mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/4] iio: accel: reject SPI devices without match data
@ 2026-09-25 12:43 Jiale Yao
  2026-09-25 12:43 ` [PATCH 1/4] iio: accel: adxl313: reject " Jiale Yao
                   ` (4 more replies)
  0 siblings, 5 replies; 6+ messages in thread
From: Jiale Yao @ 2026-09-25 12:43 UTC (permalink / raw)
  To: Lucas Stankus, Nuno Sá,
	Michael Hennerich, Jonathan Cameron, David Lechner,
	Andy Shevchenko, Marcelo Schmitt, Antoniu Miclaus,
	Ramona Gradinariu, Harshit Mogalapalli, Linus Walleij,
	Uwe Kleine-König (The Capable Hub),
	Krzysztof Kozlowski, linux, linux-iio, linux-kernel
  Cc: Jiale Yao

SPI driver_override can bind a device to a driver without a matching OF
entry or SPI device ID. In that case, spi_get_device_match_data() returns
NULL.

The ADXL313, ADXL372, ADXL380, and SCA3000 SPI probe paths assume that the
returned chip information is present and later dereference it. Reject
devices without match data before the pointer is used, following the
handling added to the AD5686 bus frontends by commit 572a00852635 ("iio:
dac: ad5686: missing NULL check on match data").

Each patch fixes one driver and can be applied independently.

Jiale Yao (4):
  iio: accel: adxl313: reject devices without match data
  iio: accel: adxl372: reject devices without match data
  iio: accel: adxl380: reject devices without match data
  iio: accel: sca3000: reject devices without match data

 drivers/iio/accel/adxl313_spi.c | 2 ++
 drivers/iio/accel/adxl372_spi.c | 2 ++
 drivers/iio/accel/adxl380_spi.c | 2 ++
 drivers/iio/accel/sca3000.c     | 2 ++
 4 files changed, 8 insertions(+)

base-commit: 93f51579e7df248780214094418f205253383cc5
-- 
2.34.1


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 1/4] iio: accel: adxl313: reject devices without match data
  2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
@ 2026-09-25 12:43 ` Jiale Yao
  2026-09-25 12:43 ` [PATCH 2/4] iio: accel: adxl372: " Jiale Yao
                   ` (3 subsequent siblings)
  4 siblings, 0 replies; 6+ messages in thread
From: Jiale Yao @ 2026-09-25 12:43 UTC (permalink / raw)
  To: Lucas Stankus, Nuno Sá,
	Michael Hennerich, Jonathan Cameron, David Lechner,
	Andy Shevchenko, Krzysztof Kozlowski, linux, linux-iio,
	linux-kernel
  Cc: Jiale Yao, stable

SPI driver_override allows a device to bind to this driver without
matching either the OF or SPI device ID table. In that case,
spi_get_device_match_data() returns NULL.

adxl313_spi_probe() dereferences chip_data to select the regmap
configuration, causing a NULL pointer dereference.

Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match
data") fixed the same driver_override issue in another SPI driver.
Reject devices without match data before selecting the configuration.

Fixes: d6e3ee74d16f ("iio: accel: adxl313: simplify with spi_get_device_match_data()")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/iio/accel/adxl313_spi.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/iio/accel/adxl313_spi.c b/drivers/iio/accel/adxl313_spi.c
index a61295de104f..0f0da44461f7 100644
--- a/drivers/iio/accel/adxl313_spi.c
+++ b/drivers/iio/accel/adxl313_spi.c
@@ -79,6 +79,8 @@ static int adxl313_spi_probe(struct spi_device *spi)
 		return ret;
 
 	chip_data = spi_get_device_match_data(spi);
+	if (!chip_data)
+		return -ENODATA;
 
 	regmap = devm_regmap_init_spi(spi,
 				      &adxl31x_spi_regmap_config[chip_data->type]);
-- 
2.34.1


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 2/4] iio: accel: adxl372: reject devices without match data
  2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
  2026-09-25 12:43 ` [PATCH 1/4] iio: accel: adxl313: reject " Jiale Yao
@ 2026-09-25 12:43 ` Jiale Yao
  2026-09-25 12:43 ` [PATCH 3/4] iio: accel: adxl380: " Jiale Yao
                   ` (2 subsequent siblings)
  4 siblings, 0 replies; 6+ messages in thread
From: Jiale Yao @ 2026-09-25 12:43 UTC (permalink / raw)
  To: Nuno Sá,
	Michael Hennerich, Marcelo Schmitt, Antoniu Miclaus,
	Jonathan Cameron, David Lechner, Andy Shevchenko, linux,
	linux-iio, linux-kernel
  Cc: Jiale Yao, stable

SPI driver_override allows a device to bind to this driver without
matching either the OF or SPI device ID table. In that case,
spi_get_device_match_data() returns NULL.

adxl372_spi_probe() passes the result to adxl372_probe(), which
dereferences chip_info to set the IIO device name and capabilities,
causing a NULL pointer dereference.

Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match
data") fixed the same driver_override issue in another SPI driver.
Reject devices without match data in the SPI frontend.

Fixes: 23d742859a2d ("iio: accel: adxl372: introduce chip_info structure")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/iio/accel/adxl372_spi.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/iio/accel/adxl372_spi.c b/drivers/iio/accel/adxl372_spi.c
index 128e148c4e96..d54544d6df6f 100644
--- a/drivers/iio/accel/adxl372_spi.c
+++ b/drivers/iio/accel/adxl372_spi.c
@@ -25,6 +25,8 @@ static int adxl372_spi_probe(struct spi_device *spi)
 	struct regmap *regmap;
 
 	chip_info = spi_get_device_match_data(spi);
+	if (!chip_info)
+		return -ENODATA;
 
 	regmap = devm_regmap_init_spi(spi, &adxl372_spi_regmap_config);
 	if (IS_ERR(regmap))
-- 
2.34.1


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 3/4] iio: accel: adxl380: reject devices without match data
  2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
  2026-09-25 12:43 ` [PATCH 1/4] iio: accel: adxl313: reject " Jiale Yao
  2026-09-25 12:43 ` [PATCH 2/4] iio: accel: adxl372: " Jiale Yao
@ 2026-09-25 12:43 ` Jiale Yao
  2026-09-25 12:43 ` [PATCH 4/4] iio: accel: sca3000: " Jiale Yao
  2026-09-27 17:51 ` [PATCH 0/4] iio: accel: reject SPI " Jonathan Cameron
  4 siblings, 0 replies; 6+ messages in thread
From: Jiale Yao @ 2026-09-25 12:43 UTC (permalink / raw)
  To: Nuno Sá,
	Michael Hennerich, Ramona Gradinariu, Antoniu Miclaus,
	Jonathan Cameron, David Lechner, Andy Shevchenko, linux,
	linux-iio, linux-kernel
  Cc: Jiale Yao, stable

SPI driver_override allows a device to bind to this driver without
matching either the OF or SPI device ID table. In that case,
spi_get_device_match_data() returns NULL.

adxl380_spi_probe() passes the result to adxl380_probe(), which
dereferences chip_info to set the IIO device name and operations,
causing a NULL pointer dereference.

Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match
data") fixed the same driver_override issue in another SPI driver.
Reject devices without match data in the SPI frontend.

Fixes: df36de13677a ("iio: accel: add ADXL380 driver")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/iio/accel/adxl380_spi.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/iio/accel/adxl380_spi.c b/drivers/iio/accel/adxl380_spi.c
index ae8467f4e6c0..8ffb3a8690a6 100644
--- a/drivers/iio/accel/adxl380_spi.c
+++ b/drivers/iio/accel/adxl380_spi.c
@@ -25,6 +25,8 @@ static int adxl380_spi_probe(struct spi_device *spi)
 	struct regmap *regmap;
 
 	chip_data = spi_get_device_match_data(spi);
+	if (!chip_data)
+		return -ENODATA;
 
 	regmap = devm_regmap_init_spi(spi, &adxl380_spi_regmap_config);
 	if (IS_ERR(regmap))
-- 
2.34.1


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 4/4] iio: accel: sca3000: reject devices without match data
  2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
                   ` (2 preceding siblings ...)
  2026-09-25 12:43 ` [PATCH 3/4] iio: accel: adxl380: " Jiale Yao
@ 2026-09-25 12:43 ` Jiale Yao
  2026-09-27 17:51 ` [PATCH 0/4] iio: accel: reject SPI " Jonathan Cameron
  4 siblings, 0 replies; 6+ messages in thread
From: Jiale Yao @ 2026-09-25 12:43 UTC (permalink / raw)
  To: Jonathan Cameron, David Lechner, Nuno Sá,
	Andy Shevchenko, Harshit Mogalapalli,
	Uwe Kleine-König (The Capable Hub),
	Antoniu Miclaus, linux-iio, linux-kernel
  Cc: Jiale Yao, stable

SPI driver_override allows a device to bind to this driver without
matching either the OF or SPI device ID table. In that case,
spi_get_device_match_data() returns NULL.

sca3000_probe() immediately dereferences the returned chip information
to set the IIO device name and channel layout, causing a NULL pointer
dereference.

Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match
data") fixed the same driver_override issue in another SPI driver.
Reject devices without match data before using the chip information.

Fixes: d6ae9f202f61 ("iio: sca3000: simplify with spi_get_device_match_data()")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/iio/accel/sca3000.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/iio/accel/sca3000.c b/drivers/iio/accel/sca3000.c
index a92a563f6a4b..0d5ed244a663 100644
--- a/drivers/iio/accel/sca3000.c
+++ b/drivers/iio/accel/sca3000.c
@@ -1462,6 +1462,8 @@ static int sca3000_probe(struct spi_device *spi)
 	st->us = spi;
 	mutex_init(&st->lock);
 	st->info = spi_get_device_match_data(spi);
+	if (!st->info)
+		return -ENODATA;
 
 	indio_dev->name = st->info->name;
 	indio_dev->info = &sca3000_info;
-- 
2.34.1


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH 0/4] iio: accel: reject SPI devices without match data
  2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
                   ` (3 preceding siblings ...)
  2026-09-25 12:43 ` [PATCH 4/4] iio: accel: sca3000: " Jiale Yao
@ 2026-09-27 17:51 ` Jonathan Cameron
  4 siblings, 0 replies; 6+ messages in thread
From: Jonathan Cameron @ 2026-09-27 17:51 UTC (permalink / raw)
  To: Jiale Yao
  Cc: Lucas Stankus, Nuno Sá,
	Michael Hennerich, David Lechner, Andy Shevchenko,
	Marcelo Schmitt, Antoniu Miclaus, Ramona Gradinariu,
	Harshit Mogalapalli, Linus Walleij,
	Uwe Kleine-König (The Capable Hub),
	Krzysztof Kozlowski, linux, linux-iio, linux-kernel

On Fri, 25 Sep 2026 20:43:27 +0800
Jiale Yao <yaojiale02@163.com> wrote:

> SPI driver_override can bind a device to a driver without a matching OF
> entry or SPI device ID. In that case, spi_get_device_match_data() returns
> NULL.
> 
> The ADXL313, ADXL372, ADXL380, and SCA3000 SPI probe paths assume that the
> returned chip information is present and later dereference it. Reject
> devices without match data before the pointer is used, following the
> handling added to the AD5686 bus frontends by commit 572a00852635 ("iio:
> dac: ad5686: missing NULL check on match data").
> 
> Each patch fixes one driver and can be applied independently.
Applied.

Thanks,

Jonathan

> 
> Jiale Yao (4):
>   iio: accel: adxl313: reject devices without match data
>   iio: accel: adxl372: reject devices without match data
>   iio: accel: adxl380: reject devices without match data
>   iio: accel: sca3000: reject devices without match data
> 
>  drivers/iio/accel/adxl313_spi.c | 2 ++
>  drivers/iio/accel/adxl372_spi.c | 2 ++
>  drivers/iio/accel/adxl380_spi.c | 2 ++
>  drivers/iio/accel/sca3000.c     | 2 ++
>  4 files changed, 8 insertions(+)
> 
> base-commit: 93f51579e7df248780214094418f205253383cc5


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-27 17:51 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-25 12:43 [PATCH 0/4] iio: accel: reject SPI devices without match data Jiale Yao
2026-09-25 12:43 ` [PATCH 1/4] iio: accel: adxl313: reject " Jiale Yao
2026-09-25 12:43 ` [PATCH 2/4] iio: accel: adxl372: " Jiale Yao
2026-09-25 12:43 ` [PATCH 3/4] iio: accel: adxl380: " Jiale Yao
2026-09-25 12:43 ` [PATCH 4/4] iio: accel: sca3000: " Jiale Yao
2026-09-27 17:51 ` [PATCH 0/4] iio: accel: reject SPI " Jonathan Cameron

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®