Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Christian Marangi" <ansuelsmth@gmail.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH net-next v17 02/12] net: phylink: introduce internal phylink PCS handling
Date: Fri, 25 Sep 2026 23:03:02 +0000	[thread overview]
Message-ID: <20260925230303.760AB1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924230211.11519-3-ansuelsmth@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] net: phylink: validation succeeds even if required PCS is missing
- [Medium] net: phylink: unsafe expansion of MAC supported interfaces with PCS capabilities
--

commit 3acb4b7eb5c7e2219464ad7dfac9f59c3b6954b8
Author: Christian Marangi <ansuelsmth@gmail.com>

net: phylink: introduce internal phylink PCS handling

This commit introduces internal handling of PCS for phylink, allowing MAC
drivers to provide a list of available PCS elements instead of implementing
the legacy mac_select_pcs callback.

> diff --git a/drivers/net/phy/phylink.c b/drivers/net/phy/phylink.c
> index a98e62fa4bd26..1156e6c61a08b 100644
> --- a/drivers/net/phy/phylink.c
> +++ b/drivers/net/phy/phylink.c

[ ... ]

> @@ -530,6 +549,21 @@ static int phylink_validate_mac_and_pcs(struct phylink *pl,
>  		pcs = pl->mac_ops->mac_select_pcs(pl->config, state->interface);
>  		if (IS_ERR(pcs))
>  			return PTR_ERR(pcs);
> +	/*
> +	 * Find a PCS in available PCS list for the requested interface.
> +	 *
> +	 * Skip searching if the MAC doesn't require a dedicated PCS for
> +	 * the requested interface.
> +	 */
> +	} else if (test_bit(state->interface, pl->config->pcs_interfaces)) {
> +		struct phylink_pcs *tmp;
> +
> +		list_for_each_entry(tmp, &pl->pcs_list, list) {
> +			if (!phylink_validate_pcs_interface(tmp, state->interface)) {
> +				pcs = tmp;
> +				break;
> +			}
> +		}
>  	}
>  
>  	if (pcs) {

[Severity: Medium]
When a dedicated PCS is required but none is found, does this skip the
validation block entirely since pcs remains NULL?

If the loop over pl->pcs_list finds no matching PCS, the function bypasses
the if (pcs) block but falls through to validate MAC capabilities,
ultimately returning 0 (success) instead of -EINVAL. Could this result
in phylink falsely advertising support for an interface mode the hardware
cannot use, breaking auto-negotiation fallback?

[ ... ]

> @@ -2031,16 +2150,31 @@ struct phylink *phylink_create(struct phylink_config *config,
>  	__set_bit(PHYLINK_DISABLE_STOPPED, &pl->phylink_disable_state);
>  	timer_setup(&pl->link_poll, phylink_fixed_poll, 0);
>  
> +	/* Fill the PCS list with available PCS from phylink config */
> +	ret = phylink_fill_available_pcs(pl, config);
> +	if (ret < 0)
> +		goto free_pl;
> +
> +	/* Link available PCS to phylink */
> +	list_for_each_entry(pcs, &pl->pcs_list, list)
> +		pcs->phylink = pl;
> +
>  	phy_interface_copy(pl->supported_interfaces,
>  			   pl->config->supported_interfaces);
>  
> +	/* Update supported interfaces */
> +	list_for_each_entry(pcs, &pl->pcs_list, list)
> +		phy_interface_or(pl->supported_interfaces,
> +				 pl->supported_interfaces,
> +				 pcs->supported_interfaces);
> +

[Severity: Medium]
Does this bitwise OR safely combine the MAC capabilities with the PCS
capabilities?

It appears to unconditionally elevate the generic PCS capabilities to the
top-level phylink instance, overwriting the MAC's strict capability
declarations. If phylink advertises support for interface modes that the
generic PCS supports but the specific MAC hardware does not, mac_prepare()
and mac_config() might be called with unrecognized modes, potentially
causing hardware configuration failures.

[ ... ]

> @@ -2076,11 +2215,20 @@ EXPORT_SYMBOL_GPL(phylink_create);
>   */
>  void phylink_destroy(struct phylink *pl)
>  {
> +	struct phylink_pcs *pcs, *tmp;
> +
>  	sfp_bus_del_upstream(pl->sfp_bus);
>  	if (pl->link_gpio)
>  		gpiod_put(pl->link_gpio);
>  
>  	cancel_work_sync(&pl->resolve);
> +
> +	/* Remove every PCS from phylink PCS list */
> +	list_for_each_entry_safe(pcs, tmp, &pl->pcs_list, list) {
> +		pcs->phylink = NULL;
> +		list_del(&pcs->list);
> +	}
> +
>  	kfree(pl);
>  }

[Severity: High]
This isn't a bug introduced by this patch, but does this cleanup properly
handle the legacy mac_select_pcs users?

While this loop correctly cleans up new users populated in pl->pcs_list, it
seems to neglect clearing pl->pcs->phylink for the currently active PCS
assigned dynamically via the legacy mac_select_pcs.

If pl->pcs->phylink is left pointing to the freed pl struct for legacy MAC
drivers, could a subsequent late interrupt from the PCS trigger a
use-after-free when phylink_pcs_change() is called?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924230211.11519-1-ansuelsmth@gmail.com?part=2

  reply	other threads:[~2026-09-25 23:03 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 23:01 [PATCH net-next v17 00/12] net: pcs: Introduce support for fwnode PCS Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 01/12] net: phylink: keep and use MAC supported_interfaces in phylink struct Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 02/12] net: phylink: introduce internal phylink PCS handling Christian Marangi
2026-09-25 23:03   ` sashiko-bot [this message]
2026-09-24 23:01 ` [PATCH net-next v17 03/12] net: pcs: implement Firmware node support for PCS driver Christian Marangi
2026-09-25 23:03   ` sashiko-bot
2026-09-24 23:01 ` [PATCH net-next v17 04/12] net: phylink: save phylink instance fwnode on phylink_create Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 05/12] net: phylink: support PCS provider release Christian Marangi
2026-09-25 23:03   ` sashiko-bot
2026-09-24 23:01 ` [PATCH net-next v17 06/12] net: phylink: support late PCS provider attach Christian Marangi
2026-09-25 23:03   ` sashiko-bot
2026-09-24 23:01 ` [PATCH net-next v17 07/12] net: Document PCS subsystem Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 08/12] MAINTAINERS: add myself as PCS subsystem maintainer Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 09/12] net: phylink: add .pcs_link_down PCS OP Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 10/12] dt-bindings: net: pcs: Document support for Airoha Ethernet PCS Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 11/12] net: pcs: airoha: add PCS driver for Airoha AN7581 SoC Christian Marangi
2026-09-25 23:03   ` sashiko-bot
2026-09-24 23:01 ` [PATCH net-next v17 12/12] net: airoha: add phylink support Christian Marangi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925230303.760AB1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=ansuelsmth@gmail.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox