From: sashiko-bot@kernel.org
To: "Ovidiu Panait" <ovidiu.panait.rb@renesas.com>
Cc: linux-clk@vger.kernel.org, wsa+renesas@sang-engineering.com
Subject: Re: [PATCH 2/2] clk: renesas: rzv2h: Convert to clk_hw based provider API
Date: Wed, 02 Sep 2026 11:04:43 +0000 [thread overview]
Message-ID: <20260902110443.959CD1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260902104939.25522-3-ovidiu.panait.rb@renesas.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing OF genpd provider cleanup on the probe error path leads to a Use-After-Free.
--
commit a63d8b10a46c55aa614df9d149b0a17736dc2cc5
Author: John Madieu <john.madieu.xa@bp.renesas.com>
clk: renesas: rzv2h: Convert to clk_hw based provider API
The driver mixes the clk consumer API with the clk_hw provider API for its
internal clock storage and OF lookup callback. Convert it to use clk_hw
consistently.
> diff --git a/drivers/clk/renesas/rzv2h-cpg.c b/drivers/clk/renesas/rzv2h-cpg.c
> index 86f6f2f700a65..9b0d691b1f5d0 100644
> --- a/drivers/clk/renesas/rzv2h-cpg.c
> +++ b/drivers/clk/renesas/rzv2h-cpg.c
[ ... ]
> @@ -1547,19 +1542,13 @@ static int __init rzv2h_cpg_add_pm_domains(struct rzv2h_cpg_priv *priv)
> return of_genpd_add_provider_simple(np, &pd->genpd);
[Severity: High]
This is a pre-existing issue, but does this missing OF genpd provider cleanup
on the probe error path lead to a Use-After-Free?
If a subsequent operation in rzv2h_cpg_probe() (such as
rzv2h_cpg_reset_controller_register()) fails, the devm framework automatically
frees the struct rzv2h_cpg_pd that was allocated with devm_kzalloc().
However, the cleanup action pm_genpd_remove() returns -EBUSY and aborts
because of_genpd_add_provider_simple() sets genpd->has_provider = true.
Because of_genpd_del_provider() is never called to unset this flag and
remove the provider, the domain remains registered in the global
of_genpd_providers list, gpd_list, and the device core.
When a consumer device subsequently probes and looks up its PM domain, or
when the PM domain core walks the lists, it could dereference the freed
pd->genpd memory.
> }
>
> -static void rzv2h_cpg_del_clk_provider(void *data)
> -{
> - of_clk_del_provider(data);
> -}
> -
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260902104939.25522-1-ovidiu.panait.rb@renesas.com?part=2
next prev parent reply other threads:[~2026-09-02 11:04 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 10:49 [PATCH 0/2] clk: renesas: rzv2h: Convert to clk_hw provider API Ovidiu Panait
2026-09-02 10:49 ` [PATCH 1/2] clk: renesas: rzv2h: Drop duplicated parent lookup in fixed_mod_status_clk_register() Ovidiu Panait
2026-09-03 13:07 ` Geert Uytterhoeven
2026-09-02 10:49 ` [PATCH 2/2] clk: renesas: rzv2h: Convert to clk_hw based provider API Ovidiu Panait
2026-09-02 11:04 ` sashiko-bot [this message]
2026-09-03 13:39 ` Geert Uytterhoeven
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902110443.959CD1F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-clk@vger.kernel.org \
--cc=ovidiu.panait.rb@renesas.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=wsa+renesas@sang-engineering.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.