ARM Sunxi Platform Development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Pablo Mazzini" <pmazzini@gmail.com>
Cc: linux-sunxi@lists.linux.dev, linux-gpio@vger.kernel.org
Subject: Re: [PATCH v3 04/11] pinctrl: sunxi: add Allwinner B288 pin controller driver
Date: Mon, 05 Oct 2026 20:42:23 +0000	[thread overview]
Message-ID: <20261005204223.87A291F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261005202731.153971-5-pmazzini@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] pinctrl: sunxi: NULL ptr deref on probe deferral due to npins accumulation
--

commit 23f0ad979270766cafcf25e2ddff2cd81bb51adc
Author: Pablo Mazzini <pmazzini@gmail.com>

pinctrl: sunxi: add Allwinner B288 pin controller driver

This commit introduces pin controller and GPIO support for the Allwinner
B288 SoC. It covers configuration for 80 pins across ports B, C, D, F, and
G, including external interrupts.

> diff --git a/drivers/pinctrl/sunxi/pinctrl-sun8i-b288.c b/drivers/pinctrl/sunxi/pinctrl-sun8i-b288.c
> new file mode 100644
> index 0000000000000..f973c2b3f2eba
> --- /dev/null
> +++ b/drivers/pinctrl/sunxi/pinctrl-sun8i-b288.c

[ ... ]

> +static struct sunxi_pinctrl_desc b288_pinctrl_data = {
> +	.irq_banks	= 4,
> +};
> +
> +static int b288_pinctrl_probe(struct platform_device *pdev)
> +{
> +	return sunxi_pinctrl_dt_table_init(pdev, b288_nr_bank_pins,
> +					   b288_irq_bank_muxes,
> +					   &b288_pinctrl_data, 0);
> +}

[Severity: High]
If b288_pinctrl_probe() fails and defers, will b288_pinctrl_data.npins
accumulate indefinitely and cause a NULL pointer dereference?

Since b288_pinctrl_data is defined as a static global variable, its state
persists across multiple probe attempts. Looking at
sunxi_pinctrl_dt_table_init(), it forwards this struct to init_pins_table()
which modifies desc->npins:

init_pins_table() {
        ...
        desc->npins += pins_per_bank[i];
        ...
}

If the probe fails and defers, or if the driver is unbound and rebound,
desc->npins is not reset to 0, so its value will double on the next probe
attempt.

This leads to the pins array being allocated for the doubled size, but only
the first 80 elements are actually initialized. The rest are zeroed out by
the allocation. Later, in prepare_function_table(), a loop iterates over
the doubled npins value and calls strcmp(pins[i].pin.name, name). For
indexes beyond the actual number of pins, pins[i].pin.name is NULL, which
triggers a crash.

Should npins be cleared to 0 before initialization, or should the static
struct be treated as read-only and copied to a local device structure?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261005202731.153971-1-pmazzini@gmail.com?part=4

  reply	other threads:[~2026-10-05 20:42 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 20:27 [PATCH v3 00/11] ARM: sunxi: add Allwinner B288 and the PocketBook Verse Pablo Mazzini
2026-10-05 20:27 ` [PATCH v3 01/11] dt-bindings: clock: sun4i-a10-ccu: add Allwinner B288 Pablo Mazzini
2026-10-05 20:27 ` [PATCH v3 02/11] clk: sunxi-ng: add Allwinner B288 CCU driver Pablo Mazzini
2026-10-05 20:27 ` [PATCH v3 03/11] dt-bindings: pinctrl: sun4i-a10: add Allwinner B288 Pablo Mazzini
2026-10-07 21:16   ` Rob Herring
2026-10-08  6:54     ` Pablo Mazzini
2026-10-08  7:50     ` Andre Przywara
2026-10-08  9:21       ` Linus Walleij
2026-10-08 10:04         ` Andre Przywara
2026-10-05 20:27 ` [PATCH v3 04/11] pinctrl: sunxi: add Allwinner B288 pin controller driver Pablo Mazzini
2026-10-05 20:42   ` sashiko-bot [this message]
2026-10-05 20:27 ` [PATCH v3 05/11] dt-bindings: rtc: sun6i-a31: add Allwinner B288 Pablo Mazzini
2026-10-05 20:31   ` sashiko-bot
2026-10-07 21:16   ` Rob Herring (Arm)
2026-10-05 20:27 ` [PATCH v3 06/11] rtc: sun6i: add Allwinner B288 compatible Pablo Mazzini
2026-10-05 20:40   ` sashiko-bot
2026-10-05 20:27 ` [PATCH v3 08/11] dt-bindings: interrupt-controller: add Allwinner B288 NMI Pablo Mazzini
2026-10-05 20:27 ` [PATCH v3 09/11] dt-bindings: watchdog: sun4i-a10-wdt: add Allwinner B288 Pablo Mazzini
2026-10-07 21:16   ` Rob Herring (Arm)
2026-10-05 20:27 ` [PATCH v3 10/11] dt-bindings: arm: sunxi: add PocketBook Verse Pablo Mazzini
2026-10-05 20:27 ` [PATCH v3 11/11] ARM: dts: allwinner: add B288 and the " Pablo Mazzini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261005204223.87A291F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-gpio@vger.kernel.org \
    --cc=linux-sunxi@lists.linux.dev \
    --cc=pmazzini@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox