Re: [PATCH v9 7/9] pinctrl: mediatek: mt6397: Add MediaTek MT6392

[email protected]
Newsgroups dev.linux.lists.mfd,org.kernel.vger.linux-devicetree,org.kernel.vger.linux-input
Message-ID <[email protected]>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Unbinding the pinctrl driver leads to a Use-After-Free of the gpiochip structure because it is never unregistered.
--

--- Patch [7]: [PATCH v9 7/9] pinctrl: mediatek: mt6397: Add MediaTek MT6392 ---
commit 8de420548b885f3f527c1ef77d05dce6a4500878
Author: Luca Leonardo Scorcia <[email protected]>

pinctrl: mediatek: mt6397: Add MediaTek MT6392
    
This commit adds support for the MT6392 pinctrl device by introducing its pins
definition and updating the MT6397 driver to retrieve device data from the
match table.

> diff --git a/drivers/pinctrl/mediatek/pinctrl-mt6397.c b/drivers/pinctrl/mediatek/pinctrl-mt6397.c
> index 03d0f65d7bcc1..8ba02e70595ce 100644
> --- a/drivers/pinctrl/mediatek/pinctrl-mt6397.c
> +++ b/drivers/pinctrl/mediatek/pinctrl-mt6397.c

[ ... ]

> @@ -40,13 +62,24 @@ static const struct mtk_pinctrl_devdata mt6397_pinctrl_data = {
>  static int mt6397_pinctrl_probe(struct platform_device *pdev)
>  {
>  	struct mt6397_chip *mt6397;
> +	const struct mtk_pinctrl_devdata *data;
> +
> +	data = device_get_match_data(&pdev->dev);
> +	if (!data)
> +		return -ENOENT;
>  
>  	mt6397 = dev_get_drvdata(pdev->dev.parent);
> -	return mtk_pctrl_init(pdev, &mt6397_pinctrl_data, mt6397->regmap);
> +	return mtk_pctrl_init(pdev, data, mt6397->regmap);
>  }

[Severity: High]
This is a pre-existing issue, but does unbinding this driver lead to a
use-after-free of the gpiochip structure?

Looking at mtk_pctrl_init() in drivers/pinctrl/mediatek/pinctrl-mtk-common.c,
the pctl->chip memory is allocated using devm_kzalloc() but registered using
the unmanaged gpiochip_add_data() function:

drivers/pinctrl/mediatek/pinctrl-mtk-common.c:mtk_pctrl_init() {
    ...
    pctl->chip = devm_kzalloc(&pdev->dev, sizeof(*pctl->chip), GFP_KERNEL);
    ...
    ret = gpiochip_add_data(pctl->chip, pctl);
    ...
}

Since the MT6397 platform driver lacks a .remove callback to explicitly call
gpiochip_remove(), unbinding the driver via sysfs causes devres to free
pctl->chip while it remains registered in the global gpiolib lists.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=7
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.