From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E5C6133F8A4 for ; Tue, 21 Jul 2026 13:05:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784639153; cv=none; b=qSJW+5Thqc4yX4EoZkAODm8EtZkdMOxSSujGdUCLitcwC5TWkugg2/hs/XzzMazkDSA7lsyYrR9nBF+LeiVnnnfE4GvjKC4t5urYEG+5Hmue/QexMRshtDHnmoT2baIjORk2ycDTtITFt9E4J3CtKm39PjkiKajrKYXKVY2a12Q= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784639153; c=relaxed/simple; bh=n5doDwhLaejisu+itSIDlWO3yMZElEHyBgMi3Ap0Aho=; h=From:Subject:Date:Message-Id:MIME-Version:Content-Type:To:Cc; b=EGKImCC1WxJaq4FMGJN57ECTFNJuT+FGbHuzLV47WEWen8XGbkPXpTmw5H3rvA5rJmLVshTtlzDaRJRKJpyZCt/CQjH6o5hkh6qCGqcGTe431VLkiZu9aqycc4J3OQJOitauwEEktI+MLVumgIkSEIhPkDujVZtbvEHWPeE1uAM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=cHGpSNvG; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=iv1bw+as; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="cHGpSNvG"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="iv1bw+as" Received: from pps.filterd (m0279867.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66LAQvm62502706 for ; Tue, 21 Jul 2026 13:05:51 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:message-id :mime-version:subject:to; s=qcppdkim1; bh=+wR0wRMni/+0ARfdzMaqeG qZmKzox5EW4BI4JkyGp08=; b=cHGpSNvGvkgGCX9PKa1XkTgx4NeOeK0t9e9NPQ 9moMyGtv5iea+jwQu4CIvKXcAoOqTU3MHJdVmlWTZrBAa9Amw6xYGLcufqyV5lRz fnuED3TSnSi3/TT52SqFiqoKRxJXAf7uJ3fMu/7rb0aB7NB7R19IxOaVPNrIB0sw Uhk7Z6fAmCw+ac6+XTffVqiXUu+V1IWTgETTCnPDAisZ4PniaoiqpRaAp6FAdA05 GVovARlhgKgKbFdr4iqUXVqhJeunuUdhPzN+eV8ZYs2xEc77/jM3e57/+X2F+YMr Jlz7FqdcGXPYJCkA6F2QshfibqtegdAntypifepDyJIsCBtw== Received: from mail-vs1-f69.google.com (mail-vs1-f69.google.com [209.85.217.69]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fj6nsrvas-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Tue, 21 Jul 2026 13:05:51 +0000 (GMT) Received: by mail-vs1-f69.google.com with SMTP id ada2fe7eead31-6751db2792dso6329041137.3 for ; Tue, 21 Jul 2026 06:05:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784639150; x=1785243950; darn=vger.kernel.org; h=cc:to:content-transfer-encoding:content-type:mime-version :message-id:date:subject:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=+wR0wRMni/+0ARfdzMaqeGqZmKzox5EW4BI4JkyGp08=; b=iv1bw+asXUgWSeIcrpHij63oj9Z4i+IxQSSn2vTprS4zvrBSVFE5bDWZ53tUVkaUl5 ARaPee9itmOsYwK4HxohnP5ECGTNT7f/2Zv7yE3Il0IN3UBVFJ8miqO4+TITOAeeiPgr IZ6eLrAlMJA8bp9wWgeaxrTtRRlz5tYLtfZkkrviHJ81WOc6NgzTQUA/EeGfjQqHQOzE lZ+LKQHMKwK7g9yvzmpK6RP41nVxWyE1+Hd/f7uTQFBl8c9SZ2dGDyg2YfIA+FZUpo4t Lsdpbcq4eo17BYsckRG8u+DEs8KIN4pw5WabHhZhTrxN3xrP2bhRyDqQn7e7t6Ycl/5H 3UZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784639150; x=1785243950; h=cc:to:content-transfer-encoding:content-type:mime-version :message-id:date:subject:from:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=+wR0wRMni/+0ARfdzMaqeGqZmKzox5EW4BI4JkyGp08=; b=ARmwkbvQhI1mK1riBfr46UMruq20SVldSRx8yIE8fJZZszh/tdrgEkjLu1UbffJY4t tj+Wun/BhAVKtfRL/51lF4TK1RSnHeDPykGQnRvTN9JQlnNzDZ72eDtSJN5VbXR5hEQE AWtBlooxj+mWZnq3Zv1DgKa8PFbwhfuDBP41cxB7FQP1/Los522mRfgrYL75TblOe7Ky PzBEapaMN8aWQdvqaNmW+4HladQ9Gph1Gph8PyXiAuG7SPPOg+N6wuW1//bEzqmwdLbW FzzRz+FJDWHYpW/8YBtW+S87HeIfUrf0GI65P6B6ENyMSNlYGYAQFMP9GdHbfaW/ZSpf FaCQ== X-Forwarded-Encrypted: i=1; AHgh+RpaE/N739QhgdLReC1cRUJcX5CoKj2dXUnA0WNoed9Vqm3MlNI9wXINJSbvL08YYGDlk3gPUA6ca0CjQKo=@vger.kernel.org X-Gm-Message-State: AOJu0Yzi8/0YMb/zA0pmMqhMZ2PfjlRo6K4C1SN/DXGUb0TWCpWAtsso 42imjhHsmTe9svh3Yw30T/UNdS3QhhRahkxt5GjI95wXD9K11fUz+Wa+VV2n1TwRbX4VKYsqB84 AxG9YwGpLic3UYeHRpjuLIyAUKVhTwaX6Xxto6hVRZ+OPOCY65z6g5VoMOTmQT/PodlHwc/rpU2 c= X-Gm-Gg: AR+sD12JD0pIr4+xuvtQEX/pntY6fXarEOzXKDkS04OCZikfuyptiRqAxydtjIIkMrf M9cBpwSKfD52UxTrEjFSAWnAcSkj67AZYfMSKdsqMXZXqN5p6Ot/Z7DhGQiQh8HCG1k2fZnow6w c5yHdEov7VSKAL+dgQ8yHcJpIIjW+T6x0N88qtYxapmEhsWf5YnRSZbNt2BLZ2IMHoErWvmmExQ A9JT8P8rRCY+cOIbLwkJwOqwLyyBG9X5B1bKj6IPnuu8TfFPmajpT5lpK87nHTb+gycdYBidSqy 64puOa0cRKpwyoSokTvroQK1SjF1psILogSjs2Hn8QL2BIJlHDw6v4tuQmAxkW8uWfh28VHJoEA sRVWkstXVxK18UyY2Hv/mkiHR04Vwdx8WHdvbAdFyXVVhll6eFR/O2xITLms+gl9U4qsS/9iVig BZIHv+8hVskZZ9t3afaowC1Xwab2kahF/d1dKHLTlWAx4B8/fnGno= X-Received: by 2002:a05:6102:918:b0:726:cd42:d023 with SMTP id ada2fe7eead31-747534ce270mr4963602137.11.1784639149649; Tue, 21 Jul 2026 06:05:49 -0700 (PDT) X-Received: by 2002:a05:6102:918:b0:726:cd42:d023 with SMTP id ada2fe7eead31-747534ce270mr4963555137.11.1784639149039; Tue, 21 Jul 2026 06:05:49 -0700 (PDT) Received: from QCOM-eG0v1AUPpu.na.qualcomm.com ([2a01:e0a:830:450:751c:d61c:c91:60dd]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c17009ae04bsm591898066b.8.2026.07.21.06.05.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 06:05:48 -0700 (PDT) From: Loic Poulain Subject: [PATCH v5 0/5] phy: qcom: Fix possible NULL-deref and runtime PM race conditions Date: Tue, 21 Jul 2026 15:05:44 +0200 Message-Id: <20260721-qcom-usb-phy-fix-null-v5-0-a181e2adbd2d@oss.qualcomm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit X-B4-Tracking: v=1; b=H4sIAKhuX2oC/4WOQQ6CMBBFr0K6dpqhFFBX3sOwqNBKk0qhBSIh3 N2BjQsXbn7yMvlv/sqiDlZHdk1WFvRso/UdQX5KWN2q7qnBNsRMoCiwFAhD7V8wxQf07QLGvqG bnANj8FKavGhSLRl1+6DpdnjvFbEJ1BrboNXXJjBPKSXyUp6zMoUUnLc17/3klO1uPkY+TMrRw xen2L2tjaMPyzF3lrv937JZAoJshEKDRZNn6tdbbdv2ASmgSWgJAQAA X-Change-ID: 20260720-qcom-usb-phy-fix-null-ff097f56d1e4 To: Vinod Koul , Neil Armstrong , Dmitry Baryshkov , Wesley Cheng Cc: linux-arm-msm@vger.kernel.org, linux-phy@lists.infradead.org, linux-kernel@vger.kernel.org, Dmitry Baryshkov , Abel Vesa , Konrad Dybcio , Loic Poulain X-Mailer: b4 0.14.2 X-Proofpoint-GUID: A3Y3iDUoSKvuwWEj6109yiuJP-LWvEcE X-Proofpoint-Spam-Info: AW1haW4tMjYwNzIxMDEzOCBTYWx0ZWRfXwgcTp1OT/bKW X4hc786DAR3bGnagTJkTz7uXxrzQ7GKkkF4uDWfmFbGL8LI4Mc/bTsDzWfrCs3fFyETmjh9xXwN Va03T/9PaCewb2WfPwNlbbUyh5V6O7w= X-Authority-Analysis: v=2.4 cv=ZJjnX37b c=1 sm=1 tr=0 ts=6a5f6eaf cx=c_pps a=5HAIKLe1ejAbszaTRHs9Ug==:117 a=xqWC_Br6kY4A:10 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=eoimf2acIAo5FJnRuUoq:22 a=VwQbUJbxAAAA:8 a=EUspDBNiAAAA:8 a=KKAkSRfTAAAA:8 a=COk6AnOGAAAA:8 a=JfrnYn6hAAAA:8 a=9gNpWytEGD6O0ATn_e0A:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=gYDTvv6II1OnSo0itH1n:22 a=cvBusfyB2V15izCimMoJ:22 a=TjNXssC_j7lpFel5tvFf:22 a=1CNFftbPRP8L7MoqJWF3:22 X-Proofpoint-ORIG-GUID: A3Y3iDUoSKvuwWEj6109yiuJP-LWvEcE X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzIxMDEzOCBTYWx0ZWRfXzAbm5+yHTfAC /6brucSDf8i8oCK3Hz+lvqbXtVETQn7dNPrEgKEGEgCR0Xt6napS1PxXSgckNEFgJEyV1CdPQPz AEoQjSICitoAe0Fzi63v7y+O1+Nl0AjffEKv9OTu21ESc3RR1ZkgpfjcHujjlE7x84Jc0QRLlfD HUBUIkHx8Ljek53rILobAhh+8BkITXXaxdnSyY8gk9Y/88MmwwPhTdkYN82q0QmLX5lBMc6V9mn rTpJePMyzgLfYvQay8fjJ0tyZi4Sta4g/p1KN8esnU/TzUlcI26vtQbjgLia8D1EmC25AM4Y77i RUqJVdAqJRks0r57vrxriqYGxz28LwuARwyw3QrUwIeWo6IQ164fcHpHhVStKYfXFPF2m7XdgR8 iENJq9mN6V2JrFNOB8F6zFb8qyHdMIHKd6uQQX09FxJUTVMxiA4/0vLMqE4/eDzzBTiVJSTEO0A FgNJ9mHDuohb5xZFm1w== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-21_01,2026-07-20_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 phishscore=0 priorityscore=1501 suspectscore=0 impostorscore=0 malwarescore=0 spamscore=0 lowpriorityscore=0 adultscore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607210138 Address potential NULL pointer dereferences and race conditions related to runtime PM in several Qualcomm PHY drivers. In all cases, enabling runtime PM before the PHY instance is fully initialized can lead to crashes during early runtime suspend callbacks. - Attach driver data before enabling runtime PM. - Introduce initialization flags where needed to avoid dereferencing uninitialized pointers. - Reorder pm_runtime_enable() and pm_runtime_forbid() calls to prevent unnecessary suspend/resume cycles during driver probe. - Use devres-managed PM runtime helpers for proper cleanup. Why it happens? The PHY is a supplier of the USB device. A USB device cannot be probed until all its suppliers are ready. As long as the PHY is not ready, the device core keeps retrying the probe, which fails with -EPROBE_DEFER. At some point the PHY probe finally runs, but the device core may still be attempting to probe the USB device concurrently. Inside __driver_probe_device(), we have: ret = really_probe(dev, drv); pm_request_idle(dev); if (dev->parent) pm_runtime_put(dev->parent); pm_runtime_put_suppliers(dev); return ret; This means that whenever a USB probe attempt completes, whether with an error or not, its suppliers are released via pm_runtime_put_suppliers(). Releasing suppliers may in turn trigger a runtime suspend. In our case, since the PHY is a supplier of the USB device, the USB core keeps 'looping' in __driver_probe_device() returning -EPROBE_DEFER until the PHY becomes ready. As a result, pm_runtime_put_suppliers() may run concurrently with the PHY's probe function. If this happens after runtime PM has been enabled for the PHY, but before the driver has forbidden suspend or taken a PM reference, the PHY may end up being runtime-suspended 'unexpectedly' --- Changes in v5: - Re-introduce phy: qcom: qmp-usb-legacy: Fix possible NULL-deref (sashiko) - Link to v4: https://lore.kernel.org/r/20260720-qcom-usb-phy-fix-null-v4-0-4d2a0f06d53a@oss.qualcomm.com Changes in V4: - Instead of moving pm/forbid, increment the pm usage counter before enabling runtime pm and decrement it after the PHY has been created. (Johan) - Drop now unnecessary dev_set_drvdata() move in snps-femto-v2 - Drop 4/5 (qmp-usb-legacy: Prevent unnecessary PM runtime suspend at boot) which is not required anymore. - Rebase - Link to v3: https://lore.kernel.org/all/20260205160240.748371-1-loic.poulain@oss.qualcomm.com/ Changes in v3: Rebase on next and remove 2/6 (obsolete) Changes in v2: Split patches 2/4 and 3/4 so that the null‑pointer dereference fix and the runtime‑PM enable/forbid reordering are logically separated. Loic Poulain (4): phy: qcom: qmp-combo: Prevent unnecessary PM runtime suspend at boot phy: qcom: qmp-usbc: Prevent unnecessary PM runtime suspend at boot phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend drivers/phy/qualcomm/phy-qcom-qmp-combo.c | 10 ++++----- .../phy/qualcomm/phy-qcom-qmp-usb-legacy.c | 21 ++++++++++++------- drivers/phy/qualcomm/phy-qcom-qmp-usbc.c | 10 ++++----- drivers/phy/qualcomm/phy-qcom-snps-femto-v2.c | 15 ++++++------- 4 files changed, 32 insertions(+), 24 deletions(-) -- 2.34.1 To: Vinod Koul To: Neil Armstrong To: Dmitry Baryshkov To: Wesley Cheng Cc: linux-arm-msm@vger.kernel.org Cc: linux-phy@lists.infradead.org Cc: linux-kernel@vger.kernel.org --- Loic Poulain (5): phy: qcom: qmp-combo: Prevent unnecessary PM runtime suspend at boot phy: qcom: qmp-usbc: Prevent unnecessary PM runtime suspend at boot phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend phy: qcom: qmp-usb-legacy: Prevent unnecessary PM runtime suspend at boot phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend drivers/phy/qualcomm/phy-qcom-qmp-combo.c | 19 ++++++++++++----- drivers/phy/qualcomm/phy-qcom-qmp-usb-legacy.c | 28 +++++++++++++++++++++----- drivers/phy/qualcomm/phy-qcom-qmp-usbc.c | 18 +++++++++++++---- drivers/phy/qualcomm/phy-qcom-snps-femto-v2.c | 17 +++++++++++++--- 4 files changed, 65 insertions(+), 17 deletions(-) --- base-commit: 910b828b22b7b91054b3bd4be676a017444b0e00 change-id: 20260720-qcom-usb-phy-fix-null-ff097f56d1e4 Best regards, -- Loic Poulain