Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Mohd Ayaan Anwar" <mohd.anwar@oss.qualcomm.com>
Cc: conor+dt@kernel.org, robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH RFC net-next 4/9] net: pcs: xpcs: add Qualcomm Nord platform support
Date: Thu, 24 Sep 2026 01:09:42 +0000	[thread overview]
Message-ID: <20260924010942.E95AB1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260923-qcom_xpcs_nord_emac-v1-4-4b1c682af70f@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] net: pcs: missing bounds check enables out-of-bounds MMIO read/write
--

commit 2b4e5bfd24ebda95c719fb78f892dda332feef24
Author: Mohd Ayaan Anwar <mohd.anwar@oss.qualcomm.com>

net: pcs: xpcs: add Qualcomm Nord platform support

Adds Qualcomm Nord platform support by exposing DW XPCS register blocks via
separate direct-MMIO windows. It introduces accessors to translate MMD
accesses to these Nord windows and selects them using the Nord synthetic
XPCS ID.

> diff --git a/drivers/net/pcs/pcs-xpcs-plat.c b/drivers/net/pcs/pcs-xpcs-plat.c
> index e78a233fb198d..e013a5253a226 100644
> --- a/drivers/net/pcs/pcs-xpcs-plat.c
> +++ b/drivers/net/pcs/pcs-xpcs-plat.c
[ ... ]
> @@ -285,7 +298,7 @@ static int xpcs_plat_init_res(struct dw_xpcs_plat *pxpcs)
>  	else
>  		spc_size = pxpcs->reg_width * SZ_2M;
>  
> -	if (resource_size(res) < spc_size) {
> +	if (!pxpcs->ops && resource_size(res) < spc_size) {
>  		dev_err(dev, "Invalid reg-space size\n");
>  		return -EINVAL;
>  	}

[Severity: High]
Does bypassing the resource_size() check for platforms with custom ops in
xpcs_plat_init_res() leave the hardware mapping size unvalidated?

Since xpcs_qcom_ops is set for the Qualcomm Nord platform, this skips
ensuring the physical mapped region is large enough to encompass the largest
possible offset.

> diff --git a/drivers/net/pcs/pcs-xpcs-qcom.c b/drivers/net/pcs/pcs-xpcs-qcom.c
> new file mode 100644
> index 0000000000000..63c95c9514548
> --- /dev/null
> +++ b/drivers/net/pcs/pcs-xpcs-qcom.c
[ ... ]
> +static int xpcs_qcom_reg_offset(int dev, int reg)
> +{
> +	switch (dev) {
[ ... ]
> +	case MDIO_MMD_VEND2:
> +		if (reg >= DW_VENDOR)
> +			return QCOM_XPCS_VR_MII_BASE +
> +			       ((reg - DW_VENDOR) << 2);

[Severity: High]
Is there a bounds check missing for the reg index in xpcs_qcom_reg_offset()?

MDIO registers can be read from userspace up to 0xFFFF via ioctl or ethtool.
With MDIO_MMD_VEND2, a large index like 0xFFFF translates into an offset of
0x24fffc (approx 2.4MB), which may exceed standard hardware mapping slices.

> +
> +		return QCOM_XPCS_SR_MII_BASE + (reg << 2);
> +
> +	default:
> +		return -EOPNOTSUPP;
> +	}
> +}
> +
> +int xpcs_qcom_reg_read(struct platform_device *pdev, void __iomem *reg_base,
> +		       int dev, int reg)
> +{
> +	int offset, ret;
> +
> +	offset = xpcs_qcom_reg_offset(dev, reg);
> +	if (offset < 0)
> +		return offset;
> +
> +	ret = pm_runtime_resume_and_get(&pdev->dev);
> +	if (ret < 0)
> +		return ret;
> +
> +	ret = readl(reg_base + offset) & 0xffff;

[Severity: High]
Could this readl() in xpcs_qcom_reg_read() trigger an out-of-bounds MMIO
access and a Data Abort?

Because xpcs_plat_init_res() bypassed the mapping size check, and
xpcs_qcom_reg_offset() translates unvalidated register indices into large
offsets, this reads from an unmapped physical address if a large reg value
is provided. (The same question applies to writel() in xpcs_qcom_reg_write()
below this block).

> +
> +	pm_runtime_put(&pdev->dev);
> +
> +	return ret;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-qcom_xpcs_nord_emac-v1-0-4b1c682af70f@oss.qualcomm.com?part=4

  parent reply	other threads:[~2026-09-24  1:09 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23  1:07 [PATCH RFC net-next 0/9] net: introduce Qualcomm XPCS support and add Nord Ethernet plumbing Mohd Ayaan Anwar
2026-09-23  1:07 ` [PATCH RFC net-next 1/9] dt-bindings: net: pcs: add Qualcomm Nord XPCS Mohd Ayaan Anwar
2026-09-23  1:07 ` [PATCH RFC net-next 2/9] net: pcs: xpcs: add USXGMII Clause 37 autoneg support Mohd Ayaan Anwar
2026-09-23 13:31   ` Mohd Ayaan Anwar
2026-09-24  1:09   ` sashiko-bot
2026-09-23  1:07 ` [PATCH RFC net-next 3/9] net: pcs: xpcs: add custom platform register accessors Mohd Ayaan Anwar
2026-09-23 12:18   ` Andrew Lunn
2026-09-23 12:37     ` Mohd Ayaan Anwar
2026-09-25 10:18   ` Lorenzo Bianconi
2026-09-23  1:07 ` [PATCH RFC net-next 4/9] net: pcs: xpcs: add Qualcomm Nord platform support Mohd Ayaan Anwar
2026-09-23 12:07   ` Andrew Lunn
2026-09-23 12:57     ` Mohd Ayaan Anwar
2026-09-24  1:09   ` sashiko-bot [this message]
2026-09-25 10:37   ` Lorenzo Bianconi
2026-09-23  1:07 ` [PATCH RFC net-next 5/9] net: pcs: xpcs: initialize runtime PM as suspended Mohd Ayaan Anwar
2026-09-25 11:03   ` Lorenzo Bianconi
2026-09-23  1:07 ` [PATCH RFC net-next 6/9] dt-bindings: net: qcom,ethqos: add Qualcomm Nord Mohd Ayaan Anwar
2026-09-24  1:09   ` sashiko-bot
2026-09-23  1:07 ` [PATCH RFC net-next 7/9] net: stmmac: support custom XGMAC register layouts Mohd Ayaan Anwar
2026-09-24  1:09   ` sashiko-bot
2026-09-25 12:22   ` Lorenzo Bianconi
2026-09-23  1:07 ` [PATCH RFC net-next 8/9] net: stmmac: qcom-ethqos: support external PCS Mohd Ayaan Anwar
2026-09-24  1:09   ` sashiko-bot
2026-09-28 15:15   ` Maxime Chevallier
2026-09-23  1:07 ` [PATCH RFC net-next 9/9] net: stmmac: qcom-ethqos: add Qualcomm Nord support Mohd Ayaan Anwar
2026-09-24  1:09   ` sashiko-bot
2026-09-25 13:02   ` Lorenzo Bianconi
2026-09-23  8:50 ` [PATCH RFC net-next 0/9] net: introduce Qualcomm XPCS support and add Nord Ethernet plumbing Zhangfei Gao
2026-09-23 15:15   ` Andrew Lunn
2026-09-28 10:21   ` Krzysztof Kozlowski
2026-09-23  9:41 ` Maxime Chevallier
2026-09-23 10:43   ` Mohd Ayaan Anwar
2026-09-23 13:17     ` Coia Prant
2026-09-23 14:03       ` Mohd Ayaan Anwar
2026-09-24  5:54         ` Coia Prant
2026-09-23 18:35       ` Andrew Lunn
2026-09-24  5:25         ` Coia Prant
2026-09-23 18:40       ` Andrew Lunn

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924010942.E95AB1F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=mohd.anwar@oss.qualcomm.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox