All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jiaxing Hu" <gahing@gahingwoo.com>
Cc: robh@kernel.org, conor+dt@kernel.org,
	dri-devel@lists.freedesktop.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v13 10/14] pmdomain: rockchip: cycle optional power-domain resets on power-on
Date: Tue, 15 Sep 2026 10:56:56 +0000	[thread overview]
Message-ID: <20260915105657.500F91F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260915104328.45901-11-gahing@gahingwoo.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] pmdomain: rockchip: UAF of reset control on probe error path
--

commit 7f227aa8bc180bf2cac448c39f64d020d6dc07cf
Author: Jiaxing Hu <gahing@gahingwoo.com>

pmdomain: rockchip: cycle optional power-domain resets on power-on

Some Rockchip domains come out of power-on with their bus interface in an
undefined state. On the RK3576 NPU this shows up as a hang on the first
register access after the domain is switched on, and pulsing the domain's
resets at this point clears it.

> diff --git a/drivers/pmdomain/rockchip/pm-domains.c b/drivers/pmdomain/rockchip/pm-domains.c
> index 39988efd86aaa..6cc8d6efda905 100644
> --- a/drivers/pmdomain/rockchip/pm-domains.c
> +++ b/drivers/pmdomain/rockchip/pm-domains.c

[ ... ]

> @@ -688,6 +690,21 @@ static int rockchip_pd_power(struct rockchip_pm_domain *pd, bool power_on)
>  		if (ret < 0)
>  			goto out;
>  
> +		/*
> +		 * Optional: some domains need their resets cycled once power
> +		 * is on. This goes BEFORE the settle delay, not after: a
> +		 * domain that asks for both is asking to settle before the
> +		 * QoS registers answer, and a reset deasserted after the
> +		 * delay would leave nothing between it and the QoS writes.
> +		 * On RK3576 the reset being cycled is the NPU core's bus
> +		 * interface, which is what those writes go through.
> +		 */
> +		if (pd->resets) {
> +			reset_control_assert(pd->resets);

[Severity: High]
Can a concurrent call to power the domain trigger a use-after-free here?

If rockchip_pm_domain_probe() fails, the error path calls
rockchip_pm_domain_cleanup(), which invokes rockchip_pm_remove_one_domain().
For domains with attached subdomains, pm_genpd_remove() returns -EBUSY and
the driver ignores this failure, proceeding to free resources.

If pd->resets is freed in rockchip_pm_remove_one_domain() but the domain
remains registered, could a concurrent request to power the domain (via another
device probe or sysfs) invoke rockchip_pd_power(), evaluate the dangling
pd->resets pointer as true, and dereference it?

> +			usleep_range(10, 20);
> +			reset_control_deassert(pd->resets);
> +		}
> +
>  		/* Some domains need to settle before the QoS registers answer. */
>  		if (pd->info->delay_us)
>  			udelay(pd->info->delay_us);

[ ... ]

> @@ -949,6 +975,7 @@ static void rockchip_pm_remove_one_domain(struct rockchip_pm_domain *pd)
>  
>  	clk_bulk_unprepare(pd->num_clks, pd->clks);
>  	clk_bulk_put(pd->num_clks, pd->clks);
> +	reset_control_put(pd->resets);

[Severity: High]
Should pd->resets be set to NULL here?

The reset control is freed here, but the pd->resets pointer is left dangling.
This is unlike pd->num_clks below, which is safely cleared.

>  
>  	/* protect the zeroing of pm->num_clks */
>  	mutex_lock(&pd->pmu->mutex);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260915104328.45901-1-gahing@gahingwoo.com?part=10

  reply	other threads:[~2026-09-15 10:56 UTC|newest]

Thread overview: 66+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 10:43 [PATCH v13 00/14] accel/rocket: RK3576 NPU (RKNN) enablement Jiaxing Hu
2026-09-15 10:43 ` Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 01/14] accel/rocket: request the core clocks by name Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 02/14] accel/rocket: take the completion register writes under job_lock Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 03/14] accel/rocket: wait for a running IRQ handler before resetting a core Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-15 10:59   ` sashiko-bot
2026-09-16 13:28   ` Igor Paunovic
2026-09-16 13:28     ` Igor Paunovic
2026-09-19  9:17     ` Jiaxing Hu
2026-09-19  9:17       ` Jiaxing Hu
2026-09-19 10:34       ` Igor Paunovic
2026-09-19 10:34         ` Igor Paunovic
2026-09-15 10:43 ` [PATCH v13 04/14] accel/rocket: let the core suspend after a reset Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-15 10:58   ` sashiko-bot
2026-09-15 10:43 ` [PATCH v13 05/14] accel/rocket: factor the completion tail out of the IRQ handler Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 06/14] dt-bindings: npu: rockchip: add rockchip,rk3576-rknn-core Jiaxing Hu
2026-09-15 10:43   ` [PATCH v13 06/14] dt-bindings: npu: rockchip: add rockchip, rk3576-rknn-core Jiaxing Hu
2026-09-15 10:43   ` [PATCH v13 06/14] dt-bindings: npu: rockchip: add rockchip,rk3576-rknn-core Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 07/14] dt-bindings: power: rockchip: allow resets in a power domain node Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-21 21:52   ` Heiko Stuebner
2026-09-21 21:52     ` Heiko Stuebner
2026-09-15 10:43 ` [PATCH v13 08/14] dt-bindings: iommu: rockchip: describe the RK3576 NPU MMU Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 09/14] pmdomain: rockchip: add optional per-domain power-on settle delay Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-21 12:41   ` Ulf Hansson
2026-09-21 12:41     ` Ulf Hansson
2026-09-21 22:06   ` Heiko Stuebner
2026-09-21 22:06     ` Heiko Stuebner
2026-09-22  1:28     ` Chaoyi Chen
2026-09-22  1:28       ` Chaoyi Chen
2026-09-24  9:08     ` Jiaxing Hu
2026-09-24  9:08       ` Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 10/14] pmdomain: rockchip: cycle optional power-domain resets on power-on Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-15 10:56   ` sashiko-bot [this message]
2026-09-21 12:43   ` Ulf Hansson
2026-09-21 12:43     ` Ulf Hansson
2026-09-23  9:38   ` Philipp Zabel
2026-09-23  9:38     ` Philipp Zabel
2026-09-15 10:43 ` [PATCH v13 11/14] accel/rocket: select the per-core clock and reset counts from match data Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 12/14] accel/rocket: add RK3576 NPU (RKNN) support Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 13/14] arm64: dts: rockchip: add NPU (RKNN) nodes to rk3576 Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-21 21:51   ` Heiko Stuebner
2026-09-21 21:51     ` Heiko Stuebner
2026-09-15 10:43 ` [PATCH v13 14/14] arm64: dts: rockchip: enable the NPU on rk3576-rock-4d Jiaxing Hu
2026-09-15 10:43   ` Jiaxing Hu
2026-09-19  7:32 ` [PATCH v13 00/14] accel/rocket: RK3576 NPU (RKNN) enablement Sidong Yang
2026-09-19  7:32   ` Sidong Yang
2026-09-19  9:17   ` Jiaxing Hu
2026-09-19  9:17     ` Jiaxing Hu
2026-09-21 12:46 ` Ulf Hansson
2026-09-21 12:46   ` Ulf Hansson
2026-09-24  9:08   ` Jiaxing Hu
2026-09-24  9:08     ` Jiaxing Hu
2026-09-24 13:48     ` Ulf Hansson
2026-09-24 13:48       ` Ulf Hansson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260915105657.500F91F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=gahing@gahingwoo.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.