Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Joshua Yeong" <joshua.yeong@starfivetech.com>
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v2 6/7] pmdomain: riscv: Add RPMI performance domains as power domains
Date: Thu, 08 Oct 2026 09:27:40 +0000	[thread overview]
Message-ID: <sashiko-outbox-163935@kernel.org> (raw)
In-Reply-To: <20261008091032.2832333-7-joshua.yeong@starfivetech.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] pmdomain: devres UAF on genpd removal via sysfs unbind
--

commit bcb5ae58c392c6ab2a9b0f57c2292a07b1a39866
Author: Joshua Yeong <joshua.yeong@starfivetech.com>
Subject: pmdomain: riscv: Add RPMI performance domains as power domains

This commit registers the performance domains of the RISC-V platform management
interface (RPMI) performance service group as generic power domains. Devices
that are not CPUs can reference these domains through the "power-domains"
property and drive them using the OPP library.

> diff --git a/drivers/pmdomain/riscv/riscv-rpmi-perf-domain.c b/drivers/pmdomain/riscv/riscv-rpmi-perf-domain.c
> new file mode 100644
> index 0000000000000..fc5c512fe0697
> --- /dev/null
> +++ b/drivers/pmdomain/riscv/riscv-rpmi-perf-domain.c
> @@ -0,0 +1,265 @@

[ ... ]

> +static int rpmi_perf_genpd_probe(struct platform_device *pdev)
> +{
> +	struct rpmi_perf **mpxy_perf = dev_get_platdata(&pdev->dev);
> +	struct device *dev = &pdev->dev;
> +	struct rpmi_perf_genpd_provider *provider;
> +	struct generic_pm_domain **domains;
> +	u32 i, num_domains, registered = 0;
> +	int ret;
> +
> +	if (!mpxy_perf || !*mpxy_perf)
> +		return -EINVAL;
> +
> +	num_domains = rpmi_perf_num_domains(*mpxy_perf);
> +
> +	provider = devm_kzalloc(dev, sizeof(*provider), GFP_KERNEL);
> +	if (!provider)
> +		return -ENOMEM;
> +
> +	provider->pds = devm_kcalloc(dev, num_domains, sizeof(*provider->pds),
> +				     GFP_KERNEL);

[Severity: High]
Since provider->pds is allocated using devm_kcalloc(), this memory will be
automatically freed as soon as the driver's remove callback returns.

> +	if (!provider->pds)
> +		return -ENOMEM;

[ ... ]

> +static void rpmi_perf_genpd_remove(struct platform_device *pdev)
> +{
> +	struct rpmi_perf_genpd_provider *provider = platform_get_drvdata(pdev);
> +	u32 i;
> +
> +	of_genpd_del_provider(dev_of_node(pdev->dev.parent));
> +
> +	for (i = 0; i < provider->data.num_domains; i++) {
> +		if (provider->data.domains[i])
> +			pm_genpd_remove(provider->data.domains[i]);

[Severity: High]
Does this code ignore the return value of pm_genpd_remove()?

If a user manually unbinds the driver via sysfs while consumer devices are
still attached to the PM domains, pm_genpd_remove() will return -EBUSY and
fail to remove the domain from the core genpd framework's global gpd_list.

Because the memory backing these domains (provider->pds) was allocated with
devres and will be freed immediately after this remove function returns,
could this leave dangling pointers in the global gpd_list?

This might lead to a use-after-free and potential kernel panic when
the gpd_list is traversed later.

> +	}
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261008091032.2832333-1-joshua.yeong@starfivetech.com?part=6

  reply	other threads:[~2026-10-08  9:27 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08  9:10 [PATCH v2 0/7] Add RISC-V RPMI performance service support Joshua Yeong
2026-10-08  9:10 ` [PATCH v2 1/7] dt-bindings: dvfs: Add RPMI performance service message proxy bindings Joshua Yeong
2026-10-08  9:10 ` [PATCH v2 2/7] dt-bindings: dvfs: Add RPMI performance service bindings Joshua Yeong
2026-10-08 10:41   ` Conor Dooley
2026-10-08  9:10 ` [PATCH v2 3/7] dt-bindings: riscv: cpus: document performance-domains property Joshua Yeong
2026-10-08  9:10 ` [PATCH v2 4/7] firmware: riscv: Add RPMI performance service Joshua Yeong
2026-10-08  9:23   ` sashiko-bot
2026-10-08  9:10 ` [PATCH v2 5/7] cpufreq: Add RISC-V RPMI cpufreq driver Joshua Yeong
2026-10-08  9:23   ` sashiko-bot
2026-10-08  9:10 ` [PATCH v2 6/7] pmdomain: riscv: Add RPMI performance domains as power domains Joshua Yeong
2026-10-08  9:27   ` sashiko-bot [this message]
2026-10-08  9:10 ` [PATCH v2 7/7] MAINTAINERS: Add RISC-V RPMI performance driver Joshua Yeong

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-163935@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=joshua.yeong@starfivetech.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox