Linux-i3c Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Adrian Hunter <adrian.hunter@intel.com>
To: <sashiko-reviews@lists.linux.dev>
Cc: Alexandre Belloni <alexandre.belloni@bootlin.com>,
	<Frank.Li@kernel.org>, <linux-i3c@lists.infradead.org>
Subject: Re: [PATCH V3 16/17] i3c: Restrict HDR modes to those supported by the bus and target
Date: Sun, 20 Sep 2026 18:48:21 +0300	[thread overview]
Message-ID: <96f4b614-b9f5-46cd-9c03-a355cfe5adb7@intel.com> (raw)
In-Reply-To: <20260920153400.0E2171F000FF@smtp.kernel.org>

On 20/09/2026 18:33, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] i3c: missing NULL check for dev->desc in i3c_device_get_supported_xfer_mode
> --
> 
> commit 62529bd655d4c18d69da34f93d179ce363aba85c
> Author: Adrian Hunter <adrian.hunter@intel.com>
> 
> i3c: Restrict HDR modes to those supported by the bus and target
> 
> This commit refactors i3c_device_get_supported_xfer_mode() to consider HDR
> modes allowed by the controller, bus configuration, and target. It
> introduces a helper i3c_dev_supported_xfer_modes_locked() and adds bus
> locking in normal use mode to access the device descriptor safely.
> 
>> diff --git a/drivers/i3c/device.c b/drivers/i3c/device.c
>> index f1ba363b22a17..4df4682af1504 100644
>> --- a/drivers/i3c/device.c
>> +++ b/drivers/i3c/device.c
> [ ... ]
>> @@ -301,16 +301,23 @@ i3c_device_match_id(struct i3c_device *i3cdev,
>>  EXPORT_SYMBOL_GPL(i3c_device_match_id);
>>  
>>  /**
>> - * i3c_device_get_supported_xfer_mode - Returns the supported transfer mode by
>> - *					connected master controller.
>> + * i3c_device_get_supported_xfer_mode - Returns the transfer modes supported by
>> + *					the connected master controller and @dev,
>> + *					and allowed by the bus configuration.
>>   * @dev: I3C device
>>   *
>>   * Return: a bit mask, which supported transfer mode, bit position is defined at
>> - *	   enum i3c_hdr_mode
>> + *	   enum i3c_xfer_mode
>>   */
>>  u32 i3c_device_get_supported_xfer_mode(struct i3c_device *dev)
>>  {
>> -	return i3c_bus_to_i3c_master(dev->bus)->this->info.hdr_cap | BIT(I3C_SDR);
>> +	u32 modes;
>> +
>> +	i3c_bus_normaluse_lock(dev->bus);
>> +	modes = i3c_dev_supported_xfer_modes_locked(dev->desc);
> 
> [Severity: High]
> Does this code risk a NULL pointer dereference during device unregistration?
> 
> If a device is being concurrently unregistered,
> i3c_master_unregister_i3c_devs() asynchronously sets dev->desc = NULL
> before driver unbinding completes. Other APIs in the I3C subsystem (such

FWIW: no it doesn't - that was fixed already, refer:

commit d2c743efd2d1ee64e94324664808f623dd865872
Author: Adrian Hunter <adrian.hunter@intel.com>
Date:   Thu Jul 23 10:57:47 2026 +0300

    i3c: master: Fix info leak and UAF in device unregister path


> as i3c_device_get_info() and i3c_device_disable_ibi()) appear to guard
> against this teardown race condition by explicitly checking if (dev->desc)
> inside the bus lock.
> 
> Without a prior NULL check here, dev->desc is passed into
> i3c_dev_supported_xfer_modes_locked(), which unconditionally dereferences
> it:
> 
> include/linux/i3c/master.h:i3c_dev_get_master() {
>     return dev->common.master;
> }
> 
> drivers/i3c/master.c:i3c_dev_supported_xfer_modes_locked() {
>     struct i3c_master_controller *master = i3c_dev_get_master(dev);
>     ...
> }
> 
> Could a check for dev->desc be added inside the lock before calling the
> helper?
> 
>> +	i3c_bus_normaluse_unlock(dev->bus);
>> +
>> +	return modes;
>>  }
> 


-- 
linux-i3c mailing list
linux-i3c@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-i3c

  reply	other threads:[~2026-09-20 15:48 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-20 15:12 [PATCH V3 00/17] i3c: Fixes, cleanups and HDR-DDR support Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 01/17] i3c: master: Fix out-of-bounds read in DMA bounce buffer setup Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 02/17] i3c: mipi-i3c-hci: Bounce short reads irrespective of the IOMMU Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 03/17] i3c: mipi-i3c-hci-pci: Set drvdata before creating LTR sysfs attribute Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 04/17] i3c: master: Match ACPI targets to the correct bus controller instance Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 05/17] i3c: master: Remove stale GETSTATUS length check Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 06/17] i3c: mipi-i3c-hci: Restore controller state if i3c_hci_enable_ibi() returns an error Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 07/17] i3c: mipi-i3c-hci: Send DISEC before disabling IBIs in hardware Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 08/17] i3c: mipi-i3c-hci: Fix runtime PM violation in i3c_hci_free_ibi() Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 09/17] i3c: mipi-i3c-hci: Process multiple IBIs per interrupt Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 10/17] i3c: mipi-i3c-hci: Move DMA suspend/resume callbacks Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 11/17] i3c: mipi-i3c-hci: Stop rings gracefully when suspending Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 12/17] i3c: mipi-i3c-hci: Correct RESP_DATA_LENGTH to bits 15:0 Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 13/17] i3c: mipi-i3c-hci: Remove invalid transfer size limit Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 14/17] i3c: mipi-i3c-hci: Remove invalid HDR-BT and Fm/Fm+ definitions Adrian Hunter
2026-09-20 15:12 ` [PATCH V3 15/17] i3c: mipi-i3c-hci: Support configurable device NACK retries Adrian Hunter
2026-09-21 18:36   ` Frank Li
2026-09-20 15:12 ` [PATCH V3 16/17] i3c: Restrict HDR modes to those supported by the bus and target Adrian Hunter
2026-09-20 15:33   ` sashiko-bot
2026-09-20 15:48     ` Adrian Hunter [this message]
2026-09-20 15:12 ` [PATCH V3 17/17] i3c: mipi-i3c-hci: Add HDR-DDR support Adrian Hunter
2026-09-21 21:27 ` [PATCH V3 00/17] i3c: Fixes, cleanups and " Alexandre Belloni

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=96f4b614-b9f5-46cd-9c03-a355cfe5adb7@intel.com \
    --to=adrian.hunter@intel.com \
    --cc=Frank.Li@kernel.org \
    --cc=alexandre.belloni@bootlin.com \
    --cc=linux-i3c@lists.infradead.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox