Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Svyatoslav Ryhel" <clamor95@gmail.com>
Cc: robh@kernel.org, lee@kernel.org, dri-devel@lists.freedesktop.org,
	devicetree@vger.kernel.org, conor+dt@kernel.org,
	mfd@lists.linux.dev, linux-leds@vger.kernel.org
Subject: Re: [PATCH v2 2/3] mfd: aat2870: Convert to use OF bindings
Date: Sun, 04 Oct 2026 16:50:55 +0000	[thread overview]
Message-ID: <20261004165055.8DF0D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261004164121.193514-3-clamor95@gmail.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] regulator: UAF and memory leak due to shared static array in of_regulator_match
- [Medium] video: backlight: functional regression when led-max-microamp is missing
- [Low] video: backlight: incompatible pointer type in device_property_read_u32
--

commit 084e352aa2d7fee86a0e56df75d5d10cdd400379
Author: Svyatoslav Ryhel <clamor95@gmail.com>
Subject: mfd: aat2870: Convert to use OF bindings

This patch converts the AAT2870 driver to use OF bindings, replacing the
MFD registration API with of_platform_populate() and adding dedicated
compatible strings for its sub-devices. It also updates the regulator and
backlight child drivers to parse properties directly from the device tree
and removes redundant platform data.

In drivers/regulator/aat2870-regulator.c around line 133, there is a static
array defined for aat2870_regulator_matches. Later in aat2870_regulator_probe()
around line 171, this shared static array is passed directly to
of_regulator_match().

[Severity: High]
Could passing this shared static array to of_regulator_match() cause a
use-after-free or memory leak if multiple AAT2870 devices are probed?
of_regulator_match() actively mutates the passed array to store device nodes
and binds its lifetime to the device via devres. If a second device probes,
it would overwrite the array, leaking the first device's nodes. Upon unbind,
devres would drop references to whatever nodes are currently in the array,
potentially causing a double-free or use-after-free for the remaining
references.

In drivers/video/backlight/aat2870_bl.c around line 141 in aat2870_bl_probe(),
the code calls device_property_read_u32() to read led-max-microamp into
aat2870_bl->max_current.

[Severity: Low]
Does this trigger an incompatible pointer types compiler warning?
aat2870_bl->max_current is declared as an int, but device_property_read_u32()
expects a u32 pointer.

Also in drivers/video/backlight/aat2870_bl.c around line 141, the max_current
value is read via device_property_read_u32() without prior initialization.

[Severity: Medium]
Will the backlight permanently disable itself if the led-max-microamp property
is omitted from the device tree? If the property is missing, max_current
remains 0. Passing 0 into clamp(0, 450, 27900) returns 450. When 450 is
divided by AAT2870_CURRENT_STEP (which is 900), the result evaluates to 0.
Since the brightness calculation multiplies by max_current, this appears to
leave the backlight permanently disabled under these conditions.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261004164121.193514-1-clamor95@gmail.com?part=2

  reply	other threads:[~2026-10-04 16:50 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-04 16:41 [PATCH v2 0/3] mfd: aat2870: Convert to use OF bindings Svyatoslav Ryhel
2026-10-04 16:41 ` [PATCH v2 1/3] dt-bindings: mfd: Document Skyworks AAT2870 Svyatoslav Ryhel
2026-10-04 16:50   ` sashiko-bot
2026-10-05 16:31   ` Daniel Thompson
2026-10-05 16:53     ` Svyatoslav Ryhel
2026-10-04 16:41 ` [PATCH v2 2/3] mfd: aat2870: Convert to use OF bindings Svyatoslav Ryhel
2026-10-04 16:50   ` sashiko-bot [this message]
2026-10-05 16:51   ` Daniel Thompson
2026-10-05 17:18     ` Svyatoslav Ryhel
2026-10-06  9:38       ` Daniel Thompson
2026-10-06 10:06         ` Svyatoslav Ryhel
2026-10-04 16:41 ` [PATCH v2 3/3] mfd: aat2870: Add support for VIN and IN-LDO power supplies Svyatoslav Ryhel
2026-10-04 16:49   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261004165055.8DF0D1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=clamor95@gmail.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=lee@kernel.org \
    --cc=linux-leds@vger.kernel.org \
    --cc=mfd@lists.linux.dev \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox