From: sashiko-bot@kernel.org
To: "Marek Vasut" <marek.vasut+renesas@mailbox.org>
Cc: linux-pci@vger.kernel.org, devicetree@vger.kernel.org,
conor+dt@kernel.org, wsa+renesas@sang-engineering.com,
robh@kernel.org
Subject: Re: [PATCH v4 3/6] PCI: dwc: rcar-gen4: Add .deinit callback
Date: Sat, 05 Sep 2026 21:38:09 +0000 [thread overview]
Message-ID: <20260905213809.9232B1F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260905212649.360498-4-marek.vasut+renesas@mailbox.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing early return or goto in error path of rcar_gen4_add_dw_pcie_ep().
--
commit 2da5cda33af2a170742ef5426b300f42371937c6
Author: Marek Vasut <marek.vasut+renesas@mailbox.org>
PCI: dwc: rcar-gen4: Add .deinit callback
Add .deinit callback in preparation for R-Car Gen5 support. The
.deinit callback will be used to tear down the PHY on R-Car Gen5.
> diff --git a/drivers/pci/controller/dwc/pcie-rcar-gen4.c b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> index a19ebbab2f8c3..04871ac11c348 100644
> --- a/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> +++ b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
[ ... ]
> @@ -580,7 +581,7 @@ static void rcar_gen4_pcie_ep_post_deinit(struct dw_pcie_ep *ep)
> struct rcar_gen4_pcie *rcar = to_rcar_gen4_pcie(dw);
>
> writel(0, rcar->base + PCIEDMAINTSTSEN);
> - rcar_gen4_pcie_common_deinit(rcar);
> + rcar->drvdata->deinit(rcar);
> }
[Severity: High]
This isn't a bug introduced by this patch, but looking at
rcar_gen4_add_dw_pcie_ep() in this same file:
ret = dw_pcie_ep_init_registers(ep);
if (ret) {
dev_err(dev, "Failed to initialize DWC endpoint registers\n");
dw_pcie_ep_deinit(ep);
}
pci_epc_init_notify(ep->epc);
return ret;
Should the error path for dw_pcie_ep_init_registers() return early or jump to
an error handler?
If dw_pcie_ep_init_registers() fails, the code falls through to
pci_epc_init_notify() despite having called dw_pcie_ep_deinit(). This causes
the Endpoint Controller (EPC) framework to spuriously notify registered
listeners (like EPF drivers) that the controller is successfully initialized
when it has actually failed and been de-initialized.
Could this lead to use-after-free or NULL-pointer dereferences in the EPF
drivers attempting to interact with the torn-down EPC?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260905212649.360498-1-marek.vasut+renesas@mailbox.org?part=3
next prev parent reply other threads:[~2026-09-05 21:38 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 21:26 [PATCH v4 0/6] PCI: dwc: rcar-gen4: Add support for R-Car X5H PCIe4 Marek Vasut
2026-09-05 21:26 ` [PATCH v4 1/6] dt-bindings: PCI: rcar-gen4-pci-host: Add R-Car X5H PCIe4 compatible Marek Vasut
2026-09-05 21:36 ` sashiko-bot
2026-09-05 21:26 ` [PATCH v4 2/6] PCI: dwc: rcar-gen4: Rework rcar_gen4_pcie_drvdata .additional_common_init into .init Marek Vasut
2026-09-05 21:33 ` sashiko-bot
2026-09-05 21:26 ` [PATCH v4 3/6] PCI: dwc: rcar-gen4: Add .deinit callback Marek Vasut
2026-09-05 21:38 ` sashiko-bot [this message]
2026-09-05 21:26 ` [PATCH v4 4/6] PCI: dwc: rcar-gen4: Split .start_link into ltssm_control and speed_control Marek Vasut
2026-09-05 21:32 ` sashiko-bot
2026-09-05 21:26 ` [PATCH v4 5/6] PCI: dwc: rcar-gen4: Handle PERST via reset subsystem Marek Vasut
2026-09-05 21:38 ` sashiko-bot
2026-09-05 21:26 ` [PATCH v4 6/6] PCI: dwc: rcar-gen4: Add support for R-Car X5H PCIe4 Marek Vasut
2026-09-05 21:40 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260905213809.9232B1F00A3D@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=marek.vasut+renesas@mailbox.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=wsa+renesas@sang-engineering.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.