All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] ARM: dts: BCM5301X: R7000: add nvram node
@ 2026-09-10  0:13 Rosen Penev
  2026-09-10  0:20 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: Rosen Penev @ 2026-09-10  0:13 UTC (permalink / raw)
  To: devicetree
  Cc: Florian Fainelli, Hauke Mehrtens, Rafał Miłecki,
	Broadcom internal kernel review list, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley,
	moderated list:BROADCOM BCM5301X ARM ARCHITECTURE, open list

Add it and set for gmac0, which is the only GMAC used on this board.

nvram size found from a random bootlog online.

Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
 .../boot/dts/broadcom/bcm4709-netgear-r7000.dts    | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts b/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
index 24ba8f8f9bf3..0f3a00bc38c1 100644
--- a/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
+++ b/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
@@ -25,6 +25,15 @@ memory@0 {
 		      <0x88000000 0x08000000>;
 	};
 
+	nvram@1c080000 {
+		compatible = "brcm,nvram";
+		reg = <0x1c080000 0x180000>;
+
+		et0macaddr: et0macaddr {
+			#nvmem-cell-cells = <1>;
+		};
+	};
+
 	leds {
 		compatible = "gpio-leds";
 
@@ -104,3 +113,8 @@ &usb3 {
 &usb3_phy {
 	status = "okay";
 };
+
+&gmac0 {
+	nvmem-cells = <&et0macaddr 0>;
+	nvmem-cell-names = "mac-address";
+};
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] ARM: dts: BCM5301X: R7000: add nvram node
  2026-09-10  0:13 [PATCH] ARM: dts: BCM5301X: R7000: add nvram node Rosen Penev
@ 2026-09-10  0:20 ` sashiko-bot
  0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-10  0:20 UTC (permalink / raw)
  To: Rosen Penev; +Cc: devicetree, robh, conor+dt

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Missing length validation in `brcm_nvram_parse` allows for out-of-bounds heap read/write and potential panics (preexisting).
--

commit fcc6c069f7250c796767f24fbe9f085f9b0e3334
Author: Rosen Penev <rosenp@gmail.com>

ARM: dts: BCM5301X: R7000: add nvram node

This commit adds the nvram node to the BCM4709 Netgear R7000 device tree
and configures it for gmac0.

> diff --git a/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts b/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
> index 24ba8f8f9bf36..0f3a00bc38c14 100644
> --- a/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
> +++ b/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
> @@ -25,6 +25,15 @@ memory@0 {
>  		      <0x88000000 0x08000000>;
>  	};
>  
> +	nvram@1c080000 {
> +		compatible = "brcm,nvram";

[Severity: High]
This is a pre-existing issue, but adding this DTS node exposes the device to a
missing length validation in the brcm_nvram driver.

In drivers/nvmem/brcm_nvram.c:brcm_nvram_parse(), if the NVRAM flash is
completely erased or uninitialized (e.g. all 0xFF or 0x00),
brcm_nvram_copy_data() calculates priv->data_len as 0. This causes
devm_kzalloc() to return ZERO_SIZE_PTR.

Will the subsequent memcmp() dereference this invalid pointer and cause a
panic?

    if (memcmp(header->magic, NVRAM_MAGIC, 4)) {

Furthermore, if len is larger than priv->data_len, it is validated against
the mapped region size (priv->nvmem_size) instead of the allocated heap
size:

    if (len > priv->nvmem_size) {

Can this lead to an out-of-bounds heap read and write in
brcm_nvram_add_cells()?

    tmp = priv->data[len - 1];
    priv->data[len - 1] = '\0';

> +		reg = <0x1c080000 0x180000>;
> +
> +		et0macaddr: et0macaddr {
> +			#nvmem-cell-cells = <1>;
> +		};
> +	};

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260910001300.117062-1-rosenp@gmail.com?part=1

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-10  0:20 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-10  0:13 [PATCH] ARM: dts: BCM5301X: R7000: add nvram node Rosen Penev
2026-09-10  0:20 ` sashiko-bot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.