Linux-PHY Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sebastian Reichel" <sebastian.reichel@collabora.com>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org,
	vkoul@kernel.org, neil.armstrong@linaro.org,
	linux-phy@lists.infradead.org, olteanv@gmail.com
Subject: Re: [PATCH v14 33/38] phy: rockchip: usbdp: Add phy reset notification support
Date: Fri, 14 Aug 2026 06:12:16 +0000	[thread overview]
Message-ID: <20260814061217.3A8541F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260813-rockchip-usbdp-cleanup-v14-33-b5ad9c68fa11@collabora.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] Unbalanced PM runtime reference decrement in the DWC3 PHY reset notifier due to mishandling of `-EINVAL`.
- [High] The PHY reset notification handler in the DWC3 Rockchip driver accesses `dwc->gadget` without adequate synchronization, leading to a potential Use-After-Free during a concurrent USB role switch.
- [Medium] The return value of `phy_notify_reset(..., PHY_NOTIFY_PRE_RESET)` is ignored in `rk_udphy_power_on()`, potentially forcing a hardware reset even if a consumer rejects the request.
--

--- Patch [33]: [PATCH v14 33/38] phy: rockchip: usbdp: Add phy reset notification support ---
commit 101376e3124c8975c12127c9a52db0a5300092c4
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
Subject: phy: rockchip: usbdp: Add phy reset notification support

To resolve issues with running into permanent cmn ana lcpll lock timeout
errors after a few device replugs, this commit adds support for reset
notifications. These notifications will be handled by the DWC3 driver to
gracefully handle the PHY being disabled. This avoids corrupting the
controller's internal state.

> diff --git a/drivers/phy/rockchip/phy-rockchip-usbdp.c b/drivers/phy/rockchip/phy-rockchip-usbdp.c
> index 59b836a3796ce..21f282216aef7 100644
> --- a/drivers/phy/rockchip/phy-rockchip-usbdp.c
> +++ b/drivers/phy/rockchip/phy-rockchip-usbdp.c
> @@ -1005,24 +1005,39 @@ static int rk_udphy_power_on(struct rk_udphy *udphy, u8 mode)
>  	}
>  
>  	if (udphy->status == UDPHY_MODE_NONE) {
> +		phy_notify_reset(udphy->phy_u3, PHY_NOTIFY_PRE_RESET);
> +

[Severity: Medium]
Is it intentional to ignore the return value of phy_notify_reset() here?

In rk_udphy_update_power_state() the return value is checked and propagated,
but here the reset proceeds even if a consumer rejects the request. Can this
force a hardware reset when the consumer is unready, risking state corruption?


[Severity: High]
Does triggering this notification expose a PM runtime usage counter underflow
in the DWC3 driver?

If the PHY mode change triggers a PRE_RESET notification while runtime PM is
disabled for the device:

drivers/usb/dwc3/dwc3-rockchip.c:dwc3_usb3_phy_notify() {
    ...
    ret = pm_runtime_get_if_active(dwc->dev);
    if (!ret)
        return NOTIFY_OK;
    ...
}

The pm_runtime_get_if_active() call returns -EINVAL if PM is disabled. Because
this is non-zero, the driver bypasses the !ret check without incrementing the
usage count.

However, during POST_RESET, it unconditionally calls:

    pm_runtime_put_autosuspend(dwc->dev);

Will this internally force a decrement of the usage count and cause an
underflow?


[Severity: High]
Does triggering this notification also expose a potential use-after-free in the
DWC3 driver during a concurrent USB role switch?

When the POST_RESET notification is handled, dwc3_usb3_phy_notify() drops
the lock and calls dwc3_rockchip_vbus_handler():

drivers/usb/dwc3/dwc3-rockchip.c:dwc3_usb3_phy_notify() {
    ...
    spin_unlock_irqrestore(&dwc->lock, flags);
    dwc3_rockchip_vbus_handler(dwc, dwc_rk->role == USB_ROLE_DEVICE);
    ...
}

Inside dwc3_rockchip_vbus_handler():

    if (!dwc->gadget || !dwc->gadget_driver)
        return;

    usb_udc_vbus_handler(dwc->gadget, present);

Since this runs asynchronously, a concurrent USB role switch to host mode
could trigger dwc3_gadget_exit(), which unregisters and frees dwc->gadget.

Is there a time-of-check to time-of-use window between the NULL check and the
dereference of dwc->gadget?

> +		rk_udphy_u3_port_disable(udphy, true);
> +		udelay(10);
> +
>  		ret = rk_udphy_setup(udphy);
> -		if (ret)
> +		if (ret) {
> +			phy_notify_reset(udphy->phy_u3, PHY_NOTIFY_POST_RESET);
>  			return ret;
> +		}
>  
>  		if (!udphy->hs && udphy->mode & UDPHY_MODE_USB)
>  			rk_udphy_u3_port_disable(udphy, false);
>  		udphy->phy_needs_reinit = false;
> +
> +		phy_notify_reset(udphy->phy_u3, PHY_NOTIFY_POST_RESET);
>  	} else if (udphy->phy_needs_reinit) {
> +		phy_notify_reset(udphy->phy_u3, PHY_NOTIFY_PRE_RESET);
> +

[Severity: Medium]
Similarly here, the return value of phy_notify_reset() for PHY_NOTIFY_PRE_RESET
is ignored before proceeding with the hardware reset. Should it be checked?

> +		rk_udphy_u3_port_disable(udphy, true);
> +		udelay(10);
> +
>  		ret = rk_udphy_init(udphy);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260813-rockchip-usbdp-cleanup-v14-0-b5ad9c68fa11@collabora.com?part=33

-- 
linux-phy mailing list
linux-phy@lists.infradead.org
https://lists.infradead.org/mailman/listinfo/linux-phy

  reply	other threads:[~2026-08-14  6:12 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-13 20:51 [PATCH v14 00/38] phy: rockchip: usbdp: Clean up the mess Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 01/38] dt-bindings: phy: rockchip-usbdp: add improved ports scheme Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 02/38] phy: rockchip: usbdp: Update mode_change after error handling Sebastian Reichel
2026-08-14  1:19   ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 03/38] phy: rockchip: usbdp: Do not lose USB3 PHY status Sebastian Reichel
2026-08-14  1:33   ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 04/38] phy: rockchip: usbdp: Fix devm_clk_bulk_get_all check Sebastian Reichel
2026-08-14  1:41   ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 05/38] phy: rockchip: usbdp: Handle missing clock-names DT property gracefully Sebastian Reichel
2026-08-14  1:53   ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 06/38] phy: rockchip: usbdp: Drop seamless DP takeover Sebastian Reichel
2026-08-14  2:06   ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 07/38] phy: rockchip: usbdp: Keep clocks running on PHY re-init Sebastian Reichel
2026-08-14  2:16   ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 08/38] phy: rockchip: usbdp: Amend SSC modulation deviation Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 09/38] phy: rockchip: usbdp: Fix LFPS detect threshold control Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 10/38] phy: rockchip: usbdp: Add missing mode_change update Sebastian Reichel
2026-08-14  2:41   ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 11/38] phy: rockchip: usbdp: Support single-lane DP Sebastian Reichel
2026-08-14  2:55   ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 12/38] phy: rockchip: usbdp: Limit DP lane count to muxed lanes Sebastian Reichel
2026-08-14  3:07   ` sashiko-bot
2026-08-13 20:51 ` [PATCH v14 13/38] phy: rockchip: usbdp: Rename DP lane functions Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 14/38] phy: rockchip: usbdp: Use FIELD_PREP_WM16_CONST Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 15/38] phy: rockchip: usbdp: Cleanup DP lane selection function Sebastian Reichel
2026-08-13 20:51 ` [PATCH v14 16/38] phy: rockchip: usbdp: Register DP aux bridge Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 17/38] phy: rockchip: usbdp: Drop DP HPD handling Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 18/38] phy: rockchip: usbdp: Rename mode_change to phy_needs_reinit Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 19/38] phy: rockchip: usbdp: Re-init the PHY on orientation change Sebastian Reichel
2026-08-14  3:57   ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 20/38] phy: rockchip: usbdp: Factor out lane_mux_sel setup Sebastian Reichel
2026-08-14  4:10   ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 21/38] phy: rockchip: usbdp: Properly handle TYPEC_STATE_SAFE and TYPEC_STATE_USB Sebastian Reichel
2026-08-14  4:23   ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 22/38] phy: rockchip: usbdp: Use guard functions for mutex Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 23/38] phy: rockchip: usbdp: Hold mutex in DP PHY configure Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 24/38] phy: rockchip: usbdp: Add some extra debug messages Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 25/38] phy: rockchip: usbdp: Avoid xHCI SErrors Sebastian Reichel
2026-08-14  4:52   ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 26/38] phy: rockchip: usbdp: Handle rk_udphy_reset_deassert errors Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 27/38] phy: rockchip: usbdp: Only enable USB3 when not in high-speed mode Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 28/38] phy: core: add notifier infrastructure Sebastian Reichel
2026-08-14  5:14   ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 29/38] usb: dwc3: rockchip: introduce glue driver Sebastian Reichel
2026-08-14  5:22   ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 30/38] usb: dwc3: core: add post PHY registration hook for platform glue Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 31/38] usb: dwc3: rockchip: support PHY reset notifications Sebastian Reichel
2026-08-14  5:43   ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 32/38] usb: dwc3: rockchip: fix USB-C reconnect in gadget mode Sebastian Reichel
2026-08-14  5:59   ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 33/38] phy: rockchip: usbdp: Add phy reset notification support Sebastian Reichel
2026-08-14  6:12   ` sashiko-bot [this message]
2026-08-13 20:52 ` [PATCH v14 34/38] phy: rockchip: usbdp: Drop -EPROBE_DEFER hack Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 35/38] phy: rockchip: usbdp: Rename mode to hw_mode Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 36/38] phy: rockchip: usbdp: Fix power state handling Sebastian Reichel
2026-08-13 20:52 ` [PATCH v14 37/38] phy: rockchip: usbdp: Re-init PHY on mux change Sebastian Reichel
2026-08-14  6:49   ` sashiko-bot
2026-08-13 20:52 ` [PATCH v14 38/38] phy: rockchip: usbdp: Add USB-C state without DP enabled Sebastian Reichel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260814061217.3A8541F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-phy@lists.infradead.org \
    --cc=neil.armstrong@linaro.org \
    --cc=olteanv@gmail.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sebastian.reichel@collabora.com \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox