Re: [cocci] [PATCH 00/21] HID: fix racy force feedback initialization via .input_configured()

Jiri Kosina <[email protected]>
Newsgroups fr.inria.cocci,org.kernel.vger.linux-doc,org.kernel.vger.linux-input,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Mon, 3 Aug 2026, Dmitry Torokhov wrote:

> When a HID driver calls hid_hw_start() with the HID_CONNECT_HIDINPUT
> flag (included in HID_CONNECT_DEFAULT), the HID core immediately registers
> the input device with the input subsystem, making it live and accessible to
> userspace.
> 
> Historically, many HID drivers initialized force-feedback capabilities (via
> input_ff_create_memless() or custom workqueues) in their probe() callback
> after calling hid_hw_start(). This introduces a window where userspace can
> open the input node and trigger force-feedback ioctls before the driver has
> finished preparing its private structures or workqueues, leading to potential
> NULL pointer dereferences and race conditions.

Hm, this has probably been the case for ages indeed. Thanks for noticing.

> To eliminate this anti-pattern across the subsystem, this series:
> - Enhances the HID core to automatically handle driver force-feedback
>   initialization during input device registration.
> - Refactors individual HID drivers to perform all force-feedback setup
>   inside the .input_configured() callback, ensuring the input device is
>   fully prepared before it is exposed to userspace.
> - Adds documentation and a Coccinelle script to prevent future regressions.
> 
> Signed-off-by: Dmitry Torokhov <[email protected]>

Now queued in hid.git#for-7.3/core.

Thanks,

-- 
Jiri Kosina
SUSE Labs
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.