: accel: sca3000: " Jiale Yao
@ 2026-09-27 17:51 ` Jonathan Cameron
4 siblings, 0 replies; 6+ messages in thread
From: Jonathan Cameron @ 2026-09-27 17:51 UTC (permalink / raw)
To: Jiale Yao
Cc: Lucas Stankus, Nuno Sá,
Michael Hennerich, David Lechner, Andy Shevchenko,
Marcelo Schmitt, Antoniu Miclaus, Ramona Gradinariu,
Harshit Mogalapalli, Linus Walleij,
Uwe Kleine-König (The Capable Hub),
Krzysztof Kozlowski, linux, linux-iio, linux-kernel
On Fri, 25 Sep 2026 20:43:27 +0800
Jiale Yao <yaojiale02@163.com> wrote:
> SPI driver_override can bind a device to a driver without a matching OF
> entry or SPI device ID. In that case, spi_get_device_match_data() returns
> NULL.
>
> The ADXL313, ADXL372, ADXL380, and SCA3000 SPI probe paths assume that the
> returned chip information is present and later dereference it. Reject
> devices without match data before the pointer is used, following the
> handling added to the AD5686 bus frontends by commit 572a00852635 ("iio:
> dac: ad5686: missing NULL check on match data").
>
> Each patch fixes one driver and can be applied independently.
Applied.
Thanks,
Jonathan
>
> Jiale Yao (4):
> iio: accel: adxl313: reject devices without match data
> iio: accel: adxl372: reject devices without match data
> iio: accel: adxl380: reject devices without match data
> iio: accel: sca3000: reject devices without match data
>
> drivers/iio/accel/adxl313_spi.c | 2 ++
> drivers/iio/accel/adxl372_spi.c | 2 ++
> drivers/iio/accel/adxl380_spi.c | 2 ++
> drivers/iio/accel/sca3000.c | 2 ++
> 4 files changed, 8 insertions(+)
>
> base-commit: 93f51579e7df248780214094418f205253383cc5
^ permalink raw reply [flat|nested] 6+ messages in thread