Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Kyle Swenson" <kyle.swenson@est.tech>
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH net-next v3 2/2] net: pse-pd: Add LTC4266 PSE controller driver
Date: Mon, 28 Sep 2026 21:30:00 +0000	[thread overview]
Message-ID: <20260928213001.0D6931F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260927212929.593366-3-kyle.swenson@est.tech>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] pse: incorrect devres registration order causes IRQ use-after-free
- [High] pse: swallowing -EPROBE_DEFER causes incorrect I_CUT limit calculation
--

commit 1aad2f6b5a72ee34250a04fe6ad2b8aea94fa801
Author: Kyle Swenson <kyle.swenson@est.tech>

net: pse-pd: Add LTC4266 PSE controller driver

Add a new driver for the Linear Technology LTC4266 I2C Power Sourcing
Equipment controller and integrate with the PSE controller core. The
LTC4266 supports Type 1 and Type 2 Powered Devices.

> diff --git a/drivers/net/pse-pd/ltc4266.c b/drivers/net/pse-pd/ltc4266.c
> index 0000000000000..37dea467811a4
> --- /dev/null
> +++ b/drivers/net/pse-pd/ltc4266.c
[ ... ]
> +static int ltc4266_pi_nominal_uv(struct ltc4266 *ltc4266, struct device_node *np)
> +{
> +	struct regulator *vpwr;
> +	int uv;
> +
> +	vpwr = of_regulator_get_optional(ltc4266->dev, np, "vpwr");
> +	if (IS_ERR(vpwr)) {
> +		/* -ENODEV means the PI describes no vpwr-supply at all, which
> +		 * is the case the fallback exists for. -EPROBE_DEFER means the
> +		 * rail _is_ described but has not registered yet, so the
> +		 * fallback is wrong for it. Asking for a probe retry is not an
> +		 * option from here: we run from setup_pi_matrix(), and
> +		 * pse_controller_register() unwinds neither its notification
> +		 * fifo nor its pse_pi array when that fails, so every retry
> +		 * would leak. Warn instead so the assumed voltage is visible.
> +		 */
> +		if (PTR_ERR(vpwr) == -EPROBE_DEFER)
> +			dev_warn(ltc4266->dev,
> +				 "%pOF: vpwr-supply is not registered yet, assuming %d uV\n",
> +				 np, LTC4266_VPORT_NOMINAL_UV);
> +
> +		return LTC4266_VPORT_NOMINAL_UV;

[Severity: High]
Does swallowing -EPROBE_DEFER here cause an incorrect I_CUT limit calculation?

If the vpwr-supply regulator is not yet registered when the LTC4266 driver
probes, of_regulator_get_optional() returns -EPROBE_DEFER. By suppressing
this error and falling back to a hardcoded 50V nominal voltage, the port
might operate with an incorrect, permanently-cached power limit. This could
result in delivering more power than administratively allowed, potentially
damaging equipment or violating PoE budgets.

[ ... ]
> +static int ltc4266_probe(struct i2c_client *client)
> +{
[ ... ]
> +	ret = devm_pse_controller_register(ltc4266->dev, &ltc4266->pcdev);
> +	if (ret)
> +		return dev_err_probe(&client->dev, ret,
> +				     "Failed to register PSE controller\n");
> +
> +	/* Enable the interrupt pin, and only report detect events on
> +	 * change (detchg) so idle ports continuously re-running
> +	 * detection in semi-auto mode don't flood the host with a
> +	 * detect event every cycle.
> +	 */
> +	ret = regmap_update_bits(ltc4266->regmap, LTC4266_REG_MCONF,
> +				 LTC4266_MCONF_INTERRUPT_ENABLE | LTC4266_MCONF_DETCHG,
> +				 LTC4266_MCONF_INTERRUPT_ENABLE | LTC4266_MCONF_DETCHG);
> +	if (ret)
> +		return dev_err_probe(&client->dev, ret,
> +				     "Failed to configure interrupts\n");
> +
> +	ret = devm_pse_irq_helper(&ltc4266->pcdev, client->irq,
> +				  0, &irq_desc);

[Severity: High]
Will this devres registration order cause an IRQ use-after-free during unbind?

Because devm_pse_controller_register() is called before devm_pse_irq_helper()
in ltc4266_probe(), the devres LIFO ordering will free the IRQ first during
module removal or probe failure teardown.

After the IRQ is freed, the devres teardown will unregister the controller,
which unconditionally calls disable_irq(pcdev->irq) inside of
pse_controller_unregister(). If the IRQ was reassigned to another device in
the meantime, this could disable that device's interrupt and cause a denial
of service.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260927212929.593366-1-kyle.swenson@est.tech?part=2

  reply	other threads:[~2026-09-28 21:30 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-27 21:29 [PATCH net-next v3 0/2] net: pse-pd: Add LTC4266 PSE controller driver Kyle Swenson
2026-09-27 21:29 ` [PATCH net-next v3 1/2] dt-bindings: net: pse-pd: Add bindings for LTC4266 PSE Controller Kyle Swenson
2026-09-30 21:31   ` netdev-bot+sashiko
2026-10-07 21:04   ` Rob Herring
2026-09-27 21:29 ` [PATCH net-next v3 2/2] net: pse-pd: Add LTC4266 PSE controller driver Kyle Swenson
2026-09-28 21:30   ` sashiko-bot [this message]
2026-09-30 21:31   ` netdev-bot+sashiko
2026-10-05  6:00     ` Kyle Swenson
2026-10-05  9:42       ` Kory Maincent
2026-10-06  7:52         ` Kyle Swenson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928213001.0D6931F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=kyle.swenson@est.tech \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox