Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "George Moussalem" <george.moussalem@outlook.com>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH ath-next 04/16] wifi: ath11k: Add support for loading m3 mbn firmware
Date: Wed, 23 Sep 2026 12:15:13 +0000	[thread overview]
Message-ID: <20260923121513.9362C1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923-ipq5018-qcn6122-mpd-v1-4-86729521a75c@outlook.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Missing IS_ERR check on devm_memremap() leads to kernel panic
- [Medium] Permanent memory mapping of firmware region risks secure memory violation
--

commit 3ba907fe6d594d6c69e92925ac78d06c3ce54aaf
Author: George Moussalem <george.moussalem@outlook.com>

wifi: ath11k: Add support for loading m3 mbn firmware

This commit adds support for loading the m3 firmware in MBN (MDT) format
for ath11k WiFi chips. It introduces a function to allocate a memory region,
request the firmware, and load MDT segments.

> diff --git a/drivers/net/wireless/ath/ath11k/ahb.c b/drivers/net/wireless/ath/ath11k/ahb.c
> index 86723a2eb3d26..9fe2e112dfb81 100644
> --- a/drivers/net/wireless/ath/ath11k/ahb.c
> +++ b/drivers/net/wireless/ath/ath11k/ahb.c
[ ... ]
> @@ -962,6 +964,58 @@ static int ath11k_ahb_boot_root_pd(struct ath11k_base *ab)
>  	return 0;
>  }
>  
> +static int ath11k_ahb_load_m3_firmware(struct ath11k_base *ab)
> +{
[ ... ]
> +	mem_phys = res.start;
> +	mem_size = resource_size(&res);
> +	mem_region = devm_memremap(ab->dev, mem_phys, mem_size, MEMREMAP_WC);

[Severity: High]
Does this code miss an error check for devm_memremap()?

When devm_memremap() fails in ath11k_ahb_load_m3_firmware() within
drivers/net/wireless/ath/ath11k/ahb.c, it returns an ERR_PTR (such as
ERR_PTR(-ENOMEM)) rather than NULL. The return value is directly assigned
to mem_region without an IS_ERR() check.

[Severity: Medium]
Could this permanent memory mapping risk a secure memory violation?

Because devm_memremap() is used instead of a temporary memremap() and
memunmap() pair, the mapping is kept active for the lifetime of the device.
This unnecessarily consumes vmalloc space, as mem_region is never used again
after the firmware is loaded.

Additionally, on Qualcomm platforms, leaving a kernel mapping open to a memory
region that may be protected by TrustZone after boot risks fatal secure memory
violations (hypervisor panic) due to speculative processor accesses.

[ ... ]
> +	if (!m3_fw->size || m3_fw->size > mem_size) {
> +		ath11k_err(ab, "Invalid firmware size\n");
> +		release_firmware(m3_fw);
> +		return -EINVAL;
> +	}
> +
> +	ret = qcom_mdt_load_no_init(ab->dev, m3_fw, m3_fw_name, mem_region,
> +				    mem_phys, mem_size, &mem_phys);

[Severity: High]
Can this lead to a kernel panic if mem_region is an error pointer?

The mem_region pointer is passed to qcom_mdt_load_no_init(), which only
checks for !mem_region. Since an ERR_PTR is not NULL, the loader proceeds to
dereference the error pointer, computing an address offset and calling memcpy().
This results in a kernel panic due to an invalid memory write.

> +	if (ret)
> +		ath11k_err(ab, "Failed to load MDT segments: %d\n", ret);
> +
> +	release_firmware(m3_fw);
> +
> +	return ret;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-ipq5018-qcn6122-mpd-v1-0-86729521a75c@outlook.com?part=4

  reply	other threads:[~2026-09-23 12:15 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 12:05 [PATCH ath-next 00/16] wifi: ath11k: add MultiPD support for AHB platforms George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 01/16] dt-bindings: net: wireless: ath11k: Sort compatible names alphabetically George Moussalem via B4 Relay
2026-09-28 10:45   ` Krzysztof Kozlowski
2026-09-23 12:05 ` [PATCH ath-next 02/16] dt-bindings: net: wireless: ath11k: Add bindings for IPQ5018 George Moussalem via B4 Relay
2026-09-23 12:14   ` sashiko-bot
2026-09-28 10:45   ` Krzysztof Kozlowski
2026-09-29 10:03     ` George Moussalem
2026-09-23 12:05 ` [PATCH ath-next 03/16] wifi: ath11k: Register root PD rproc notifier George Moussalem via B4 Relay
2026-09-23 12:17   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 04/16] wifi: ath11k: Add support for loading m3 mbn firmware George Moussalem via B4 Relay
2026-09-23 12:15   ` sashiko-bot [this message]
2026-09-23 12:05 ` [PATCH ath-next 05/16] wifi: ath11k: Add ability to set BDF and M3 dump memory addresses George Moussalem via B4 Relay
2026-09-23 12:18   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 06/16] firmware: qcom: scm: Add support for setting internal WiFi power mode George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 07/16] wifi: ath11k: Register userPD interrupts and SMEM entries George Moussalem via B4 Relay
2026-09-23 12:19   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 08/16] wifi: ath11k: Power up userPD George Moussalem via B4 Relay
2026-09-23 12:17   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 09/16] wifi: ath11k: Power down userPD George Moussalem via B4 Relay
2026-09-23 12:15   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 10/16] dt-bindings: net: wireless: ath11k: Add bindings for QCN6122 George Moussalem via B4 Relay
2026-09-23 12:17   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 11/16] wifi: ath11k: add hw params " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 12/16] wifi: ath11k: add hal regs " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 13/16] wifi: ath11k: add hw ring mask " George Moussalem via B4 Relay
2026-09-23 12:29   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 14/16] wifi: ath11k: update hif and pci ops " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 15/16] wifi: ath11k: define userPDs " George Moussalem via B4 Relay
2026-09-23 12:28   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 16/16] wifi: ath11k: add QCN6122 device support George Moussalem via B4 Relay
2026-09-23 12:25   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923121513.9362C1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=george.moussalem@outlook.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox