All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Dumitru Ceclan" <dumitru.ceclan@analog.com>
Cc: media-ci@linuxtv.org, robh@kernel.org, conor+dt@kernel.org,
	devicetree@vger.kernel.org
Subject: Re: [PATCH v15 13/22] media: i2c: add Maxim GMSL2/3 serializer and deserializer framework
Date: Fri, 07 Aug 2026 13:36:43 +0000	[thread overview]
Message-ID: <20260807133644.2302C1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260807-gmsl2-3_serdes-v15-13-7212e9e5156a@analog.com>

Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
- [High] Using devres allocation (`devm_kcalloc`) in a dynamically called helper function leads to an unbounded memory leak.
- [Medium] max_serdes_get_tpg_timings() returns 0 (success) without initializing the timings output parameter if entry is NULL.
- [Medium] The commit message claims the framework enables support for multiple features that are entirely absent from the code.
- [Medium] Output parameter 'doubled_bpp' is left uninitialized on success path in max_serdes_process_bpps.
- [Low] Most of the framework functions lack EXPORT_SYMBOL_GPL, rendering them unusable by external modules.
--

--- Patch [13]: [PATCH v15 13/22] media: i2c: add Maxim GMSL2/3 serializer and deserializer framework ---
commit 318efe00d7eeba7a3e3cd45eca83e30dec1c313f
Author: Cosmin Tanislav <demonsingur@gmail.com>

media: i2c: add Maxim GMSL2/3 serializer and deserializer framework

These drivers are meant to be used as a common framework for Maxim
GMSL2/3 serializers and deserializers.

> This framework enables support for the following new features across
> all the chips:
>  * Full Streams API support
>  * .get_frame_desc()
>  * .get_mbus_config()
>  * I2C ATR
>  * automatic GMSL link version negotiation
>  * automatic stream id selection
>  * automatic VC remapping
>  * automatic pixel mode / tunnel mode selection
>  * automatic double mode selection / data padding
>  * logging of internal state and chip status registers via .log_status()
>  * PHY modes
>  * serializer pinctrl
>  * TPG

[Severity: Medium]
The commit message explicitly claims that the framework enables support
for .get_mbus_config(), automatic GMSL link version negotiation, VC remapping,
pinctrl, and other features.

However, the submitted code only includes basic data structures and a few helper
functions for streams and TPG. The logic for the claimed features appears to be
missing.

Could the commit message be updated to reflect only the features
currently implemented in this patch?

> diff --git a/drivers/media/i2c/maxim-serdes/max_serdes.c b/drivers/media/i2c/maxim-serdes/max_serdes.c
> new file mode 100644
> index 0000000000000..7d013c4739d11
> --- /dev/null
> +++ b/drivers/media/i2c/maxim-serdes/max_serdes.c

[ ... ]

> +int max_serdes_process_bpps(struct device *dev, u32 bpps,
> +			    u32 allowed_double_bpps, unsigned int *doubled_bpp)
> +{
> +	unsigned int min_bpp;
> +	unsigned int max_bpp;
> +	bool doubled = false;
> +
> +	if (!bpps)
> +		return 0;
> +
> +	*doubled_bpp = 0;

[Severity: Medium]
If a caller invokes max_serdes_process_bpps() with bpps == 0, the function
returns 0 (success) immediately before the *doubled_bpp = 0 assignment. 

Will this cause the caller to consume an uninitialized value for doubled_bpp?
Should *doubled_bpp = 0 be moved before the if (!bpps) check?

[ ... ]

> +int max_serdes_get_streams_masks(struct device *dev,
> +				 const struct v4l2_subdev_state *state,
> +				 u32 pad, u64 updated_streams_mask,
> +				 u32 num_pads, u64 *old_streams_masks,
> +				 u64 **new_streams_masks, bool enable)
> +{
> +	u64 *streams_masks;
> +	unsigned int i;
> +
> +	streams_masks = devm_kcalloc(dev, num_pads, sizeof(*streams_masks), GFP_KERNEL);

[Severity: High]
Does using devm_kcalloc() here lead to an unbounded memory leak?

This helper function appears to be called dynamically during stream
enable/disable operations. Because devm_kcalloc() ties the memory
lifecycle to the device rather than the stream operation, won't repeated
stream start/stop cycles continually leak memory until the device is unbound?

[ ... ]

> +int max_serdes_get_tpg_timings(const struct max_serdes_tpg_entry *entry,
> +			       struct max_serdes_tpg_timings *timings)
> +{
> +	u32 fps;
> +
> +	if (!entry)
> +		return 0;

[Severity: Medium]
When a caller invokes max_serdes_get_tpg_timings() with entry == NULL, this
early return path yields 0 (success) without initializing the timings
output parameter. 

Will callers relying on a success return code then consume uninitialized
stack or heap data?

[ ... ]

> +	return -EINVAL;
> +}
> +EXPORT_SYMBOL_NS_GPL(max_serdes_get_tpg_timings, "MAX_SERDES");

[Severity: Low]
Most of the framework functions in this file lack EXPORT_SYMBOL_GPL
declarations. 

Since this framework is built as a module and intended to be consumed by
external serializer drivers, will dependent modules fail to link against
these unexported symbols?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260807-gmsl2-3_serdes-v15-0-7212e9e5156a@analog.com?part=13

  reply	other threads:[~2026-08-07 13:36 UTC|newest]

Thread overview: 56+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-07 13:02 [PATCH v15 00/22] media: i2c: add Maxim GMSL2/3 serializer and deserializer drivers Dumitru Ceclan via B4 Relay
2026-08-07 13:02 ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 01/22] media: mc: Add INTERNAL pad flag Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 02/22] dt-bindings: media: i2c: max96717: add support for I2C ATR Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:17   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 03/22] dt-bindings: media: i2c: max96717: add support for pinctrl/pinconf Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 04/22] dt-bindings: media: i2c: max96717: add support for MAX9295A Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 05/22] dt-bindings: media: i2c: max96717: add support for MAX96793 Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 06/22] dt-bindings: media: i2c: max96712: use pattern properties for ports Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 07/22] dt-bindings: media: i2c: max96712: add support for I2C ATR Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:32   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 08/22] dt-bindings: media: i2c: max96712: add support for POC supplies Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 09/22] dt-bindings: media: i2c: max96712: add support for MAX96724F/R Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 10/22] dt-bindings: media: i2c: max96712: add control-channel-port property Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 11/22] dt-bindings: media: i2c: max96714: add support for MAX96714R Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:26   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 12/22] dt-bindings: media: i2c: add MAX9296A, MAX96716A, MAX96792A Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:38   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 13/22] media: i2c: add Maxim GMSL2/3 serializer and deserializer framework Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:36   ` sashiko-bot [this message]
2026-08-07 13:02 ` [PATCH v15 14/22] media: i2c: add Maxim GMSL2/3 serializer framework Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:42   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 15/22] media: i2c: add Maxim GMSL2/3 deserializer framework Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:42   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 16/22] media: i2c: maxim-serdes: add MAX96717 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:51   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 17/22] media: i2c: maxim-serdes: add MAX96724 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 18/22] media: i2c: maxim-serdes: add MAX9296A driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:55   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 19/22] arm64: defconfig: disable deprecated MAX96712 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:47   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 20/22] staging: media: remove " Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 21/22] media: i2c: remove MAX96717 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 22/22] media: i2c: remove MAX96714 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260807133644.2302C1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dumitru.ceclan@analog.com \
    --cc=media-ci@linuxtv.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.