]> git.ipfire.org Git - thirdparty/linux.git/commit
i2c: imx: Fix slave registration race and error handling
authorLiem <liem16213@gmail.com>
Mon, 29 Jun 2026 02:38:28 +0000 (10:38 +0800)
committerAndi Shyti <andi.shyti@kernel.org>
Tue, 28 Jul 2026 21:23:20 +0000 (23:23 +0200)
commitd64ec362c369bbc33833f7936d5f3a706b0d5c45
tree1cbe2afc48b944497a34746d482402166dac8df0
parent98f2e9e6d6f91a6abb43f166b244b428ba85fa2b
i2c: imx: Fix slave registration race and error handling

In i2c_imx_reg_slave(), the slave pointer was assigned before
pm_runtime_resume_and_get().  If pm_runtime_resume_and_get() failed,
the error path returned without clearing i2c_imx->slave, leaving it
non-NULL and causing all subsequent registration attempts to fail
with -EBUSY.

Additionally, because this driver uses a shared IRQ, the interrupt
handler i2c_imx_isr() can execute concurrently and, after acquiring
slave_lock, dereference i2c_imx->slave.  The previous fix attempt
added a lockless i2c_imx->slave = NULL on the error path, but that
could race with the ISR under the lock and still cause a NULL pointer
dereference.

Fix both issues by deferring the assignment of i2c_imx->slave and
i2c_imx->last_slave_event to after a successful resume, and by
performing the assignment inside the slave_lock critical section.
This guarantees that the slave pointer is never left stale on the
error path and is always valid when observed by the interrupt handler.

Fixes: f7414cd6923f ("i2c: imx: support slave mode for imx I2C driver")
Signed-off-by: Liem <liem16213@gmail.com>
Cc: <stable@vger.kernel.org> # v5.11+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Acked-by: Carlos Song <carlos.song@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260629023829.152651-2-liem16213@gmail.com
drivers/i2c/busses/i2c-imx.c