[PATCH] platform/chrome: cros_ec_debugfs: unregister panic notifier

Hongyan Xu <[email protected]> Tue, 28 Jul 2026 20:33:37 +0800
Newsgroups dev.linux.lists.chrome-platform,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
cros_ec_debugfs_probe() registers debug_info->notifier_panic with the EC
panic notifier chain. The remove path tears down debugfs and cancels the
console log work, but leaves the notifier on the chain. A later panic
notification can call back into a removed driver instance and reschedule
the delayed work.

Unregister the notifier before tearing down debugfs state. Also run the
console-log cleanup in the probe error path.

This issue was found by a static analysis tool.

Signed-off-by: Hongyan Xu <[email protected]>
---
 drivers/platform/chrome/cros_ec_debugfs.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/platform/chrome/cros_ec_debugfs.c b/drivers/platform/chrome/cros_ec_debugfs.c
index 92ac9a2f9..6f93aedbd 100644
--- a/drivers/platform/chrome/cros_ec_debugfs.c
+++ b/drivers/platform/chrome/cros_ec_debugfs.c
@@ -534,6 +534,7 @@ static int cros_ec_debugfs_probe(struct platform_device *pd)
 	return 0;
 
 remove_debugfs:
+	cros_ec_cleanup_console_log(debug_info);
 	debugfs_remove_recursive(debug_info->dir);
 	return ret;
 }
@@ -542,6 +543,8 @@ static void cros_ec_debugfs_remove(struct platform_device *pd)
 {
 	struct cros_ec_dev *ec = dev_get_drvdata(pd->dev.parent);
 
+	blocking_notifier_chain_unregister(&ec->ec_dev->panic_notifier,
+					   &ec->debug_info->notifier_panic);
 	debugfs_remove_recursive(ec->debug_info->dir);
 	cros_ec_cleanup_console_log(ec->debug_info);
 }
-- 
2.50.1.windows.1