On Fri, Oct 02, 2026 at 11:04:39PM -0400, Myeonghun Pak wrote:
> The interrupt handler queues delayed work to read the interrupt status.
> After free_irq() stops the producer, this work can still be waiting on its
> timer. destroy_workqueue() cannot drain delayed work that has not yet been
> queued by its timer, so the timer can outlive both the workqueue and the
> devm-allocated chip containing the work.
>
> Cancel the delayed work synchronously after freeing the IRQ and before
> destroying the workqueue. This also waits for any running status read to
> finish before the chip's resources are released.
>
> This issue was identified during our ongoing static-analysis research
> while reviewing kernel code.
>
> Fixes: 0c2a665a648e ("backlight: add Backlight driver for lm3630 chip")
> Cc: [email protected]
> Assisted-by: LLM
> Co-developed-by: Ijae Kim <[email protected]>
> Signed-off-by: Ijae Kim <[email protected]>
> Signed-off-by: Myeonghun Pak <[email protected]>Reviewed-by: Daniel Thompson (RISCstar) <[email protected]> Daniel.
