From: sashiko-bot@kernel.org
To: "Eduard Bostina" <egbostina@gmail.com>
Cc: mfd@lists.linux.dev, devicetree@vger.kernel.org, robh@kernel.org,
conor+dt@kernel.org, lee@kernel.org
Subject: Re: [PATCH] dt-bindings: mfd: Convert TPS61050 to DT schema
Date: Sat, 15 Aug 2026 08:40:37 +0000 [thread overview]
Message-ID: <20260815084037.E9E1B1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260815083145.2145984-1-egbostina@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] The MFD core driver dynamically mutates static `mfd_cell` structures to pass custom parent data via `platform_data`, violating MFD guidelines and introducing a race condition.
--
--- Patch [1]: [PATCH] dt-bindings: mfd: Convert TPS61050 to DT schema ---
commit c3b0af0c4f22b90e8d39db54cb33489eff5b078e
Author: Eduard Bostina <egbostina@gmail.com>
dt-bindings: mfd: Convert TPS61050 to DT schema
Convert the Texas Instruments TPS61050/TPS61052 boost converters bindings
to DT schema.
> diff --git a/Documentation/devicetree/bindings/mfd/ti,tps61050.yaml b/Documentation/devicetree/bindings/mfd/ti,tps61050.yaml
> new file mode 100644
> index 0000000000000..974ef78d6e26e
> --- /dev/null
> +++ b/Documentation/devicetree/bindings/mfd/ti,tps61050.yaml
> @@ -0,0 +1,92 @@
> +# SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause)
> +%YAML 1.2
> +---
> +$id: http://devicetree.org/schemas/mfd/ti,tps61050.yaml#
> +$schema: http://devicetree.org/meta-schemas/core.yaml#
> +
> +title: Texas Instruments TPS61050/TPS61052 Boost Converter
[Severity: High]
This isn't a bug introduced by this patch, but the core driver for these
devices dynamically mutates static mfd_cell structures.
Looking at tps6105x_add_device() in drivers/mfd/tps6105x.c, the function
modifies the shared static mfd_cell's platform_data field with a pointer to
the newly allocated parent data:
drivers/mfd/tps6105x.c:tps6105x_add_device() {
...
cell->platform_data = tps6105x;
cell->pdata_size = sizeof(*tps6105x);
...
}
Because the cell is declared as static but not const:
drivers/mfd/tps6105x.c:
static struct mfd_cell tps6105x_gpio_cell = {
.name = "tps6105x-gpio",
};
Could this create a data race if multiple I2C adapter initialization threads
concurrently call tps6105x_probe()?
Additionally, the child driver incorrectly reads the duplicated platform_data
instead of using dev_get_drvdata() on the parent device as mandated by MFD
rules:
drivers/leds/leds-tps6105x.c:tps6105x_led_probe() {
...
struct tps6105x *tps6105x = dev_get_platdata(&pdev->dev);
...
}
Because platform_device_add_data() makes a kmemdup copy of the struct passed
via platform_data, if device B unbinds, device A's child may hold a copy of
pointers that were freed, leading to a Use-After-Free.
Could the child driver be updated to retrieve parent data via
dev_get_drvdata(pdev->dev.parent), allowing the mfd_cell arrays to be static
const?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260815083145.2145984-1-egbostina@gmail.com?part=1
next prev parent reply other threads:[~2026-08-15 8:40 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-15 8:31 [PATCH] dt-bindings: mfd: Convert TPS61050 to DT schema Eduard Bostina
2026-08-15 8:40 ` sashiko-bot [this message]
2026-08-31 13:26 ` Rob Herring (Arm)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260815084037.E9E1B1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=egbostina@gmail.com \
--cc=lee@kernel.org \
--cc=mfd@lists.linux.dev \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.