From: sashiko-bot@kernel.org
To: "David Heidelberg" <david@ixit.cz>
Cc: robh@kernel.org, lee@kernel.org, devicetree@vger.kernel.org,
mfd@lists.linux.dev, conor+dt@kernel.org
Subject: Re: [PATCH RFC 06/12] usb: typec: qcom: Add gen1 Type-C port support
Date: Sat, 26 Sep 2026 12:53:03 +0000 [thread overview]
Message-ID: <20260926125303.957881F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260926-typec-v1-6-31adc19f32c6@ixit.cz>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] usb: typec: qcom: data race on port->tcpm_port causes NULL dereference
--
commit c724ae85ceb0ca42ea62d9d3f8a3d994453a3cf9
Author: David Heidelberg <david@ixit.cz>
usb: typec: qcom: Add gen1 Type-C port support
Add a port backend for the first generation of the Qualcomm PMIC Type-C
block, found on PM660 and PMI8998.
> diff --git a/drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port_gen1.c b/drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port_gen1.c
> new file mode 100644
> index 0000000000000..b4e3e49664f9d
> --- /dev/null
> +++ b/drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port_gen1.c
[ ... ]
> +static int gen1_typec_set_vbus(struct tcpc_dev *tcpc, bool on, bool sink)
> +{
> + struct pmic_typec *tcpm = tcpc_to_tcpm(tcpc);
> + struct gen1_typec_port *port = tcpm->pmic_typec_port;
> + bool changed = false;
> + int ret = 0;
[ ... ]
> + /*
> + * set_vbus() may run during tcpm_register_port() before port_start()
> + * provides tcpm_port. Once registered, notify TCPM whenever the
> + * source regulator actually changes state. get_vbus() also accounts
> + * for vbus_enabled when GEN1 does not reflect sourced VBUS in
> + * TYPEC_VBUS_STATUS.
> + */
> + if (changed && port->tcpm_port)
> + tcpm_vbus_change(port->tcpm_port);
[Severity: High]
Could this sequence lead to a NULL pointer dereference if device teardown
occurs concurrently?
It appears port->tcpm_port is evaluated outside port->lock. Without
READ_ONCE(), the compiler could emit a double fetch (TOCTOU) here.
If the TCPM worker thread (driven by external cable events) executes a VBUS
state transition concurrently with unbind, the pointer could become NULL
between the condition check and the function call, causing
tcpm_vbus_change(NULL) to crash.
[ ... ]
> +static void gen1_typec_port_stop(struct pmic_typec *tcpm)
> +{
> + struct gen1_typec_port *port = tcpm->pmic_typec_port;
> +
> + disable_irq(port->irq);
> + port->tcpm_port = NULL;
[Severity: High]
Is it safe to clear port->tcpm_port locklessly here?
During unbind, qcom_pmic_typec_remove() calls gen1_typec_port_stop(),
which executes port->tcpm_port = NULL without holding a lock. This appears
to be what creates the potential race with gen1_typec_set_vbus() shown above.
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260926-typec-v1-0-31adc19f32c6@ixit.cz?part=6
next prev parent reply other threads:[~2026-09-26 12:53 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 12:40 [PATCH RFC 00/12] Qualcomm Type-C support for 1st generation David Heidelberg via B4 Relay
2026-09-26 12:40 ` [PATCH RFC 01/12] usb: typec: tcpm: qcom: Release the connector fwnode reference David Heidelberg via B4 Relay
2026-09-26 12:45 ` sashiko-bot
2026-09-28 13:48 ` Heikki Krogerus
2026-09-26 12:40 ` [PATCH RFC 02/12] dt-bindings: usb: qcom,pmic-typec: Update example with vbus-supply David Heidelberg via B4 Relay
2026-09-26 12:45 ` sashiko-bot
2026-09-26 13:34 ` Bryan O'Donoghue
2026-09-26 12:40 ` [PATCH RFC 03/12] dt-bindings: usb: Add Qualcomm 1st-gen PMIC Type-C David Heidelberg via B4 Relay
2026-09-26 12:44 ` sashiko-bot
2026-09-26 12:40 ` [PATCH RFC 04/12] usb: typec: qcom: Make PMIC port probe selectable David Heidelberg via B4 Relay
2026-09-26 12:45 ` sashiko-bot
2026-09-26 13:39 ` Bryan O'Donoghue
2026-09-26 12:40 ` [PATCH RFC 05/12] usb: typec: qcom: Make typec_port accept also different structure David Heidelberg via B4 Relay
2026-09-26 12:48 ` sashiko-bot
2026-09-26 13:40 ` Bryan O'Donoghue
2026-09-26 12:40 ` [PATCH RFC 06/12] usb: typec: qcom: Add gen1 Type-C port support David Heidelberg via B4 Relay
2026-09-26 12:53 ` sashiko-bot [this message]
2026-09-26 14:22 ` Bryan O'Donoghue
2026-09-26 14:32 ` David Heidelberg
2026-09-26 14:41 ` Bryan O'Donoghue
2026-09-26 14:45 ` David Heidelberg
2026-09-26 12:40 ` [PATCH RFC 07/12] arm64: dts: qcom: pm660: Add USB Type-C port controller node David Heidelberg via B4 Relay
2026-09-26 12:45 ` sashiko-bot
2026-09-26 14:25 ` Bryan O'Donoghue
2026-09-26 12:40 ` [PATCH RFC 08/12] arm64: dts: qcom: pmi8998: " David Heidelberg via B4 Relay
2026-09-26 12:45 ` sashiko-bot
2026-09-26 14:28 ` Bryan O'Donoghue
2026-09-26 12:40 ` [PATCH RFC 09/12] arm64: dts: qcom: sdm670-google-common: Enable USB Type-C port controller David Heidelberg via B4 Relay
2026-09-26 12:45 ` sashiko-bot
2026-09-26 12:40 ` [PATCH RFC 10/12] arm64: dts: qcom: sdm845-google-common: " David Heidelberg via B4 Relay
2026-09-26 12:46 ` sashiko-bot
2026-09-26 12:40 ` [PATCH RFC 11/12] arm64: dts: qcom: sdm845-oneplus-common: " David Heidelberg via B4 Relay
2026-09-26 12:49 ` sashiko-bot
2026-09-26 12:40 ` [PATCH RFC 12/12] arm64: dts: qcom: sdm845-shift-axolotl: " David Heidelberg via B4 Relay
2026-09-26 12:49 ` sashiko-bot
2026-09-27 13:05 ` [PATCH RFC 00/12] Qualcomm Type-C support for 1st generation Dmitry Baryshkov
2026-09-27 15:16 ` David Heidelberg
2026-09-27 16:33 ` Dmitry Baryshkov
2026-09-28 15:54 ` Bryan O'Donoghue
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926125303.957881F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=david@ixit.cz \
--cc=devicetree@vger.kernel.org \
--cc=lee@kernel.org \
--cc=mfd@lists.linux.dev \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox