Commit 8444d66aa6b6 for kernel

commit 8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783
Author: Hongyan Xu <getshell@seu.edu.cn>
Date:   Thu Aug 6 14:06:13 2026 +0800

    watchdog: at91sam9_wdt: prevent timer rearm during teardown

    at91_ping() rearms the watchdog timer from its callback. timer_delete()
    neither waits for a running callback nor prevents it from rearming the
    timer, so probe failure or driver removal can leave the timer accessing the
    devm-allocated at91wdt after it has been freed.

    Use timer_shutdown_sync() on both teardown paths. It waits for a running
    callback and rejects any attempt by the callback to rearm the timer.

    Fixes: 5161b31dc39a ("watchdog: at91sam9_wdt: better watchdog support")
    Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
    Link: https://lore.kernel.org/r/20260806060613.1830-1-getshell@seu.edu.cn
    Signed-off-by: Guenter Roeck <linux@roeck-us.net>

diff --git a/drivers/watchdog/at91sam9_wdt.c b/drivers/watchdog/at91sam9_wdt.c
index aba66b8e9d03..80ba04df54ad 100644
--- a/drivers/watchdog/at91sam9_wdt.c
+++ b/drivers/watchdog/at91sam9_wdt.c
@@ -242,7 +242,7 @@ static int at91_wdt_init(struct platform_device *pdev, struct at91wdt *wdt)
 	return 0;

 out_stop_timer:
-	timer_delete(&wdt->timer);
+	timer_shutdown_sync(&wdt->timer);
 	return err;
 }

@@ -378,7 +378,7 @@ static void at91wdt_remove(struct platform_device *pdev)
 	watchdog_unregister_device(&wdt->wdd);

 	pr_warn("I quit now, hardware will probably reboot!\n");
-	timer_delete(&wdt->timer);
+	timer_shutdown_sync(&wdt->timer);
 }

 #if defined(CONFIG_OF)