HID: steam: Rearrange teardown sequence

This fixes a narrow window during the teardown sequence where callbacks
could still be scheduled during cleanup that would then have a dangling
pointer to the now-freed steam struct.

This also puts work canceling for rumble and mode switch in
steam_unregister, as that shouldn't persist while the client hdev is open.

Signed-off-by: Vicki Pfau <vi@endrift.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
This commit is contained in:
Vicki Pfau 2026-07-29 21:12:30 -07:00 committed by Jiri Kosina
parent cd33a91d37
commit ddce9641ce

View File

@ -1156,6 +1156,9 @@ static void steam_unregister(struct steam_device *steam)
steam_battery_unregister(steam);
steam_sensors_unregister(steam);
steam_input_unregister(steam);
cancel_work_sync(&steam->rumble_work);
cancel_delayed_work_sync(&steam->mode_switch);
cancel_delayed_work_sync(&steam->coalesce_rumble_work);
mutex_lock(&steam_devices_lock);
list_del_init(&steam->list);
mutex_unlock(&steam_devices_lock);
@ -1441,25 +1444,24 @@ static int steam_probe(struct hid_device *hdev,
static void steam_remove(struct hid_device *hdev)
{
struct steam_device *steam = hid_get_drvdata(hdev);
unsigned long flags;
if (!steam || hdev->group == HID_GROUP_STEAM) {
hid_hw_stop(hdev);
return;
}
hid_hw_close(hdev);
hid_destroy_device(steam->client_hdev);
cancel_delayed_work_sync(&steam->mode_switch);
cancel_work_sync(&steam->work_connect);
cancel_work_sync(&steam->rumble_work);
cancel_delayed_work_sync(&steam->coalesce_rumble_work);
steam->client_hdev = NULL;
spin_lock_irqsave(&steam->lock, flags);
steam->client_opened = 0;
spin_unlock_irqrestore(&steam->lock, flags);
cancel_work_sync(&steam->work_connect);
if (steam->quirks & STEAM_QUIRK_WIRELESS) {
hid_info(hdev, "Steam wireless receiver disconnected");
}
hid_hw_close(hdev);
hid_hw_stop(hdev);
steam_unregister(steam);
hid_hw_stop(hdev);
}
static void steam_do_connect_event(struct steam_device *steam, bool connected)