Linux kernel and device drivers for NXP i.MX platforms
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rudi Heitbaum" <rudi@heitbaum.com>
Cc: linux-pci@vger.kernel.org, Frank.Li@kernel.org, imx@lists.linux.dev
Subject: Re: [PATCH v2] PCI: imx6: Avoid dereferencing a NULL clock name
Date: Mon, 14 Sep 2026 12:49:03 +0000	[thread overview]
Message-ID: <20260914124904.1F9CC1F00893@smtp.kernel.org> (raw)
In-Reply-To: <aqfqE4OLhnN4a1lW@b65e9c1eb12f>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] The return value of imx_pcie_host_init() is completely ignored in imx_add_pcie_ep().
--

commit 628ea0e01756defcb86187cc3b9ad1e2b8354965
Author: Rudi Heitbaum <rudi@heitbaum.com>

PCI: imx6: Avoid dereferencing a NULL clock name

This commit prevents a NULL pointer dereference when accessing clock IDs by
checking that clk_bulk_data::id is not NULL before using it in strncmp().
This fixes a probe crash caused by unpopulated clock names.

Link: https://lore.kernel.org/all/am8iBwJSEhYhWTqk@6cfee64030a6/

> diff --git a/drivers/pci/controller/dwc/pci-imx6.c b/drivers/pci/controller/dwc/pci-imx6.c
> index 39790e66b98dc..f8dd83a88ddf7 100644
> --- a/drivers/pci/controller/dwc/pci-imx6.c
> +++ b/drivers/pci/controller/dwc/pci-imx6.c
> @@ -542,7 +542,7 @@ static int imx_setup_phy_mpll(struct imx_pcie *imx_pcie)
>  		return 0;
>  
>  	for (i = 0; i < imx_pcie->num_clks; i++)
> -		if (strncmp(clks[i].id, "pcie_phy", 8) == 0)
> +		if (clks[i].id && strncmp(clks[i].id, "pcie_phy", 8) == 0)
>  			phy_rate = clk_get_rate(clks[i].clk);
>  
>  	switch (phy_rate) {

[ ... ]

> @@ -1836,7 +1836,8 @@ static int imx_pcie_probe(struct platform_device *pdev)
>  		return dev_err_probe(dev, imx_pcie->num_clks,
>  				     "failed to get clocks\n");
>  	for (i = 0; i < imx_pcie->num_clks; i++)
> -		if (strncmp(imx_pcie->clks[i].id, "extref", 6) == 0)
> +		if (imx_pcie->clks[i].id &&
> +		    strncmp(imx_pcie->clks[i].id, "extref", 6) == 0)
>  			imx_pcie->enable_ext_refclk = true;
>  
>  	if (imx_check_flag(imx_pcie, IMX_PCIE_FLAG_HAS_PHYDRV)) {

[Severity: High]
This isn't a bug introduced by this patch, but I noticed a potential problem
with error handling in imx_add_pcie_ep() within this file:

drivers/pci/controller/dwc/pci-imx6.c:imx_add_pcie_ep() {
    ...
	imx_pcie_host_init(pp);
	ep = &pci->ep;
    ...
	ret = dw_pcie_ep_init(ep);
	if (ret) {
    ...
}

The return value of imx_pcie_host_init() is completely ignored. If hardware
initialization steps in imx_pcie_host_init() fail (e.g., regulator_enable or
clk_enable returning an error), it returns a negative error code.

Does ignoring this return value allow execution to proceed and initialize the
endpoint on unpowered or unclocked hardware, triggering a system crash upon
register access in dw_pcie_ep_init()?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/aqfqE4OLhnN4a1lW@b65e9c1eb12f?part=1

      reply	other threads:[~2026-09-14 12:49 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-14 12:35 [PATCH v2] PCI: imx6: Avoid dereferencing a NULL clock name Rudi Heitbaum
2026-09-14 12:49 ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260914124904.1F9CC1F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=imx@lists.linux.dev \
    --cc=linux-pci@vger.kernel.org \
    --cc=rudi@heitbaum.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox