Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Long Zhao" <longzhao@ambarella.com>
Cc: linux-serial@vger.kernel.org, robh@kernel.org,
	linux-clk@vger.kernel.org, lee@kernel.org, conor+dt@kernel.org,
	mfd@lists.linux.dev, devicetree@vger.kernel.org
Subject: Re: [PATCH v9 11/15] gpio: pl061: switch data path to gpio-regmap
Date: Thu, 01 Oct 2026 12:56:06 +0000	[thread overview]
Message-ID: <20261001125606.D99071F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261001-cv75-v5-v9-11-486cc289a4b8@ambarella.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] gpio: pl061: UAF due to LIFO devres cleanup ordering
- [High] gpio: pl061: Missing GPIOCHIP_IRQ_RESOURCE_HELPERS allows HW conflict
- [Medium] gpio: pl061: Missing synchronize_irq() causes UAF on module unload
--

commit 0dd970f78f76a57be040a10722f95f7c065440ed
Author: Long Zhao <longzhao@ambarella.com>

gpio: pl061: switch data path to gpio-regmap

This commit migrates the PL061 driver to use gpio-regmap for its data path,
handling the PL061 quirk where output values must be written after a direction
change. It sets up a custom irqchip and domain attached via gpio-regmap, and
modifies the interrupt handler to appropriately check regmap reads.

> diff --git a/drivers/gpio/gpio-pl061.c b/drivers/gpio/gpio-pl061.c
> index c821a5117eede..08d45f8923c2a 100644
> --- a/drivers/gpio/gpio-pl061.c
> +++ b/drivers/gpio/gpio-pl061.c
[ ... ]
> -static const struct irq_chip pl061_irq_chip = {
> +static const struct irq_chip pl061_irqchip = {
> +	.name			= "pl061",
>  	.irq_ack		= pl061_irq_ack,
>  	.irq_mask		= pl061_irq_mask,
>  	.irq_unmask		= pl061_irq_unmask,
> @@ -322,67 +256,187 @@ static const struct irq_chip pl061_irq_chip = {
>  	.irq_set_wake		= pl061_irq_set_wake,
>  	.irq_print_chip		= pl061_irq_print_chip,
>  	.flags			= IRQCHIP_IMMUTABLE,
> -	GPIOCHIP_IRQ_RESOURCE_HELPERS,
> -};
> +};

[Severity: High]
Does the omission of GPIOCHIP_IRQ_RESOURCE_HELPERS from this irq_chip
definition detach it from gpiolib's resource locking?

Without these helpers, gpiochip_lock_as_irq() is never called when a pin
is requested as an IRQ, so GPIOD_FLAG_USED_AS_IRQ is not set. Could this
allow userspace to accidentally reconfigure an active IRQ pin as an output,
causing hardware conflicts?

> +
> +static int pl061_irq_domain_map(struct irq_domain *d, unsigned int virq,
[ ... ]
> +static void pl061_remove_irq(void *data)
> +{
> +	struct pl061 *pl061 = data;
> +
> +	irq_set_chained_handler_and_data(pl061->parent_irq, NULL, NULL);

[Severity: Medium]
Is a call to synchronize_irq() needed here before proceeding?

While the chained handler is cleared, there appears to be no synchronization
with in-flight handlers. If pl061_irq_handler() is running concurrently
on another CPU, it might still be executing when we proceed.

> +
> +	for (unsigned int i = 0; i < pl061->data->ngpio; i++) {
> +		unsigned int virq;
> +
> +		virq = irq_find_mapping(pl061->irq_domain, i);
> +		if (virq)
> +			irq_dispose_mapping(virq);
> +	}
> +
> +	irq_domain_remove(pl061->irq_domain);

[Severity: Medium]
If pl061_irq_handler() is still running, could it access this freed domain
when it calls generic_handle_domain_irq(pl061->irq_domain, offset)?

> +}
[ ... ]
> +static int pl061_probe(struct amba_device *adev, const struct amba_id *id)
> +{
[ ... ]
> +	config.parent = dev;
> +	config.regmap = pl061->regmap;
> +	config.ngpio = data->ngpio;
> +	config.reg_dat_base = GPIO_REGMAP_ADDR(regs->dat);
> +	config.reg_set_base = GPIO_REGMAP_ADDR(regs->dat);
> +	config.reg_dir_out_base = GPIO_REGMAP_ADDR(regs->dir);
> +	config.reg_mask_xlate = data->reg_mask_xlate;
> +	config.quirks = data->quirks;
> +	config.irq_domain = pl061->irq_domain;
> +	config.drvdata = pl061;
> +
> +	gpio_regmap = devm_gpio_regmap_register(dev, &config);
> +	if (IS_ERR(gpio_regmap)) {
> +		if (pl061->irq_domain)
> +			irq_domain_remove(pl061->irq_domain);
> +		return PTR_ERR(gpio_regmap);
> +	}
> +
> +	if (irq) {
> +		ret = devm_add_action_or_reset(dev, pl061_remove_irq, pl061);

[Severity: High]
Can this devres action registration order cause a use-after-free during
driver unbind?

Since devm_add_action_or_reset() is called after devm_gpio_regmap_register(),
devres will execute pl061_remove_irq() first during teardown because it uses
LIFO ordering.

This means pl061_remove_irq() will run and free pl061->irq_domain, but
the gpiochip is still registered. When gpio_regmap subsequently unregisters
the gpiochip, gpiochip_remove() will eventually call
gpiochip_free_remaining_irqs(), which will attempt to use the already-freed
irq.domain pointer.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261001-cv75-v5-v9-0-486cc289a4b8@ambarella.com?part=11

  reply	other threads:[~2026-10-01 12:56 UTC|newest]

Thread overview: 41+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 12:40 [PATCH v9 00/15] Ambarella CV75 SoC minimal bring-up Long Zhao via B4 Relay
2026-10-01 12:40 ` [PATCH v9 01/15] dt-bindings: arm: add Ambarella CV75 platforms Long Zhao via B4 Relay
2026-10-01 12:43   ` sashiko-bot
2026-10-01 12:40 ` [PATCH v9 02/15] dt-bindings: mfd: syscon: add Ambarella CV75 secure scratchpad Long Zhao via B4 Relay
2026-10-01 12:43   ` sashiko-bot
2026-10-01 12:40 ` [PATCH v9 03/15] dt-bindings: clock: add Ambarella CV75 RCT Long Zhao via B4 Relay
2026-10-01 12:45   ` sashiko-bot
2026-10-01 12:40 ` [PATCH v9 04/15] dt-bindings: gpio: pl061: add Ambarella CV75 variant Long Zhao via B4 Relay
2026-10-01 12:50   ` sashiko-bot
2026-10-01 19:23   ` Conor Dooley
2026-10-01 19:36     ` Linus Walleij
2026-10-01 21:16       ` Conor Dooley
2026-10-01 12:40 ` [PATCH v9 05/15] dt-bindings: serial: snps-dw-apb-uart: add ambarella,cv75-uart Long Zhao via B4 Relay
2026-10-01 12:43   ` sashiko-bot
2026-10-01 12:40 ` [PATCH v9 06/15] clk: ambarella: add CV75 RCT clock controller Long Zhao via B4 Relay
2026-10-01 12:47   ` sashiko-bot
2026-10-02  8:10   ` Andy Shevchenko
2026-10-01 12:40 ` [PATCH v9 07/15] gpiolib: regmap: add GPIO_REGMAP_QUIRK_SET_AFTER_DIR Long Zhao via B4 Relay
2026-10-01 12:45   ` sashiko-bot
2026-10-02  7:41   ` Andy Shevchenko
2026-10-01 12:40 ` [PATCH v9 08/15] gpio: pl061: convert register access to regmap Long Zhao via B4 Relay
2026-10-01 12:47   ` sashiko-bot
2026-10-02  8:26   ` Andy Shevchenko
2026-10-01 12:40 ` [PATCH v9 09/15] gpio: pl061: use IRQ_TYPE_LEVEL_MASK and IRQ_TYPE_EDGE_BOTH Long Zhao via B4 Relay
2026-10-01 12:45   ` sashiko-bot
2026-10-02  9:22   ` Andy Shevchenko
2026-10-01 12:40 ` [PATCH v9 10/15] gpio: pl061: use cleanup helpers for locks Long Zhao via B4 Relay
2026-10-01 12:46   ` sashiko-bot
2026-10-01 12:41 ` [PATCH v9 11/15] gpio: pl061: switch data path to gpio-regmap Long Zhao via B4 Relay
2026-10-01 12:56   ` sashiko-bot [this message]
2026-10-01 12:41 ` [PATCH v9 12/15] gpio: pl061: add Ambarella register-layout variant Long Zhao via B4 Relay
2026-10-01 12:55   ` sashiko-bot
2026-10-01 12:41 ` [PATCH v9 13/15] serial: 8250_dw: add Ambarella CV75 quirks Long Zhao via B4 Relay
2026-10-01 12:49   ` sashiko-bot
2026-10-01 12:52   ` Greg Kroah-Hartman
2026-10-01 19:20     ` Linus Walleij
2026-10-02  2:17       ` zl020895
2026-10-02  8:09         ` Jerome Brunet
2026-10-01 12:41 ` [PATCH v9 14/15] arm64: ambarella: add ARCH_AMBARELLA and CV75 EVK DT Long Zhao via B4 Relay
2026-10-01 12:54   ` sashiko-bot
2026-10-01 12:41 ` [PATCH v9 15/15] MAINTAINERS: add ARM/AMBARELLA SoC support Long Zhao via B4 Relay

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001125606.D99071F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=lee@kernel.org \
    --cc=linux-clk@vger.kernel.org \
    --cc=linux-serial@vger.kernel.org \
    --cc=longzhao@ambarella.com \
    --cc=mfd@lists.linux.dev \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox