All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Vladimir Oltean" <vladimir.oltean@nxp.com>
Cc: neil.armstrong@linaro.org, linux-phy@lists.infradead.org,
	robh@kernel.org, devicetree@vger.kernel.org, olteanv@gmail.com,
	conor+dt@kernel.org, vkoul@kernel.org
Subject: Re: [PATCH v3 phy-next 6/8] dt-bindings: fsl: layerscape-dcfg: define DCFG_DCSR region
Date: Mon, 20 Jul 2026 13:57:50 +0000	[thread overview]
Message-ID: <20260720135750.AEF131F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260720133642.136324-7-vladimir.oltean@nxp.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Dereferencing NULL pointer `soc_dev_attr` on the error path.
--

--- Patch [6]: [PATCH v3 phy-next 6/8] dt-bindings: fsl: layerscape-dcfg: define DCFG_DCSR region ---
commit 87aa71bb5ea85cc0388e2ad87f720397de246b0d
Author: Vladimir Oltean <vladimir.oltean@nxp.com>

dt-bindings: fsl: layerscape-dcfg: define DCFG_DCSR region

This commit defines a secondary "reg" array element in the DCFG binding
for the hidden DCSR register space. Exposing this area permits operating
systems to perform Reset Configuration Word (RCW) overrides, enabling
runtime reconfiguration of networking SerDes lanes.

> diff --git a/Documentation/devicetree/bindings/soc/fsl/fsl,layerscape-dcfg.yaml b/Documentation/devicetree/bindings/soc/fsl/fsl,layerscape-dcfg.yaml
> index 3fb0534ea597b..fc14fd0bf84b1 100644
> --- a/Documentation/devicetree/bindings/soc/fsl/fsl,layerscape-dcfg.yaml
> +++ b/Documentation/devicetree/bindings/soc/fsl/fsl,layerscape-dcfg.yaml
> @@ -36,7 +36,20 @@ properties:
>            - const: simple-mfd
>  
>    reg:
> -    maxItems: 1
> +    minItems: 1

[ ... ]

[Severity: High]
Does the error path in fsl_guts_init() cause a NULL pointer dereference?

drivers/soc/fsl/guts.c:fsl_guts_init() {
    ...
	soc.dcfg_ccsr = of_iomap(np, DCFG_CCSR);
	if (!soc.dcfg_ccsr) {
		of_node_put(np);
		goto err_nomem;
	}
    ...
err_nomem:
	ret = -ENOMEM;
err:
	kfree(soc_dev_attr->family);
	kfree(soc_dev_attr->soc_id);
    ...
}

If of_iomap() or the allocation for soc_dev_attr fails in fsl_guts_init(),
the error handling path jumps to err_nomem while soc_dev_attr is still NULL.

The cleanup code at the err label unconditionally evaluates
soc_dev_attr->family and soc_dev_attr->soc_id before passing them to
kfree(). Reading these fields dereferences the NULL soc_dev_attr pointer,
which can cause an immediate page fault during initialization.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260720133642.136324-1-vladimir.oltean@nxp.com?part=6

WARNING: multiple messages have this Message-ID (diff)
From: sashiko-bot@kernel.org
To: "Vladimir Oltean" <vladimir.oltean@nxp.com>
Cc: neil.armstrong@linaro.org, linux-phy@lists.infradead.org,
	robh@kernel.org, devicetree@vger.kernel.org, olteanv@gmail.com,
	conor+dt@kernel.org, vkoul@kernel.org
Subject: Re: [PATCH v3 phy-next 6/8] dt-bindings: fsl: layerscape-dcfg: define DCFG_DCSR region
Date: Mon, 20 Jul 2026 13:57:50 +0000	[thread overview]
Message-ID: <20260720135750.AEF131F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260720133642.136324-7-vladimir.oltean@nxp.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Dereferencing NULL pointer `soc_dev_attr` on the error path.
--

--- Patch [6]: [PATCH v3 phy-next 6/8] dt-bindings: fsl: layerscape-dcfg: define DCFG_DCSR region ---
commit 87aa71bb5ea85cc0388e2ad87f720397de246b0d
Author: Vladimir Oltean <vladimir.oltean@nxp.com>

dt-bindings: fsl: layerscape-dcfg: define DCFG_DCSR region

This commit defines a secondary "reg" array element in the DCFG binding
for the hidden DCSR register space. Exposing this area permits operating
systems to perform Reset Configuration Word (RCW) overrides, enabling
runtime reconfiguration of networking SerDes lanes.

> diff --git a/Documentation/devicetree/bindings/soc/fsl/fsl,layerscape-dcfg.yaml b/Documentation/devicetree/bindings/soc/fsl/fsl,layerscape-dcfg.yaml
> index 3fb0534ea597b..fc14fd0bf84b1 100644
> --- a/Documentation/devicetree/bindings/soc/fsl/fsl,layerscape-dcfg.yaml
> +++ b/Documentation/devicetree/bindings/soc/fsl/fsl,layerscape-dcfg.yaml
> @@ -36,7 +36,20 @@ properties:
>            - const: simple-mfd
>  
>    reg:
> -    maxItems: 1
> +    minItems: 1

[ ... ]

[Severity: High]
Does the error path in fsl_guts_init() cause a NULL pointer dereference?

drivers/soc/fsl/guts.c:fsl_guts_init() {
    ...
	soc.dcfg_ccsr = of_iomap(np, DCFG_CCSR);
	if (!soc.dcfg_ccsr) {
		of_node_put(np);
		goto err_nomem;
	}
    ...
err_nomem:
	ret = -ENOMEM;
err:
	kfree(soc_dev_attr->family);
	kfree(soc_dev_attr->soc_id);
    ...
}

If of_iomap() or the allocation for soc_dev_attr fails in fsl_guts_init(),
the error handling path jumps to err_nomem while soc_dev_attr is still NULL.

The cleanup code at the err label unconditionally evaluates
soc_dev_attr->family and soc_dev_attr->soc_id before passing them to
kfree(). Reading these fields dereferences the NULL soc_dev_attr pointer,
which can cause an immediate page fault during initialization.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260720133642.136324-1-vladimir.oltean@nxp.com?part=6

-- 
linux-phy mailing list
linux-phy@lists.infradead.org
https://lists.infradead.org/mailman/listinfo/linux-phy

  reply	other threads:[~2026-07-20 13:57 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-20 13:36 [PATCH v3 phy-next 0/8] RCW override for 10G Lynx dynamic protocol reconfiguration Vladimir Oltean
2026-07-20 13:36 ` Vladimir Oltean
2026-07-20 13:36 ` [PATCH v3 phy-next 1/8] soc: fsl: guts: use a macro to encode the DCFG CCSR space Vladimir Oltean
2026-07-20 13:36   ` Vladimir Oltean
2026-07-20 13:36 ` [PATCH v3 phy-next 2/8] soc: fsl: guts: add a global structure to hold state Vladimir Oltean
2026-07-20 13:36   ` Vladimir Oltean
2026-07-20 13:50   ` sashiko-bot
2026-07-20 13:50     ` sashiko-bot
2026-07-20 14:01     ` Vladimir Oltean
2026-07-20 14:01       ` Vladimir Oltean
2026-07-20 14:57       ` Vladimir Oltean
2026-07-20 14:57         ` Vladimir Oltean
2026-07-21  8:44         ` Michael Walle
2026-07-21  8:44           ` Michael Walle
2026-07-21 10:43           ` Vladimir Oltean
2026-07-21 10:43             ` Vladimir Oltean
2026-07-20 13:36 ` [PATCH v3 phy-next 3/8] soc: fsl: guts: add a central fsl_guts_read() function Vladimir Oltean
2026-07-20 13:36   ` Vladimir Oltean
2026-07-20 13:51   ` sashiko-bot
2026-07-20 13:51     ` sashiko-bot
2026-07-20 13:36 ` [PATCH v3 phy-next 4/8] soc: fsl: guts: make it easier to determine on which SoC we are running Vladimir Oltean
2026-07-20 13:36   ` Vladimir Oltean
2026-07-20 13:53   ` sashiko-bot
2026-07-20 13:53     ` sashiko-bot
2026-07-20 13:36 ` [PATCH v3 phy-next 5/8] soc: fsl: guts: make fsl_soc_data available after fsl_guts_init() Vladimir Oltean
2026-07-20 13:36   ` Vladimir Oltean
2026-07-20 13:58   ` sashiko-bot
2026-07-20 13:58     ` sashiko-bot
2026-07-20 13:36 ` [PATCH v3 phy-next 6/8] dt-bindings: fsl: layerscape-dcfg: define DCFG_DCSR region Vladimir Oltean
2026-07-20 13:36   ` Vladimir Oltean
2026-07-20 13:57   ` sashiko-bot [this message]
2026-07-20 13:57     ` sashiko-bot
2026-07-20 13:36 ` [PATCH v3 phy-next 7/8] soc: fsl: guts: implement the RCW override procedure Vladimir Oltean
2026-07-20 13:36   ` Vladimir Oltean
2026-07-20 14:03   ` sashiko-bot
2026-07-20 14:03     ` sashiko-bot
2026-07-20 13:36 ` [PATCH v3 phy-next 8/8] phy: lynx-10g: use RCW override procedure for dynamic protocol change Vladimir Oltean
2026-07-20 13:36   ` Vladimir Oltean
2026-07-20 14:13   ` sashiko-bot
2026-07-20 14:13     ` sashiko-bot
2026-07-20 16:34   ` Vinod Koul
2026-07-20 16:34     ` Vinod Koul
2026-07-20 20:12     ` Vladimir Oltean
2026-07-20 20:12       ` Vladimir Oltean

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260720135750.AEF131F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-phy@lists.infradead.org \
    --cc=neil.armstrong@linaro.org \
    --cc=olteanv@gmail.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    --cc=vladimir.oltean@nxp.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.