Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Coia Prant" <coiaprant@gmail.com>
Cc: conor+dt@kernel.org, wsa+renesas@sang-engineering.com,
	linux-phy@lists.infradead.org, neil.armstrong@linaro.org,
	robh@kernel.org, vkoul@kernel.org, olteanv@gmail.com,
	devicetree@vger.kernel.org
Subject: Re: [PATCH net-next v8 07/11] net: pcs: xpcs: add Rockchip RK3568 platform glue driver
Date: Sun, 20 Sep 2026 12:53:19 +0000	[thread overview]
Message-ID: <20260920125319.8D9001F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260919125119.2107089-8-coiaprant@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] net: pcs: xpcs-rk: UAF in xpcs_rk_create due to TOCTOU and unprotected devres access
--

commit 2e7f490907e83788481369bf43ad35abe0d56504
Author: Coia Prant <coiaprant@gmail.com>

net: pcs: xpcs: add Rockchip RK3568 platform glue driver

This commit introduces a generic platform glue driver for the Synopsys
DesignWare XPCS on Rockchip RK3568 SoCs. It translates standard MDIO
operations into APB3 memory-mapped register accesses by creating a
virtual MDIO bus.

Link: https://dl.radxa.com/rock3/docs/hw/datasheet/Rockchip%20RK3568%20TRM%20Part1%20V1.1-20210301.pdf
Link: https://dl.radxa.com/rock3/docs/hw/datasheet/Rockchip%20RK3568%20TRM%20Part2%20V1.1-20210301.pdf

> diff --git a/drivers/net/pcs/pcs-xpcs-rk.c b/drivers/net/pcs/pcs-xpcs-rk.c
> new file mode 100644
> index 0000000000000..84f8ea7fa57e8
> --- /dev/null
> +++ b/drivers/net/pcs/pcs-xpcs-rk.c

[ ... ]

> +struct dw_xpcs *xpcs_rk_create(struct device *dev, struct device_node *np)
> +{
> +	struct platform_device *pdev;

[ ... ]

> +	if (!device_link_add(dev, &pdev->dev, DL_FLAG_AUTOREMOVE_CONSUMER)) {
> +		put_device(&pdev->dev);
> +		return ERR_PTR(-EPROBE_DEFER);
> +	}
> +
> +	device_lock(&pdev->dev);
> +	if (!device_is_bound(&pdev->dev)) {
> +		device_unlock(&pdev->dev);
> +		put_device(&pdev->dev);
> +		return ERR_PTR(-EPROBE_DEFER);
> +	}
> +	device_unlock(&pdev->dev);
> +
> +	pxpcs = platform_get_drvdata(pdev);
> +	if (!pxpcs || !pxpcs->bus) {

[Severity: High]
Can this result in a use-after-free of the supplier devres data?

If the XPCS driver unbinds while a second MAC consumer probes, the newly
created device link will be in the DL_STATE_SUPPLIER_UNBIND state. Because
of this state, device_links_unbind_consumers() ignores it and does not wait.

Since the device_lock() is dropped before calling platform_get_drvdata(),
could the unbind finish and free the pxpcs devres allocation before we
dereference pxpcs->bus below?

CPU1 (Supplier Unbinding)             CPU2 (Consumer Probing)
                                      device_link_add()
                                      device_lock()
                                      device_is_bound() returns true
                                      device_unlock()
unbind completes
devres frees pxpcs
                                      pxpcs = platform_get_drvdata(pdev);
                                      xpcs_create_mdiodev(pxpcs->bus, ...)

> +		put_device(&pdev->dev);
> +		return ERR_PTR(-EPROBE_DEFER);
> +	}
> +
> +	xpcs = xpcs_create_mdiodev(pxpcs->bus, (int)port);
> +	if (IS_ERR(xpcs)) {
> +		put_device(&pdev->dev);
> +		return xpcs;
> +	}

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260919125119.2107089-1-coiaprant@gmail.com?part=7

  reply	other threads:[~2026-09-20 12:53 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-19 12:51 [PATCH net-next v8 00/11] net: pcs: add basic support for RK3568 XPCS Coia Prant
2026-09-19 12:51 ` [PATCH net-next v8 01/11] net: stmmac: move XPCS lifetime management to platform drivers Coia Prant
2026-09-19 12:51 ` [PATCH net-next v8 02/11] dt-bindings: phy: rockchip: naneng-combphy: add rockchip,sgmii-mac-sel property Coia Prant
2026-09-19 12:51 ` [PATCH net-next v8 03/11] phy: rockchip: naneng-combphy: add SGMII MAC selection for RK3568 Coia Prant
2026-09-19 12:51 ` [PATCH net-next v8 04/11] dt-bindings: net: pcs: add rockchip,rk3568-xpcs support Coia Prant
2026-09-19 12:51 ` [PATCH net-next v8 05/11] arm64: dts: rockchip: rk3568: add XPCS and fixed-clock nodes Coia Prant
2026-09-20 12:53   ` sashiko-bot
2026-09-19 12:51 ` [PATCH net-next v8 06/11] net: pcs: xpcs: add ANRESTART support for SGMII link recovery Coia Prant
2026-09-19 12:51 ` [PATCH net-next v8 07/11] net: pcs: xpcs: add Rockchip RK3568 platform glue driver Coia Prant
2026-09-20 12:53   ` sashiko-bot [this message]
2026-09-19 12:51 ` [PATCH net-next v8 08/11] dt-bindings: net: rockchip-dwmac: document pcs-handle Coia Prant
2026-09-19 12:51 ` [PATCH net-next v8 09/11] net: stmmac: dwmac-rk: add SGMII support for RK3568 Coia Prant
2026-09-19 15:27   ` Maxime Chevallier
2026-09-19 12:51 ` [PATCH net-next v8 10/11] arm64: dts: rockchip: rk3568-photonicat: enable SGMII LAN port Coia Prant
2026-09-19 12:51 ` [PATCH net-next v8 11/11] MAINTAINERS: add entry for Rockchip XPCS driver Coia Prant

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260920125319.8D9001F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=coiaprant@gmail.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-phy@lists.infradead.org \
    --cc=neil.armstrong@linaro.org \
    --cc=olteanv@gmail.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    --cc=wsa+renesas@sang-engineering.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox