All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Gregor Herburger" <gregor.herburger@linutronix.de>
Cc: conor+dt@kernel.org, devicetree@vger.kernel.org, robh@kernel.org
Subject: Re: [PATCH RESEND v3 3/4] firmware: raspberrypi: Add reboot mode support
Date: Thu, 03 Sep 2026 15:08:44 +0000	[thread overview]
Message-ID: <20260903150844.82B981F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903-rpi-tryboot-v3-3-ce94c347e932@linutronix.de>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Use-after-free race condition if devm_add_action_or_reset() fails after drvdata is set.
--

commit ea24b0bc9b26402781f7da38607787a0f6b47e39
Author: Gregor Herburger <gregor.herburger@linutronix.de>

firmware: raspberrypi: Add reboot mode support
    
The Raspberry Pi firmware has a tryboot mode where it tries to boot from
another partition. This can be used to create a A/B update scheme.

To enable this on the next boot, the RPI_FIRMWARE_SET_REBOOT_FLAGS
message must be sent to the firmware. Add support for this by
registering a reboot mode driver.

> diff --git a/drivers/firmware/raspberrypi.c b/drivers/firmware/raspberrypi.c
> index 0aa322e9a2e73..2a0c40b8052e5 100644
> --- a/drivers/firmware/raspberrypi.c
> +++ b/drivers/firmware/raspberrypi.c
[ ... ]
> @@ -302,9 +331,14 @@ static int rpi_firmware_probe(struct platform_device *pdev)
>  
>  	platform_set_drvdata(pdev, fw);
>  
> +	ret = devm_add_action_or_reset(dev, devm_rpi_firmware_put, fw);
> +	if (ret)
> +		return ret;

[Severity: High]
If devm_add_action_or_reset() fails here, could this create a use-after-free 
race condition?

When the failure occurs, devm_add_action_or_reset() immediately executes
devm_rpi_firmware_put(), which drops the refcount and frees the fw context. 
Because platform_set_drvdata() was already called, the driver data 
will point to this freed memory until the core probe cleanup mechanism 
eventually clears it.

During this window, a consumer driver could call rpi_firmware_get(), which
performs a lockless lookup of drvdata and attempts to dereference the freed
pointer:

drivers/firmware/raspberrypi.c:rpi_firmware_get() {
    ...
	fw = platform_get_drvdata(pdev);
	if (!fw)
		goto err_put_device;

	if (!kref_get_unless_zero(&fw->consumers))
		goto err_put_device;
    ...
}

> +
>  	rpi_firmware_print_firmware_revision(fw);
>  	rpi_register_hwmon_driver(dev, fw);
>  	rpi_register_clk_driver(dev);
> +	rpi_register_reboot_mode(dev, fw);
>  
>  	return 0;
>  }
[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903-rpi-tryboot-v3-0-ce94c347e932@linutronix.de?part=3

  reply	other threads:[~2026-09-03 15:08 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03 14:48 [PATCH RESEND v3 0/4] firmware: raspberrypi: Add support for the tryboot mode Gregor Herburger
2026-09-03 14:48 ` [PATCH RESEND v3 1/4] firmware: raspberrypi: reorder rpi_firmware_property_tag enum Gregor Herburger
2026-09-03 14:48 ` [PATCH RESEND v3 2/4] dt-bindings: raspberrypi,bcm2835-firmware: Include 'reboot-mode.yaml' Gregor Herburger
2026-09-03 14:48 ` [PATCH RESEND v3 3/4] firmware: raspberrypi: Add reboot mode support Gregor Herburger
2026-09-03 15:08   ` sashiko-bot [this message]
2026-09-03 20:30     ` Gregor Herburger
2026-09-03 17:55   ` Stefan Wahren
2026-09-03 20:41     ` Gregor Herburger
2026-09-03 18:08   ` Stefan Wahren
2026-09-03 20:31     ` Gregor Herburger
2026-09-03 14:48 ` [PATCH RESEND v3 4/4] arm64: dts: broadcom: bcm2712: Add reboot modes to firmware node Gregor Herburger
  -- strict thread matches above, loose matches on Subject: below --
2026-07-30 10:59 [PATCH RESEND v3 0/4] firmware: raspberrypi: Add support for the tryboot mode Gregor Herburger
2026-07-30 10:59 ` [PATCH RESEND v3 3/4] firmware: raspberrypi: Add reboot mode support Gregor Herburger
2026-07-30 11:11   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903150844.82B981F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=gregor.herburger@linutronix.de \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.