Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Paul Louvel" <paul.louvel@bootlin.com>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org,
	wsa+renesas@sang-engineering.com, robh@kernel.org
Subject: Re: [PATCH v2 2/3] EDAC/cadence: Add Cadence DDR EDAC driver
Date: Thu, 24 Sep 2026 13:50:42 +0000	[thread overview]
Message-ID: <20260924135043.45F561F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924-paul-v7-3-rc1-edac-v2-2-bc1406161ecc@bootlin.com>

Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
- [High] locking: uninitialized mutex priv->lock causes panic on sysfs write
- [Medium] driver-core: premature sysfs registration creates probe failure race
- [Low] build: FIELD_MODIFY fails build with non-constant mask parameter
- [Low] log: missing newline in edac_mc_chipset_printk format string
--

commit a0e3a033fb0a852091db86b577bfa6524860f48e
Author: Paul Louvel <paul.louvel@bootlin.com>

EDAC/cadence: Add Cadence DDR EDAC driver

This commit adds a new EDAC driver for the Cadence DDR memory controller
found on the Renesas RZ/N1x SoC. It supports single bit error correction,
double bit error detection, and software scrubbing.

> diff --git a/drivers/edac/cadence_edac.c b/drivers/edac/cadence_edac.c
> new file mode 100644
> index 0000000000000..7edac7795fa70
> --- /dev/null
> +++ b/drivers/edac/cadence_edac.c
[ ... ]
> +static void cdns_rmw(struct cdns_mc_priv *priv, u32 reg, u32 mask, u32 val)
> +{
> +	u32 regval;
> +
> +	mutex_lock(&priv->lock);
> +	regval = readl(priv->io_base + reg);
> +	FIELD_MODIFY(mask, &regval, val);

[Severity: Low]
Will this cause a build failure on some configurations? FIELD_MODIFY
internally requires its mask parameter to be a compile-time constant,
enforced via a build-time check. Since cdns_rmw() takes mask as a standard
function parameter and isn't explicitly inlined, the compiler might not be
able to resolve it as a constant.

> +	writel(regval, priv->io_base + reg);
> +	mutex_unlock(&priv->lock);
> +}
[ ... ]
> +static int cdns_mc_probe(struct platform_device *pdev)
> +{
[ ... ]
> +	mci->pdev = &pdev->dev;
> +	priv = mci->pvt_info;

[Severity: High]
Is priv->lock missing a call to mutex_init()? 

The edac_mc_alloc() function allocates mci->pvt_info with kzalloc(), meaning
the mutex is zero-initialized but never properly initialized. Calling
mutex_lock() on this in cdns_rmw() can corrupt the wait list or trigger a
kernel panic, which could be reached if userspace writes to the inject_ctrl
sysfs attribute.

> +
> +	priv->io_base = devm_platform_ioremap_resource(pdev, 0);
[ ... ]
> +	ret = edac_mc_add_mc_with_groups(mci, cdns_edac_groups);
> +	if (ret)
> +		return dev_err_probe(&pdev->dev, ret, "failed to add mc\n");
> +
> +	ret = devm_add_action_or_reset(&pdev->dev, devm_cdns_edac_del, &pdev->dev);
> +	if (ret)
> +		return ret;
> +
> +	writel(CDNS_DDR_ECC_INT_CTRL_MASK_ALL, priv->io_base + CDNS_DDR_ECC_INT_CTRL);
> +
> +	irq = platform_get_irq(pdev, 0);

[Severity: Medium]
Could exposing the sysfs interface before claiming the IRQ create a race
condition?

Calling edac_mc_add_mc_with_groups() registers the controller and exposes
sysfs attributes like inject_ctrl to userspace. If platform_get_irq() or the
subsequent devm_request_irq() defers or fails, the probe unwinds and tears
down the device. A concurrent userspace access during this window might
interact with a partially initialized or destroyed state.

> +	if (irq < 0)
> +		return dev_err_probe(&pdev->dev, irq, "unable to get irq\n");
[ ... ]
> +	edac_mc_chipset_printk(mci, KERN_DEBUG, DRV_NAME, "ECC %s",
> +			       (mci->edac_cap == EDAC_FLAG_NONE) ? "disabled" : "enabled");

[Severity: Low]
Is this format string missing a trailing newline? 

The edac_mc_chipset_printk() macro translates directly to a printk() call
and does not append a newline character automatically. Without it, subsequent
logs might end up appended to the same line in dmesg.

> +
> +	return 0;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924-paul-v7-3-rc1-edac-v2-0-bc1406161ecc@bootlin.com?part=2

  reply	other threads:[~2026-09-24 13:50 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 13:41 [PATCH v2 0/3] Add Renesas RZ/N1x EDAC driver Paul Louvel
2026-09-24 13:41 ` [PATCH v2 1/3] dt-bindings: edac: cdns,ddr-edac: add Cadence DDR EDAC binding Paul Louvel
2026-09-24 13:41 ` [PATCH v2 2/3] EDAC/cadence: Add Cadence DDR EDAC driver Paul Louvel
2026-09-24 13:50   ` sashiko-bot [this message]
2026-09-24 13:41 ` [PATCH v2 3/3] ARM: dts: renesas: r9a06g032: add EDAC node Paul Louvel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924135043.45F561F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=paul.louvel@bootlin.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wsa+renesas@sang-engineering.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox