Linux PCI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Manivannan Sadhasivam via B4 Relay"
	<devnull+manivannan.sadhasivam.oss.qualcomm.com@kernel.org>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v2 8/9] power: sequencing: Add an API to return the pwrseq device's 'dev' pointer
Date: Fri, 08 May 2026 01:16:25 +0000	[thread overview]
Message-ID: <20260508011626.3A275C2BCB2@smtp.kernel.org> (raw)
In-Reply-To: <20260507-pwrseq-m2-bt-v2-8-1740bd478539@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Exposing the internal `struct device` breaks abstraction boundaries and bypasses subsystem locks, leading to a Use-After-Free on the device's `fwnode`.
- [Medium] The API returns `NULL` when disabled or passed a `NULL` descriptor, causing a null pointer dereference in property querying APIs.
--

commit 92d97440cc414d34602dcddead25760951c5cdce
Author: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>

power: sequencing: Add an API to return the pwrseq device's 'dev' pointer

This commit adds a new pwrseq_to_device() API to retrieve the underlying
device pointer from a power sequencing descriptor. The intent is to allow
consumers to query the power sequencer's device tree node for specific
properties.

> diff --git a/drivers/power/sequencing/core.c b/drivers/power/sequencing/core.c
> index 4dff71be11b60..96ad557297f5b 100644
> --- a/drivers/power/sequencing/core.c
> +++ b/drivers/power/sequencing/core.c
> @@ -965,6 +965,15 @@ int pwrseq_power_off(struct pwrseq_desc *desc)
>  }
>  EXPORT_SYMBOL_GPL(pwrseq_power_off);
>  
> +struct device *pwrseq_to_device(struct pwrseq_desc *desc)
> +{
> +	if (!desc)
> +		return NULL;
> +
> +	return &desc->pwrseq->dev;

Does exposing the internal device pointer bypass the subsystem locks and
registration checks?

The power sequencing framework internally protects device teardown by
wrapping device accesses in rw_lock and checking device_is_registered(),
such as in pwrseq_power_off():

	guard(rwsem_read)(&pwrseq->rw_lock);
	if (!device_is_registered(&pwrseq->dev))
		return -ENODEV;

If a consumer queries properties on the returned device directly, they might
do so concurrently with or after provider unregistration. In
pwrseq_device_unregister(), device_del() is called, which drops the
reference to the parent device. If the parent is subsequently freed, its
fwnode can be destroyed, leaving pwrseq->dev.fwnode as a dangling pointer.

To safely allow property queries without exposing the raw device pointer,
could the framework provide a dedicated wrapper function like
pwrseq_property_present() that internally holds the lock and checks
registration?

> +}
> +EXPORT_SYMBOL_GPL(pwrseq_to_device);

[ ... ]

> diff --git a/include/linux/pwrseq/consumer.h b/include/linux/pwrseq/consumer.h
> index 7d583b4f266e6..3c907c9e1885d 100644
> --- a/include/linux/pwrseq/consumer.h
> +++ b/include/linux/pwrseq/consumer.h

[ ... ]

> @@ -51,6 +53,11 @@ static inline int pwrseq_power_off(struct pwrseq_desc *desc)
>  	return -ENOSYS;
>  }
>  
> +static inline struct device *pwrseq_to_device(struct pwrseq_desc *desc)
> +{
> +	return NULL;

Will returning NULL here cause a NULL pointer dereference in consumers?

The commit message notes this API is intended for checking the existence of
specific properties on the device. However, functions like
device_property_present() do not accept a NULL device pointer and will
unconditionally dereference it (e.g., when calling __dev_fwnode_const()).

If a consumer uses optional power sequencers or dummy configurations when
CONFIG_POWER_SEQUENCING is disabled, passing the result to
device_property_present() could crash the kernel.

> +}
> +
>  #endif /* CONFIG_POWER_SEQUENCING */

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260507-pwrseq-m2-bt-v2-0-1740bd478539@oss.qualcomm.com?part=8

  reply	other threads:[~2026-05-08  1:16 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-07 16:06 [PATCH v2 0/9] Fixes/improvements for the PCI M.2 power sequencing driver Manivannan Sadhasivam via B4 Relay
2026-05-07 16:06 ` [PATCH v2 1/9] power: sequencing: pcie-m2: Fix inconsistent function prefixes Manivannan Sadhasivam via B4 Relay
2026-05-07 16:06 ` [PATCH v2 2/9] power: sequencing: pcie-m2: Allow creating serdev for multiple PCI devices Manivannan Sadhasivam via B4 Relay
2026-05-07 23:28   ` sashiko-bot
2026-05-07 16:06 ` [PATCH v2 3/9] power: sequencing: pcie-m2: Improve PCI device ID check Manivannan Sadhasivam via B4 Relay
2026-05-07 16:06 ` [PATCH v2 4/9] power: sequencing: pcie-m2: Create serdev for PCI devices present before probe Manivannan Sadhasivam via B4 Relay
2026-05-07 23:54   ` sashiko-bot
2026-05-07 16:06 ` [PATCH v2 5/9] power: sequencing: pcie-m2: Create BT node based on the pci_device_id[] table Manivannan Sadhasivam via B4 Relay
2026-05-07 16:06 ` [PATCH v2 6/9] Bluetooth: hci_qca: Add M.2 Bluetooth device support using pwrseq Manivannan Sadhasivam via B4 Relay
2026-05-08  0:44   ` sashiko-bot
2026-05-07 16:06 ` [PATCH v2 7/9] Bluetooth: hci_qca: Rename 'power_ctrl_enabled' to 'bt_en_available' Manivannan Sadhasivam via B4 Relay
2026-05-08  0:53   ` sashiko-bot
2026-05-11 11:34   ` Bartosz Golaszewski
2026-05-07 16:06 ` [PATCH v2 8/9] power: sequencing: Add an API to return the pwrseq device's 'dev' pointer Manivannan Sadhasivam via B4 Relay
2026-05-08  1:16   ` sashiko-bot [this message]
2026-05-11 11:34   ` Bartosz Golaszewski
2026-05-07 16:06 ` [PATCH v2 9/9] Bluetooth: hci_qca: Set 'bt_en_available' based on W_DISABLE2# presence in M.2 connector Manivannan Sadhasivam via B4 Relay
2026-05-08  2:06   ` sashiko-bot
2026-05-11 11:36   ` Bartosz Golaszewski
2026-05-08 12:49 ` [PATCH v2 0/9] Fixes/improvements for the PCI M.2 power sequencing driver Wei Deng

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260508011626.3A275C2BCB2@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=devnull+manivannan.sadhasivam.oss.qualcomm.com@kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=sashiko@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox