From: sashiko-bot@kernel.org
To: "Sebastian Reichel" <sebastian.reichel@collabora.com>
Cc: conor+dt@kernel.org, robh@kernel.org, neil.armstrong@linaro.org,
linux-phy@lists.infradead.org, vkoul@kernel.org,
olteanv@gmail.com, devicetree@vger.kernel.org
Subject: Re: [PATCH v14 05/38] phy: rockchip: usbdp: Handle missing clock-names DT property gracefully
Date: Fri, 14 Aug 2026 01:53:02 +0000 [thread overview]
Message-ID: <20260814015307.396081F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260813-rockchip-usbdp-cleanup-v14-5-b5ad9c68fa11@collabora.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] The exact NULL pointer dereference vulnerability fixed in `phy-rockchip-usbdp.c` exists in multiple other drivers which were overlooked in this patch.
- [High] Clock prepare/enable and reset assertion imbalance if probe fails when PHY is already in DP mode.
--
--- Patch [5]: [PATCH v14 05/38] phy: rockchip: usbdp: Handle missing clock-names DT property gracefully ---
commit 6c56ea962e4b5726f304742232f476db1aa9e0f2
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
phy: rockchip: usbdp: Handle missing clock-names DT property gracefully
This commit fixes a null pointer dereference in the phy clock initialization
when a non-compliant device tree specifies clocks but no clock-names.
Fixes: 2f70bbddeb45 ("phy: rockchip: add usbdp combo phy driver")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/message/20260619154349.071321F000E9%40smtp.kernel.org
Tested-by: Igor Paunovic <royalnet026@gmail.com> # Orange Pi 5 Plus
> diff --git a/drivers/phy/rockchip/phy-rockchip-usbdp.c b/drivers/phy/rockchip/phy-rockchip-usbdp.c
> index 2845a012eafcc..3fc8222fcaec2 100644
> --- a/drivers/phy/rockchip/phy-rockchip-usbdp.c
> +++ b/drivers/phy/rockchip/phy-rockchip-usbdp.c
> @@ -432,6 +432,9 @@ static int rk_udphy_clk_init(struct rk_udphy *udphy, struct device *dev)
>
> /* used for configure phy reference clock frequency */
> for (i = 0; i < udphy->num_clks; i++) {
> + if (!udphy->clks[i].id)
> + continue;
> +
[Severity: High]
This isn't a bug introduced by this patch, but since you are fixing the
missing clock-names property gracefully here, should similar fixes be
applied to other drivers that use devm_clk_bulk_get_all() and check the id?
The same null pointer dereference can occur in these locations if
clock-names is missing from the device tree:
drivers/phy/rockchip/phy-rockchip-inno-usb2.c:rockchip_usb2phy_clk480m_register()
if (!strncmp(rphy->clks[i].id, "phyclk", 6)) {
drivers/phy/rockchip/phy-rockchip-naneng-combphy.c:rockchip_combphy_parse_dt()
if (!strncmp(priv->clks[i].id, "ref", 3)) {
drivers/pci/controller/dwc/pci-imx6.c:imx_setup_phy_mpll()
if (strncmp(clks[i].id, "pcie_phy", 8) == 0)
drivers/pci/controller/dwc/pci-imx6.c:imx_pcie_probe()
if (strncmp(imx_pcie->clks[i].id, "extref", 6) == 0)
drivers/spi/spi-rzv2h-rspi.c:rspi_probe()
if (!strcmp(clks[i].id, rspi->info->tclk_name)) {
Could these drivers also crash on boot with a malformed device tree?
> if (!strncmp(udphy->clks[i].id, "refclk", 6)) {
> udphy->refclk = udphy->clks[i].clk;
> break;
[ ... ]
[Severity: High]
This is a pre-existing issue, but does probe failure lead to a resource
leak if the phy is already in dp mode?
If the phy is already active, rk_udphy_get_initial_status() prepares and
enables the clocks but intentionally skips rk_udphy_disable() to keep them
active:
drivers/phy/rockchip/phy-rockchip-usbdp.c:rk_udphy_get_initial_status() {
...
rk_udphy_disable(udphy);
}
If a subsequent step in probe fails, the function returns without cleaning
up those resources:
drivers/phy/rockchip/phy-rockchip-usbdp.c:rk_udphy_probe() {
ret = rk_udphy_get_initial_status(udphy);
if (ret)
return ret;
...
if (ret)
return ret;
}
Since devm_clk_bulk_get_all() only registers a devres action to call
clk_put(), wouldn't this permanently leak the enable counts and unasserted
resets on probe deferral?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813-rockchip-usbdp-cleanup-v14-0-b5ad9c68fa11@collabora.com?part=5
--
linux-phy mailing list
linux-phy@lists.infradead.org
https://lists.infradead.org/mailman/listinfo/linux-phy
WARNING: multiple messages have this Message-ID (diff)
From: sashiko-bot@kernel.org
To: "Sebastian Reichel" <sebastian.reichel@collabora.com>
Cc: conor+dt@kernel.org, robh@kernel.org, neil.armstrong@linaro.org,
linux-phy@lists.infradead.org, vkoul@kernel.org,
olteanv@gmail.com, devicetree@vger.kernel.org
Subject: Re: [PATCH v14 05/38] phy: rockchip: usbdp: Handle missing clock-names DT property gracefully
Date: Fri, 14 Aug 2026 01:53:02 +0000 [thread overview]
Message-ID: <20260814015307.396081F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260813-rockchip-usbdp-cleanup-v14-5-b5ad9c68fa11@collabora.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] The exact NULL pointer dereference vulnerability fixed in `phy-rockchip-usbdp.c` exists in multiple other drivers which were overlooked in this patch.
- [High] Clock prepare/enable and reset assertion imbalance if probe fails when PHY is already in DP mode.
--
--- Patch [5]: [PATCH v14 05/38] phy: rockchip: usbdp: Handle missing clock-names DT property gracefully ---
commit 6c56ea962e4b5726f304742232f476db1aa9e0f2
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
phy: rockchip: usbdp: Handle missing clock-names DT property gracefully
This commit fixes a null pointer dereference in the phy clock initialization
when a non-compliant device tree specifies clocks but no clock-names.
Fixes: 2f70bbddeb45 ("phy: rockchip: add usbdp combo phy driver")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/message/20260619154349.071321F000E9%40smtp.kernel.org
Tested-by: Igor Paunovic <royalnet026@gmail.com> # Orange Pi 5 Plus
> diff --git a/drivers/phy/rockchip/phy-rockchip-usbdp.c b/drivers/phy/rockchip/phy-rockchip-usbdp.c
> index 2845a012eafcc..3fc8222fcaec2 100644
> --- a/drivers/phy/rockchip/phy-rockchip-usbdp.c
> +++ b/drivers/phy/rockchip/phy-rockchip-usbdp.c
> @@ -432,6 +432,9 @@ static int rk_udphy_clk_init(struct rk_udphy *udphy, struct device *dev)
>
> /* used for configure phy reference clock frequency */
> for (i = 0; i < udphy->num_clks; i++) {
> + if (!udphy->clks[i].id)
> + continue;
> +
[Severity: High]
This isn't a bug introduced by this patch, but since you are fixing the
missing clock-names property gracefully here, should similar fixes be
applied to other drivers that use devm_clk_bulk_get_all() and check the id?
The same null pointer dereference can occur in these locations if
clock-names is missing from the device tree:
drivers/phy/rockchip/phy-rockchip-inno-usb2.c:rockchip_usb2phy_clk480m_register()
if (!strncmp(rphy->clks[i].id, "phyclk", 6)) {
drivers/phy/rockchip/phy-rockchip-naneng-combphy.c:rockchip_combphy_parse_dt()
if (!strncmp(priv->clks[i].id, "ref", 3)) {
drivers/pci/controller/dwc/pci-imx6.c:imx_setup_phy_mpll()
if (strncmp(clks[i].id, "pcie_phy", 8) == 0)
drivers/pci/controller/dwc/pci-imx6.c:imx_pcie_probe()
if (strncmp(imx_pcie->clks[i].id, "extref", 6) == 0)
drivers/spi/spi-rzv2h-rspi.c:rspi_probe()
if (!strcmp(clks[i].id, rspi->info->tclk_name)) {
Could these drivers also crash on boot with a malformed device tree?
> if (!strncmp(udphy->clks[i].id, "refclk", 6)) {
> udphy->refclk = udphy->clks[i].clk;
> break;
[ ... ]
[Severity: High]
This is a pre-existing issue, but does probe failure lead to a resource
leak if the phy is already in dp mode?
If the phy is already active, rk_udphy_get_initial_status() prepares and
enables the clocks but intentionally skips rk_udphy_disable() to keep them
active:
drivers/phy/rockchip/phy-rockchip-usbdp.c:rk_udphy_get_initial_status() {
...
rk_udphy_disable(udphy);
}
If a subsequent step in probe fails, the function returns without cleaning
up those resources:
drivers/phy/rockchip/phy-rockchip-usbdp.c:rk_udphy_probe() {
ret = rk_udphy_get_initial_status(udphy);
if (ret)
return ret;
...
if (ret)
return ret;
}
Since devm_clk_bulk_get_all() only registers a devres action to call
clk_put(), wouldn't this permanently leak the enable counts and unasserted
resets on probe deferral?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813-rockchip-usbdp-cleanup-v14-0-b5ad9c68fa11@collabora.com?part=5
next prev parent reply other threads:[~2026-08-14 1:53 UTC|newest]
Thread overview: 155+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 20:51 [PATCH v14 00/38] phy: rockchip: usbdp: Clean up the mess Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 01/38] dt-bindings: phy: rockchip-usbdp: add improved ports scheme Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 02/38] phy: rockchip: usbdp: Update mode_change after error handling Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-14 1:19 ` sashiko-bot
2026-08-14 1:19 ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 03/38] phy: rockchip: usbdp: Do not lose USB3 PHY status Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-14 1:33 ` sashiko-bot
2026-08-14 1:33 ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 04/38] phy: rockchip: usbdp: Fix devm_clk_bulk_get_all check Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-14 1:41 ` sashiko-bot
2026-08-14 1:41 ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 05/38] phy: rockchip: usbdp: Handle missing clock-names DT property gracefully Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-14 1:53 ` sashiko-bot [this message]
2026-08-14 1:53 ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 06/38] phy: rockchip: usbdp: Drop seamless DP takeover Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-14 2:06 ` sashiko-bot
2026-08-14 2:06 ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 07/38] phy: rockchip: usbdp: Keep clocks running on PHY re-init Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-14 2:16 ` sashiko-bot
2026-08-14 2:16 ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 08/38] phy: rockchip: usbdp: Amend SSC modulation deviation Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 09/38] phy: rockchip: usbdp: Fix LFPS detect threshold control Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 10/38] phy: rockchip: usbdp: Add missing mode_change update Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-14 2:41 ` sashiko-bot
2026-08-14 2:41 ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 11/38] phy: rockchip: usbdp: Support single-lane DP Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-14 2:55 ` sashiko-bot
2026-08-14 2:55 ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 12/38] phy: rockchip: usbdp: Limit DP lane count to muxed lanes Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-14 3:07 ` sashiko-bot
2026-08-14 3:07 ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 13/38] phy: rockchip: usbdp: Rename DP lane functions Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 14/38] phy: rockchip: usbdp: Use FIELD_PREP_WM16_CONST Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 15/38] phy: rockchip: usbdp: Cleanup DP lane selection function Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 16/38] phy: rockchip: usbdp: Register DP aux bridge Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:51 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 17/38] phy: rockchip: usbdp: Drop DP HPD handling Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 18/38] phy: rockchip: usbdp: Rename mode_change to phy_needs_reinit Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 19/38] phy: rockchip: usbdp: Re-init the PHY on orientation change Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 3:57 ` sashiko-bot
2026-08-14 3:57 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 20/38] phy: rockchip: usbdp: Factor out lane_mux_sel setup Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 4:10 ` sashiko-bot
2026-08-14 4:10 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 21/38] phy: rockchip: usbdp: Properly handle TYPEC_STATE_SAFE and TYPEC_STATE_USB Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 4:23 ` sashiko-bot
2026-08-14 4:23 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 22/38] phy: rockchip: usbdp: Use guard functions for mutex Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 23/38] phy: rockchip: usbdp: Hold mutex in DP PHY configure Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 24/38] phy: rockchip: usbdp: Add some extra debug messages Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 25/38] phy: rockchip: usbdp: Avoid xHCI SErrors Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 4:52 ` sashiko-bot
2026-08-14 4:52 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 26/38] phy: rockchip: usbdp: Handle rk_udphy_reset_deassert errors Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 27/38] phy: rockchip: usbdp: Only enable USB3 when not in high-speed mode Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 28/38] phy: core: add notifier infrastructure Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 5:14 ` sashiko-bot
2026-08-14 5:14 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 29/38] usb: dwc3: rockchip: introduce glue driver Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 5:22 ` sashiko-bot
2026-08-14 5:22 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 30/38] usb: dwc3: core: add post PHY registration hook for platform glue Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 31/38] usb: dwc3: rockchip: support PHY reset notifications Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 5:43 ` sashiko-bot
2026-08-14 5:43 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 32/38] usb: dwc3: rockchip: fix USB-C reconnect in gadget mode Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 5:59 ` sashiko-bot
2026-08-14 5:59 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 33/38] phy: rockchip: usbdp: Add phy reset notification support Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 6:12 ` sashiko-bot
2026-08-14 6:12 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 34/38] phy: rockchip: usbdp: Drop -EPROBE_DEFER hack Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 35/38] phy: rockchip: usbdp: Rename mode to hw_mode Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 36/38] phy: rockchip: usbdp: Fix power state handling Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 37/38] phy: rockchip: usbdp: Re-init PHY on mux change Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-14 6:49 ` sashiko-bot
2026-08-14 6:49 ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 38/38] phy: rockchip: usbdp: Add USB-C state without DP enabled Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
2026-08-13 20:52 ` Sebastian Reichel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814015307.396081F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=linux-phy@lists.infradead.org \
--cc=neil.armstrong@linaro.org \
--cc=olteanv@gmail.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sebastian.reichel@collabora.com \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.