* [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure
@ 2026-10-09 3:45 Haotian Zhang
2026-10-09 6:10 ` Krzysztof Kozlowski
2026-10-09 16:42 ` kernel test robot
0 siblings, 2 replies; 3+ messages in thread
From: Haotian Zhang @ 2026-10-09 3:45 UTC (permalink / raw)
To: Marek Szyprowski, Will Deacon, Robin Murphy, Krzysztof Kozlowski,
Peter Griffin, Alim Akhtar, Joerg Roedel
Cc: iommu, linux-arm-kernel, linux-samsung-soc, linux-kernel
exynos_iommu_probe_device() stores the result of device_link_add() in
data->link without checking it for failure, although device_link_add()
returns NULL when the supplier is not PM initialized, on a dependency
cycle or on allocation failure. exynos_iommu_release_device() then calls
device_link_del() on that entry unconditionally, and device_link_del()
dereferences link->flags, so a NULL data->link causes a NULL pointer
dereference when the device is released.
Check the returned device link for NULL, unwind the links that were
already created and fail the probe instead.
Fixes: 7a974b29fe5d ("iommu/exynos: Rework runtime PM links management")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
---
drivers/iommu/exynos-iommu.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)
diff --git a/drivers/iommu/exynos-iommu.c b/drivers/iommu/exynos-iommu.c
index 874d05f4b396..ce0492691ef4 100644
--- a/drivers/iommu/exynos-iommu.c
+++ b/drivers/iommu/exynos-iommu.c
@@ -1403,7 +1403,7 @@ static phys_addr_t exynos_iommu_iova_to_phys(struct iommu_domain *iommu_domain,
static struct iommu_device *exynos_iommu_probe_device(struct device *dev)
{
struct exynos_iommu_owner *owner = dev_iommu_priv_get(dev);
- struct sysmmu_drvdata *data;
+ struct sysmmu_drvdata *data, *tmp;
if (!has_sysmmu(dev))
return ERR_PTR(-ENODEV);
@@ -1417,6 +1417,11 @@ static struct iommu_device *exynos_iommu_probe_device(struct device *dev)
data->link = device_link_add(dev, data->sysmmu,
DL_FLAG_STATELESS |
DL_FLAG_PM_RUNTIME);
+ if (!data->link) {
+ dev_err(dev, "Unable to link %s\n",
+ dev_name(data->sysmmu));
+ goto err_unlink;
+ }
}
/* There is always at least one entry, see exynos_iommu_of_xlate() */
@@ -1424,6 +1429,13 @@ static struct iommu_device *exynos_iommu_probe_device(struct device *dev)
struct sysmmu_drvdata, owner_node);
return &data->iommu;
+
+err_unlink:
+ list_for_each_entry_continue_reverse(tmp, &owner->controllers,
+ owner_node)
+ device_link_del(tmp->link);
+
+ return ERR_PTR(-ENODEV);
}
static void exynos_iommu_release_device(struct device *dev)
--
2.25.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure
2026-10-09 3:45 [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure Haotian Zhang
@ 2026-10-09 6:10 ` Krzysztof Kozlowski
2026-10-09 16:42 ` kernel test robot
1 sibling, 0 replies; 3+ messages in thread
From: Krzysztof Kozlowski @ 2026-10-09 6:10 UTC (permalink / raw)
To: Haotian Zhang
Cc: linux-kernel, linux-arm-kernel, iommu, linux-samsung-soc,
Marek Szyprowski, Will Deacon, Alim Akhtar, Peter Griffin,
Robin Murphy, Joerg Roedel
On Fri, 09 Oct 2026 11:45:39 +0800, Haotian Zhang wrote:
> exynos_iommu_probe_device() stores the result of device_link_add() in
> data->link without checking it for failure, although device_link_add()
> returns NULL when the supplier is not PM initialized, on a dependency
> cycle or on allocation failure. exynos_iommu_release_device() then calls
> device_link_del() on that entry unconditionally, and device_link_del()
> dereferences link->flags, so a NULL data->link causes a NULL pointer
> dereference when the device is released.
>
> Check the returned device link for NULL, unwind the links that were
> already created and fail the probe instead.
>
> Fixes: 7a974b29fe5d ("iommu/exynos: Rework runtime PM links management")
> Assisted-by: DeepSeek-V4.1-Flash
> Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
> ---
> drivers/iommu/exynos-iommu.c | 14 +++++++++++++-
> 1 file changed, 13 insertions(+), 1 deletion(-)
>
Multiple things here:
1. Your team ignored completely previous feedback.
2. You use multiple identities with this email, thus I actually doubt we speak
with actual person.
3. Finally, same feedback:
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.
More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.
This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down. Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.
Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem (so a patchset grouping multiple patches with a short cover
letter), how to document usage of LLM and how what you should not do
if this was posted in a good faith.
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure
2026-10-09 3:45 [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure Haotian Zhang
2026-10-09 6:10 ` Krzysztof Kozlowski
@ 2026-10-09 16:42 ` kernel test robot
1 sibling, 0 replies; 3+ messages in thread
From: kernel test robot @ 2026-10-09 16:42 UTC (permalink / raw)
To: Haotian Zhang, Marek Szyprowski, Will Deacon, Robin Murphy,
Krzysztof Kozlowski, Peter Griffin, Alim Akhtar, Joerg Roedel
Cc: llvm, oe-kbuild-all, iommu, linux-arm-kernel, linux-samsung-soc,
linux-kernel
Hi Haotian,
kernel test robot noticed the following build warnings:
[auto build test WARNING on krzk/for-next]
[also build test WARNING on arm-perf/for-next/perf pinctrl-samsung/for-next linus/master v7.3-rc6 next-20261008]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Haotian-Zhang/iommu-exynos-fix-NULL-pointer-dereference-on-device_link_add-failure/20261009-114539
base: https://git.kernel.org/pub/scm/linux/kernel/git/krzk/linux.git for-next
patch link: https://lore.kernel.org/r/20261009034539.3073100-1-vulab%40iscas.ac.cn
patch subject: [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure
config: arm-defconfig (https://download.01.org/0day-ci/archive/20261010/202610100049.FvaUUeCb-lkp@intel.com/config)
compiler: clang version 24.0.0git (https://github.com/llvm/llvm-project 242243a5814307de825db3428662d67b064e2cbc)
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20261010/202610100049.FvaUUeCb-lkp@intel.com/reproduce)
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202610100049.FvaUUeCb-lkp@intel.com/
All warnings (new ones prefixed by >>):
>> drivers/iommu/exynos-iommu.c:1434:39: warning: variable 'tmp' is uninitialized when used here [-Wuninitialized]
1434 | list_for_each_entry_continue_reverse(tmp, &owner->controllers,
| ^~~
drivers/iommu/exynos-iommu.c:1406:35: note: initialize the variable 'tmp' to silence this warning
1406 | struct sysmmu_drvdata *data, *tmp;
| ^
| = NULL
1 warning generated.
vim +/tmp +1434 drivers/iommu/exynos-iommu.c
1402
1403 static struct iommu_device *exynos_iommu_probe_device(struct device *dev)
1404 {
1405 struct exynos_iommu_owner *owner = dev_iommu_priv_get(dev);
1406 struct sysmmu_drvdata *data, *tmp;
1407
1408 if (!has_sysmmu(dev))
1409 return ERR_PTR(-ENODEV);
1410
1411 list_for_each_entry(data, &owner->controllers, owner_node) {
1412 /*
1413 * SYSMMU will be runtime activated via device link
1414 * (dependency) to its master device, so there are no
1415 * direct calls to pm_runtime_get/put in this driver.
1416 */
1417 data->link = device_link_add(dev, data->sysmmu,
1418 DL_FLAG_STATELESS |
1419 DL_FLAG_PM_RUNTIME);
1420 if (!data->link) {
1421 dev_err(dev, "Unable to link %s\n",
1422 dev_name(data->sysmmu));
1423 goto err_unlink;
1424 }
1425 }
1426
1427 /* There is always at least one entry, see exynos_iommu_of_xlate() */
1428 data = list_first_entry(&owner->controllers,
1429 struct sysmmu_drvdata, owner_node);
1430
1431 return &data->iommu;
1432
1433 err_unlink:
> 1434 list_for_each_entry_continue_reverse(tmp, &owner->controllers,
1435 owner_node)
1436 device_link_del(tmp->link);
1437
1438 return ERR_PTR(-ENODEV);
1439 }
1440
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-09 16:43 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09 3:45 [PATCH] iommu/exynos: fix NULL pointer dereference on device_link_add() failure Haotian Zhang
2026-10-09 6:10 ` Krzysztof Kozlowski
2026-10-09 16:42 ` kernel test robot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®