All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: kr494167@gmail.com
Cc: lee@kernel.org, linux-leds@vger.kernel.org
Subject: Re: [PATCH v2 1/2] leds: rgb: s2m: Wire up of_match_table in platform driver
Date: Wed, 22 Jul 2026 16:29:34 +0000	[thread overview]
Message-ID: <20260722162934.73B141F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260722161519.9610-2-kr494167@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Type confusion and potential crash due to unsafe cast of parent drvdata when probed via Device Tree.
--

--- Patch [1]: [PATCH v2 1/2] leds: rgb: s2m: Wire up of_match_table in platform driver ---
commit fe8555b3e7add30597af4722b7f9538af69ac8af
Author: Surendra <kr494167@gmail.com>

leds: rgb: s2m: Wire up of_match_table in platform driver

This commit assigns the of_match_table in the platform driver to enable
Device Tree matching. It also adds validation for the parent device and its
driver data to prevent a NULL pointer dereference during probe.

> diff --git a/drivers/leds/rgb/leds-s2m-rgb.c b/drivers/leds/rgb/leds-s2m-rgb.c
> index d239f54eee901..7ac2b1160c1e3 100644
> --- a/drivers/leds/rgb/leds-s2m-rgb.c
> +++ b/drivers/leds/rgb/leds-s2m-rgb.c
> @@ -363,11 +363,18 @@ static const struct mc_subled s2mu005_rgb_subled_info[] = {
>  static int s2m_rgb_probe(struct platform_device *pdev)
>  {
>  	struct device *dev = &pdev->dev;
> -	struct sec_pmic_dev *pmic_drvdata = dev_get_drvdata(dev->parent);
> +	struct sec_pmic_dev *pmic_drvdata;
>  	struct s2m_rgb *rgb;
>  	struct led_init_data init_data = {};
>  	int ret;
>  
> +	if (!dev->parent)
> +		return -ENODEV;
> +
> +	pmic_drvdata = dev_get_drvdata(dev->parent);
> +	if (!pmic_drvdata)
> +		return -ENODEV;
> +
>  	rgb = devm_kzalloc(dev, sizeof(*rgb), GFP_KERNEL);
>  	if (!rgb)
>  		return -ENOMEM;
> @@ -415,6 +422,7 @@ MODULE_DEVICE_TABLE(of, s2m_rgb_of_match_table);
>  static struct platform_driver s2m_rgb_driver = {
>  	.driver = {
>  		.name = "s2m-rgb",
> +		.of_match_table = s2m_rgb_of_match_table,

[Severity: Medium]
By enabling Device Tree matching here, the driver can be probed natively 
via DT. This exposes the driver to being probed under arbitrary parents 
rather than strictly the expected MFD parent.

If probed under an unexpected parent (such as an I2C controller or another
platform device), that parent's driver data is blindly cast to 
struct sec_pmic_dev * earlier in s2m_rgb_probe():

    pmic_drvdata = dev_get_drvdata(dev->parent);

Could this lead to memory corruption or a crash when the type-confused 
pointer is later dereferenced in s2m_rgb_probe() to fetch the regmap?

    rgb->regmap = pmic_drvdata->regmap_pmic;

Would it be safer to retrieve the regmap using dev_get_regmap() instead, 
to ensure we safely get a valid regmap pointer regardless of the parent 
device type?

>  	},
>  	.probe = s2m_rgb_probe,
>  	.id_table = s2m_rgb_id_table,

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260722161519.9610-1-kr494167@gmail.com?part=1

  reply	other threads:[~2026-07-22 16:29 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22 16:15 [PATCH v2 0/2] leds: s2m: Wire up of_match_table in platform drivers kr494167
2026-07-22 16:15 ` [PATCH v2 1/2] leds: rgb: s2m: Wire up of_match_table in platform driver kr494167
2026-07-22 16:29   ` sashiko-bot [this message]
2026-07-22 18:07   ` Kaustabh Chakraborty
2026-07-22 16:15 ` [PATCH v2 2/2] leds: flash: " kr494167
2026-07-22 16:29   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260722162934.73B141F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kr494167@gmail.com \
    --cc=lee@kernel.org \
    --cc=linux-leds@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.