All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sven Peter" <sven@kernel.org>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH v2 16/22] thunderbolt: Add add_links to tb_nhi_ops
Date: Sun, 06 Sep 2026 18:55:33 +0000	[thread overview]
Message-ID: <20260906185533.A93741F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260906-b4-apple-soc-tbt-v2-16-1f80085f93fb@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Fallback path in tb_probe() blindly casts a generic platform device to a PCI device, leading to a struct mismatch out-of-bounds read.
--

commit c3cbdbc00334a1dc32e8f14d7f05432dee177b2c
Author: Sven Peter <sven@kernel.org>

thunderbolt: Add add_links to tb_nhi_ops

This commit introduces an add_links callback to tb_nhi_ops for platform
drivers to discover and add device links. This enables drivers like the Apple
Silicon one to use device tree connections instead of ACPI or PCI topology.

> diff --git a/drivers/thunderbolt/tb.c b/drivers/thunderbolt/tb.c
> index d2832323cc360..72418a07166e3 100644
> --- a/drivers/thunderbolt/tb.c
> +++ b/drivers/thunderbolt/tb.c
> @@ -3434,7 +3434,8 @@ struct tb *tb_probe(struct tb_nhi *nhi)
>  	 * before the PCIe/USB stack is resumed so complain here if we
>  	 * found them missing.
>  	 */
> -	if (!tb_apple_add_links(nhi) && !tb_acpi_add_links(nhi))
> +	if (!(nhi->ops->add_links && nhi->ops->add_links(nhi)) &&
> +	    !tb_apple_add_links(nhi) && !tb_acpi_add_links(nhi))
>  		tb_warn(tb, "device links to tunneled native ports are missing!\n");

[Severity: Medium]
If a platform driver does not provide add_links or it returns false on an x86
Apple machine, could this fallback logic cause an out-of-bounds read?

Looking at tb_apple_add_links() called here:

static bool tb_apple_add_links(struct tb_nhi *nhi)
{
	struct pci_dev *nhi_pdev = to_pci_dev(nhi->dev);
	...
	if (!x86_apple_machine)
		return false;

	switch (nhi_pdev->device) {
	...

Because this patch opens up tb_probe() to non-PCI platform drivers, passing a
generic platform device to tb_apple_add_links() will result in an invalid
cast via to_pci_dev(). If evaluated on an x86 Apple machine, the subsequent
access to nhi_pdev->device will read out of bounds. 

Is there a way to verify the device is actually a PCI device before calling
tb_apple_add_links()?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260906-b4-apple-soc-tbt-v2-0-1f80085f93fb@kernel.org?part=16

  reply	other threads:[~2026-09-06 18:55 UTC|newest]

Thread overview: 55+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-06 18:36 [PATCH v2 00/22] Initial USB4/Thunderbolt support for Apple M1/M2/M3 SoCs Sven Peter
2026-09-06 18:36 ` [PATCH v2 01/22] usb: typec: Add alternate mode state notifiers Sven Peter
2026-09-06 18:48   ` sashiko-bot
2026-09-07 13:27   ` Joshua Peisach
2026-09-08 12:00   ` Heikki Krogerus
2026-09-06 18:36 ` [PATCH v2 02/22] usb: typec: Represent USB4 on the Type-C bus Sven Peter
2026-09-06 18:52   ` sashiko-bot
2026-09-07 13:31   ` Joshua Peisach
2026-09-08 12:07   ` Heikki Krogerus
2026-09-06 18:36 ` [PATCH v2 03/22] usb: typec: tipd: Register a USB4 port mode for CD321x Sven Peter
2026-09-06 18:47   ` sashiko-bot
2026-09-06 18:36 ` [PATCH v2 04/22] usb: typec: tipd: Publish CD321x partner alternate modes Sven Peter
2026-09-06 18:54   ` sashiko-bot
2026-09-06 18:36 ` [PATCH v2 05/22] dt-bindings: thunderbolt: Add Apple USB4/Thunderbolt NHI Sven Peter
2026-09-17 22:30   ` Rob Herring (Arm)
2026-09-06 18:36 ` [PATCH v2 06/22] dt-bindings: thunderbolt: Add Apple USB4/Thunderbolt ACIO block Sven Peter
2026-09-17 22:33   ` Rob Herring (Arm)
2026-09-06 18:36 ` [PATCH v2 07/22] thunderbolt: Try reading host DROM from device tree first Sven Peter
2026-09-15 17:20   ` Konrad Dybcio
2026-09-06 18:36 ` [PATCH v2 08/22] thunderbolt: Don't read the UID if we already know it Sven Peter
2026-09-06 19:07   ` sashiko-bot
2026-09-06 18:36 ` [PATCH v2 09/22] thunderbolt: Allocate ring HopID before requesting the ring interrupt Sven Peter
2026-09-06 18:36 ` [PATCH v2 10/22] thunderbolt: Unlock host router ports during startup Sven Peter
2026-09-06 19:03   ` sashiko-bot
2026-09-08  8:22   ` Mika Westerberg
2026-09-06 18:36 ` [PATCH v2 11/22] thunderbolt: Find Apple VSE capability " Sven Peter
2026-09-06 18:45   ` sashiko-bot
2026-09-07 13:38   ` Joshua Peisach
2026-09-08 20:24     ` Sven Peter
2026-09-06 18:36 ` [PATCH v2 12/22] thunderbolt: Add ring_interrupt_active to tb_nhi_ops Sven Peter
2026-09-06 18:36 ` [PATCH v2 13/22] thunderbolt: Add ring register accessors " Sven Peter
2026-09-08  8:32   ` Mika Westerberg
2026-09-06 18:36 ` [PATCH v2 14/22] thunderbolt: Add ring_interrupt_mask " Sven Peter
2026-09-06 18:36 ` [PATCH v2 15/22] thunderbolt: Add ring_configure " Sven Peter
2026-09-06 18:53   ` sashiko-bot
2026-09-06 18:36 ` [PATCH v2 16/22] thunderbolt: Add add_links " Sven Peter
2026-09-06 18:55   ` sashiko-bot [this message]
2026-09-08  8:35   ` Mika Westerberg
2026-09-06 18:36 ` [PATCH v2 17/22] thunderbolt: Add QUIRK_NO_USB3_BW_ALLOC Sven Peter
2026-09-06 18:36 ` [PATCH v2 18/22] thunderbolt: Export symbols required by the Apple Silicon driver Sven Peter
2026-09-06 18:36 ` [PATCH v2 19/22] thunderbolt: Add Apple Silicon support Sven Peter
2026-09-06 18:59   ` sashiko-bot
2026-09-08  9:18   ` Mika Westerberg
2026-09-08 19:02     ` Sven Peter
2026-09-08 19:04       ` Sven Peter
2026-09-09  6:06       ` Mika Westerberg
2026-09-09 15:20         ` Sven Peter
2026-09-09 15:25           ` Sven Peter
2026-09-10  4:52             ` Mika Westerberg
2026-09-10  4:50           ` Mika Westerberg
2026-09-06 18:36 ` [PATCH v2 20/22] arm64: dts: apple: t8103: Add USB4 ACIO and NHI Sven Peter
2026-09-06 18:36 ` [PATCH v2 21/22] arm64: dts: apple: t8112: " Sven Peter
2026-09-06 18:36 ` [PATCH v2 22/22] arm64: dts: apple: t60xx: " Sven Peter
2026-09-06 18:57   ` sashiko-bot
2026-09-07 13:52 ` [PATCH v2 00/22] Initial USB4/Thunderbolt support for Apple M1/M2/M3 SoCs Joshua Peisach

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260906185533.A93741F00A3D@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sven@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.