From: sashiko-bot@kernel.org
To: "Christian Marangi" <ansuelsmth@gmail.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH net-next v17 02/12] net: phylink: introduce internal phylink PCS handling
Date: Fri, 25 Sep 2026 23:03:02 +0000 [thread overview]
Message-ID: <20260925230303.760AB1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924230211.11519-3-ansuelsmth@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] net: phylink: validation succeeds even if required PCS is missing
- [Medium] net: phylink: unsafe expansion of MAC supported interfaces with PCS capabilities
--
commit 3acb4b7eb5c7e2219464ad7dfac9f59c3b6954b8
Author: Christian Marangi <ansuelsmth@gmail.com>
net: phylink: introduce internal phylink PCS handling
This commit introduces internal handling of PCS for phylink, allowing MAC
drivers to provide a list of available PCS elements instead of implementing
the legacy mac_select_pcs callback.
> diff --git a/drivers/net/phy/phylink.c b/drivers/net/phy/phylink.c
> index a98e62fa4bd26..1156e6c61a08b 100644
> --- a/drivers/net/phy/phylink.c
> +++ b/drivers/net/phy/phylink.c
[ ... ]
> @@ -530,6 +549,21 @@ static int phylink_validate_mac_and_pcs(struct phylink *pl,
> pcs = pl->mac_ops->mac_select_pcs(pl->config, state->interface);
> if (IS_ERR(pcs))
> return PTR_ERR(pcs);
> + /*
> + * Find a PCS in available PCS list for the requested interface.
> + *
> + * Skip searching if the MAC doesn't require a dedicated PCS for
> + * the requested interface.
> + */
> + } else if (test_bit(state->interface, pl->config->pcs_interfaces)) {
> + struct phylink_pcs *tmp;
> +
> + list_for_each_entry(tmp, &pl->pcs_list, list) {
> + if (!phylink_validate_pcs_interface(tmp, state->interface)) {
> + pcs = tmp;
> + break;
> + }
> + }
> }
>
> if (pcs) {
[Severity: Medium]
When a dedicated PCS is required but none is found, does this skip the
validation block entirely since pcs remains NULL?
If the loop over pl->pcs_list finds no matching PCS, the function bypasses
the if (pcs) block but falls through to validate MAC capabilities,
ultimately returning 0 (success) instead of -EINVAL. Could this result
in phylink falsely advertising support for an interface mode the hardware
cannot use, breaking auto-negotiation fallback?
[ ... ]
> @@ -2031,16 +2150,31 @@ struct phylink *phylink_create(struct phylink_config *config,
> __set_bit(PHYLINK_DISABLE_STOPPED, &pl->phylink_disable_state);
> timer_setup(&pl->link_poll, phylink_fixed_poll, 0);
>
> + /* Fill the PCS list with available PCS from phylink config */
> + ret = phylink_fill_available_pcs(pl, config);
> + if (ret < 0)
> + goto free_pl;
> +
> + /* Link available PCS to phylink */
> + list_for_each_entry(pcs, &pl->pcs_list, list)
> + pcs->phylink = pl;
> +
> phy_interface_copy(pl->supported_interfaces,
> pl->config->supported_interfaces);
>
> + /* Update supported interfaces */
> + list_for_each_entry(pcs, &pl->pcs_list, list)
> + phy_interface_or(pl->supported_interfaces,
> + pl->supported_interfaces,
> + pcs->supported_interfaces);
> +
[Severity: Medium]
Does this bitwise OR safely combine the MAC capabilities with the PCS
capabilities?
It appears to unconditionally elevate the generic PCS capabilities to the
top-level phylink instance, overwriting the MAC's strict capability
declarations. If phylink advertises support for interface modes that the
generic PCS supports but the specific MAC hardware does not, mac_prepare()
and mac_config() might be called with unrecognized modes, potentially
causing hardware configuration failures.
[ ... ]
> @@ -2076,11 +2215,20 @@ EXPORT_SYMBOL_GPL(phylink_create);
> */
> void phylink_destroy(struct phylink *pl)
> {
> + struct phylink_pcs *pcs, *tmp;
> +
> sfp_bus_del_upstream(pl->sfp_bus);
> if (pl->link_gpio)
> gpiod_put(pl->link_gpio);
>
> cancel_work_sync(&pl->resolve);
> +
> + /* Remove every PCS from phylink PCS list */
> + list_for_each_entry_safe(pcs, tmp, &pl->pcs_list, list) {
> + pcs->phylink = NULL;
> + list_del(&pcs->list);
> + }
> +
> kfree(pl);
> }
[Severity: High]
This isn't a bug introduced by this patch, but does this cleanup properly
handle the legacy mac_select_pcs users?
While this loop correctly cleans up new users populated in pl->pcs_list, it
seems to neglect clearing pl->pcs->phylink for the currently active PCS
assigned dynamically via the legacy mac_select_pcs.
If pl->pcs->phylink is left pointing to the freed pl struct for legacy MAC
drivers, could a subsequent late interrupt from the PCS trigger a
use-after-free when phylink_pcs_change() is called?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924230211.11519-1-ansuelsmth@gmail.com?part=2
next prev parent reply other threads:[~2026-09-25 23:03 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 23:01 [PATCH net-next v17 00/12] net: pcs: Introduce support for fwnode PCS Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 01/12] net: phylink: keep and use MAC supported_interfaces in phylink struct Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 02/12] net: phylink: introduce internal phylink PCS handling Christian Marangi
2026-09-25 23:03 ` sashiko-bot [this message]
2026-09-24 23:01 ` [PATCH net-next v17 03/12] net: pcs: implement Firmware node support for PCS driver Christian Marangi
2026-09-25 23:03 ` sashiko-bot
2026-09-24 23:01 ` [PATCH net-next v17 04/12] net: phylink: save phylink instance fwnode on phylink_create Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 05/12] net: phylink: support PCS provider release Christian Marangi
2026-09-25 23:03 ` sashiko-bot
2026-09-24 23:01 ` [PATCH net-next v17 06/12] net: phylink: support late PCS provider attach Christian Marangi
2026-09-25 23:03 ` sashiko-bot
2026-09-24 23:01 ` [PATCH net-next v17 07/12] net: Document PCS subsystem Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 08/12] MAINTAINERS: add myself as PCS subsystem maintainer Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 09/12] net: phylink: add .pcs_link_down PCS OP Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 10/12] dt-bindings: net: pcs: Document support for Airoha Ethernet PCS Christian Marangi
2026-09-24 23:01 ` [PATCH net-next v17 11/12] net: pcs: airoha: add PCS driver for Airoha AN7581 SoC Christian Marangi
2026-09-25 23:03 ` sashiko-bot
2026-09-24 23:01 ` [PATCH net-next v17 12/12] net: airoha: add phylink support Christian Marangi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260925230303.760AB1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=ansuelsmth@gmail.com \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox