From: sashiko-bot@kernel.org
To: "Markus Stockhausen" <markus.stockhausen@gmx.de>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH net-next v8 4/9] net: mdio: realtek-rtl9300: extend controller structure lifetime
Date: Thu, 30 Jul 2026 16:03:30 +0000 [thread overview]
Message-ID: <20260730160331.03A471F00ACF@smtp.kernel.org> (raw)
In-Reply-To: <20260729160227.155613-5-markus.stockhausen@gmx.de>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] Calling devm_add_action_or_reset() on the uninitialized &bus->dev causes a guaranteed NULL pointer dereference, and on error paths leaks resources.
--
--- Patch [4]: [PATCH net-next v8 4/9] net: mdio: realtek-rtl9300: extend controller structure lifetime ---
commit 34bdc9b9e9ece2a1428b242a3ed3e140500fd37f
Author: Markus Stockhausen <markus.stockhausen@gmx.de>
net: mdio: realtek-rtl9300: extend controller structure lifetime
This patch changes the allocation of the otto_emdio_priv structure from
devm_kzalloc() to kzalloc() and introduces a kref counter. It attempts to
decouple the controller's lifetime from the platform device by tying it
to the registered MDIO buses via devm_add_action_or_reset().
> diff --git a/drivers/net/mdio/mdio-realtek-rtl9300.c b/drivers/net/mdio/mdio-realtek-rtl9300.c
> index 73ac5fdcd2674..3b99978a2511e 100644
> --- a/drivers/net/mdio/mdio-realtek-rtl9300.c
> +++ b/drivers/net/mdio/mdio-realtek-rtl9300.c
[ ... ]
> @@ -617,6 +634,11 @@ static int otto_emdio_probe_one(struct device *dev, struct otto_emdio_priv *priv
>
> snprintf(bus->id, MII_BUS_ID_SIZE, "%s-%d", dev_name(dev), mdio_bus);
>
> + kref_get(&priv->kref);
> + err = devm_add_action_or_reset(&bus->dev, otto_emdio_cleanup_bus, priv);
[Severity: Critical]
Will this cause a list corruption crash unconditionally on every probe?
The bus structure is allocated via devm_mdiobus_alloc_size(), which returns
zero-initialized memory, meaning bus->dev.devres_head is uninitialized.
Calling devm_add_action_or_reset() here will attempt to append to this
zero-initialized list.
Additionally, if the crash is bypassed, devm_of_mdiobus_register() later
calls device_initialize(&bus->dev). This resets devres_head to empty,
destroying the action and leaking the kref.
Finally, if mdiobus_register() is never reached on an error path,
mdiobus_free() handles the MDIOBUS_ALLOCATED state by directly calling
kfree(bus). This bypasses device_release() and devres_release_all(),
permanently leaking the devres structure and the priv kref.
> + if (err)
> + return dev_err_probe(dev, err, "cannot register cleanup action\n");
> +
> err = devm_of_mdiobus_register(dev, bus, to_of_node(node));
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260729160227.155613-1-markus.stockhausen@gmx.de?part=4
next prev parent reply other threads:[~2026-07-30 16:03 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 16:02 [PATCH net-next v8 0/9] net: mdio: realtek-rtl9300: Add RTL83xx support Markus Stockhausen
2026-07-29 16:02 ` [PATCH net-next v8 1/9] dt-bindings: net: realtek,rtl9301-mdio: Add RTL83xx series Markus Stockhausen
2026-07-29 16:02 ` [PATCH net-next v8 2/9] net: mdio: realtek-rtl9300: Add polling documentation Markus Stockhausen
2026-07-29 16:02 ` [PATCH net-next v8 3/9] net: phy: add (*notify_phy_attach/detach)() hooks to struct mii_bus Markus Stockhausen
2026-07-30 16:03 ` sashiko-bot
2026-07-29 16:02 ` [PATCH net-next v8 4/9] net: mdio: realtek-rtl9300: extend controller structure lifetime Markus Stockhausen
2026-07-30 16:03 ` sashiko-bot [this message]
2026-07-29 16:02 ` [PATCH net-next v8 5/9] net: mdio: realtek-rtl9300: Configure hardware polling during probing Markus Stockhausen
2026-07-30 16:03 ` sashiko-bot
2026-07-29 16:02 ` [PATCH net-next v8 6/9] net: mdio: realtek-rtl9300: Add page tracking Markus Stockhausen
2026-07-30 16:03 ` sashiko-bot
2026-07-29 16:02 ` [PATCH net-next v8 7/9] net: mdio: realtek-rtl9300: Increase MDIO timeout Markus Stockhausen
2026-07-29 16:02 ` [PATCH net-next v8 8/9] net: mdio: realtek-rtl9300: Add support for RTL838x Markus Stockhausen
2026-07-29 16:02 ` [PATCH net-next v8 9/9] net: mdio: realtek-rtl9300: Add support for RTL839x Markus Stockhausen
-- strict thread matches above, loose matches on Subject: below --
2026-07-27 19:15 [PATCH net-next v8 0/9] net: mdio: realtek-rtl9300: Add RTL83xx support Markus Stockhausen
2026-07-27 19:15 ` [PATCH net-next v8 4/9] net: mdio: realtek-rtl9300: extend controller structure lifetime Markus Stockhausen
2026-07-28 19:16 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260730160331.03A471F00ACF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=markus.stockhausen@gmx.de \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.