* [PATCH] ARM: dts: BCM5301X: R7000: add nvram node
@ 2026-09-10 0:13 Rosen Penev
2026-09-10 0:20 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Rosen Penev @ 2026-09-10 0:13 UTC (permalink / raw)
To: devicetree
Cc: Florian Fainelli, Hauke Mehrtens, Rafał Miłecki,
Broadcom internal kernel review list, Rob Herring,
Krzysztof Kozlowski, Conor Dooley,
moderated list:BROADCOM BCM5301X ARM ARCHITECTURE, open list
Add it and set for gmac0, which is the only GMAC used on this board.
nvram size found from a random bootlog online.
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
.../boot/dts/broadcom/bcm4709-netgear-r7000.dts | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts b/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
index 24ba8f8f9bf3..0f3a00bc38c1 100644
--- a/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
+++ b/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
@@ -25,6 +25,15 @@ memory@0 {
<0x88000000 0x08000000>;
};
+ nvram@1c080000 {
+ compatible = "brcm,nvram";
+ reg = <0x1c080000 0x180000>;
+
+ et0macaddr: et0macaddr {
+ #nvmem-cell-cells = <1>;
+ };
+ };
+
leds {
compatible = "gpio-leds";
@@ -104,3 +113,8 @@ &usb3 {
&usb3_phy {
status = "okay";
};
+
+&gmac0 {
+ nvmem-cells = <&et0macaddr 0>;
+ nvmem-cell-names = "mac-address";
+};
--
2.55.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] ARM: dts: BCM5301X: R7000: add nvram node
2026-09-10 0:13 [PATCH] ARM: dts: BCM5301X: R7000: add nvram node Rosen Penev
@ 2026-09-10 0:20 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-10 0:20 UTC (permalink / raw)
To: Rosen Penev; +Cc: devicetree, robh, conor+dt
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing length validation in `brcm_nvram_parse` allows for out-of-bounds heap read/write and potential panics (preexisting).
--
commit fcc6c069f7250c796767f24fbe9f085f9b0e3334
Author: Rosen Penev <rosenp@gmail.com>
ARM: dts: BCM5301X: R7000: add nvram node
This commit adds the nvram node to the BCM4709 Netgear R7000 device tree
and configures it for gmac0.
> diff --git a/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts b/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
> index 24ba8f8f9bf36..0f3a00bc38c14 100644
> --- a/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
> +++ b/arch/arm/boot/dts/broadcom/bcm4709-netgear-r7000.dts
> @@ -25,6 +25,15 @@ memory@0 {
> <0x88000000 0x08000000>;
> };
>
> + nvram@1c080000 {
> + compatible = "brcm,nvram";
[Severity: High]
This is a pre-existing issue, but adding this DTS node exposes the device to a
missing length validation in the brcm_nvram driver.
In drivers/nvmem/brcm_nvram.c:brcm_nvram_parse(), if the NVRAM flash is
completely erased or uninitialized (e.g. all 0xFF or 0x00),
brcm_nvram_copy_data() calculates priv->data_len as 0. This causes
devm_kzalloc() to return ZERO_SIZE_PTR.
Will the subsequent memcmp() dereference this invalid pointer and cause a
panic?
if (memcmp(header->magic, NVRAM_MAGIC, 4)) {
Furthermore, if len is larger than priv->data_len, it is validated against
the mapped region size (priv->nvmem_size) instead of the allocated heap
size:
if (len > priv->nvmem_size) {
Can this lead to an out-of-bounds heap read and write in
brcm_nvram_add_cells()?
tmp = priv->data[len - 1];
priv->data[len - 1] = '\0';
> + reg = <0x1c080000 0x180000>;
> +
> + et0macaddr: et0macaddr {
> + #nvmem-cell-cells = <1>;
> + };
> + };
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260910001300.117062-1-rosenp@gmail.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-10 0:20 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-10 0:13 [PATCH] ARM: dts: BCM5301X: R7000: add nvram node Rosen Penev
2026-09-10 0:20 ` sashiko-bot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.