* [PATCH v14 0/4] Add phy_get_by_of_node and devm helper
@ 2026-09-03 22:59 Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 1/4] phy: core: Fix use-after-free in phy_get paths Bryan O'Donoghue
` (3 more replies)
0 siblings, 4 replies; 8+ messages in thread
From: Bryan O'Donoghue @ 2026-09-03 22:59 UTC (permalink / raw)
To: Bjorn Andersson, Michael Turquette, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley, Robert Foss, Todor Tomov,
Mauro Carvalho Chehab, Konrad Dybcio, Vladimir Zapolskiy,
Bryan O'Donoghue, Loic Poulain, Vinod Koul, Neil Armstrong,
Greg Kroah-Hartman, Kishon Vijay Abraham I, Felipe Balbi
Cc: linux-arm-msm, linux-clk, devicetree, linux-kernel, linux-media,
linux-phy, Bryan O'Donoghue, Krzysztof Kozlowski, stable
This series has evolved from a CAMSS standalone series to a series that is
mostly on the PHY side now, so I've split the series up to reflect that
fact.
Starting off by fixing a long-standing use-after-free race-condition in the
phy core flagged by Sashiko in v13. While my series doesn't introduce the
bug it seems appropriate to address it anyway once flagged.
Once addressed two new helper functions are introduced to the PHY core to
enable finding of a PHY using the media graph.
Finally the usage of that new API is shown with CAMSS.
Changes in v14:
- Fixes existing bug highlited by Sashiko in v13.
The bug has appropriate Fixes: tags applied for back-porting.
- RB accumulated from v13 for the now standalone CAMSS patch.
- YAML changes carried thus far will instead be posted with dtsi changes
where they 'feel' more logical.
- Depends-on: https://lore.kernel.org/r/20260903-x1e-csi2-phy-v17-0-26606fa9a039@linaro.org
- Link to v13: https://patch.msgid.link/20260728-b4-linux-next-25-03-13-dtsi-x1e80100-camss-v13-0-ae811e2f0799@linaro.org
Changes in v13:
- Introduces struct device_node phy helper lookup.
This allows for finding a phy from a device_node entry.
- Uses media-graph exclusively to reference phys. - Neil, Vlad, Vinod
- Performs runtime check for legacy v non-legacy phys - Krzysztof
- Link to v12: https://patch.msgid.link/20260708-b4-linux-next-25-03-13-dtsi-x1e80100-camss-v12-0-f8588da41f16@linaro.org
Changes in v12:
- Updates camss sensor find method to find the sensor in the CSIPHY port. -
Neil, Vlad, Bryan
- Drops dependency on passing polarities and positions. Moved into CSIPHY
port as agreed. Neil, Vlad, Bryan
- Omitted mux to CSID as discussed this will be done when splitting CSID
out as its own individual node. Neil, Bryan
- Updated Reviewed-by: - Loic
- Link to v11: https://lore.kernel.org/r/20260326-b4-linux-next-25-03-13-dtsi-x1e80100-camss-v11-0-5b93415be6dd@linaro.org
Changes in v11:
- Dropped simple-mfd in dts for devm_of_platform_populate() - Krzysztof
- Pass polarity and position for data and clock lanes - bod
- Remove check for PHY_TYPE_DPHY - PHY driver validates its own mode - bod
- Depends-on: https://lore.kernel.org/r/20260325-dphy-params-extension-v1-0-c6df5599284a@linaro.org
- Depends-on: https://lore.kernel.org/r/20260326-x1e-csi2-phy-v5-0-0c0fc7f5c01b@linaro.org
- Link to v10: https://lore.kernel.org/r/20260316-b4-linux-next-25-03-13-dtsi-x1e80100-camss-v10-0-fdfe984fe941@linaro.org
Changes in v10:
- compat simple-mfd added to CAMSS allows probing sub-nodes.
The other way to do this would be simple-bus however, CAMSS
is really a collection of devices in a block as opposed to a
discoverable bus.
- csiphy nodes are sub-nodes of CAMSS.
Sub-nodes as pointed out by Dmitry will allow us to show some love to
older platforms.
- Depends-on: https://lore.kernel.org/r/20260315-x1e-csi2-phy-v4-0-90c09203888d@linaro.org
- Link to v9: https://lore.kernel.org/r/20260226-b4-linux-next-25-03-13-dtsi-x1e80100-camss-v9-0-a59c3f037d0b@linaro.org
v9:
- Adds phy handles as optional nodes
- Adds minItems: 5 for iommu entries
I believe this should be acceptable as maxItems: 8 continues
to be valid
- Makes CAMSS-level rails optional for x1e
Similarly I think this should be OK as the legacy binding
is still valid it is simply optional instead of mandatory now
- Supports CSIPHY nodes adjacent to CAMSS while leaving
csiphy regs intact.
- Pushes dtsi drop to another series everything in this series
can go through linux-media
- Depends-on: https://lore.kernel.org/r/20260226-x1e-csi2-phy-v3-0-11e608759410@linaro.org
- Link to v8: https://lore.kernel.org/r/20260225-b4-linux-next-25-03-13-dtsi-x1e80100-camss-v8-0-95517393bcb2@linaro.org
v8:
- This version rebases on latest media-committers/next - bod
- Adds support for "combo-mode" PHYs in the YAML.
It will be possible to build out the code to support this later - Vlad
- Maintains the upstream model of connecting sensors to CSI decoders.
Every other upstream implementation does it this way so
CAMSS will do it this way too.
- Reduces the number of IOMMU entires in CAMSS to those required for
CSID, VFE/RDI/PIX respectively.
Including all of the IOMMUs implies we will also "stuff" CAMSS
with ever increasing lists of registers but a better approach
is to have individual nodes for functional blocks.
For example this series supports CSIPHy as a separate block
CCI is already a separate block - and we will add ICP, BPS, IPE
etc as additional standalone nodes.
camss@someaddr {
//existing bindings vfe, csid, csiphy go here
iommus = <just what's needed for this>;
};
bps@some_other_address {
iommus = <bps specific iommus>;
}
In particular this model will save us from going down the same
path as the vpu which has ended up tripping over the total size
an iommu entry may span.
Nobody really likes the legacy binding much so instead of
continuing to bludgeon more entries into it, I've conciously
not included BPS, IPE, ICP etc.
Depends-on: https://lore.kernel.org/r/20260225-x1e-csi2-phy-v2-0-7756edb67ea9@linaro.org
Link to v7: https://lore.kernel.org/r/20250711-b4-linux-next-25-03-13-dtsi-x1e80100-camss-v7-0-0bc5da82f526@linaro.org
Working tree: https://gitlab.com/Linaro/arm64-laptops/linux/-/tree/qcom-laptops-v6.19-rc8-camss?ref_type=heads
v7:
- Reimagine the PHYs as individual nodes.
A v1 of the schmea and driver for the CSI PHY has been published with
some review feedback from Rob Herring and Konrad Dybcio
https://lore.kernel.org/r/20250710-x1e-csi2-phy-v1-0-74acbb5b162b@linaro.org
Both the clock name changes from Rob and OPP changes suggested by Konrad
are _not_ yet present in this submission however stipulating to those
changes, I think publishing this v7 of the CAMSS/DT changes is warranted.
Its important to publish a whole view of changes for reviewers without
necessarily munging everything together in one sprawling series.
TL;DR I moved the PHY driver to its own series review comments there
are not reflected here yet but "shouldn't" have a big impact here.
- Having separate nodes in the DT for the PHYS allows for switching on PHYs
as we do for just about every other PHYs.
&csiphyX {
status = "okay";
};
We just list phys = <> in the core dtsi and enable the PHYs we want in
the platform dts.
- The level of code change in CAMSS itself turns out to be quite small.
Adding the PHY structure to the CSIPHY device
Differentiating the existing camss.c -> camss-csiphy.c init functions
A few new function pointers to facilitate parallel support of legacy
and new PHY interfaces.
- A key goal of this updated series is both to introduce a new PHY method
to CAMSS but to do it _only_ for a new SoC while taking care to ensure
that legacy CAMSS-PHY and legacy DT ABI continues to work.
This is a key point coming from the DT people which I've slowly imbibed
and hopefully succeeded in implementing.
- In addition to the CRD both T14s and Slim7x are supported.
I have the Inspirion14 working and the XPS but since we haven't landed
the Inspirion upstream yet, I've chosen to hold off on the XPS too.
- There is another proposal on the list to make PHY devices as sub-devices
I believe having those separate like most of our other PHYs
is the more appropriate way to go.
Similarly there is less code change to the CAMSS driver with this change.
Finally I believe we should contine to have endpoints go from the sensor
to CAMSS not the PHY as CAMSS' CSI decoder is the consumer of the data
not the PHY.
- Working tree: https://git.codelinaro.org/bryan.odonoghue/kernel/-/tree/x1e80100-6.16-rcX-dell-inspiron14-camss-ov02c10-ov02e10-audio-iris-phy-v3
- Link to v6: https://lore.kernel.org/r/20250314-b4-linux-next-25-03-13-dtsi-x1e80100-camss-v6-0-edcb2cfc3122@linaro.org
v6:
- Removes 'A phandle to an OPP node describing' per Krzysztof's comment
on patch #1
- Drops Fixes: from patch #1 - Krzysztof
- The ordering of opp description MXC and MMXC is kept as it matches the
power-domain ordering - Krzysztof/bod
- Link to v5: https://lore.kernel.org/r/20250313-b4-linux-next-25-03-13-dtsi-x1e80100-camss-v5-0-846c9a6493a8@linaro.org
v5:
- Picks up a Fixes: that is a valid precursor for this series - Vlad
- Applies RB from Vlad
- Drops "cam" prefix in interconnect names - Krzysztof/Vlad
- Amends sorting of regs, clocks consistent with recent 8550 - Depeng/Vlad
- Link to v4: https://lore.kernel.org/r/20250119-b4-linux-next-24-11-18-dtsi-x1e80100-camss-v4-0-c2964504131c@linaro.org
v4:
- Applies RB from Konrad
- Adds the second CCI I2C bus to CCI commit log description.
I previously considered leaving out the always on pins but, decided
to include them in the end and forgot to align the commit log.
- Alphabetises the camcc.h included in the dtsi. - Vlad
- Link to v3: https://lore.kernel.org/r/20250102-b4-linux-next-24-11-18-dtsi-x1e80100-camss-v3-0-cb66d55d20cc@linaro.org
v3:
- Fixes ordering of headers in dtsi - Vlad
- Changes camcc to always on - Vlad
- Applies RB as indicated - Krzysztof, Konrad
- Link to v2: https://lore.kernel.org/r/20241227-b4-linux-next-24-11-18-dtsi-x1e80100-camss-v2-0-06fdd5a7d5bb@linaro.org
v2:
I've gone through each comment and implemented each suggestion since IMO
they were all good/correct comments.
Detail:
- Moves x1e80100 camcc to its own yaml - Krzysztof
- csid_wrapper comes first because it is the most relevant
register set - configuring all CSID blocks subordinate to it - bod, Krzysztof
- Fixes missing commit log - Krz
- Updates to latest format established @ sc7280 - bod
- Includes CSID lite which I forgot to add @ v1 - Konrad, bod
- Replaces static ICC parameters with defines - Konrad
- Drops newlines between x and x-name - Konrad
- Drops redundant iommu extents - Konrad
- Leaves CAMERA_AHB_CLK as-is - Kronrad, Dmitry
Link: https://lore.kernel.org/r/3f1a960f-062e-4c29-ae7d-126192f35a8b@oss.qualcomm.com
- Interrupt EDGE_RISING - Vladimir
- Implements suggested regulator names pending refactor to PHY API - Vladimir
- Drop slow_ahb_src clock - Vladimir
Link to v1:
https://lore.kernel.org/r/20241119-b4-linux-next-24-11-18-dtsi-x1e80100-camss-v1-0-54075d75f654@linaro.org
Working tree:
https://git.codelinaro.org/bryan.odonoghue/kernel/-/tree/arm-laptop/wip/x1e80100-6.13-rc3
v1:
This series adds dt-bindings and dtsi for CAMSS on x1e80100.
The primary difference between x1e80100 and other platforms is a new VFE
and CSID pair at version 680.
Some minor driver churn will be required to support outside of the new VFE
and CSID blocks but nothing too major.
The CAMCC in this silicon requires two, not one power-domain requiring
either this fix I've proposed here or something similar:
https://lore.kernel.org/linux-arm-msm/bad60452-41b3-42fb-acba-5b7226226d2d@linaro.org/T/#t
That doesn't gate adoption of the binding description though.
A working tree in progress can be found here:
https://git.codelinaro.org/bryan.odonoghue/kernel/-/tree/x1e80100-6.12-rc7+camss?ref_type=heads
Signed-off-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
---
Bryan O'Donoghue (4):
phy: core: Fix use-after-free in phy_get paths
phy: core: Add phy_get_by_of_node()
phy: core: Add devm_phy_get_by_of_node()
media: qcom: camss: Add support for PHY API devices
drivers/media/platform/qcom/camss/Kconfig | 1 +
drivers/media/platform/qcom/camss/camss-csiphy.c | 177 +++++++++++++++++++++--
drivers/media/platform/qcom/camss/camss-csiphy.h | 11 +-
drivers/media/platform/qcom/camss/camss.c | 104 +++++++++++--
drivers/media/platform/qcom/camss/camss.h | 1 +
drivers/phy/phy-core.c | 166 ++++++++++++++++-----
include/linux/phy/phy.h | 13 ++
7 files changed, 405 insertions(+), 68 deletions(-)
---
base-commit: 2e41fb778334db3d260c52c6be4c4d44fbed87ac
change-id: 20250313-b4-linux-next-25-03-13-dtsi-x1e80100-camss-1506f74bbd3a
Best regards,
--
Bryan O'Donoghue <bryan.odonoghue@linaro.org>
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH v14 1/4] phy: core: Fix use-after-free in phy_get paths
2026-09-03 22:59 [PATCH v14 0/4] Add phy_get_by_of_node and devm helper Bryan O'Donoghue
@ 2026-09-03 22:59 ` Bryan O'Donoghue
2026-09-04 7:45 ` Loic Poulain
2026-09-03 22:59 ` [PATCH v14 2/4] phy: core: Add phy_get_by_of_node() Bryan O'Donoghue
` (2 subsequent siblings)
3 siblings, 1 reply; 8+ messages in thread
From: Bryan O'Donoghue @ 2026-09-03 22:59 UTC (permalink / raw)
To: Bjorn Andersson, Michael Turquette, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley, Robert Foss, Todor Tomov,
Mauro Carvalho Chehab, Konrad Dybcio, Vladimir Zapolskiy,
Bryan O'Donoghue, Loic Poulain, Vinod Koul, Neil Armstrong,
Greg Kroah-Hartman, Kishon Vijay Abraham I, Felipe Balbi
Cc: linux-arm-msm, linux-clk, devicetree, linux-kernel, linux-media,
linux-phy, Bryan O'Donoghue, Krzysztof Kozlowski, stable
Sashiko asked during a patch review if the existing usage pattern had a
race condition; specifically in of_phy_get() if it was possible between
returning from _of_phy_get() and running try_module_get() that a module
might be unbound leading to use-after-free.
Looking at the code this appears to be so, there is no linkage between the
phy and module under a synchronisation primitive.
Using the phy_provider_mutex in phy_get() will ensure there is a link between
the returned phy pointer and the module_get() bumping the module reference
count.
Amend phy_get(), of_phy_get() and devm_of_phy_get_by_index() to fix the
same usage pattern.
phy_provider_unregister() must take the phy_provider_mutex so amending
phy_get()/of_phy_get() to take that same mutex guarantees there is no
use-after-free.
Fixes: ff764963479a1 ("drivers: phy: add generic PHY framework")
Cc: stable@vger.kernel.org
Signed-off-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
---
drivers/phy/phy-core.c | 41 ++++++++++++++++++++++++++---------------
1 file changed, 26 insertions(+), 15 deletions(-)
diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c
index 21aaf2f76e53e..cd9ace125567a 100644
--- a/drivers/phy/phy-core.c
+++ b/drivers/phy/phy-core.c
@@ -124,13 +124,11 @@ static struct phy *phy_find(struct device *dev, const char *con_id)
const char *dev_id = dev_name(dev);
struct phy_lookup *p, *pl = NULL;
- mutex_lock(&phy_provider_mutex);
list_for_each_entry(p, &phys, node)
if (!strcmp(p->dev_id, dev_id) && !strcmp(p->con_id, con_id)) {
pl = p;
break;
}
- mutex_unlock(&phy_provider_mutex);
return pl ? pl->phy : ERR_PTR(-ENODEV);
}
@@ -635,11 +633,10 @@ static struct phy *_of_phy_get(struct device_node *np, int index)
goto out_put_node;
}
- mutex_lock(&phy_provider_mutex);
phy_provider = of_phy_provider_lookup(args.np);
if (IS_ERR(phy_provider) || !try_module_get(phy_provider->owner)) {
phy = ERR_PTR(-EPROBE_DEFER);
- goto out_unlock;
+ goto out_put_node;
}
if (!of_device_is_available(args.np)) {
@@ -653,8 +650,6 @@ static struct phy *_of_phy_get(struct device_node *np, int index)
out_put_module:
module_put(phy_provider->owner);
-out_unlock:
- mutex_unlock(&phy_provider_mutex);
out_put_node:
of_node_put(args.np);
@@ -678,15 +673,21 @@ struct phy *of_phy_get(struct device_node *np, const char *con_id)
if (con_id)
index = of_property_match_string(np, "phy-names", con_id);
+ mutex_lock(&phy_provider_mutex);
+
phy = _of_phy_get(np, index);
if (IS_ERR(phy))
- return phy;
+ goto out_unlock;
- if (!try_module_get(phy->ops->owner))
- return ERR_PTR(-EPROBE_DEFER);
+ if (!try_module_get(phy->ops->owner)) {
+ phy = ERR_PTR(-EPROBE_DEFER);
+ goto out_unlock;
+ }
get_device(&phy->dev);
+out_unlock:
+ mutex_unlock(&phy_provider_mutex);
return phy;
}
EXPORT_SYMBOL_GPL(of_phy_get);
@@ -786,6 +787,7 @@ struct phy *phy_get(struct device *dev, const char *string)
struct phy *phy;
struct device_link *link;
+ mutex_lock(&phy_provider_mutex);
if (dev->of_node) {
if (string)
index = of_property_match_string(dev->of_node, "phy-names",
@@ -796,15 +798,18 @@ struct phy *phy_get(struct device *dev, const char *string)
} else {
if (string == NULL) {
dev_WARN(dev, "missing string\n");
- return ERR_PTR(-EINVAL);
+ phy = ERR_PTR(-EINVAL);
+ goto out_unlock;
}
phy = phy_find(dev, string);
}
if (IS_ERR(phy))
- return phy;
+ goto out_unlock;
- if (!try_module_get(phy->ops->owner))
- return ERR_PTR(-EPROBE_DEFER);
+ if (!try_module_get(phy->ops->owner)) {
+ phy = ERR_PTR(-EPROBE_DEFER);
+ goto out_unlock;
+ }
get_device(&phy->dev);
@@ -813,6 +818,8 @@ struct phy *phy_get(struct device *dev, const char *string)
dev_dbg(dev, "failed to create device link to %s\n",
dev_name(phy->dev.parent));
+out_unlock:
+ mutex_unlock(&phy_provider_mutex);
return phy;
}
EXPORT_SYMBOL_GPL(phy_get);
@@ -961,15 +968,17 @@ struct phy *devm_of_phy_get_by_index(struct device *dev, struct device_node *np,
if (!ptr)
return ERR_PTR(-ENOMEM);
+ mutex_lock(&phy_provider_mutex);
phy = _of_phy_get(np, index);
if (IS_ERR(phy)) {
devres_free(ptr);
- return phy;
+ goto out_unlock;
}
if (!try_module_get(phy->ops->owner)) {
devres_free(ptr);
- return ERR_PTR(-EPROBE_DEFER);
+ phy = ERR_PTR(-EPROBE_DEFER);
+ goto out_unlock;
}
get_device(&phy->dev);
@@ -982,6 +991,8 @@ struct phy *devm_of_phy_get_by_index(struct device *dev, struct device_node *np,
dev_dbg(dev, "failed to create device link to %s\n",
dev_name(phy->dev.parent));
+out_unlock:
+ mutex_unlock(&phy_provider_mutex);
return phy;
}
EXPORT_SYMBOL_GPL(devm_of_phy_get_by_index);
--
2.55.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [PATCH v14 2/4] phy: core: Add phy_get_by_of_node()
2026-09-03 22:59 [PATCH v14 0/4] Add phy_get_by_of_node and devm helper Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 1/4] phy: core: Fix use-after-free in phy_get paths Bryan O'Donoghue
@ 2026-09-03 22:59 ` Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 3/4] phy: core: Add devm_phy_get_by_of_node() Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 4/4] media: qcom: camss: Add support for PHY API devices Bryan O'Donoghue
3 siblings, 0 replies; 8+ messages in thread
From: Bryan O'Donoghue @ 2026-09-03 22:59 UTC (permalink / raw)
To: Bjorn Andersson, Michael Turquette, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley, Robert Foss, Todor Tomov,
Mauro Carvalho Chehab, Konrad Dybcio, Vladimir Zapolskiy,
Bryan O'Donoghue, Loic Poulain, Vinod Koul, Neil Armstrong,
Greg Kroah-Hartman, Kishon Vijay Abraham I, Felipe Balbi
Cc: linux-arm-msm, linux-clk, devicetree, linux-kernel, linux-media,
linux-phy, Bryan O'Donoghue, Krzysztof Kozlowski
Add new function phy_get_by_of_node() allowing lookup of a phy by
device_node. Separates existing logic in _of_phy_get() into an internal
helper method _of_phy_get_with_args() to allow for reuse in new method.
Signed-off-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
---
drivers/phy/phy-core.c | 93 +++++++++++++++++++++++++++++++++++++------------
include/linux/phy/phy.h | 6 ++++
2 files changed, 76 insertions(+), 23 deletions(-)
diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c
index cd9ace125567a..1d060bc22d02c 100644
--- a/drivers/phy/phy-core.c
+++ b/drivers/phy/phy-core.c
@@ -604,22 +604,49 @@ int phy_validate(struct phy *phy, enum phy_mode mode, int submode,
}
EXPORT_SYMBOL_GPL(phy_validate);
+/**
+ * _of_phy_get_with_args() - lookup and obtain a reference to a phy by of_phandle_args
+ * @args: of_phandle_args to the phy
+ *
+ * Returns the phy from the provider's of_xlate, -ENODEV if disabled,
+ * -EPROBE_DEFER if the provider is not yet registered.
+ */
+static struct phy *_of_phy_get_with_args(struct of_phandle_args *args)
+{
+ struct phy *phy;
+ struct phy_provider *phy_provider;
+
+ phy_provider = of_phy_provider_lookup(args->np);
+ if (IS_ERR(phy_provider) || !try_module_get(phy_provider->owner))
+ return ERR_PTR(-EPROBE_DEFER);
+
+ if (!of_device_is_available(args->np)) {
+ dev_warn(phy_provider->dev, "Requested PHY is disabled\n");
+ phy = ERR_PTR(-ENODEV);
+ goto out_put_module;
+ }
+
+ phy = phy_provider->of_xlate(phy_provider->dev, args);
+
+out_put_module:
+ module_put(phy_provider->owner);
+
+ return phy;
+}
+
/**
* _of_phy_get() - lookup and obtain a reference to a phy by phandle
* @np: device_node for which to get the phy
* @index: the index of the phy
*
- * Returns the phy associated with the given phandle value,
- * after getting a refcount to it or -ENODEV if there is no such phy or
- * -EPROBE_DEFER if there is a phandle to the phy, but the device is
- * not yet loaded. This function uses of_xlate call back function provided
- * while registering the phy_provider to find the phy instance.
+ * Returns the phy associated with the given phandle value after getting
+ * a refcount to it; -ENODEV if there is no such phy or the phy is
+ * disabled; -EPROBE_DEFER if the phy provider is not yet available.
*/
static struct phy *_of_phy_get(struct device_node *np, int index)
{
int ret;
- struct phy_provider *phy_provider;
- struct phy *phy = NULL;
+ struct phy *phy;
struct of_phandle_args args;
ret = of_parse_phandle_with_args(np, "phys", "#phy-cells",
@@ -633,22 +660,7 @@ static struct phy *_of_phy_get(struct device_node *np, int index)
goto out_put_node;
}
- phy_provider = of_phy_provider_lookup(args.np);
- if (IS_ERR(phy_provider) || !try_module_get(phy_provider->owner)) {
- phy = ERR_PTR(-EPROBE_DEFER);
- goto out_put_node;
- }
-
- if (!of_device_is_available(args.np)) {
- dev_warn(phy_provider->dev, "Requested PHY is disabled\n");
- phy = ERR_PTR(-ENODEV);
- goto out_put_module;
- }
-
- phy = phy_provider->of_xlate(phy_provider->dev, &args);
-
-out_put_module:
- module_put(phy_provider->owner);
+ phy = _of_phy_get_with_args(&args);
out_put_node:
of_node_put(args.np);
@@ -997,6 +1009,41 @@ struct phy *devm_of_phy_get_by_index(struct device *dev, struct device_node *np,
}
EXPORT_SYMBOL_GPL(devm_of_phy_get_by_index);
+/**
+ * phy_get_by_of_node() - lookup and obtain a reference to a phy by device_node
+ * @np: node containing the phy
+ *
+ * Returns the phy associated with the device node or ERR_PTR.
+ */
+struct phy *phy_get_by_of_node(struct device_node *np)
+{
+ struct of_phandle_args args = { .np = np, .args_count = 0 };
+ struct phy *phy;
+
+ if (!np)
+ return ERR_PTR(-EINVAL);
+
+ mutex_lock(&phy_provider_mutex);
+
+ phy = _of_phy_get_with_args(&args);
+
+ if (IS_ERR(phy))
+ goto out_unlock;
+
+ if (!try_module_get(phy->ops->owner)) {
+ phy = ERR_PTR(-EPROBE_DEFER);
+ goto out_unlock;
+ }
+
+ get_device(&phy->dev);
+
+out_unlock:
+ mutex_unlock(&phy_provider_mutex);
+
+ return phy;
+}
+EXPORT_SYMBOL_GPL(phy_get_by_of_node);
+
/**
* phy_create() - create a new phy
* @dev: device that is creating the new phy
diff --git a/include/linux/phy/phy.h b/include/linux/phy/phy.h
index ea47975e288ae..71c2e16397130 100644
--- a/include/linux/phy/phy.h
+++ b/include/linux/phy/phy.h
@@ -284,6 +284,7 @@ struct phy *devm_of_phy_optional_get(struct device *dev, struct device_node *np,
const char *con_id);
struct phy *devm_of_phy_get_by_index(struct device *dev, struct device_node *np,
int index);
+struct phy *phy_get_by_of_node(struct device_node *np);
void of_phy_put(struct phy *phy);
void phy_put(struct device *dev, struct phy *phy);
void devm_phy_put(struct device *dev, struct phy *phy);
@@ -493,6 +494,11 @@ static inline struct phy *devm_of_phy_get_by_index(struct device *dev,
return ERR_PTR(-ENOSYS);
}
+static inline struct phy *phy_get_by_of_node(struct device_node *np)
+{
+ return ERR_PTR(-ENOSYS);
+}
+
static inline void of_phy_put(struct phy *phy)
{
}
--
2.55.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [PATCH v14 3/4] phy: core: Add devm_phy_get_by_of_node()
2026-09-03 22:59 [PATCH v14 0/4] Add phy_get_by_of_node and devm helper Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 1/4] phy: core: Fix use-after-free in phy_get paths Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 2/4] phy: core: Add phy_get_by_of_node() Bryan O'Donoghue
@ 2026-09-03 22:59 ` Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 4/4] media: qcom: camss: Add support for PHY API devices Bryan O'Donoghue
3 siblings, 0 replies; 8+ messages in thread
From: Bryan O'Donoghue @ 2026-09-03 22:59 UTC (permalink / raw)
To: Bjorn Andersson, Michael Turquette, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley, Robert Foss, Todor Tomov,
Mauro Carvalho Chehab, Konrad Dybcio, Vladimir Zapolskiy,
Bryan O'Donoghue, Loic Poulain, Vinod Koul, Neil Armstrong,
Greg Kroah-Hartman, Kishon Vijay Abraham I, Felipe Balbi
Cc: linux-arm-msm, linux-clk, devicetree, linux-kernel, linux-media,
linux-phy, Bryan O'Donoghue, Krzysztof Kozlowski
Add a devm variant of phy_get_by_of_node() to allow for the familiar
pattern of having devres automatically release resources on the driver's
exit path.
Signed-off-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
---
drivers/phy/phy-core.c | 34 ++++++++++++++++++++++++++++++++++
include/linux/phy/phy.h | 7 +++++++
2 files changed, 41 insertions(+)
diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c
index 1d060bc22d02c..1316cd477bcba 100644
--- a/drivers/phy/phy-core.c
+++ b/drivers/phy/phy-core.c
@@ -1044,6 +1044,40 @@ struct phy *phy_get_by_of_node(struct device_node *np)
}
EXPORT_SYMBOL_GPL(phy_get_by_of_node);
+/**
+ * devm_phy_get_by_of_node() - devm managed lookup and obtain phy reference by device node
+ * @dev: device requesting the PHY
+ * @np: device_node of the PHY provider
+ *
+ * Returns phy associated with the device_node or ERR_PTR. devres manages
+ * releasing resources.
+ */
+struct phy *devm_phy_get_by_of_node(struct device *dev, struct device_node *np)
+{
+ struct phy **ptr, *phy;
+ struct device_link *link;
+
+ ptr = devres_alloc(devm_phy_release, sizeof(*ptr), GFP_KERNEL);
+ if (!ptr)
+ return ERR_PTR(-ENOMEM);
+
+ phy = phy_get_by_of_node(np);
+ if (IS_ERR(phy)) {
+ devres_free(ptr);
+ return phy;
+ }
+
+ *ptr = phy;
+ devres_add(dev, ptr);
+ link = device_link_add(dev, &phy->dev, DL_FLAG_STATELESS);
+ if (!link)
+ dev_dbg(dev, "failed to create device link to %s\n",
+ dev_name(phy->dev.parent));
+
+ return phy;
+}
+EXPORT_SYMBOL_GPL(devm_phy_get_by_of_node);
+
/**
* phy_create() - create a new phy
* @dev: device that is creating the new phy
diff --git a/include/linux/phy/phy.h b/include/linux/phy/phy.h
index 71c2e16397130..14b924a88411f 100644
--- a/include/linux/phy/phy.h
+++ b/include/linux/phy/phy.h
@@ -285,6 +285,7 @@ struct phy *devm_of_phy_optional_get(struct device *dev, struct device_node *np,
struct phy *devm_of_phy_get_by_index(struct device *dev, struct device_node *np,
int index);
struct phy *phy_get_by_of_node(struct device_node *np);
+struct phy *devm_phy_get_by_of_node(struct device *dev, struct device_node *np);
void of_phy_put(struct phy *phy);
void phy_put(struct device *dev, struct phy *phy);
void devm_phy_put(struct device *dev, struct phy *phy);
@@ -499,6 +500,12 @@ static inline struct phy *phy_get_by_of_node(struct device_node *np)
return ERR_PTR(-ENOSYS);
}
+static inline struct phy *devm_phy_get_by_of_node(struct device *dev,
+ struct device_node *np)
+{
+ return ERR_PTR(-ENOSYS);
+}
+
static inline void of_phy_put(struct phy *phy)
{
}
--
2.55.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [PATCH v14 4/4] media: qcom: camss: Add support for PHY API devices
2026-09-03 22:59 [PATCH v14 0/4] Add phy_get_by_of_node and devm helper Bryan O'Donoghue
` (2 preceding siblings ...)
2026-09-03 22:59 ` [PATCH v14 3/4] phy: core: Add devm_phy_get_by_of_node() Bryan O'Donoghue
@ 2026-09-03 22:59 ` Bryan O'Donoghue
3 siblings, 0 replies; 8+ messages in thread
From: Bryan O'Donoghue @ 2026-09-03 22:59 UTC (permalink / raw)
To: Bjorn Andersson, Michael Turquette, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley, Robert Foss, Todor Tomov,
Mauro Carvalho Chehab, Konrad Dybcio, Vladimir Zapolskiy,
Bryan O'Donoghue, Loic Poulain, Vinod Koul, Neil Armstrong,
Greg Kroah-Hartman, Kishon Vijay Abraham I, Felipe Balbi
Cc: linux-arm-msm, linux-clk, devicetree, linux-kernel, linux-media,
linux-phy, Bryan O'Donoghue, Krzysztof Kozlowski
Add the ability to use a PHY pointer which interacts with the standard PHY
API.
In the first instance the code will try to use the new PHY interface. If no
PHYs are present in the DT then the legacy method will be attempted.
Signed-off-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
---
drivers/media/platform/qcom/camss/Kconfig | 1 +
drivers/media/platform/qcom/camss/camss-csiphy.c | 177 +++++++++++++++++++++--
drivers/media/platform/qcom/camss/camss-csiphy.h | 11 +-
drivers/media/platform/qcom/camss/camss.c | 104 +++++++++++--
drivers/media/platform/qcom/camss/camss.h | 1 +
5 files changed, 263 insertions(+), 31 deletions(-)
diff --git a/drivers/media/platform/qcom/camss/Kconfig b/drivers/media/platform/qcom/camss/Kconfig
index 4eda48cb1adf0..1edc5e5a1829e 100644
--- a/drivers/media/platform/qcom/camss/Kconfig
+++ b/drivers/media/platform/qcom/camss/Kconfig
@@ -7,3 +7,4 @@ config VIDEO_QCOM_CAMSS
select VIDEO_V4L2_SUBDEV_API
select VIDEOBUF2_DMA_SG
select V4L2_FWNODE
+ select PHY_QCOM_MIPI_CSI2
diff --git a/drivers/media/platform/qcom/camss/camss-csiphy.c b/drivers/media/platform/qcom/camss/camss-csiphy.c
index 539ac4888b608..e00748dd83b02 100644
--- a/drivers/media/platform/qcom/camss/camss-csiphy.c
+++ b/drivers/media/platform/qcom/camss/camss-csiphy.c
@@ -13,6 +13,8 @@
#include <linux/io.h>
#include <linux/kernel.h>
#include <linux/of.h>
+#include <linux/of_graph.h>
+#include <linux/phy/phy.h>
#include <linux/platform_device.h>
#include <linux/pm_runtime.h>
#include <media/media-entity.h>
@@ -131,10 +133,10 @@ static u8 csiphy_get_bpp(const struct csiphy_format_info *formats,
}
/*
- * csiphy_set_clock_rates - Calculate and set clock rates on CSIPHY module
+ * csiphy_set_clock_rates_legacy - Calculate and set clock rates on CSIPHY module
* @csiphy: CSIPHY device
*/
-static int csiphy_set_clock_rates(struct csiphy_device *csiphy)
+static int csiphy_set_clock_rates_legacy(struct csiphy_device *csiphy)
{
struct device *dev = csiphy->camss->dev;
s64 link_freq;
@@ -200,7 +202,7 @@ static int csiphy_set_clock_rates(struct csiphy_device *csiphy)
*
* Return 0 on success or a negative error code otherwise
*/
-static int csiphy_set_power(struct v4l2_subdev *sd, int on)
+static int csiphy_set_power_legacy(struct v4l2_subdev *sd, int on)
{
struct csiphy_device *csiphy = v4l2_get_subdevdata(sd);
struct device *dev = csiphy->camss->dev;
@@ -219,7 +221,7 @@ static int csiphy_set_power(struct v4l2_subdev *sd, int on)
return ret;
}
- ret = csiphy_set_clock_rates(csiphy);
+ ret = csiphy_set_clock_rates_legacy(csiphy);
if (ret < 0) {
regulator_bulk_disable(csiphy->num_supplies,
csiphy->supplies);
@@ -254,7 +256,7 @@ static int csiphy_set_power(struct v4l2_subdev *sd, int on)
}
/*
- * csiphy_stream_on - Enable streaming on CSIPHY module
+ * csiphy_stream_on_legacy - Enable streaming on CSIPHY module
* @csiphy: CSIPHY device
*
* Helper function to enable streaming on CSIPHY module.
@@ -262,7 +264,7 @@ static int csiphy_set_power(struct v4l2_subdev *sd, int on)
*
* Return 0 on success or a negative error code otherwise
*/
-static int csiphy_stream_on(struct csiphy_device *csiphy)
+static int csiphy_stream_on_legacy(struct csiphy_device *csiphy)
{
struct csiphy_config *cfg = &csiphy->cfg;
s64 link_freq;
@@ -306,11 +308,88 @@ static int csiphy_stream_on(struct csiphy_device *csiphy)
*
* Helper function to disable streaming on CSIPHY module
*/
-static void csiphy_stream_off(struct csiphy_device *csiphy)
+static void csiphy_stream_off_legacy(struct csiphy_device *csiphy)
{
csiphy->res->hw_ops->lanes_disable(csiphy, &csiphy->cfg);
}
+/*
+ * csiphy_stream_on - Enable streaming on CSIPHY module
+ * @csiphy: CSIPHY device
+ *
+ * Helper function to enable streaming on CSIPHY module.
+ * Main configuration of CSIPHY module is also done here.
+ *
+ * Return 0 on success or a negative error code otherwise
+ */
+static int csiphy_stream_on(struct csiphy_device *csiphy)
+{
+ u8 bpp = csiphy_get_bpp(csiphy->res->formats->formats, csiphy->res->formats->nformats,
+ csiphy->fmt[MSM_CSIPHY_PAD_SINK].code);
+ struct csiphy_lanes_cfg *lncfg = &csiphy->cfg.csi2->lane_cfg;
+ struct phy_configure_opts_mipi_dphy *dphy_cfg;
+ union phy_configure_opts dphy_opts = { 0 };
+ struct device *dev = csiphy->camss->dev;
+ u8 num_lanes = lncfg->num_data;
+ s64 link_freq;
+ int ret;
+
+ dphy_cfg = &dphy_opts.mipi_dphy;
+
+ link_freq = camss_get_link_freq(&csiphy->subdev.entity, bpp, num_lanes);
+
+ if (link_freq < 0) {
+ dev_err(dev,
+ "Cannot get CSI2 transmitter's link frequency\n");
+ return -EINVAL;
+ }
+
+ phy_mipi_dphy_get_default_config_for_hsclk(link_freq, num_lanes, dphy_cfg);
+
+ phy_set_mode(csiphy->phy, PHY_MODE_MIPI_DPHY);
+
+ ret = phy_configure(csiphy->phy, &dphy_opts);
+ if (ret) {
+ dev_err(dev, "failed to configure MIPI D-PHY\n");
+ goto error;
+ }
+
+ return phy_power_on(csiphy->phy);
+
+error:
+ return ret;
+}
+
+/*
+ * csiphy_stream_off - Disable streaming on CSIPHY module
+ * @csiphy: CSIPHY device
+ *
+ * Helper function to disable streaming on CSIPHY module
+ */
+static void csiphy_stream_off(struct csiphy_device *csiphy)
+{
+ phy_power_off(csiphy->phy);
+}
+
+/*
+ * csiphy_set_stream - Enable/disable streaming on CSIPHY module
+ * @sd: CSIPHY V4L2 subdevice
+ * @enable: Requested streaming state
+ *
+ * Return 0 on success or a negative error code otherwise
+ */
+static int csiphy_set_stream_legacy(struct v4l2_subdev *sd, int enable)
+{
+ struct csiphy_device *csiphy = v4l2_get_subdevdata(sd);
+ int ret = 0;
+
+ if (enable)
+ ret = csiphy_stream_on_legacy(csiphy);
+ else
+ csiphy_stream_off_legacy(csiphy);
+
+ return ret;
+}
/*
* csiphy_set_stream - Enable/disable streaming on CSIPHY module
@@ -572,16 +651,16 @@ csiphy_match_clock_name(const char *clock_name, const char *format, ...)
}
/*
- * msm_csiphy_subdev_init - Initialize CSIPHY device structure and resources
+ * msm_csiphy_subdev_init_legacy - Initialize CSIPHY device structure and resources
* @csiphy: CSIPHY device
* @res: CSIPHY module resources table
* @id: CSIPHY module id
*
* Return 0 on success or a negative error code otherwise
*/
-int msm_csiphy_subdev_init(struct camss *camss,
- struct csiphy_device *csiphy,
- const struct camss_subdev_resources *res, u8 id)
+int msm_csiphy_subdev_init_legacy(struct camss *camss,
+ struct csiphy_device *csiphy,
+ const struct camss_subdev_resources *res, u8 id)
{
struct device *dev = camss->dev;
struct platform_device *pdev = to_platform_device(dev);
@@ -709,6 +788,56 @@ int msm_csiphy_subdev_init(struct camss *camss,
return ret;
}
+/*
+ * msm_csiphy_subdev_init - Initialize CSIPHY device structure and resources
+ * @camss: CAMSS structure
+ * @port: DT port index
+ *
+ * Return 0 on success or absence of link, negative error code otherwise
+ */
+int msm_csiphy_subdev_init(struct camss *camss, u8 port)
+{
+ const struct camss_subdev_resources *res = &camss->res->csiphy_res[port];
+ struct csiphy_device *csiphy = &camss->csiphy[port];
+ struct device *dev = camss->dev;
+ struct device_node *ep, *remote;
+ int ret;
+
+ ep = of_graph_get_endpoint_by_regs(dev->of_node, port, -1);
+ if (!ep)
+ return 0;
+
+ remote = of_graph_get_remote_port_parent(ep);
+ of_node_put(ep);
+ if (!remote)
+ return 0;
+
+ if (!of_device_is_available(remote)) {
+ of_node_put(remote);
+ return 0;
+ }
+
+ csiphy->phy = devm_phy_get_by_of_node(dev, remote);
+ of_node_put(remote);
+ if (IS_ERR(csiphy->phy)) {
+ ret = PTR_ERR(csiphy->phy);
+ goto done;
+ }
+
+ csiphy->camss = camss;
+ csiphy->id = res->csiphy.id;
+ csiphy->res = &res->csiphy;
+
+ snprintf(csiphy->name, ARRAY_SIZE(csiphy->name), "csi%d", csiphy->id);
+
+ ret = phy_init(csiphy->phy);
+ if (ret)
+ dev_err(dev, "%s init fail %d\n", csiphy->name, ret);
+
+done:
+ return ret;
+}
+
/*
* csiphy_link_setup - Setup CSIPHY connections
* @entity: Pointer to media entity structure
@@ -743,8 +872,12 @@ static int csiphy_link_setup(struct media_entity *entity,
return 0;
}
-static const struct v4l2_subdev_core_ops csiphy_core_ops = {
- .s_power = csiphy_set_power,
+static const struct v4l2_subdev_core_ops csiphy_core_ops_legacy = {
+ .s_power = csiphy_set_power_legacy,
+};
+
+static const struct v4l2_subdev_video_ops csiphy_video_ops_legacy = {
+ .s_stream = csiphy_set_stream_legacy,
};
static const struct v4l2_subdev_video_ops csiphy_video_ops = {
@@ -758,8 +891,13 @@ static const struct v4l2_subdev_pad_ops csiphy_pad_ops = {
.set_fmt = csiphy_set_format,
};
+static const struct v4l2_subdev_ops csiphy_v4l2_ops_legacy = {
+ .core = &csiphy_core_ops_legacy,
+ .video = &csiphy_video_ops_legacy,
+ .pad = &csiphy_pad_ops,
+};
+
static const struct v4l2_subdev_ops csiphy_v4l2_ops = {
- .core = &csiphy_core_ops,
.video = &csiphy_video_ops,
.pad = &csiphy_pad_ops,
};
@@ -785,10 +923,15 @@ int msm_csiphy_register_entity(struct csiphy_device *csiphy,
{
struct v4l2_subdev *sd = &csiphy->subdev;
struct media_pad *pads = csiphy->pads;
- struct device *dev = csiphy->camss->dev;
+ struct camss *camss = csiphy->camss;
+ struct device *dev = camss->dev;
int ret;
- v4l2_subdev_init(sd, &csiphy_v4l2_ops);
+ if (camss->legacy_phy)
+ v4l2_subdev_init(sd, &csiphy_v4l2_ops_legacy);
+ else
+ v4l2_subdev_init(sd, &csiphy_v4l2_ops);
+
sd->internal_ops = &csiphy_v4l2_internal_ops;
sd->flags |= V4L2_SUBDEV_FL_HAS_DEVNODE;
snprintf(sd->name, ARRAY_SIZE(sd->name), "%s%d",
@@ -828,6 +971,8 @@ int msm_csiphy_register_entity(struct csiphy_device *csiphy,
*/
void msm_csiphy_unregister_entity(struct csiphy_device *csiphy)
{
+ if (!IS_ERR(csiphy->phy))
+ phy_exit(csiphy->phy);
v4l2_device_unregister_subdev(&csiphy->subdev);
media_entity_cleanup(&csiphy->subdev.entity);
}
diff --git a/drivers/media/platform/qcom/camss/camss-csiphy.h b/drivers/media/platform/qcom/camss/camss-csiphy.h
index 9d9657b82f748..7a357044b9fdb 100644
--- a/drivers/media/platform/qcom/camss/camss-csiphy.h
+++ b/drivers/media/platform/qcom/camss/camss-csiphy.h
@@ -12,6 +12,7 @@
#include <linux/clk.h>
#include <linux/interrupt.h>
+#include <linux/phy/phy.h>
#include <media/media-entity.h>
#include <media/v4l2-device.h>
#include <media/v4l2-mediabus.h>
@@ -97,6 +98,7 @@ struct csiphy_device_regs {
struct csiphy_device {
struct camss *camss;
+ struct phy *phy;
u8 id;
struct v4l2_subdev subdev;
struct media_pad pads[MSM_CSIPHY_PADS_NUM];
@@ -104,6 +106,7 @@ struct csiphy_device {
void __iomem *base_clk_mux;
u32 irq;
char irq_name[30];
+ char name[16];
struct camss_clock *clock;
bool *rate_set;
int nclocks;
@@ -118,9 +121,11 @@ struct csiphy_device {
struct camss_subdev_resources;
-int msm_csiphy_subdev_init(struct camss *camss,
- struct csiphy_device *csiphy,
- const struct camss_subdev_resources *res, u8 id);
+int msm_csiphy_subdev_init_legacy(struct camss *camss,
+ struct csiphy_device *csiphy,
+ const struct camss_subdev_resources *res, u8 id);
+
+int msm_csiphy_subdev_init(struct camss *camss, u8 port);
int msm_csiphy_register_entity(struct csiphy_device *csiphy,
struct v4l2_device *v4l2_dev);
diff --git a/drivers/media/platform/qcom/camss/camss.c b/drivers/media/platform/qcom/camss/camss.c
index 2123f6388e3d7..84097d82d99c9 100644
--- a/drivers/media/platform/qcom/camss/camss.c
+++ b/drivers/media/platform/qcom/camss/camss.c
@@ -4799,8 +4799,43 @@ static int camss_parse_ports(struct camss *camss)
fwnode_graph_for_each_endpoint(fwnode, ep) {
struct camss_async_subdev *csd;
- csd = v4l2_async_nf_add_fwnode_remote(&camss->notifier, ep,
- typeof(*csd));
+ if (!fwnode_device_is_available(ep))
+ continue;
+
+ if (camss->legacy_phy) {
+ csd = v4l2_async_nf_add_fwnode_remote(&camss->notifier, ep,
+ typeof(*csd));
+ } else {
+ struct fwnode_handle *phy_out, *phy_node, *phy_in, *sensor_ep;
+
+ phy_out = fwnode_graph_get_remote_endpoint(ep);
+ if (!phy_out)
+ continue;
+
+ phy_node = fwnode_graph_get_port_parent(phy_out);
+ fwnode_handle_put(phy_out);
+ if (!phy_node)
+ continue;
+
+ phy_in = fwnode_graph_get_endpoint_by_id(phy_node, 0, 0, 0);
+ fwnode_handle_put(phy_node);
+ if (!phy_in)
+ continue;
+
+ sensor_ep = fwnode_graph_get_remote_endpoint(phy_in);
+ fwnode_handle_put(phy_in);
+ if (!sensor_ep)
+ continue;
+
+ csd = v4l2_async_nf_add_fwnode(&camss->notifier, sensor_ep,
+ struct camss_async_subdev);
+ fwnode_handle_put(sensor_ep);
+ if (IS_ERR(csd)) {
+ ret = PTR_ERR(csd);
+ goto err_cleanup;
+ }
+ }
+
if (IS_ERR(csd)) {
ret = PTR_ERR(csd);
goto err_cleanup;
@@ -4819,6 +4854,29 @@ static int camss_parse_ports(struct camss *camss)
return ret;
}
+static void camss_detect_legacy_phy(struct camss *camss)
+{
+ struct device_node *remote;
+ struct device_node *ep;
+
+ camss->legacy_phy = true;
+
+ /* Find first remote-endpoint and determine if its a PHY */
+ for_each_endpoint_of_node(camss->dev->of_node, ep) {
+ remote = of_graph_get_remote_port_parent(ep);
+ if (!remote)
+ continue;
+
+ camss->legacy_phy = !of_node_name_eq(remote, "phy");
+ of_node_put(remote);
+ of_node_put(ep);
+ break;
+ }
+
+ dev_dbg(camss->dev, "legacy phy mode %s\n",
+ camss->legacy_phy ? "true" : "false");
+}
+
/*
* camss_init_subdevices - Initialize subdev structures and resources
* @camss: CAMSS device
@@ -4832,14 +4890,21 @@ static int camss_init_subdevices(struct camss *camss)
unsigned int i;
int ret;
+ camss_detect_legacy_phy(camss);
+
for (i = 0; i < camss->res->csiphy_num; i++) {
- ret = msm_csiphy_subdev_init(camss, &camss->csiphy[i],
- &res->csiphy_res[i],
- res->csiphy_res[i].csiphy.id);
+ if (!camss->legacy_phy) {
+ ret = msm_csiphy_subdev_init(camss, i);
+ } else {
+ ret = msm_csiphy_subdev_init_legacy(camss,
+ &camss->csiphy[i],
+ &res->csiphy_res[i],
+ res->csiphy_res[i].csiphy.id);
+ }
+
if (ret < 0) {
- dev_err(camss->dev,
- "Failed to init csiphy%d sub-device: %d\n",
- i, ret);
+ dev_err(camss->dev, "csiphy %d init fail\n",
+ res->csiphy_res[i].csiphy.id);
return ret;
}
}
@@ -4917,6 +4982,11 @@ inline void camss_link_err(struct camss *camss,
ret);
}
+static inline bool csiphy_enabled(struct camss *camss, struct csiphy_device *c)
+{
+ return camss->legacy_phy || c->phy;
+}
+
/*
* camss_link_entities - Register subdev nodes and create links
* @camss: CAMSS device
@@ -4930,6 +5000,9 @@ static int camss_link_entities(struct camss *camss)
for (i = 0; i < camss->res->csiphy_num; i++) {
for (j = 0; j < camss->res->csid_num; j++) {
+ if (!csiphy_enabled(camss, &camss->csiphy[i]))
+ continue;
+
ret = media_create_pad_link(&camss->csiphy[i].subdev.entity,
MSM_CSIPHY_PAD_SRC,
&camss->csid[j].subdev.entity,
@@ -5056,6 +5129,9 @@ static int camss_register_entities(struct camss *camss)
int ret;
for (i = 0; i < camss->res->csiphy_num; i++) {
+ if (!csiphy_enabled(camss, &camss->csiphy[i]))
+ continue;
+
ret = msm_csiphy_register_entity(&camss->csiphy[i],
&camss->v4l2_dev);
if (ret < 0) {
@@ -5131,8 +5207,10 @@ static int camss_register_entities(struct camss *camss)
i = camss->res->csiphy_num;
err_reg_csiphy:
- for (i--; i >= 0; i--)
- msm_csiphy_unregister_entity(&camss->csiphy[i]);
+ for (i--; i >= 0; i--) {
+ if (csiphy_enabled(camss, &camss->csiphy[i]))
+ msm_csiphy_unregister_entity(&camss->csiphy[i]);
+ }
return ret;
}
@@ -5147,8 +5225,10 @@ static void camss_unregister_entities(struct camss *camss)
{
unsigned int i;
- for (i = 0; i < camss->res->csiphy_num; i++)
- msm_csiphy_unregister_entity(&camss->csiphy[i]);
+ for (i = 0; i < camss->res->csiphy_num; i++) {
+ if (csiphy_enabled(camss, &camss->csiphy[i]))
+ msm_csiphy_unregister_entity(&camss->csiphy[i]);
+ }
if (camss->tpg) {
for (i = 0; i < camss->res->tpg_num; i++)
diff --git a/drivers/media/platform/qcom/camss/camss.h b/drivers/media/platform/qcom/camss/camss.h
index 93d691c8ac63b..ba3d51d9c0bf8 100644
--- a/drivers/media/platform/qcom/camss/camss.h
+++ b/drivers/media/platform/qcom/camss/camss.h
@@ -138,6 +138,7 @@ struct camss {
struct device_link *genpd_link;
struct icc_path *icc_path[ICC_SM8250_COUNT];
const struct camss_resources *res;
+ bool legacy_phy;
};
struct camss_camera_interface {
--
2.55.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [PATCH v14 1/4] phy: core: Fix use-after-free in phy_get paths
2026-09-03 22:59 ` [PATCH v14 1/4] phy: core: Fix use-after-free in phy_get paths Bryan O'Donoghue
@ 2026-09-04 7:45 ` Loic Poulain
2026-09-04 9:41 ` Bryan O'Donoghue
0 siblings, 1 reply; 8+ messages in thread
From: Loic Poulain @ 2026-09-04 7:45 UTC (permalink / raw)
To: Bryan O'Donoghue
Cc: Bjorn Andersson, Michael Turquette, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley, Robert Foss, Todor Tomov,
Mauro Carvalho Chehab, Konrad Dybcio, Vladimir Zapolskiy,
Bryan O'Donoghue, Vinod Koul, Neil Armstrong,
Greg Kroah-Hartman, Kishon Vijay Abraham I, Felipe Balbi,
linux-arm-msm, linux-clk, devicetree, linux-kernel, linux-media,
linux-phy, Krzysztof Kozlowski, stable
Hi Bryan,
On Fri, Sep 4, 2026 at 12:59 AM Bryan O'Donoghue
<bryan.odonoghue@linaro.org> wrote:
>
> Sashiko asked during a patch review if the existing usage pattern had a
> race condition; specifically in of_phy_get() if it was possible between
> returning from _of_phy_get() and running try_module_get() that a module
> might be unbound leading to use-after-free.
>
> Looking at the code this appears to be so, there is no linkage between the
> phy and module under a synchronisation primitive.
>
> Using the phy_provider_mutex in phy_get() will ensure there is a link between
> the returned phy pointer and the module_get() bumping the module reference
> count.
>
> Amend phy_get(), of_phy_get() and devm_of_phy_get_by_index() to fix the
> same usage pattern.
>
> phy_provider_unregister() must take the phy_provider_mutex so amending
> phy_get()/of_phy_get() to take that same mutex guarantees there is no
> use-after-free.
>
> Fixes: ff764963479a1 ("drivers: phy: add generic PHY framework")
> Cc: stable@vger.kernel.org
> Signed-off-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
> ---
> drivers/phy/phy-core.c | 41 ++++++++++++++++++++++++++---------------
> 1 file changed, 26 insertions(+), 15 deletions(-)
>
> diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c
> index 21aaf2f76e53e..cd9ace125567a 100644
> --- a/drivers/phy/phy-core.c
> +++ b/drivers/phy/phy-core.c
> @@ -124,13 +124,11 @@ static struct phy *phy_find(struct device *dev, const char *con_id)
> const char *dev_id = dev_name(dev);
> struct phy_lookup *p, *pl = NULL;
>
> - mutex_lock(&phy_provider_mutex);
> list_for_each_entry(p, &phys, node)
> if (!strcmp(p->dev_id, dev_id) && !strcmp(p->con_id, con_id)) {
> pl = p;
> break;
> }
> - mutex_unlock(&phy_provider_mutex);
>
> return pl ? pl->phy : ERR_PTR(-ENODEV);
> }
> @@ -635,11 +633,10 @@ static struct phy *_of_phy_get(struct device_node *np, int index)
> goto out_put_node;
> }
>
> - mutex_lock(&phy_provider_mutex);
Then, now we're moving the responsibility to the callers, maybe we should have:
lockdep_assert_held(&phy_provider_mutex)
> phy_provider = of_phy_provider_lookup(args.np);
> if (IS_ERR(phy_provider) || !try_module_get(phy_provider->owner)) {
> phy = ERR_PTR(-EPROBE_DEFER);
> - goto out_unlock;
> + goto out_put_node;
> }
>
> if (!of_device_is_available(args.np)) {
> @@ -653,8 +650,6 @@ static struct phy *_of_phy_get(struct device_node *np, int index)
> out_put_module:
> module_put(phy_provider->owner);
>
> -out_unlock:
> - mutex_unlock(&phy_provider_mutex);
> out_put_node:
> of_node_put(args.np);
>
> @@ -678,15 +673,21 @@ struct phy *of_phy_get(struct device_node *np, const char *con_id)
> if (con_id)
> index = of_property_match_string(np, "phy-names", con_id);
>
> + mutex_lock(&phy_provider_mutex);
> +
> phy = _of_phy_get(np, index);
> if (IS_ERR(phy))
> - return phy;
> + goto out_unlock;
>
> - if (!try_module_get(phy->ops->owner))
> - return ERR_PTR(-EPROBE_DEFER);
> + if (!try_module_get(phy->ops->owner)) {
> + phy = ERR_PTR(-EPROBE_DEFER);
> + goto out_unlock;
> + }
>
> get_device(&phy->dev);
>
> +out_unlock:
> + mutex_unlock(&phy_provider_mutex);
> return phy;
> }
> EXPORT_SYMBOL_GPL(of_phy_get);
> @@ -786,6 +787,7 @@ struct phy *phy_get(struct device *dev, const char *string)
> struct phy *phy;
> struct device_link *link;
>
> + mutex_lock(&phy_provider_mutex);
> if (dev->of_node) {
> if (string)
> index = of_property_match_string(dev->of_node, "phy-names",
> @@ -796,15 +798,18 @@ struct phy *phy_get(struct device *dev, const char *string)
> } else {
> if (string == NULL) {
> dev_WARN(dev, "missing string\n");
> - return ERR_PTR(-EINVAL);
> + phy = ERR_PTR(-EINVAL);
> + goto out_unlock;
> }
> phy = phy_find(dev, string);
> }
> if (IS_ERR(phy))
> - return phy;
> + goto out_unlock;
>
> - if (!try_module_get(phy->ops->owner))
> - return ERR_PTR(-EPROBE_DEFER);
> + if (!try_module_get(phy->ops->owner)) {
> + phy = ERR_PTR(-EPROBE_DEFER);
> + goto out_unlock;
> + }
>
> get_device(&phy->dev);
>
> @@ -813,6 +818,8 @@ struct phy *phy_get(struct device *dev, const char *string)
> dev_dbg(dev, "failed to create device link to %s\n",
> dev_name(phy->dev.parent));
>
> +out_unlock:
> + mutex_unlock(&phy_provider_mutex);
> return phy;
> }
> EXPORT_SYMBOL_GPL(phy_get);
> @@ -961,15 +968,17 @@ struct phy *devm_of_phy_get_by_index(struct device *dev, struct device_node *np,
> if (!ptr)
> return ERR_PTR(-ENOMEM);
>
> + mutex_lock(&phy_provider_mutex);
> phy = _of_phy_get(np, index);
> if (IS_ERR(phy)) {
> devres_free(ptr);
> - return phy;
> + goto out_unlock;
> }
>
> if (!try_module_get(phy->ops->owner)) {
> devres_free(ptr);
> - return ERR_PTR(-EPROBE_DEFER);
> + phy = ERR_PTR(-EPROBE_DEFER);
> + goto out_unlock;
> }
>
> get_device(&phy->dev);
> @@ -982,6 +991,8 @@ struct phy *devm_of_phy_get_by_index(struct device *dev, struct device_node *np,
> dev_dbg(dev, "failed to create device link to %s\n",
> dev_name(phy->dev.parent));
>
> +out_unlock:
> + mutex_unlock(&phy_provider_mutex);
> return phy;
> }
> EXPORT_SYMBOL_GPL(devm_of_phy_get_by_index);
>
> --
> 2.55.0
>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH v14 1/4] phy: core: Fix use-after-free in phy_get paths
2026-09-04 7:45 ` Loic Poulain
@ 2026-09-04 9:41 ` Bryan O'Donoghue
2026-09-04 12:39 ` Loic Poulain
0 siblings, 1 reply; 8+ messages in thread
From: Bryan O'Donoghue @ 2026-09-04 9:41 UTC (permalink / raw)
To: Loic Poulain, Bryan O'Donoghue
Cc: Bjorn Andersson, Michael Turquette, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley, Robert Foss, Todor Tomov,
Mauro Carvalho Chehab, Konrad Dybcio, Vladimir Zapolskiy,
Vinod Koul, Neil Armstrong, Greg Kroah-Hartman,
Kishon Vijay Abraham I, Felipe Balbi, linux-arm-msm, linux-clk,
devicetree, linux-kernel, linux-media, linux-phy,
Krzysztof Kozlowski, stable
On 04/09/2026 08:45, Loic Poulain wrote:
>> - mutex_lock(&phy_provider_mutex);
> Then, now we're moving the responsibility to the callers, maybe we should have:
> lockdep_assert_held(&phy_provider_mutex)
An LLM suggested the same thing to me but, I thought the resulting patch
"looked messy".
Do you want it added, its only three additional callsites.
---
bod
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH v14 1/4] phy: core: Fix use-after-free in phy_get paths
2026-09-04 9:41 ` Bryan O'Donoghue
@ 2026-09-04 12:39 ` Loic Poulain
0 siblings, 0 replies; 8+ messages in thread
From: Loic Poulain @ 2026-09-04 12:39 UTC (permalink / raw)
To: Bryan O'Donoghue
Cc: Bryan O'Donoghue, Bjorn Andersson, Michael Turquette,
Stephen Boyd, Rob Herring, Krzysztof Kozlowski, Conor Dooley,
Robert Foss, Todor Tomov, Mauro Carvalho Chehab, Konrad Dybcio,
Vladimir Zapolskiy, Vinod Koul, Neil Armstrong,
Greg Kroah-Hartman, Kishon Vijay Abraham I, Felipe Balbi,
linux-arm-msm, linux-clk, devicetree, linux-kernel, linux-media,
linux-phy, Krzysztof Kozlowski, stable
On Fri, Sep 4, 2026 at 11:41 AM Bryan O'Donoghue <bod@kernel.org> wrote:
>
> On 04/09/2026 08:45, Loic Poulain wrote:
> >> - mutex_lock(&phy_provider_mutex);
> > Then, now we're moving the responsibility to the callers, maybe we should have:
> > lockdep_assert_held(&phy_provider_mutex)
>
> An LLM suggested the same thing to me but, I thought the resulting patch
> "looked messy".
>
> Do you want it added, its only three additional callsites.
It's only a minor suggestion, but if you end up submitting a new
version, it might be worth including.
I would also probably use a scoped/guarded locking pattern for the
mutex, as it tends to simplify the error paths. That said, it's mostly
a matter of personal preference, and some maintainers prefer explicit
lock/unlock pairs for clarity.
Regards,
Loic
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-04 12:39 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03 22:59 [PATCH v14 0/4] Add phy_get_by_of_node and devm helper Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 1/4] phy: core: Fix use-after-free in phy_get paths Bryan O'Donoghue
2026-09-04 7:45 ` Loic Poulain
2026-09-04 9:41 ` Bryan O'Donoghue
2026-09-04 12:39 ` Loic Poulain
2026-09-03 22:59 ` [PATCH v14 2/4] phy: core: Add phy_get_by_of_node() Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 3/4] phy: core: Add devm_phy_get_by_of_node() Bryan O'Donoghue
2026-09-03 22:59 ` [PATCH v14 4/4] media: qcom: camss: Add support for PHY API devices Bryan O'Donoghue
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox