From: Rudi Heitbaum <rudi@heitbaum.com>
To: Manivannan Sadhasivam <mani@kernel.org>,
Richard Zhu <hongxing.zhu@nxp.com>
Cc: "Rudi Heitbaum" <rudi@heitbaum.com>,
"Lucas Stach" <l.stach@pengutronix.de>,
"Lorenzo Pieralisi" <lpieralisi@kernel.org>,
"Krzysztof Wilczyński" <kwilczynski@kernel.org>,
"Rob Herring" <robh@kernel.org>,
"Bjorn Helgaas" <bhelgaas@google.com>,
linux-pci@vger.kernel.org, linux-arm-kernel@lists.infradead.org,
imx@lists.linux.dev, linux-kernel@vger.kernel.org,
stable@vger.kernel.org
Subject: [PATCH v2] PCI: imx6: Avoid dereferencing a NULL clock name
Date: Mon, 14 Sep 2026 12:35:31 +0000 [thread overview]
Message-ID: <aqfqE4OLhnN4a1lW@b65e9c1eb12f> (raw)
of_clk_bulk_get() leaves clk_bulk_data::id as NULL for every clock that
has no matching entry in "clock-names", which is legal: a node may list
more "clocks" phandles than it names. Both scans of the bulk array
dereference that id unconditionally, so such a node oopses during probe.
The loop in imx_pcie_probe() has been wrong since it was written. The
loop in imx_setup_phy_mpll() was not: it read a fixed clks[] whose ids
came from the driver's own clk_names[] and were never NULL, and only
became wrong when the driver moved to the bulk array.
Check clk_bulk_data::id before dereferencing it in both.
Fixes: f6a1fdfc78e2 ("PCI: imx6: Use devm_clk_bulk_get_all() to fetch clocks")
Fixes: d8574ce57d76 ("PCI: imx6: Add external reference clock input mode support")
Cc: stable@vger.kernel.org
Acked-by: Richard Zhu <hongxing.zhu@nxp.com>
Signed-off-by: Rudi Heitbaum <rudi@heitbaum.com>
---
Changes in v2:
- Also guard the identical unchecked dereference in imx_setup_phy_mpll(),
reported by Sashiko and requested by Manivannan Sadhasivam.
- Add the Fixes: tag for that site.
- v1: https://lore.kernel.org/all/am8iBwJSEhYhWTqk@6cfee64030a6/
drivers/pci/controller/dwc/pci-imx6.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/pci/controller/dwc/pci-imx6.c b/drivers/pci/controller/dwc/pci-imx6.c
index 39790e66b98d..f8dd83a88ddf 100644
--- a/drivers/pci/controller/dwc/pci-imx6.c
+++ b/drivers/pci/controller/dwc/pci-imx6.c
@@ -542,7 +542,7 @@ static int imx_setup_phy_mpll(struct imx_pcie *imx_pcie)
return 0;
for (i = 0; i < imx_pcie->num_clks; i++)
- if (strncmp(clks[i].id, "pcie_phy", 8) == 0)
+ if (clks[i].id && strncmp(clks[i].id, "pcie_phy", 8) == 0)
phy_rate = clk_get_rate(clks[i].clk);
switch (phy_rate) {
@@ -1836,7 +1836,8 @@ static int imx_pcie_probe(struct platform_device *pdev)
return dev_err_probe(dev, imx_pcie->num_clks,
"failed to get clocks\n");
for (i = 0; i < imx_pcie->num_clks; i++)
- if (strncmp(imx_pcie->clks[i].id, "extref", 6) == 0)
+ if (imx_pcie->clks[i].id &&
+ strncmp(imx_pcie->clks[i].id, "extref", 6) == 0)
imx_pcie->enable_ext_refclk = true;
if (imx_check_flag(imx_pcie, IMX_PCIE_FLAG_HAS_PHYDRV)) {
--
2.53.0
next reply other threads:[~2026-09-14 12:35 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 12:35 Rudi Heitbaum [this message]
2026-09-14 12:49 ` [PATCH v2] PCI: imx6: Avoid dereferencing a NULL clock name sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aqfqE4OLhnN4a1lW@b65e9c1eb12f \
--to=rudi@heitbaum.com \
--cc=bhelgaas@google.com \
--cc=hongxing.zhu@nxp.com \
--cc=imx@lists.linux.dev \
--cc=kwilczynski@kernel.org \
--cc=l.stach@pengutronix.de \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=mani@kernel.org \
--cc=robh@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.