Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Coia Prant" <coiaprant@gmail.com>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH net-next v10 5/6] net: stmmac: dwmac-rk: add SGMII support for RK3568
Date: Tue, 06 Oct 2026 22:31:21 +0000	[thread overview]
Message-ID: <sashiko-outbox-162491@kernel.org> (raw)
In-Reply-To: <20261005223011.1124347-6-coiaprant@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] net: stmmac: memory leak and SGMII breakage due to xpcs overwrite
--

commit 9f6d3f852317e81db5e938c043afc40343ece6e9
Author: Coia Prant <coiaprant@gmail.com>

net: stmmac: dwmac-rk: add SGMII support for RK3568

This commit adds SGMII support for the RK3568 SoC to the dwmac-rk driver.
It configures the necessary glue logic, sets up the MAC for in-band
negotiation, and provides callbacks to initialize and manage an XPCS via
the Rockchip platform driver.

Link: https://dl.radxa.com/rock3/docs/hw/datasheet/Rockchip%20RK3568%20TRM%20Part1%20V1.1-20210301.pdf

> diff --git a/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c b/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c
> index 72bdbcb5e863a..3b50ad3c600b9 100644
> --- a/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c
> +++ b/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c

[ ... ]

> @@ -1211,6 +1239,43 @@ static void rk_phy_powerdown(struct rk_priv_data *bsp_priv)
> +static int rk_pcs_init(struct stmmac_priv *priv)
> +{
> +	struct device_node *np = priv->device->of_node;
> +	struct device_node *pcs_node;
> +	struct dw_xpcs *xpcs;
> +
> +	pcs_node = of_parse_phandle(np, "pcs-handle", 0);
> +	if (!pcs_node)
> +		return -ENODEV;
> +
> +	xpcs = xpcs_rk_create(priv->device, pcs_node);
> +	of_node_put(pcs_node);
> +	if (IS_ERR(xpcs))
> +		return PTR_ERR(xpcs);
> +
> +	priv->hw->xpcs = xpcs;

[Severity: High]
Does assigning priv->hw->xpcs here leak the allocated memory and break
SGMII initialization?

Looking at stmmac_pcs_setup() in
drivers/net/ethernet/stmicro/stmmac/stmmac_mdio.c, the local xpcs variable
initializes to NULL and remains NULL when priv->plat->pcs_init() is called:

stmmac_mdio.c:stmmac_pcs_setup() {
    struct dw_xpcs *xpcs = NULL;
    ...
    if (priv->plat->pcs_init) {
        ret = priv->plat->pcs_init(priv);
    } else if (fwnode_property_present(devnode, "pcs-handle")) {
        ...
    }
    ...
    priv->hw->xpcs = xpcs;
}

Because rk_pcs_init() successfully allocates an XPCS and assigns it to
priv->hw->xpcs, the caller will immediately overwrite priv->hw->xpcs with
its local NULL variable. This drops the reference to the newly allocated
dw_xpcs structure and leaves the device without a valid XPCS, which breaks
rk_select_pcs() and the SGMII configuration.

Should rk_pcs_init() be updated to return the xpcs pointer, or does the
core stmmac_pcs_setup() logic need to be modified to avoid overwriting the
platform-allocated xpcs pointer?

> +	return 0;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261005223011.1124347-1-coiaprant@gmail.com?part=5

  reply	other threads:[~2026-10-06 22:31 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 22:30 [PATCH net-next v10 0/6] net: pcs: add basic support for RK3568 XPCS Coia Prant
2026-10-05 22:30 ` [PATCH net-next v10 1/6] dt-bindings: net: pcs: add rockchip,rk3568-xpcs support Coia Prant
2026-10-06 13:24   ` Rob Herring
2026-10-06 13:59     ` Coia Prant
2026-10-06 15:08       ` Rob Herring
2026-10-06 15:52         ` Coia Prant
2026-10-07 10:00           ` Coia Prant
2026-10-08 16:32   ` netdev-bot+sashiko
2026-10-05 22:30 ` [PATCH net-next v10 2/6] net: pcs: xpcs: add ANRESTART support for SGMII link recovery Coia Prant
2026-10-08 16:32   ` netdev-bot+sashiko
2026-10-05 22:30 ` [PATCH net-next v10 3/6] net: pcs: xpcs: add Rockchip RK3568 platform glue driver Coia Prant
2026-10-08 16:32   ` netdev-bot+sashiko
2026-10-05 22:30 ` [PATCH net-next v10 4/6] dt-bindings: net: rockchip-dwmac: document pcs-handle Coia Prant
2026-10-06 13:48   ` Rob Herring
2026-10-06 13:55     ` Coia Prant
2026-10-05 22:30 ` [PATCH net-next v10 5/6] net: stmmac: dwmac-rk: add SGMII support for RK3568 Coia Prant
2026-10-06 22:31   ` sashiko-bot [this message]
2026-10-08 16:32   ` netdev-bot+sashiko
2026-10-08 17:22     ` Coia Prant
2026-10-05 22:30 ` [PATCH net-next v10 6/6] MAINTAINERS: add entry for Rockchip XPCS driver Coia Prant

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-162491@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=coiaprant@gmail.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox