From: sashiko-bot@kernel.org
To: "Mohd Ayaan Anwar" <mohd.anwar@oss.qualcomm.com>
Cc: conor+dt@kernel.org, robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH RFC net-next 4/9] net: pcs: xpcs: add Qualcomm Nord platform support
Date: Thu, 24 Sep 2026 01:09:42 +0000 [thread overview]
Message-ID: <20260924010942.E95AB1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260923-qcom_xpcs_nord_emac-v1-4-4b1c682af70f@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] net: pcs: missing bounds check enables out-of-bounds MMIO read/write
--
commit 2b4e5bfd24ebda95c719fb78f892dda332feef24
Author: Mohd Ayaan Anwar <mohd.anwar@oss.qualcomm.com>
net: pcs: xpcs: add Qualcomm Nord platform support
Adds Qualcomm Nord platform support by exposing DW XPCS register blocks via
separate direct-MMIO windows. It introduces accessors to translate MMD
accesses to these Nord windows and selects them using the Nord synthetic
XPCS ID.
> diff --git a/drivers/net/pcs/pcs-xpcs-plat.c b/drivers/net/pcs/pcs-xpcs-plat.c
> index e78a233fb198d..e013a5253a226 100644
> --- a/drivers/net/pcs/pcs-xpcs-plat.c
> +++ b/drivers/net/pcs/pcs-xpcs-plat.c
[ ... ]
> @@ -285,7 +298,7 @@ static int xpcs_plat_init_res(struct dw_xpcs_plat *pxpcs)
> else
> spc_size = pxpcs->reg_width * SZ_2M;
>
> - if (resource_size(res) < spc_size) {
> + if (!pxpcs->ops && resource_size(res) < spc_size) {
> dev_err(dev, "Invalid reg-space size\n");
> return -EINVAL;
> }
[Severity: High]
Does bypassing the resource_size() check for platforms with custom ops in
xpcs_plat_init_res() leave the hardware mapping size unvalidated?
Since xpcs_qcom_ops is set for the Qualcomm Nord platform, this skips
ensuring the physical mapped region is large enough to encompass the largest
possible offset.
> diff --git a/drivers/net/pcs/pcs-xpcs-qcom.c b/drivers/net/pcs/pcs-xpcs-qcom.c
> new file mode 100644
> index 0000000000000..63c95c9514548
> --- /dev/null
> +++ b/drivers/net/pcs/pcs-xpcs-qcom.c
[ ... ]
> +static int xpcs_qcom_reg_offset(int dev, int reg)
> +{
> + switch (dev) {
[ ... ]
> + case MDIO_MMD_VEND2:
> + if (reg >= DW_VENDOR)
> + return QCOM_XPCS_VR_MII_BASE +
> + ((reg - DW_VENDOR) << 2);
[Severity: High]
Is there a bounds check missing for the reg index in xpcs_qcom_reg_offset()?
MDIO registers can be read from userspace up to 0xFFFF via ioctl or ethtool.
With MDIO_MMD_VEND2, a large index like 0xFFFF translates into an offset of
0x24fffc (approx 2.4MB), which may exceed standard hardware mapping slices.
> +
> + return QCOM_XPCS_SR_MII_BASE + (reg << 2);
> +
> + default:
> + return -EOPNOTSUPP;
> + }
> +}
> +
> +int xpcs_qcom_reg_read(struct platform_device *pdev, void __iomem *reg_base,
> + int dev, int reg)
> +{
> + int offset, ret;
> +
> + offset = xpcs_qcom_reg_offset(dev, reg);
> + if (offset < 0)
> + return offset;
> +
> + ret = pm_runtime_resume_and_get(&pdev->dev);
> + if (ret < 0)
> + return ret;
> +
> + ret = readl(reg_base + offset) & 0xffff;
[Severity: High]
Could this readl() in xpcs_qcom_reg_read() trigger an out-of-bounds MMIO
access and a Data Abort?
Because xpcs_plat_init_res() bypassed the mapping size check, and
xpcs_qcom_reg_offset() translates unvalidated register indices into large
offsets, this reads from an unmapped physical address if a large reg value
is provided. (The same question applies to writel() in xpcs_qcom_reg_write()
below this block).
> +
> + pm_runtime_put(&pdev->dev);
> +
> + return ret;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-qcom_xpcs_nord_emac-v1-0-4b1c682af70f@oss.qualcomm.com?part=4
next prev parent reply other threads:[~2026-09-24 1:09 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 1:07 [PATCH RFC net-next 0/9] net: introduce Qualcomm XPCS support and add Nord Ethernet plumbing Mohd Ayaan Anwar
2026-09-23 1:07 ` [PATCH RFC net-next 1/9] dt-bindings: net: pcs: add Qualcomm Nord XPCS Mohd Ayaan Anwar
2026-09-23 1:07 ` [PATCH RFC net-next 2/9] net: pcs: xpcs: add USXGMII Clause 37 autoneg support Mohd Ayaan Anwar
2026-09-23 13:31 ` Mohd Ayaan Anwar
2026-09-24 1:09 ` sashiko-bot
2026-09-23 1:07 ` [PATCH RFC net-next 3/9] net: pcs: xpcs: add custom platform register accessors Mohd Ayaan Anwar
2026-09-23 12:18 ` Andrew Lunn
2026-09-23 12:37 ` Mohd Ayaan Anwar
2026-09-25 10:18 ` Lorenzo Bianconi
2026-09-23 1:07 ` [PATCH RFC net-next 4/9] net: pcs: xpcs: add Qualcomm Nord platform support Mohd Ayaan Anwar
2026-09-23 12:07 ` Andrew Lunn
2026-09-23 12:57 ` Mohd Ayaan Anwar
2026-09-24 1:09 ` sashiko-bot [this message]
2026-09-25 10:37 ` Lorenzo Bianconi
2026-09-23 1:07 ` [PATCH RFC net-next 5/9] net: pcs: xpcs: initialize runtime PM as suspended Mohd Ayaan Anwar
2026-09-25 11:03 ` Lorenzo Bianconi
2026-09-23 1:07 ` [PATCH RFC net-next 6/9] dt-bindings: net: qcom,ethqos: add Qualcomm Nord Mohd Ayaan Anwar
2026-09-24 1:09 ` sashiko-bot
2026-09-23 1:07 ` [PATCH RFC net-next 7/9] net: stmmac: support custom XGMAC register layouts Mohd Ayaan Anwar
2026-09-24 1:09 ` sashiko-bot
2026-09-25 12:22 ` Lorenzo Bianconi
2026-09-23 1:07 ` [PATCH RFC net-next 8/9] net: stmmac: qcom-ethqos: support external PCS Mohd Ayaan Anwar
2026-09-24 1:09 ` sashiko-bot
2026-09-28 15:15 ` Maxime Chevallier
2026-09-23 1:07 ` [PATCH RFC net-next 9/9] net: stmmac: qcom-ethqos: add Qualcomm Nord support Mohd Ayaan Anwar
2026-09-24 1:09 ` sashiko-bot
2026-09-25 13:02 ` Lorenzo Bianconi
2026-09-23 8:50 ` [PATCH RFC net-next 0/9] net: introduce Qualcomm XPCS support and add Nord Ethernet plumbing Zhangfei Gao
2026-09-23 15:15 ` Andrew Lunn
2026-09-28 10:21 ` Krzysztof Kozlowski
2026-09-23 9:41 ` Maxime Chevallier
2026-09-23 10:43 ` Mohd Ayaan Anwar
2026-09-23 13:17 ` Coia Prant
2026-09-23 14:03 ` Mohd Ayaan Anwar
2026-09-24 5:54 ` Coia Prant
2026-09-23 18:35 ` Andrew Lunn
2026-09-24 5:25 ` Coia Prant
2026-09-23 18:40 ` Andrew Lunn
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924010942.E95AB1F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=mohd.anwar@oss.qualcomm.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox