From: sashiko-bot@kernel.org
To: "George Moussalem" <george.moussalem@outlook.com>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH ath-next 04/16] wifi: ath11k: Add support for loading m3 mbn firmware
Date: Wed, 23 Sep 2026 12:15:13 +0000 [thread overview]
Message-ID: <20260923121513.9362C1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923-ipq5018-qcn6122-mpd-v1-4-86729521a75c@outlook.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Missing IS_ERR check on devm_memremap() leads to kernel panic
- [Medium] Permanent memory mapping of firmware region risks secure memory violation
--
commit 3ba907fe6d594d6c69e92925ac78d06c3ce54aaf
Author: George Moussalem <george.moussalem@outlook.com>
wifi: ath11k: Add support for loading m3 mbn firmware
This commit adds support for loading the m3 firmware in MBN (MDT) format
for ath11k WiFi chips. It introduces a function to allocate a memory region,
request the firmware, and load MDT segments.
> diff --git a/drivers/net/wireless/ath/ath11k/ahb.c b/drivers/net/wireless/ath/ath11k/ahb.c
> index 86723a2eb3d26..9fe2e112dfb81 100644
> --- a/drivers/net/wireless/ath/ath11k/ahb.c
> +++ b/drivers/net/wireless/ath/ath11k/ahb.c
[ ... ]
> @@ -962,6 +964,58 @@ static int ath11k_ahb_boot_root_pd(struct ath11k_base *ab)
> return 0;
> }
>
> +static int ath11k_ahb_load_m3_firmware(struct ath11k_base *ab)
> +{
[ ... ]
> + mem_phys = res.start;
> + mem_size = resource_size(&res);
> + mem_region = devm_memremap(ab->dev, mem_phys, mem_size, MEMREMAP_WC);
[Severity: High]
Does this code miss an error check for devm_memremap()?
When devm_memremap() fails in ath11k_ahb_load_m3_firmware() within
drivers/net/wireless/ath/ath11k/ahb.c, it returns an ERR_PTR (such as
ERR_PTR(-ENOMEM)) rather than NULL. The return value is directly assigned
to mem_region without an IS_ERR() check.
[Severity: Medium]
Could this permanent memory mapping risk a secure memory violation?
Because devm_memremap() is used instead of a temporary memremap() and
memunmap() pair, the mapping is kept active for the lifetime of the device.
This unnecessarily consumes vmalloc space, as mem_region is never used again
after the firmware is loaded.
Additionally, on Qualcomm platforms, leaving a kernel mapping open to a memory
region that may be protected by TrustZone after boot risks fatal secure memory
violations (hypervisor panic) due to speculative processor accesses.
[ ... ]
> + if (!m3_fw->size || m3_fw->size > mem_size) {
> + ath11k_err(ab, "Invalid firmware size\n");
> + release_firmware(m3_fw);
> + return -EINVAL;
> + }
> +
> + ret = qcom_mdt_load_no_init(ab->dev, m3_fw, m3_fw_name, mem_region,
> + mem_phys, mem_size, &mem_phys);
[Severity: High]
Can this lead to a kernel panic if mem_region is an error pointer?
The mem_region pointer is passed to qcom_mdt_load_no_init(), which only
checks for !mem_region. Since an ERR_PTR is not NULL, the loader proceeds to
dereference the error pointer, computing an address offset and calling memcpy().
This results in a kernel panic due to an invalid memory write.
> + if (ret)
> + ath11k_err(ab, "Failed to load MDT segments: %d\n", ret);
> +
> + release_firmware(m3_fw);
> +
> + return ret;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-ipq5018-qcn6122-mpd-v1-0-86729521a75c@outlook.com?part=4
next prev parent reply other threads:[~2026-09-23 12:15 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 12:05 [PATCH ath-next 00/16] wifi: ath11k: add MultiPD support for AHB platforms George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 01/16] dt-bindings: net: wireless: ath11k: Sort compatible names alphabetically George Moussalem via B4 Relay
2026-09-28 10:45 ` Krzysztof Kozlowski
2026-09-23 12:05 ` [PATCH ath-next 02/16] dt-bindings: net: wireless: ath11k: Add bindings for IPQ5018 George Moussalem via B4 Relay
2026-09-23 12:14 ` sashiko-bot
2026-09-28 10:45 ` Krzysztof Kozlowski
2026-09-29 10:03 ` George Moussalem
2026-09-23 12:05 ` [PATCH ath-next 03/16] wifi: ath11k: Register root PD rproc notifier George Moussalem via B4 Relay
2026-09-23 12:17 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 04/16] wifi: ath11k: Add support for loading m3 mbn firmware George Moussalem via B4 Relay
2026-09-23 12:15 ` sashiko-bot [this message]
2026-09-23 12:05 ` [PATCH ath-next 05/16] wifi: ath11k: Add ability to set BDF and M3 dump memory addresses George Moussalem via B4 Relay
2026-09-23 12:18 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 06/16] firmware: qcom: scm: Add support for setting internal WiFi power mode George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 07/16] wifi: ath11k: Register userPD interrupts and SMEM entries George Moussalem via B4 Relay
2026-09-23 12:19 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 08/16] wifi: ath11k: Power up userPD George Moussalem via B4 Relay
2026-09-23 12:17 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 09/16] wifi: ath11k: Power down userPD George Moussalem via B4 Relay
2026-09-23 12:15 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 10/16] dt-bindings: net: wireless: ath11k: Add bindings for QCN6122 George Moussalem via B4 Relay
2026-09-23 12:17 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 11/16] wifi: ath11k: add hw params " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 12/16] wifi: ath11k: add hal regs " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 13/16] wifi: ath11k: add hw ring mask " George Moussalem via B4 Relay
2026-09-23 12:29 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 14/16] wifi: ath11k: update hif and pci ops " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 15/16] wifi: ath11k: define userPDs " George Moussalem via B4 Relay
2026-09-23 12:28 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 16/16] wifi: ath11k: add QCN6122 device support George Moussalem via B4 Relay
2026-09-23 12:25 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923121513.9362C1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=george.moussalem@outlook.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox