From: sashiko-bot@kernel.org
To: "Paolo Pisati" <p.pisati@gmail.com>
Cc: cassel@kernel.org, linux-ide@vger.kernel.org, dlemoal@kernel.org
Subject: Re: [PATCH v5 2/2] m68k: defconfig: enable PATA_CSWARP
Date: Mon, 24 Aug 2026 15:41:40 +0000 [thread overview]
Message-ID: <20260824154140.CF46E1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260824153339.512487-3-p.pisati@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Missing check for ioremap() failure in pata_cswarp_probe().
- [Medium] Missing iounmap() on the ata_host_activate() error path.
--
--- Patch [2]: [PATCH v5 2/2] m68k: defconfig: enable PATA_CSWARP ---
commit 50c3007b9ddccb0c0a488126c545810ad538a593
Author: Paolo Pisati <p.pisati@gmail.com>
ata: pata_cswarp: Add Amiga cslab ata support
This commit introduces the pata_cswarp driver to provide support for
the on-board IDE interface on the CS-Lab Warp Expansion Card.
> diff --git a/drivers/ata/pata_cswarp.c b/drivers/ata/pata_cswarp.c
> new file mode 100644
> index 0000000000000..55f000f427384
> --- /dev/null
> +++ b/drivers/ata/pata_cswarp.c
> @@ -0,0 +1,180 @@
[ ... ]
> +static int pata_cswarp_probe(struct zorro_dev *z,
> + const struct zorro_device_id *ent)
> +{
[ ... ]
> + host = ata_host_alloc(&z->dev, 1);
> + if (!host)
> + return -ENXIO;
> +
> + ap = host->ports[0];
> + base = ioremap(board + WARP_OFFSET_ATA, 0x1800);
> +
> + ap->ops = &pata_cswarp_ops;
[Severity: High]
Is it possible for ioremap() to fail and return a NULL pointer here?
If memory mapping fails during device probe, base would be NULL.
This NULL pointer is then used to calculate and assign various ATA port I/O
addresses (e.g., ap->ioaddr.error_addr = base + 1 * 4).
When the block layer or ATA framework later attempts to access these I/O
ports, will this result in a kernel panic due to an invalid pointer
dereference?
> +
> + ap->pio_mask = ATA_PIO4;
[ ... ]
> + ata_port_desc(ap, " cmd 0x%lx ctl 0x%lx", (unsigned long)base,
> + (unsigned long)ap->ioaddr.ctl_addr);
> +
> + return ata_host_activate(host, 0, NULL,
> + IRQF_SHARED, &pata_cswarp_sht);
> +}
[Severity: Medium]
Does this error path leak the I/O memory mapping?
If ata_host_activate() fails, it returns a non-zero error code which is
immediately returned by pata_cswarp_probe().
Since this driver uses manual memory mapping rather than devm_ioremap()
(as seen by the manual iounmap() call in pata_cswarp_remove()), should
iounmap(base) be called before returning the error?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260824153339.512487-1-p.pisati@gmail.com?part=2
prev parent reply other threads:[~2026-08-24 15:41 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 15:33 [PATCH v5 0/2] m68k: pata_cswarp: Add Amiga cslab ata support Paolo Pisati
2026-08-24 15:33 ` [PATCH v5 1/2] ata: " Paolo Pisati
2026-08-24 15:41 ` sashiko-bot
2026-08-25 7:53 ` Geert Uytterhoeven
2026-08-25 9:55 ` Geert Uytterhoeven
2026-08-26 8:55 ` Paolo Pisati
2026-08-26 19:31 ` Michael Schmitz
2026-08-27 7:29 ` Geert Uytterhoeven
2026-08-24 15:33 ` [PATCH v5 2/2] m68k: defconfig: enable PATA_CSWARP Paolo Pisati
2026-08-24 15:41 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260824154140.CF46E1F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=cassel@kernel.org \
--cc=dlemoal@kernel.org \
--cc=linux-ide@vger.kernel.org \
--cc=p.pisati@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.