input: fingerprint: etxxx: Fix CFI failure on module init

[    2.458802] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010
[    2.459516] Internal error: Oops: 96000005 [#1] PREEMPT SMP
[    2.459788] Modules linked in: ec617_drv(+) wcd9xxx_dlkm(+) bolero_cdc_dlkm(+) mbhc_dlkm stub_dlkm q6_dlkm adsp_loader_dlkm leds_aw2016 wcd937x_slave_dlkm rdbg focaltech_fts sec_ts_drv(+) p73 btpower apr_dlkm wcd938x_slave_dlkm wsa881x_analog_dlkm bu520x1nvx q6_notifier_dlkm rmnet_shs wcd_core_dlkm rmnet_offload q6_pdr_dlkm haptic snd_event_dlkm rmnet_core swr_dlkm rmnet_ctl snx0
[    2.460075] CPU: 2 PID: 546 Comm: modprobe Tainted: G S                5.4.302-qgki-g3972ebf038eb #3
[    2.460221] Hardware name: Sony Mobile Communications. PDX225(BLAIR v4) (DT)
[    2.460285] pstate: 80400005 (Nzcv daif +PAN -UAO)
[    2.460398] pc : __cfi_check_fail+0x4/0x50 [ec617_drv]
[    2.460457] lr : __cfi_check+0x1ac/0x1e0 [ec617_drv]
[    2.460912] x21: 02b3a43e29242445 x20: 0000000000000010
[    2.462187] Call trace:
[    2.462240]  __cfi_check_fail+0x4/0x50 [ec617_drv]
[    2.462332]  __cfi_slowpath+0x10c/0x168
[    2.462383]  do_one_initcall+0x1dc/0x384
[    2.462435]  do_init_module+0x4c/0x204
[    2.462522]  load_module+0x1734/0x18c0
[    2.462569]  __arm64_sys_finit_module+0xb4/0xf0
[    2.462617]  el0_svc_common+0xc0/0x1a8
[    2.462698]  el0_svc_handler+0x24/0x70
[    2.462745]  el0_svc+0x8/0x100
[    2.462877] ---[ end trace 711a96c503b0de92 ]---
[    2.481911] Kernel panic - not syncing: Fatal exception

module_init()/module_exit() define init_module/cleanup_module as aliases
of the given functions. With clang r584948 and cross-DSO CFI, such an
alias only gets its own jump table entry when the aliasee has internal
linkage. Since egisfp_init()/egisfp_exit() were declared non-static,
modpost ended up pointing __this_module.init at the raw .init.text
address instead of init_module.cfi_jt:

  R_AARCH64_ABS64  init_module + 0
  R_AARCH64_ABS64  cleanup_module + 0

__cfi_check() then compared the initcall pointer (type id
02b3a43e29242445) against egisfp_init.cfi_jt, failed, and jumped to
__cfi_check_fail(), which faulted while dereferencing its bogus diag
argument.

Make both functions static, as they should have been in the first place.
The relocations now resolve to the jump table:

  R_AARCH64_ABS64  init_module.cfi_jt + 0
  R_AARCH64_ABS64  cleanup_module.cfi_jt + 0

Assisted-by: ClaudeCode:claude-opus-5
Change-Id: I3bf5a698bc5103e1fe0ae13e4c9c52cad9b41c7e
This commit is contained in:
LuK1337 2026-08-28 11:11:07 +02:00 • committed by Michael Bestas
commit aba9e36d0f
No known key found for this signature in database
3 changed files with 6 additions and 6 deletions

View file

@ -1543,7 +1543,7 @@ egistec_probe_failed:
return status;
}
int __init egisfp_init(void)
static int __init egisfp_init(void)
{
int status;
INFO_PRINT(" %s : module init \n", __func__);
@ -1556,7 +1556,7 @@ int __init egisfp_init(void)
INFO_PRINT(" %s : module init OK ! \n", __func__);
return status;
}
void __exit egisfp_exit(void)
static void __exit egisfp_exit(void)
{
INFO_PRINT("module exit \n");
platform_driver_unregister(&egisfp_driver);

View file

@ -1473,7 +1473,7 @@ egistec_probe_failed:
return status;
}
int __init egisfp_init(void)
static int __init egisfp_init(void)
{
int status;
INFO_PRINT(" %s : module init \n", __func__);
@ -1486,7 +1486,7 @@ int __init egisfp_init(void)
INFO_PRINT(" %s : module init OK ! \n", __func__);
return status;
}
void __exit egisfp_exit(void)
static void __exit egisfp_exit(void)
{
INFO_PRINT("module exit \n");
platform_driver_unregister(&egisfp_driver);

View file

@ -1389,7 +1389,7 @@ egistec_probe_failed:
return status;
}
int __init egisfp_init(void)
static int __init egisfp_init(void)
{
int status;
INFO_PRINT(" %s : module init \n", __func__);
@ -1402,7 +1402,7 @@ int __init egisfp_init(void)
INFO_PRINT(" %s : module init OK ! \n", __func__);
return status;
}
void __exit egisfp_exit(void)
static void __exit egisfp_exit(void)
{
INFO_PRINT("module exit \n");
platform_driver_unregister(&egisfp_driver);