Skip to content

input: joystick: adc-joystick: guard against NULL active_scan_mask - #17

Open
wormuz wants to merge 1 commit into
OpenDingux:jz-6.13from
wormuz:fix/adc-joystick-null-scan-mask
Open

input: joystick: adc-joystick: guard against NULL active_scan_mask#17
wormuz wants to merge 1 commit into
OpenDingux:jz-6.13from
wormuz:fix/adc-joystick-null-scan-mask

Conversation

@wormuz

@wormuz wormuz commented Aug 15, 2026

Copy link
Copy Markdown

adc_joystick_get_chan_offsets() dereferences indio_dev->active_scan_mask without checking it. The mask is only allocated once the IIO buffer is enabled; when adc-joystick binds before the buffer setup has run, the pointer is NULL and test_bit() faults.

Observed as a probe-time oops on an RG350P handheld (JZ4770, ingenic-adc).

adc_joystick_get_chan_offsets() dereferences
indio_dev->active_scan_mask without checking it. The mask is only
allocated once the IIO buffer is enabled; when the joystick probes
against a driver whose buffer setup has not run yet (or was torn
down), the pointer is NULL and test_bit() faults.

Observed as a probe-time oops on JZ4770 (RG350P handheld) with the
ingenic-adc driver, where adc-joystick can bind before the IIO
buffer exists.

Treat a NULL mask the same as a channel without a valid scan index:
mark the offset as -1 and fall back to per-channel reads.

Signed-off-by: wormuz <3341798+wormuz@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant