From: sashiko-bot@kernel.org
To: "Louis-Alexis Eyraud" <louisalexis.eyraud@collabora.com>
Cc: robh@kernel.org, neil.armstrong@linaro.org, olteanv@gmail.com,
devicetree@vger.kernel.org, linux-scsi@vger.kernel.org,
linux-phy@lists.infradead.org, vkoul@kernel.org,
conor+dt@kernel.org
Subject: Re: [PATCH v10 11/26] scsi: ufs: mediatek: Remove undocumented downstream reset cruft
Date: Thu, 30 Jul 2026 10:23:53 +0000 [thread overview]
Message-ID: <20260730102353.E811F1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260730-mt8196-ufs-v10-11-bc5ecef202dc@collabora.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] The kobject reference for `phy_dev` is dropped too early during probe, leaving a dangling pointer stored in `host->phy_dev` that leads to a use-after-free in runtime PM callbacks.
- [High] The runtime PM usage count and enablement state for `phy_dev` are permanently leaked if the probe fails, and the PM state is never restored on driver removal.
--
--- Patch [11]: [PATCH v10 11/26] scsi: ufs: mediatek: Remove undocumented downstream reset cruft ---
commit 2e47ec1b9626d31e1288701fe0c4a25c195e38d4
Author: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
scsi: ufs: mediatek: Remove undocumented downstream reset cruft
The MediaTek UFS host driver's probe function allows using a ti,syscon-reset
as a reset, without going through the appropriate abstractions or documenting
this in the binding. This commit removes this downstream code as it does not
belong here.
> diff --git a/drivers/ufs/host/ufs-mediatek.c b/drivers/ufs/host/ufs-mediatek.c
> index 65036c8390318..a2749e79514c4 100644
> --- a/drivers/ufs/host/ufs-mediatek.c
> +++ b/drivers/ufs/host/ufs-mediatek.c
> @@ -2402,38 +2402,12 @@ MODULE_DEVICE_TABLE(of, ufs_mtk_of_match);
> static int ufs_mtk_probe(struct platform_device *pdev)
> {
> int err;
> - struct device *dev = &pdev->dev, *phy_dev = NULL;
> - struct device_node *reset_node, *phy_node = NULL;
> - struct platform_device *reset_pdev, *phy_pdev = NULL;
> - struct device_link *link;
> struct ufs_hba *hba;
> + struct platform_device *phy_pdev = NULL;
> + struct device *dev = &pdev->dev, *phy_dev = NULL;
> + struct device_node *phy_node = NULL;
> struct ufs_mtk_host *host;
>
> - reset_node = of_find_compatible_node(NULL, NULL,
> - "ti,syscon-reset");
> - if (!reset_node) {
> - dev_notice(dev, "find ti,syscon-reset fail\n");
> - goto skip_reset;
> - }
> - reset_pdev = of_find_device_by_node(reset_node);
> - if (!reset_pdev) {
> - dev_notice(dev, "find reset_pdev fail\n");
> - goto skip_reset;
> - }
> - link = device_link_add(dev, &reset_pdev->dev,
> - DL_FLAG_AUTOPROBE_CONSUMER);
> - put_device(&reset_pdev->dev);
> - if (!link) {
> - dev_notice(dev, "add reset device_link fail\n");
> - goto skip_reset;
> - }
> - /* supplier is not probed */
> - if (link->status == DL_STATE_DORMANT) {
> - err = -EPROBE_DEFER;
> - goto out;
> - }
> -
> -skip_reset:
> /* find phy node */
> phy_node = of_parse_phandle(dev->of_node, "phys", 0);
>
> @@ -2479,7 +2453,6 @@ static int ufs_mtk_probe(struct platform_device *pdev)
>
> out:
> of_node_put(phy_node);
> - of_node_put(reset_node);
> return err;
> }
[Severity: High]
This isn't a bug introduced by this patch, but could this lead to a
use-after-free of phy_dev?
In ufs_mtk_probe(), after looking up the PHY device, the kobject reference
is dropped almost immediately:
drivers/ufs/host/ufs-mediatek.c:ufs_mtk_probe() {
phy_pdev = of_find_device_by_node(phy_node);
if (!phy_pdev)
goto skip_phy;
phy_dev = &phy_pdev->dev;
...
put_device(phy_dev);
...
}
However, the pointer is later saved into the host structure for later use:
drivers/ufs/host/ufs-mediatek.c:ufs_mtk_probe() {
...
if (phy_node && phy_dev) {
host = ufshcd_get_variant(hba);
host->phy_dev = phy_dev;
}
...
}
If the PHY device is later unbound via sysfs and its memory freed, would the
UFS host's runtime PM callbacks, such as ufs_mtk_runtime_suspend(),
dereference this dangling host->phy_dev pointer when calling
pm_runtime_put_sync()?
[Severity: High]
This is also a pre-existing issue, but is there a PM runtime usage count
leak in ufs_mtk_probe() on error paths?
If a failure occurs during initialization (e.g., ufshcd_pltfrm_init() fails),
the function jumps to the out label without calling pm_runtime_put_sync() or
pm_runtime_disable() for phy_dev:
drivers/ufs/host/ufs-mediatek.c:ufs_mtk_probe() {
if (phy_node) {
...
pm_runtime_enable(phy_dev);
pm_runtime_get_sync(phy_dev);
...
}
...
err = ufshcd_pltfrm_init(pdev, &ufs_hba_mtk_vops);
if (err)
goto out;
...
out:
of_node_put(phy_node);
return err;
}
Additionally, ufs_mtk_remove() doesn't appear to tear down this state.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260730-mt8196-ufs-v10-0-bc5ecef202dc@collabora.com?part=11
next prev parent reply other threads:[~2026-07-30 10:23 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-30 9:48 [PATCH v10 00/26] MediaTek UFS Cleanup and MT8196 Enablement Louis-Alexis Eyraud
2026-07-30 9:48 ` [PATCH v10 01/26] dt-bindings: phy: Add mediatek,mt8196-ufsphy variant Louis-Alexis Eyraud
2026-07-30 9:48 ` [PATCH v10 02/26] dt-bindings: ufs: mediatek,ufs: Complete the binding Louis-Alexis Eyraud
2026-07-30 9:57 ` sashiko-bot
2026-07-30 9:48 ` [PATCH v10 03/26] dt-bindings: ufs: mediatek,ufs: Add mt8196 variant Louis-Alexis Eyraud
2026-07-30 9:59 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 04/26] scsi: ufs: mediatek: Move MTK_SIP_UFS_CONTROL to mtk_sip_svc.h Louis-Alexis Eyraud
2026-07-30 9:49 ` [PATCH v10 05/26] phy: mediatek: ufs: Add support for resets Louis-Alexis Eyraud
2026-07-30 9:49 ` [PATCH v10 06/26] scsi: ufs: mediatek: Rework resets Louis-Alexis Eyraud
2026-07-30 10:29 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 07/26] scsi: ufs: mediatek: Rework 0.9V regulator Louis-Alexis Eyraud
2026-07-30 10:13 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 08/26] scsi: ufs: mediatek: Rework init function Louis-Alexis Eyraud
2026-07-30 10:07 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 09/26] scsi: ufs: mediatek: Rework the crypt-boost stuff Louis-Alexis Eyraud
2026-07-30 10:16 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 10/26] scsi: ufs: mediatek: Handle misc host voltage regulators Louis-Alexis Eyraud
2026-07-30 10:29 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 11/26] scsi: ufs: mediatek: Remove undocumented downstream reset cruft Louis-Alexis Eyraud
2026-07-30 10:23 ` sashiko-bot [this message]
2026-07-30 9:49 ` [PATCH v10 12/26] scsi: ufs: mediatek: Remove vendor kernel quirks cruft Louis-Alexis Eyraud
2026-07-30 10:30 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 13/26] scsi: ufs: mediatek: Use the common PHY framework Louis-Alexis Eyraud
2026-07-30 10:40 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 14/26] scsi: ufs: mediatek: Remove mediatek,ufs-broken-rtc property Louis-Alexis Eyraud
2026-07-30 9:49 ` [PATCH v10 15/26] scsi: ufs: mediatek: Rework _ufs_mtk_clk_scale error paths Louis-Alexis Eyraud
2026-07-30 10:34 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 16/26] scsi: ufs: mediatek: Clean up logging prints Louis-Alexis Eyraud
2026-07-30 9:49 ` [PATCH v10 17/26] scsi: ufs: mediatek: Rework ufs_mtk_wait_idle_state Louis-Alexis Eyraud
2026-07-30 9:49 ` [PATCH v10 18/26] scsi: ufs: mediatek: Don't acquire dvfsrc-vcore twice Louis-Alexis Eyraud
2026-07-30 10:41 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 19/26] scsi: ufs: mediatek: Rework hardware version reading Louis-Alexis Eyraud
2026-07-30 9:49 ` [PATCH v10 20/26] scsi: ufs: mediatek: Back up idle timer in per-instance struct Louis-Alexis Eyraud
2026-07-30 10:53 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 21/26] scsi: ufs: mediatek: Remove ret local from link_startup_notify Louis-Alexis Eyraud
2026-07-30 9:49 ` [PATCH v10 22/26] scsi: ufs: mediatek: Remove undocumented "clk-scale-up-vcore-min" Louis-Alexis Eyraud
2026-07-30 10:49 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 23/26] scsi: ufs: mediatek: Add MT8196 compatible, update copyright Louis-Alexis Eyraud
2026-07-30 9:49 ` [PATCH v10 24/26] arm64: dts: mediatek: mt8195: Align ufshci node to dt-bindings changes Louis-Alexis Eyraud
2026-07-30 11:13 ` sashiko-bot
2026-07-30 9:49 ` [PATCH v10 25/26] arm64: dts: mediatek: mt8395-genio-1200-evk-ufs: Complete UFS power supplies Louis-Alexis Eyraud
2026-07-30 9:49 ` [PATCH v10 26/26] arm64: dts: mediatek: mt8395-radxa-nio-12l: " Louis-Alexis Eyraud
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260730102353.E811F1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=linux-phy@lists.infradead.org \
--cc=linux-scsi@vger.kernel.org \
--cc=louisalexis.eyraud@collabora.com \
--cc=neil.armstrong@linaro.org \
--cc=olteanv@gmail.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox