Linux SCSI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Louis-Alexis Eyraud" <louisalexis.eyraud@collabora.com>
Cc: robh@kernel.org, neil.armstrong@linaro.org, olteanv@gmail.com,
	devicetree@vger.kernel.org, linux-scsi@vger.kernel.org,
	linux-phy@lists.infradead.org, vkoul@kernel.org,
	conor+dt@kernel.org
Subject: Re: [PATCH v10 11/26] scsi: ufs: mediatek: Remove undocumented downstream reset cruft
Date: Thu, 30 Jul 2026 10:23:53 +0000	[thread overview]
Message-ID: <20260730102353.E811F1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260730-mt8196-ufs-v10-11-bc5ecef202dc@collabora.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

Pre-existing issues:
- [High] The kobject reference for `phy_dev` is dropped too early during probe, leaving a dangling pointer stored in `host->phy_dev` that leads to a use-after-free in runtime PM callbacks.
- [High] The runtime PM usage count and enablement state for `phy_dev` are permanently leaked if the probe fails, and the PM state is never restored on driver removal.
--

--- Patch [11]: [PATCH v10 11/26] scsi: ufs: mediatek: Remove undocumented downstream reset cruft ---
commit 2e47ec1b9626d31e1288701fe0c4a25c195e38d4
Author: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>

scsi: ufs: mediatek: Remove undocumented downstream reset cruft

The MediaTek UFS host driver's probe function allows using a ti,syscon-reset
as a reset, without going through the appropriate abstractions or documenting
this in the binding. This commit removes this downstream code as it does not
belong here.

> diff --git a/drivers/ufs/host/ufs-mediatek.c b/drivers/ufs/host/ufs-mediatek.c
> index 65036c8390318..a2749e79514c4 100644
> --- a/drivers/ufs/host/ufs-mediatek.c
> +++ b/drivers/ufs/host/ufs-mediatek.c
> @@ -2402,38 +2402,12 @@ MODULE_DEVICE_TABLE(of, ufs_mtk_of_match);
>  static int ufs_mtk_probe(struct platform_device *pdev)
>  {
>  	int err;
> -	struct device *dev = &pdev->dev, *phy_dev = NULL;
> -	struct device_node *reset_node, *phy_node = NULL;
> -	struct platform_device *reset_pdev, *phy_pdev = NULL;
> -	struct device_link *link;
>  	struct ufs_hba *hba;
> +	struct platform_device *phy_pdev = NULL;
> +	struct device *dev = &pdev->dev, *phy_dev = NULL;
> +	struct device_node *phy_node = NULL;
>  	struct ufs_mtk_host *host;
>  
> -	reset_node = of_find_compatible_node(NULL, NULL,
> -					     "ti,syscon-reset");
> -	if (!reset_node) {
> -		dev_notice(dev, "find ti,syscon-reset fail\n");
> -		goto skip_reset;
> -	}
> -	reset_pdev = of_find_device_by_node(reset_node);
> -	if (!reset_pdev) {
> -		dev_notice(dev, "find reset_pdev fail\n");
> -		goto skip_reset;
> -	}
> -	link = device_link_add(dev, &reset_pdev->dev,
> -		DL_FLAG_AUTOPROBE_CONSUMER);
> -	put_device(&reset_pdev->dev);
> -	if (!link) {
> -		dev_notice(dev, "add reset device_link fail\n");
> -		goto skip_reset;
> -	}
> -	/* supplier is not probed */
> -	if (link->status == DL_STATE_DORMANT) {
> -		err = -EPROBE_DEFER;
> -		goto out;
> -	}
> -
> -skip_reset:
>  	/* find phy node */
>  	phy_node = of_parse_phandle(dev->of_node, "phys", 0);
>  
> @@ -2479,7 +2453,6 @@ static int ufs_mtk_probe(struct platform_device *pdev)
>  
>  out:
>  	of_node_put(phy_node);
> -	of_node_put(reset_node);
>  	return err;
>  }

[Severity: High]
This isn't a bug introduced by this patch, but could this lead to a
use-after-free of phy_dev?

In ufs_mtk_probe(), after looking up the PHY device, the kobject reference
is dropped almost immediately:

drivers/ufs/host/ufs-mediatek.c:ufs_mtk_probe() {
	phy_pdev = of_find_device_by_node(phy_node);
	if (!phy_pdev)
		goto skip_phy;
	phy_dev = &phy_pdev->dev;
	...
	put_device(phy_dev);
	...
}

However, the pointer is later saved into the host structure for later use:

drivers/ufs/host/ufs-mediatek.c:ufs_mtk_probe() {
	...
	if (phy_node && phy_dev) {
		host = ufshcd_get_variant(hba);
		host->phy_dev = phy_dev;
	}
	...
}

If the PHY device is later unbound via sysfs and its memory freed, would the
UFS host's runtime PM callbacks, such as ufs_mtk_runtime_suspend(),
dereference this dangling host->phy_dev pointer when calling
pm_runtime_put_sync()?

[Severity: High]
This is also a pre-existing issue, but is there a PM runtime usage count
leak in ufs_mtk_probe() on error paths?

If a failure occurs during initialization (e.g., ufshcd_pltfrm_init() fails),
the function jumps to the out label without calling pm_runtime_put_sync() or
pm_runtime_disable() for phy_dev:

drivers/ufs/host/ufs-mediatek.c:ufs_mtk_probe() {
	if (phy_node) {
		...
		pm_runtime_enable(phy_dev);
		pm_runtime_get_sync(phy_dev);
		...
	}
	...
	err = ufshcd_pltfrm_init(pdev, &ufs_hba_mtk_vops);
	if (err)
		goto out;
	...
out:
	of_node_put(phy_node);
	return err;
}

Additionally, ufs_mtk_remove() doesn't appear to tear down this state.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260730-mt8196-ufs-v10-0-bc5ecef202dc@collabora.com?part=11

  reply	other threads:[~2026-07-30 10:23 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-30  9:48 [PATCH v10 00/26] MediaTek UFS Cleanup and MT8196 Enablement Louis-Alexis Eyraud
2026-07-30  9:48 ` [PATCH v10 01/26] dt-bindings: phy: Add mediatek,mt8196-ufsphy variant Louis-Alexis Eyraud
2026-07-30  9:48 ` [PATCH v10 02/26] dt-bindings: ufs: mediatek,ufs: Complete the binding Louis-Alexis Eyraud
2026-07-30  9:57   ` sashiko-bot
2026-07-30  9:48 ` [PATCH v10 03/26] dt-bindings: ufs: mediatek,ufs: Add mt8196 variant Louis-Alexis Eyraud
2026-07-30  9:59   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 04/26] scsi: ufs: mediatek: Move MTK_SIP_UFS_CONTROL to mtk_sip_svc.h Louis-Alexis Eyraud
2026-07-30  9:49 ` [PATCH v10 05/26] phy: mediatek: ufs: Add support for resets Louis-Alexis Eyraud
2026-07-30  9:49 ` [PATCH v10 06/26] scsi: ufs: mediatek: Rework resets Louis-Alexis Eyraud
2026-07-30 10:29   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 07/26] scsi: ufs: mediatek: Rework 0.9V regulator Louis-Alexis Eyraud
2026-07-30 10:13   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 08/26] scsi: ufs: mediatek: Rework init function Louis-Alexis Eyraud
2026-07-30 10:07   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 09/26] scsi: ufs: mediatek: Rework the crypt-boost stuff Louis-Alexis Eyraud
2026-07-30 10:16   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 10/26] scsi: ufs: mediatek: Handle misc host voltage regulators Louis-Alexis Eyraud
2026-07-30 10:29   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 11/26] scsi: ufs: mediatek: Remove undocumented downstream reset cruft Louis-Alexis Eyraud
2026-07-30 10:23   ` sashiko-bot [this message]
2026-07-30  9:49 ` [PATCH v10 12/26] scsi: ufs: mediatek: Remove vendor kernel quirks cruft Louis-Alexis Eyraud
2026-07-30 10:30   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 13/26] scsi: ufs: mediatek: Use the common PHY framework Louis-Alexis Eyraud
2026-07-30 10:40   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 14/26] scsi: ufs: mediatek: Remove mediatek,ufs-broken-rtc property Louis-Alexis Eyraud
2026-07-30  9:49 ` [PATCH v10 15/26] scsi: ufs: mediatek: Rework _ufs_mtk_clk_scale error paths Louis-Alexis Eyraud
2026-07-30 10:34   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 16/26] scsi: ufs: mediatek: Clean up logging prints Louis-Alexis Eyraud
2026-07-30  9:49 ` [PATCH v10 17/26] scsi: ufs: mediatek: Rework ufs_mtk_wait_idle_state Louis-Alexis Eyraud
2026-07-30  9:49 ` [PATCH v10 18/26] scsi: ufs: mediatek: Don't acquire dvfsrc-vcore twice Louis-Alexis Eyraud
2026-07-30 10:41   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 19/26] scsi: ufs: mediatek: Rework hardware version reading Louis-Alexis Eyraud
2026-07-30  9:49 ` [PATCH v10 20/26] scsi: ufs: mediatek: Back up idle timer in per-instance struct Louis-Alexis Eyraud
2026-07-30 10:53   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 21/26] scsi: ufs: mediatek: Remove ret local from link_startup_notify Louis-Alexis Eyraud
2026-07-30  9:49 ` [PATCH v10 22/26] scsi: ufs: mediatek: Remove undocumented "clk-scale-up-vcore-min" Louis-Alexis Eyraud
2026-07-30 10:49   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 23/26] scsi: ufs: mediatek: Add MT8196 compatible, update copyright Louis-Alexis Eyraud
2026-07-30  9:49 ` [PATCH v10 24/26] arm64: dts: mediatek: mt8195: Align ufshci node to dt-bindings changes Louis-Alexis Eyraud
2026-07-30 11:13   ` sashiko-bot
2026-07-30  9:49 ` [PATCH v10 25/26] arm64: dts: mediatek: mt8395-genio-1200-evk-ufs: Complete UFS power supplies Louis-Alexis Eyraud
2026-07-30  9:49 ` [PATCH v10 26/26] arm64: dts: mediatek: mt8395-radxa-nio-12l: " Louis-Alexis Eyraud

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260730102353.E811F1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-phy@lists.infradead.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=louisalexis.eyraud@collabora.com \
    --cc=neil.armstrong@linaro.org \
    --cc=olteanv@gmail.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox