[PATCH v13 2/5] phy: core: Add devm_phy_get_by_of_node()

Bryan O'Donoghue bryan.odonoghue at linaro.org
Tue Jul 28 03:21:50 PDT 2026


On 28/07/2026 10:47, sashiko-bot at kernel.org wrote:
>> +struct phy *devm_phy_get_by_of_node(struct device *dev, struct device_node *np)
>> +{
>> +	struct phy **ptr, *phy;
>> +	struct device_link *link;
>> +
>> +	ptr = devres_alloc(devm_phy_release, sizeof(*ptr), GFP_KERNEL);
>> +	if (!ptr)
>> +		return ERR_PTR(-ENOMEM);
>> +
>> +	phy = phy_get_by_of_node(np);
> [Severity: High]
> This is a pre-existing issue, but does a TOCTOU race condition exist in the
> underlying phy_get_by_of_node() that could lead to a use-after-free here?
> 
> Looking at phy_get_by_of_node(), it calls _of_phy_get_with_args() to look up
> the PHY. Inside _of_phy_get_with_args(), the function temporarily elevates the
> provider's module refcount, calls of_xlate() (which returns a bare phy
> pointer without incrementing the device refcount), and then drops the module
> refcount and unlocks phy_provider_mutex before returning the raw phy pointer.

This is an interesting idea.

Sounds not implausible and I haven't taken the mutex given in this file 
which is used for adding.

Yes taking the phy_provider mutex seems warranted until the get_device() 
completes.

Actually this is a result of functional decomposition so, I think I 
should add a patch prior here to take the mutex and hold until the 
get_device() in the existing code, then decompose that.

thx

---
bod



More information about the linux-phy mailing list