From 631adfa03595c63b2a621cdc62db60bb1ce5f91c Mon Sep 17 00:00:00 2001 From: Pengpeng Hou Date: Mon, 15 Jun 2026 14:31:05 +0800 Subject: power: supply: cros_pchg: unregister EC notifier cros_pchg_probe() registers an EC event notifier whose callback uses the devm-allocated charger_data via container_of(). The driver has no remove callback and does not unregister the notifier, so the notifier chain can retain a pointer to freed driver state after unbind or probe cleanup. Register a devm cleanup action immediately after the notifier is installed so the notifier is unregistered before the driver state is released. Also fail probe if the notifier cannot be registered, instead of leaving a charger device that cannot receive EC events. Signed-off-by: Pengpeng Hou Reviewed-by: Tzung-Bi Shih Link: https://patch.msgid.link/20260615063105.39152-1-pengpeng@iscas.ac.cn Signed-off-by: Sebastian Reichel --- drivers/power/supply/cros_peripheral_charger.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/drivers/power/supply/cros_peripheral_charger.c b/drivers/power/supply/cros_peripheral_charger.c index 9f67a6dbd94e..0f4e34710b46 100644 --- a/drivers/power/supply/cros_peripheral_charger.c +++ b/drivers/power/supply/cros_peripheral_charger.c @@ -259,6 +259,14 @@ static int cros_ec_notify(struct notifier_block *nb, return cros_pchg_event(charger); } +static void cros_pchg_unregister_notifier(void *data) +{ + struct charger_data *charger = data; + + blocking_notifier_chain_unregister(&charger->ec_device->event_notifier, + &charger->notifier); +} + static int cros_pchg_probe(struct platform_device *pdev) { struct device *dev = &pdev->dev; @@ -346,9 +354,10 @@ static int cros_pchg_probe(struct platform_device *pdev) ret = blocking_notifier_chain_register(&ec_dev->ec_dev->event_notifier, nb); if (ret < 0) - dev_err(dev, "Failed to register notifier (err:%d)\n", ret); + return dev_err_probe(dev, ret, "Failed to register notifier\n"); - return 0; + return devm_add_action_or_reset(dev, cros_pchg_unregister_notifier, + charger); } #ifdef CONFIG_PM_SLEEP -- cgit v1.2.3