All of lore.kernel.org
 help / color / mirror / Atom feed
From: huhai  <15815827059@163.com>
To: "Jakub Kicinski" <kuba@kernel.org>
Cc: "Xuanqiang Luo" <xuanqiang.luo@linux.dev>,
	netdev@vger.kernel.org, huhai <huhai@kylinos.cn>,
	andrew@lunn.ch, divya.koppera@microchip.com
Subject: Re:Re: [PATCH] net: phy: microchip_t1: fix NULL pointer dereference in lan887x_phy_init()
Date: Thu, 3 Sep 2026 17:01:29 +0800 (CST)	[thread overview]
Message-ID: <2a9bd784.78bc.1a0668072f0.Coremail.15815827059@163.com> (raw)
In-Reply-To: <20260902155825.63974224@kernel.org>

At 2026-09-03 06:58:25, "Jakub Kicinski" <kuba@kernel.org> wrote:
>On Wed, 2 Sep 2026 17:16:48 +0800 Xuanqiang Luo wrote:
>> > mchp_rds_ptp_probe() may return NULL when CONFIG_PTP_1588_CLOCK is disabled.  
>> 
>> When CONFIG_MICROCHIP_PHY_RDS_PTP=n, the stub for
>> mchp_rds_ptp_probe() also returns NULL, even if
>> CONFIG_PTP_1588_CLOCK=y. Please mention this case in the commit message.
>
>Speaking of improvements to the commits message - please also explain
>how the issue was found, reproduced, and fix validated.
>

The issue was discovered via smatch:

make CHECK="smatch -p=kernel"  C=2  drivers/net/phy/microchip_t1.o
  CHECK   scripts/mod/empty.c
  DESCEND objtool
  CHECK   drivers/net/phy/microchip_t1.c
drivers/net/phy/microchip_t1.c:1295 lan887x_phy_init() warn: 'priv->clock' can also be NULL

I will add the above information to the commit message in the next version of the patch.

Then, disassembly confirmed that a null pointer dereference does indeed exist:

objdump -drSwC --no-show-raw-insn --disassemble=lan887x_phy_init drivers/net/phy/microchip_t1.o
             	priv->clock = mchp_rds_ptp_probe(phydev, MDIO_MMD_VEND1,
    10c2:       movq   $0x0,0x30(%r13)   # priv->clock = NULL
                ... ...
                priv->clock->event_pin = 3;
    10e7:       mov    0x30(%r13),%rax   # rax = priv->clock = NULL
    10eb:       movl   $0x3,0x190(%rax)  # *(u32 *)(NULL + 0x190) = 3

Additionally, I do not have hardware available to verify and reproduce the issue,
it was identified purely through analysis. After applying a patch, smatch no longer 
produces the warning.

>It'd be good to improve the spalling of your name (rather just
>repeating your email login) a little; or just add your real name in
>unicode characters in () brackets, like huhai ($unicode chars) <email>.

Regarding the name spelling suggestion, I will update my signed-off-by
line to use my full English name in the next version of the patch.

Thanks.

      reply	other threads:[~2026-09-03  9:02 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02  8:33 [PATCH] net: phy: microchip_t1: fix NULL pointer dereference in lan887x_phy_init() huhai
2026-09-02  8:56 ` Divya.Koppera
2026-09-02  9:16 ` Xuanqiang Luo
2026-09-02 22:58   ` Jakub Kicinski
2026-09-03  9:01     ` huhai [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2a9bd784.78bc.1a0668072f0.Coremail.15815827059@163.com \
    --to=15815827059@163.com \
    --cc=andrew@lunn.ch \
    --cc=divya.koppera@microchip.com \
    --cc=huhai@kylinos.cn \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=xuanqiang.luo@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.