From: sashiko-bot@kernel.org
To: "Adrian Hunter" <adrian.hunter@intel.com>
Cc: "Alexandre Belloni" <alexandre.belloni@bootlin.com>,
Frank.Li@kernel.org, linux-i3c@lists.infradead.org
Subject: Re: [PATCH V3 16/17] i3c: Restrict HDR modes to those supported by the bus and target
Date: Sun, 20 Sep 2026 15:33:59 +0000 [thread overview]
Message-ID: <20260920153400.0E2171F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260920151248.46936-17-adrian.hunter@intel.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] i3c: missing NULL check for dev->desc in i3c_device_get_supported_xfer_mode
--
commit 62529bd655d4c18d69da34f93d179ce363aba85c
Author: Adrian Hunter <adrian.hunter@intel.com>
i3c: Restrict HDR modes to those supported by the bus and target
This commit refactors i3c_device_get_supported_xfer_mode() to consider HDR
modes allowed by the controller, bus configuration, and target. It
introduces a helper i3c_dev_supported_xfer_modes_locked() and adds bus
locking in normal use mode to access the device descriptor safely.
> diff --git a/drivers/i3c/device.c b/drivers/i3c/device.c
> index f1ba363b22a17..4df4682af1504 100644
> --- a/drivers/i3c/device.c
> +++ b/drivers/i3c/device.c
[ ... ]
> @@ -301,16 +301,23 @@ i3c_device_match_id(struct i3c_device *i3cdev,
> EXPORT_SYMBOL_GPL(i3c_device_match_id);
>
> /**
> - * i3c_device_get_supported_xfer_mode - Returns the supported transfer mode by
> - * connected master controller.
> + * i3c_device_get_supported_xfer_mode - Returns the transfer modes supported by
> + * the connected master controller and @dev,
> + * and allowed by the bus configuration.
> * @dev: I3C device
> *
> * Return: a bit mask, which supported transfer mode, bit position is defined at
> - * enum i3c_hdr_mode
> + * enum i3c_xfer_mode
> */
> u32 i3c_device_get_supported_xfer_mode(struct i3c_device *dev)
> {
> - return i3c_bus_to_i3c_master(dev->bus)->this->info.hdr_cap | BIT(I3C_SDR);
> + u32 modes;
> +
> + i3c_bus_normaluse_lock(dev->bus);
> + modes = i3c_dev_supported_xfer_modes_locked(dev->desc);
[Severity: High]
Does this code risk a NULL pointer dereference during device unregistration?
If a device is being concurrently unregistered,
i3c_master_unregister_i3c_devs() asynchronously sets dev->desc = NULL
before driver unbinding completes. Other APIs in the I3C subsystem (such
as i3c_device_get_info() and i3c_device_disable_ibi()) appear to guard
against this teardown race condition by explicitly checking if (dev->desc)
inside the bus lock.
Without a prior NULL check here, dev->desc is passed into
i3c_dev_supported_xfer_modes_locked(), which unconditionally dereferences
it:
include/linux/i3c/master.h:i3c_dev_get_master() {
return dev->common.master;
}
drivers/i3c/master.c:i3c_dev_supported_xfer_modes_locked() {
struct i3c_master_controller *master = i3c_dev_get_master(dev);
...
}
Could a check for dev->desc be added inside the lock before calling the
helper?
> + i3c_bus_normaluse_unlock(dev->bus);
> +
> + return modes;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260920151248.46936-1-adrian.hunter@intel.com?part=16
--
linux-i3c mailing list
linux-i3c@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-i3c
next prev parent reply other threads:[~2026-09-20 15:34 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-20 15:12 [PATCH V3 00/17] i3c: Fixes, cleanups and HDR-DDR support Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 01/17] i3c: master: Fix out-of-bounds read in DMA bounce buffer setup Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 02/17] i3c: mipi-i3c-hci: Bounce short reads irrespective of the IOMMU Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 03/17] i3c: mipi-i3c-hci-pci: Set drvdata before creating LTR sysfs attribute Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 04/17] i3c: master: Match ACPI targets to the correct bus controller instance Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 05/17] i3c: master: Remove stale GETSTATUS length check Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 06/17] i3c: mipi-i3c-hci: Restore controller state if i3c_hci_enable_ibi() returns an error Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 07/17] i3c: mipi-i3c-hci: Send DISEC before disabling IBIs in hardware Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 08/17] i3c: mipi-i3c-hci: Fix runtime PM violation in i3c_hci_free_ibi() Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 09/17] i3c: mipi-i3c-hci: Process multiple IBIs per interrupt Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 10/17] i3c: mipi-i3c-hci: Move DMA suspend/resume callbacks Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 11/17] i3c: mipi-i3c-hci: Stop rings gracefully when suspending Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 12/17] i3c: mipi-i3c-hci: Correct RESP_DATA_LENGTH to bits 15:0 Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 13/17] i3c: mipi-i3c-hci: Remove invalid transfer size limit Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 14/17] i3c: mipi-i3c-hci: Remove invalid HDR-BT and Fm/Fm+ definitions Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 15/17] i3c: mipi-i3c-hci: Support configurable device NACK retries Adrian Hunter
2026-09-21 18:36 ` Frank Li
2026-09-20 15:12 ` [PATCH V3 16/17] i3c: Restrict HDR modes to those supported by the bus and target Adrian Hunter
2026-09-20 15:33 ` sashiko-bot [this message]
2026-09-20 15:48 ` Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 17/17] i3c: mipi-i3c-hci: Add HDR-DDR support Adrian Hunter
2026-09-21 21:27 ` [PATCH V3 00/17] i3c: Fixes, cleanups and " Alexandre Belloni
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260920153400.0E2171F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=adrian.hunter@intel.com \
--cc=alexandre.belloni@bootlin.com \
--cc=linux-i3c@lists.infradead.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox