Re: [PATCH v9 7/9] pinctrl: mediatek: mt6397: Add MediaTek MT6392
| Newsgroups | org.kernel.vger.linux-input,dev.linux.lists.mfd,org.kernel.vger.linux-devicetree |
|---|---|
| Message-ID | <[email protected]> |
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: Pre-existing issues: - [High] Unbinding the pinctrl driver leads to a Use-After-Free of the gpiochip structure because it is never unregistered. -- --- Patch [7]: [PATCH v9 7/9] pinctrl: mediatek: mt6397: Add MediaTek MT6392 --- commit 8de420548b885f3f527c1ef77d05dce6a4500878 Author: Luca Leonardo Scorcia <[email protected]> pinctrl: mediatek: mt6397: Add MediaTek MT6392 This commit adds support for the MT6392 pinctrl device by introducing its pins definition and updating the MT6397 driver to retrieve device data from the match table. > diff --git a/drivers/pinctrl/mediatek/pinctrl-mt6397.c b/drivers/pinctrl/mediatek/pinctrl-mt6397.c > index 03d0f65d7bcc1..8ba02e70595ce 100644 > --- a/drivers/pinctrl/mediatek/pinctrl-mt6397.c > +++ b/drivers/pinctrl/mediatek/pinctrl-mt6397.c [ ... ] > @@ -40,13 +62,24 @@ static const struct mtk_pinctrl_devdata mt6397_pinctrl_data = { > static int mt6397_pinctrl_probe(struct platform_device *pdev) > { > struct mt6397_chip *mt6397; > + const struct mtk_pinctrl_devdata *data; > + > + data = device_get_match_data(&pdev->dev); > + if (!data) > + return -ENOENT; > > mt6397 = dev_get_drvdata(pdev->dev.parent); > - return mtk_pctrl_init(pdev, &mt6397_pinctrl_data, mt6397->regmap); > + return mtk_pctrl_init(pdev, data, mt6397->regmap); > } [Severity: High] This is a pre-existing issue, but does unbinding this driver lead to a use-after-free of the gpiochip structure? Looking at mtk_pctrl_init() in drivers/pinctrl/mediatek/pinctrl-mtk-common.c, the pctl->chip memory is allocated using devm_kzalloc() but registered using the unmanaged gpiochip_add_data() function: drivers/pinctrl/mediatek/pinctrl-mtk-common.c:mtk_pctrl_init() { ... pctl->chip = devm_kzalloc(&pdev->dev, sizeof(*pctl->chip), GFP_KERNEL); ... ret = gpiochip_add_data(pctl->chip, pctl); ... } Since the MT6397 platform driver lacks a .remove callback to explicitly call gpiochip_remove(), unbinding the driver via sysfs causes devres to free pctl->chip while it remains registered in the global gpiolib lists. -- Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=7