[PATCH v10 11/26] scsi: ufs: mediatek: Remove undocumented downstream reset cruft
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Thu Jul 30 03:23:53 PDT 2026
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] The kobject reference for `phy_dev` is dropped too early during probe, leaving a dangling pointer stored in `host->phy_dev` that leads to a use-after-free in runtime PM callbacks.
- [High] The runtime PM usage count and enablement state for `phy_dev` are permanently leaked if the probe fails, and the PM state is never restored on driver removal.
--
--- Patch [11]: [PATCH v10 11/26] scsi: ufs: mediatek: Remove undocumented downstream reset cruft ---
commit 2e47ec1b9626d31e1288701fe0c4a25c195e38d4
Author: Nicolas Frattaroli <nicolas.frattaroli at collabora.com>
scsi: ufs: mediatek: Remove undocumented downstream reset cruft
The MediaTek UFS host driver's probe function allows using a ti,syscon-reset
as a reset, without going through the appropriate abstractions or documenting
this in the binding. This commit removes this downstream code as it does not
belong here.
> diff --git a/drivers/ufs/host/ufs-mediatek.c b/drivers/ufs/host/ufs-mediatek.c
> index 65036c8390318..a2749e79514c4 100644
> --- a/drivers/ufs/host/ufs-mediatek.c
> +++ b/drivers/ufs/host/ufs-mediatek.c
> @@ -2402,38 +2402,12 @@ MODULE_DEVICE_TABLE(of, ufs_mtk_of_match);
> static int ufs_mtk_probe(struct platform_device *pdev)
> {
> int err;
> - struct device *dev = &pdev->dev, *phy_dev = NULL;
> - struct device_node *reset_node, *phy_node = NULL;
> - struct platform_device *reset_pdev, *phy_pdev = NULL;
> - struct device_link *link;
> struct ufs_hba *hba;
> + struct platform_device *phy_pdev = NULL;
> + struct device *dev = &pdev->dev, *phy_dev = NULL;
> + struct device_node *phy_node = NULL;
> struct ufs_mtk_host *host;
>
> - reset_node = of_find_compatible_node(NULL, NULL,
> - "ti,syscon-reset");
> - if (!reset_node) {
> - dev_notice(dev, "find ti,syscon-reset fail\n");
> - goto skip_reset;
> - }
> - reset_pdev = of_find_device_by_node(reset_node);
> - if (!reset_pdev) {
> - dev_notice(dev, "find reset_pdev fail\n");
> - goto skip_reset;
> - }
> - link = device_link_add(dev, &reset_pdev->dev,
> - DL_FLAG_AUTOPROBE_CONSUMER);
> - put_device(&reset_pdev->dev);
> - if (!link) {
> - dev_notice(dev, "add reset device_link fail\n");
> - goto skip_reset;
> - }
> - /* supplier is not probed */
> - if (link->status == DL_STATE_DORMANT) {
> - err = -EPROBE_DEFER;
> - goto out;
> - }
> -
> -skip_reset:
> /* find phy node */
> phy_node = of_parse_phandle(dev->of_node, "phys", 0);
>
> @@ -2479,7 +2453,6 @@ static int ufs_mtk_probe(struct platform_device *pdev)
>
> out:
> of_node_put(phy_node);
> - of_node_put(reset_node);
> return err;
> }
[Severity: High]
This isn't a bug introduced by this patch, but could this lead to a
use-after-free of phy_dev?
In ufs_mtk_probe(), after looking up the PHY device, the kobject reference
is dropped almost immediately:
drivers/ufs/host/ufs-mediatek.c:ufs_mtk_probe() {
phy_pdev = of_find_device_by_node(phy_node);
if (!phy_pdev)
goto skip_phy;
phy_dev = &phy_pdev->dev;
...
put_device(phy_dev);
...
}
However, the pointer is later saved into the host structure for later use:
drivers/ufs/host/ufs-mediatek.c:ufs_mtk_probe() {
...
if (phy_node && phy_dev) {
host = ufshcd_get_variant(hba);
host->phy_dev = phy_dev;
}
...
}
If the PHY device is later unbound via sysfs and its memory freed, would the
UFS host's runtime PM callbacks, such as ufs_mtk_runtime_suspend(),
dereference this dangling host->phy_dev pointer when calling
pm_runtime_put_sync()?
[Severity: High]
This is also a pre-existing issue, but is there a PM runtime usage count
leak in ufs_mtk_probe() on error paths?
If a failure occurs during initialization (e.g., ufshcd_pltfrm_init() fails),
the function jumps to the out label without calling pm_runtime_put_sync() or
pm_runtime_disable() for phy_dev:
drivers/ufs/host/ufs-mediatek.c:ufs_mtk_probe() {
if (phy_node) {
...
pm_runtime_enable(phy_dev);
pm_runtime_get_sync(phy_dev);
...
}
...
err = ufshcd_pltfrm_init(pdev, &ufs_hba_mtk_vops);
if (err)
goto out;
...
out:
of_node_put(phy_node);
return err;
}
Additionally, ufs_mtk_remove() doesn't appear to tear down this state.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260730-mt8196-ufs-v10-0-bc5ecef202dc@collabora.com?part=11
More information about the linux-phy
mailing list