mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure
@ 2026-10-09  3:45 Haotian Zhang
  2026-10-09  6:10 ` Krzysztof Kozlowski
  2026-10-09 16:42 ` kernel test robot
  0 siblings, 2 replies; 3+ messages in thread
From: Haotian Zhang @ 2026-10-09  3:45 UTC (permalink / raw)
  To: Marek Szyprowski, Will Deacon, Robin Murphy, Krzysztof Kozlowski,
	Peter Griffin, Alim Akhtar, Joerg Roedel
  Cc: iommu, linux-arm-kernel, linux-samsung-soc, linux-kernel

exynos_iommu_probe_device() stores the result of device_link_add() in
data->link without checking it for failure, although device_link_add()
returns NULL when the supplier is not PM initialized, on a dependency
cycle or on allocation failure. exynos_iommu_release_device() then calls
device_link_del() on that entry unconditionally, and device_link_del()
dereferences link->flags, so a NULL data->link causes a NULL pointer
dereference when the device is released.

Check the returned device link for NULL, unwind the links that were
already created and fail the probe instead.

Fixes: 7a974b29fe5d ("iommu/exynos: Rework runtime PM links management")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
---
 drivers/iommu/exynos-iommu.c | 14 +++++++++++++-
 1 file changed, 13 insertions(+), 1 deletion(-)

diff --git a/drivers/iommu/exynos-iommu.c b/drivers/iommu/exynos-iommu.c
index 874d05f4b396..ce0492691ef4 100644
--- a/drivers/iommu/exynos-iommu.c
+++ b/drivers/iommu/exynos-iommu.c
@@ -1403,7 +1403,7 @@ static phys_addr_t exynos_iommu_iova_to_phys(struct iommu_domain *iommu_domain,
 static struct iommu_device *exynos_iommu_probe_device(struct device *dev)
 {
 	struct exynos_iommu_owner *owner = dev_iommu_priv_get(dev);
-	struct sysmmu_drvdata *data;
+	struct sysmmu_drvdata *data, *tmp;
 
 	if (!has_sysmmu(dev))
 		return ERR_PTR(-ENODEV);
@@ -1417,6 +1417,11 @@ static struct iommu_device *exynos_iommu_probe_device(struct device *dev)
 		data->link = device_link_add(dev, data->sysmmu,
 					     DL_FLAG_STATELESS |
 					     DL_FLAG_PM_RUNTIME);
+		if (!data->link) {
+			dev_err(dev, "Unable to link %s\n",
+				dev_name(data->sysmmu));
+			goto err_unlink;
+		}
 	}
 
 	/* There is always at least one entry, see exynos_iommu_of_xlate() */
@@ -1424,6 +1429,13 @@ static struct iommu_device *exynos_iommu_probe_device(struct device *dev)
 				struct sysmmu_drvdata, owner_node);
 
 	return &data->iommu;
+
+err_unlink:
+	list_for_each_entry_continue_reverse(tmp, &owner->controllers,
+					     owner_node)
+		device_link_del(tmp->link);
+
+	return ERR_PTR(-ENODEV);
 }
 
 static void exynos_iommu_release_device(struct device *dev)
-- 
2.25.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure
  2026-10-09  3:45 [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure Haotian Zhang
@ 2026-10-09  6:10 ` Krzysztof Kozlowski
  2026-10-09 16:42 ` kernel test robot
  1 sibling, 0 replies; 3+ messages in thread
From: Krzysztof Kozlowski @ 2026-10-09  6:10 UTC (permalink / raw)
  To: Haotian Zhang
  Cc: linux-kernel, linux-arm-kernel, iommu, linux-samsung-soc,
	Marek Szyprowski, Will Deacon, Alim Akhtar, Peter Griffin,
	Robin Murphy, Joerg Roedel


On Fri, 09 Oct 2026 11:45:39 +0800, Haotian Zhang wrote:
> exynos_iommu_probe_device() stores the result of device_link_add() in
> data->link without checking it for failure, although device_link_add()
> returns NULL when the supplier is not PM initialized, on a dependency
> cycle or on allocation failure. exynos_iommu_release_device() then calls
> device_link_del() on that entry unconditionally, and device_link_del()
> dereferences link->flags, so a NULL data->link causes a NULL pointer
> dereference when the device is released.
> 
> Check the returned device link for NULL, unwind the links that were
> already created and fail the probe instead.
> 
> Fixes: 7a974b29fe5d ("iommu/exynos: Rework runtime PM links management")
> Assisted-by: DeepSeek-V4.1-Flash
> Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
> ---
>  drivers/iommu/exynos-iommu.c | 14 +++++++++++++-
>  1 file changed, 13 insertions(+), 1 deletion(-)
> 



Multiple things here:
1. Your team ignored completely previous feedback.

2. You use multiple identities with this email, thus I actually doubt we speak
   with actual person.

3. Finally, same feedback:
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.

More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.

This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down.  Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.

Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem (so a patchset grouping multiple patches with a short cover
letter), how to document usage of LLM and how what you should not do
if this was posted in a good faith.

Best regards,
Krzysztof





^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure
  2026-10-09  3:45 [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure Haotian Zhang
  2026-10-09  6:10 ` Krzysztof Kozlowski
@ 2026-10-09 16:42 ` kernel test robot
  1 sibling, 0 replies; 3+ messages in thread
From: kernel test robot @ 2026-10-09 16:42 UTC (permalink / raw)
  To: Haotian Zhang, Marek Szyprowski, Will Deacon, Robin Murphy,
	Krzysztof Kozlowski, Peter Griffin, Alim Akhtar, Joerg Roedel
  Cc: llvm, oe-kbuild-all, iommu, linux-arm-kernel, linux-samsung-soc,
	linux-kernel

Hi Haotian,

kernel test robot noticed the following build warnings:

[auto build test WARNING on krzk/for-next]
[also build test WARNING on arm-perf/for-next/perf pinctrl-samsung/for-next linus/master v7.3-rc6 next-20261008]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]

url:    https://github.com/intel-lab-lkp/linux/commits/Haotian-Zhang/iommu-exynos-fix-NULL-pointer-dereference-on-device_link_add-failure/20261009-114539
base:   https://git.kernel.org/pub/scm/linux/kernel/git/krzk/linux.git for-next
patch link:    https://lore.kernel.org/r/20261009034539.3073100-1-vulab%40iscas.ac.cn
patch subject: [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure
config: arm-defconfig (https://download.01.org/0day-ci/archive/20261010/202610100049.FvaUUeCb-lkp@intel.com/config)
compiler: clang version 24.0.0git (https://github.com/llvm/llvm-project 242243a5814307de825db3428662d67b064e2cbc)
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20261010/202610100049.FvaUUeCb-lkp@intel.com/reproduce)

If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202610100049.FvaUUeCb-lkp@intel.com/

All warnings (new ones prefixed by >>):

>> drivers/iommu/exynos-iommu.c:1434:39: warning: variable 'tmp' is uninitialized when used here [-Wuninitialized]
    1434 |         list_for_each_entry_continue_reverse(tmp, &owner->controllers,
         |                                              ^~~
   drivers/iommu/exynos-iommu.c:1406:35: note: initialize the variable 'tmp' to silence this warning
    1406 |         struct sysmmu_drvdata *data, *tmp;
         |                                          ^
         |                                           = NULL
   1 warning generated.


vim +/tmp +1434 drivers/iommu/exynos-iommu.c

  1402	
  1403	static struct iommu_device *exynos_iommu_probe_device(struct device *dev)
  1404	{
  1405		struct exynos_iommu_owner *owner = dev_iommu_priv_get(dev);
  1406		struct sysmmu_drvdata *data, *tmp;
  1407	
  1408		if (!has_sysmmu(dev))
  1409			return ERR_PTR(-ENODEV);
  1410	
  1411		list_for_each_entry(data, &owner->controllers, owner_node) {
  1412			/*
  1413			 * SYSMMU will be runtime activated via device link
  1414			 * (dependency) to its master device, so there are no
  1415			 * direct calls to pm_runtime_get/put in this driver.
  1416			 */
  1417			data->link = device_link_add(dev, data->sysmmu,
  1418						     DL_FLAG_STATELESS |
  1419						     DL_FLAG_PM_RUNTIME);
  1420			if (!data->link) {
  1421				dev_err(dev, "Unable to link %s\n",
  1422					dev_name(data->sysmmu));
  1423				goto err_unlink;
  1424			}
  1425		}
  1426	
  1427		/* There is always at least one entry, see exynos_iommu_of_xlate() */
  1428		data = list_first_entry(&owner->controllers,
  1429					struct sysmmu_drvdata, owner_node);
  1430	
  1431		return &data->iommu;
  1432	
  1433	err_unlink:
> 1434		list_for_each_entry_continue_reverse(tmp, &owner->controllers,
  1435						     owner_node)
  1436			device_link_del(tmp->link);
  1437	
  1438		return ERR_PTR(-ENODEV);
  1439	}
  1440	

--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-09 16:43 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09  3:45 [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure Haotian Zhang
2026-10-09  6:10 ` Krzysztof Kozlowski
2026-10-09 16:42 ` kernel test robot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®