On Thu, Sep 10, 2026 at 02:31:06PM +0000, sashiko-bot@kernel.org wrote: > Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider: > > Pre-existing issues: > - [Critical] Missing bounds check in `of_parse_phandle_with_args_map` allows a malformed Devicetree to trigger a stack buffer overflow. > - [High] Missing cycle detection in `of_parse_phandle_with_args_map` allows a malformed Devicetree to cause an infinite loop. > -- > > commit 17ae1bc408452875cfad3c0d990add52c676f9b9 > Author: Ernest Van Hoecke > > of: property: fw_devlink: Follow PWM nexus maps > > PWM consumers use of_parse_phandle_with_args_map() to resolve specifiers > through pwm-map properties. fw_devlink instead parses the pwms property > as a direct phandle reference, so it records the nexus node as the > supplier rather than the mapped PWM provider. > > Use the map-aware parser for pwms so fw_devlink resolves the same > provider as the PWM consumer API. Direct PWM references continue to work > because the map-aware parser returns the original provider when no > pwm-map property is present. > > Link: https://lore.kernel.org/all/juuc4af7ndbajcl7gzf4tg5qz2q2j5tt3rvql4jbauradujrre@gc5nbdhhixaf/ > > > diff --git a/drivers/of/property.c b/drivers/of/property.c > > index eba7e9fe6c386..a9c51d639a2b5 100644 > > --- a/drivers/of/property.c > > +++ b/drivers/of/property.c > > @@ -1426,7 +1435,7 @@ DEFINE_SIMPLE_PROP(extcon, "extcon", NULL) > > DEFINE_SIMPLE_PROP(nvmem_cells, "nvmem-cells", "#nvmem-cell-cells") > > DEFINE_SIMPLE_PROP(phys, "phys", "#phy-cells") > > DEFINE_SIMPLE_PROP(wakeup_parent, "wakeup-parent", NULL) > > -DEFINE_SIMPLE_PROP(pwms, "pwms", "#pwm-cells") > > +DEFINE_SIMPLE_NEXUS_PROP(pwms, "pwms", "pwm") > > [Severity: Critical] > This isn't a bug introduced by this patch, but this change exposes a > pre-existing stack buffer overflow in of_parse_phandle_with_args_map() by > parsing pwms properties automatically during early boot. > > Does this code overflow initial_match_array[]? If a provider node in a > malformed Devicetree has a #pwm-cells property larger than MAX_PHANDLE_ARGS > (16), list_size is read without bounds checking: > > drivers/of/base.c:of_parse_phandle_with_args_map() { > ... > /* Precalculate the match array - this simplifies match loop */ > for (i = 0; i < list_size; i++) > initial_match_array[i] = cpu_to_be32(out_args->args[i]); > ... > } > > Because fw_devlink now automatically calls parse_nexus_prop() and > of_parse_phandle_with_args_map() for all pwms properties, this regression can > now be trivially triggered without requiring consumer drivers to probe. Does this need diff --git a/drivers/of/base.c b/drivers/of/base.c index d71ae0449360..68d3eaa86742 100644 --- a/drivers/of/base.c +++ b/drivers/of/base.c @@ -1579,6 +1579,9 @@ int of_parse_phandle_with_args_map(const struct device_node *np, if (ret < 0) goto put; + if (list_size > MAX_PHANDLE_ARGS) + return -EINVAL; + /* Precalculate the match array - this simplifies match loop */ for (i = 0; i < list_size; i++) initial_match_array[i] = cpu_to_be32(out_args->args[i]); ? Best regards Uwe