From: sashiko-bot@kernel.org
To: "Louis-Alexis Eyraud" <louisalexis.eyraud@collabora.com>
Cc: linux-phy@lists.infradead.org, robh@kernel.org,
conor+dt@kernel.org, vkoul@kernel.org,
linux-scsi@vger.kernel.org, olteanv@gmail.com,
devicetree@vger.kernel.org, neil.armstrong@linaro.org
Subject: Re: [PATCH v12 08/24] scsi: ufs: mediatek: Add dual 0.9V supply support
Date: Mon, 14 Sep 2026 12:21:24 +0000 [thread overview]
Message-ID: <20260914122124.B80631F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260914-mt8196-ufs-v12-8-9279d7ef814d@collabora.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Unchecked NULL pointer dereference of optional regulator `host->reg_avdd09` in error recovery paths.
--
commit c69b1189125cd5106318d877fff7d1bf82dfd012
Author: Louis-Alexis Eyraud <louisalexis.eyraud@collabora.com>
scsi: ufs: mediatek: Add dual 0.9V supply support
This commit adds support for an additional 0.9V supply on the MT8196 SoC.
It introduces a second optional 0.9V regulator named "avdd09-1" to the
platform data and manages its enabling and disabling alongside the primary
supply.
> diff --git a/drivers/ufs/host/ufs-mediatek.c b/drivers/ufs/host/ufs-mediatek.c
> index f43bee50adb28..467fc77c90e12 100644
> --- a/drivers/ufs/host/ufs-mediatek.c
> +++ b/drivers/ufs/host/ufs-mediatek.c
[ ... ]
> @@ -513,18 +514,37 @@ static int ufs_mtk_wait_link_state(struct ufs_hba *hba, u32 state,
> static int ufs_mtk_09v_off(struct ufs_mtk_host *host)
> {
> struct arm_smccc_res res;
> - int ret;
> + int ret, ret2;
>
> - if (!host->reg_avdd09)
> + if (!host->reg_avdd09 && !host->reg_avdd09_1)
> return 0;
>
> ufs_mtk_va09_pwr_ctrl(res, 0);
> - ret = regulator_disable(host->reg_avdd09);
> - if (ret) {
> - dev_err(host->hba->dev, "Failed to disable avdd09-supply: %pe\n",
> - ERR_PTR(ret));
> - ufs_mtk_va09_pwr_ctrl(res, 1);
> - return ret;
> +
> + if (host->reg_avdd09) {
> + ret = regulator_disable(host->reg_avdd09);
> + if (ret) {
> + dev_err(host->hba->dev, "Failed to disable avdd09-supply: %pe\n",
> + ERR_PTR(ret));
> + ufs_mtk_va09_pwr_ctrl(res, 1);
> + return ret;
> + }
> + }
> +
> + if (host->reg_avdd09_1) {
> + ret = regulator_disable(host->reg_avdd09_1);
> + if (ret) {
> + dev_err(host->hba->dev, "Failed to disable avdd09-1-supply: %pe\n",
> + ERR_PTR(ret));
> +
> + ret2 = regulator_enable(host->reg_avdd09);
[Severity: High]
Can this cause a NULL pointer dereference?
Since host->reg_avdd09 is fetched using devm_regulator_get_optional(), it
can be NULL if it is absent from the device tree. If a system only has the
avdd09-1 supply configured and disabling it fails, this error path will
unconditionally call regulator_enable() with a NULL pointer, which will
cause a crash when the core API dereferences it.
> + if (ret2)
> + dev_err(host->hba->dev, "Failed to re-enable avdd09-supply: %pe\n",
> + ERR_PTR(ret2));
> +
> + ufs_mtk_va09_pwr_ctrl(res, 1);
> + return ret;
> + }
> }
>
> return 0;
> @@ -535,14 +555,26 @@ static int ufs_mtk_09v_on(struct ufs_mtk_host *host)
> struct arm_smccc_res res;
> int ret;
>
> - if (!host->reg_avdd09)
> + if (!host->reg_avdd09 && !host->reg_avdd09_1)
> return 0;
>
> - ret = regulator_enable(host->reg_avdd09);
> - if (ret) {
> - dev_err(host->hba->dev, "Failed to enable avdd09-supply: %pe\n",
> - ERR_PTR(ret));
> - return ret;
> + if (host->reg_avdd09) {
> + ret = regulator_enable(host->reg_avdd09);
> + if (ret) {
> + dev_err(host->hba->dev, "Failed to enable avdd09-supply: %pe\n",
> + ERR_PTR(ret));
> + return ret;
> + }
> + }
> +
> + if (host->reg_avdd09_1) {
> + ret = regulator_enable(host->reg_avdd09_1);
> + if (ret) {
> + dev_err(host->hba->dev, "Failed to enable avdd09-1-supply: %pe\n",
> + ERR_PTR(ret));
> + regulator_disable(host->reg_avdd09);
[Severity: High]
Could this lead to a kernel panic if avdd09 is missing from the device tree?
Similar to the off path, if host->reg_avdd09 is NULL and enabling
reg_avdd09_1 fails during runtime, calling regulator_disable() on a NULL
pointer will result in an immediate crash.
Should there be a check to ensure host->reg_avdd09 is not NULL before
attempting to disable or enable it in these error paths?
> + return ret;
> + }
> }
>
> ufs_mtk_va09_pwr_ctrl(res, 1);
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260914-mt8196-ufs-v12-0-9279d7ef814d@collabora.com?part=8
--
linux-phy mailing list
linux-phy@lists.infradead.org
https://lists.infradead.org/mailman/listinfo/linux-phy
WARNING: multiple messages have this Message-ID (diff)
From: sashiko-bot@kernel.org
To: "Louis-Alexis Eyraud" <louisalexis.eyraud@collabora.com>
Cc: linux-phy@lists.infradead.org, robh@kernel.org,
conor+dt@kernel.org, vkoul@kernel.org,
linux-scsi@vger.kernel.org, olteanv@gmail.com,
devicetree@vger.kernel.org, neil.armstrong@linaro.org
Subject: Re: [PATCH v12 08/24] scsi: ufs: mediatek: Add dual 0.9V supply support
Date: Mon, 14 Sep 2026 12:21:24 +0000 [thread overview]
Message-ID: <20260914122124.B80631F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260914-mt8196-ufs-v12-8-9279d7ef814d@collabora.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Unchecked NULL pointer dereference of optional regulator `host->reg_avdd09` in error recovery paths.
--
commit c69b1189125cd5106318d877fff7d1bf82dfd012
Author: Louis-Alexis Eyraud <louisalexis.eyraud@collabora.com>
scsi: ufs: mediatek: Add dual 0.9V supply support
This commit adds support for an additional 0.9V supply on the MT8196 SoC.
It introduces a second optional 0.9V regulator named "avdd09-1" to the
platform data and manages its enabling and disabling alongside the primary
supply.
> diff --git a/drivers/ufs/host/ufs-mediatek.c b/drivers/ufs/host/ufs-mediatek.c
> index f43bee50adb28..467fc77c90e12 100644
> --- a/drivers/ufs/host/ufs-mediatek.c
> +++ b/drivers/ufs/host/ufs-mediatek.c
[ ... ]
> @@ -513,18 +514,37 @@ static int ufs_mtk_wait_link_state(struct ufs_hba *hba, u32 state,
> static int ufs_mtk_09v_off(struct ufs_mtk_host *host)
> {
> struct arm_smccc_res res;
> - int ret;
> + int ret, ret2;
>
> - if (!host->reg_avdd09)
> + if (!host->reg_avdd09 && !host->reg_avdd09_1)
> return 0;
>
> ufs_mtk_va09_pwr_ctrl(res, 0);
> - ret = regulator_disable(host->reg_avdd09);
> - if (ret) {
> - dev_err(host->hba->dev, "Failed to disable avdd09-supply: %pe\n",
> - ERR_PTR(ret));
> - ufs_mtk_va09_pwr_ctrl(res, 1);
> - return ret;
> +
> + if (host->reg_avdd09) {
> + ret = regulator_disable(host->reg_avdd09);
> + if (ret) {
> + dev_err(host->hba->dev, "Failed to disable avdd09-supply: %pe\n",
> + ERR_PTR(ret));
> + ufs_mtk_va09_pwr_ctrl(res, 1);
> + return ret;
> + }
> + }
> +
> + if (host->reg_avdd09_1) {
> + ret = regulator_disable(host->reg_avdd09_1);
> + if (ret) {
> + dev_err(host->hba->dev, "Failed to disable avdd09-1-supply: %pe\n",
> + ERR_PTR(ret));
> +
> + ret2 = regulator_enable(host->reg_avdd09);
[Severity: High]
Can this cause a NULL pointer dereference?
Since host->reg_avdd09 is fetched using devm_regulator_get_optional(), it
can be NULL if it is absent from the device tree. If a system only has the
avdd09-1 supply configured and disabling it fails, this error path will
unconditionally call regulator_enable() with a NULL pointer, which will
cause a crash when the core API dereferences it.
> + if (ret2)
> + dev_err(host->hba->dev, "Failed to re-enable avdd09-supply: %pe\n",
> + ERR_PTR(ret2));
> +
> + ufs_mtk_va09_pwr_ctrl(res, 1);
> + return ret;
> + }
> }
>
> return 0;
> @@ -535,14 +555,26 @@ static int ufs_mtk_09v_on(struct ufs_mtk_host *host)
> struct arm_smccc_res res;
> int ret;
>
> - if (!host->reg_avdd09)
> + if (!host->reg_avdd09 && !host->reg_avdd09_1)
> return 0;
>
> - ret = regulator_enable(host->reg_avdd09);
> - if (ret) {
> - dev_err(host->hba->dev, "Failed to enable avdd09-supply: %pe\n",
> - ERR_PTR(ret));
> - return ret;
> + if (host->reg_avdd09) {
> + ret = regulator_enable(host->reg_avdd09);
> + if (ret) {
> + dev_err(host->hba->dev, "Failed to enable avdd09-supply: %pe\n",
> + ERR_PTR(ret));
> + return ret;
> + }
> + }
> +
> + if (host->reg_avdd09_1) {
> + ret = regulator_enable(host->reg_avdd09_1);
> + if (ret) {
> + dev_err(host->hba->dev, "Failed to enable avdd09-1-supply: %pe\n",
> + ERR_PTR(ret));
> + regulator_disable(host->reg_avdd09);
[Severity: High]
Could this lead to a kernel panic if avdd09 is missing from the device tree?
Similar to the off path, if host->reg_avdd09 is NULL and enabling
reg_avdd09_1 fails during runtime, calling regulator_disable() on a NULL
pointer will result in an immediate crash.
Should there be a check to ensure host->reg_avdd09 is not NULL before
attempting to disable or enable it in these error paths?
> + return ret;
> + }
> }
>
> ufs_mtk_va09_pwr_ctrl(res, 1);
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260914-mt8196-ufs-v12-0-9279d7ef814d@collabora.com?part=8
next prev parent reply other threads:[~2026-09-14 12:21 UTC|newest]
Thread overview: 76+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 11:38 [PATCH v12 00/24] MediaTek UFS Cleanup and MT8196 Enablement Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 11:38 ` [PATCH v12 01/24] dt-bindings: phy: Add mediatek,mt8196-ufsphy variant Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 11:38 ` [PATCH v12 02/24] dt-bindings: ufs: mediatek,ufs: Complete the binding Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 12:04 ` AngeloGioacchino Del Regno
2026-09-14 12:04 ` AngeloGioacchino Del Regno
2026-09-24 15:26 ` Rob Herring (Arm)
2026-09-24 15:26 ` Rob Herring (Arm)
2026-09-14 11:38 ` [PATCH v12 03/24] dt-bindings: ufs: mediatek,ufs: Add mt8196 variant Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 12:04 ` AngeloGioacchino Del Regno
2026-09-14 12:04 ` AngeloGioacchino Del Regno
2026-09-24 15:27 ` Rob Herring (Arm)
2026-09-24 15:27 ` Rob Herring (Arm)
2026-09-14 11:38 ` [PATCH v12 04/24] scsi: ufs: mediatek: Move MTK_SIP_UFS_CONTROL to mtk_sip_svc.h Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 11:38 ` [PATCH v12 05/24] phy: mediatek: ufs: Add support for resets Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 11:38 ` [PATCH v12 06/24] scsi: ufs: mediatek: Rework resets Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 11:38 ` [PATCH v12 07/24] scsi: ufs: mediatek: Rework 0.9V regulator Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 12:19 ` sashiko-bot
2026-09-14 12:19 ` sashiko-bot
2026-09-14 11:38 ` [PATCH v12 08/24] scsi: ufs: mediatek: Add dual 0.9V supply support Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 12:02 ` AngeloGioacchino Del Regno
2026-09-14 12:02 ` AngeloGioacchino Del Regno
2026-09-14 12:21 ` sashiko-bot [this message]
2026-09-14 12:21 ` sashiko-bot
2026-09-14 11:38 ` [PATCH v12 09/24] scsi: ufs: mediatek: Rework init function Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 11:38 ` [PATCH v12 10/24] scsi: ufs: mediatek: Rework the crypt-boost stuff Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 11:38 ` [PATCH v12 11/24] scsi: ufs: mediatek: Handle misc host voltage regulators Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 11:38 ` [PATCH v12 12/24] scsi: ufs: mediatek: Remove undocumented downstream reset cruft Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 11:38 ` [PATCH v12 13/24] scsi: ufs: mediatek: Remove vendor kernel quirks cruft Louis-Alexis Eyraud
2026-09-14 11:38 ` Louis-Alexis Eyraud
2026-09-14 12:45 ` sashiko-bot
2026-09-14 12:45 ` sashiko-bot
2026-09-14 11:39 ` [PATCH v12 14/24] scsi: ufs: mediatek: Use the common PHY framework Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 12:58 ` sashiko-bot
2026-09-14 12:58 ` sashiko-bot
2026-09-14 11:39 ` [PATCH v12 15/24] scsi: ufs: mediatek: Remove mediatek,ufs-broken-rtc property Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 12:52 ` sashiko-bot
2026-09-14 12:52 ` sashiko-bot
2026-09-14 11:39 ` [PATCH v12 16/24] scsi: ufs: mediatek: Rework _ufs_mtk_clk_scale error paths Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 13:03 ` sashiko-bot
2026-09-14 13:03 ` sashiko-bot
2026-09-14 11:39 ` [PATCH v12 17/24] scsi: ufs: mediatek: Clean up logging prints Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 11:39 ` [PATCH v12 18/24] scsi: ufs: mediatek: Rework ufs_mtk_wait_idle_state Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 11:39 ` [PATCH v12 19/24] scsi: ufs: mediatek: Don't acquire dvfsrc-vcore twice Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 11:39 ` [PATCH v12 20/24] scsi: ufs: mediatek: Rework hardware version reading Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 11:39 ` [PATCH v12 21/24] scsi: ufs: mediatek: Back up idle timer in per-instance struct Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 11:39 ` [PATCH v12 22/24] scsi: ufs: mediatek: Remove ret local from link_startup_notify Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 11:39 ` [PATCH v12 23/24] scsi: ufs: mediatek: Remove undocumented "clk-scale-up-vcore-min" Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 13:25 ` sashiko-bot
2026-09-14 13:25 ` sashiko-bot
2026-09-14 11:39 ` [PATCH v12 24/24] scsi: ufs: mediatek: Add MT8196 compatible, update copyright Louis-Alexis Eyraud
2026-09-14 11:39 ` Louis-Alexis Eyraud
2026-09-14 13:41 ` sashiko-bot
2026-09-14 13:41 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260914122124.B80631F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=linux-phy@lists.infradead.org \
--cc=linux-scsi@vger.kernel.org \
--cc=louisalexis.eyraud@collabora.com \
--cc=neil.armstrong@linaro.org \
--cc=olteanv@gmail.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.