From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 650F43AB5DC for ; Fri, 21 Aug 2026 11:53:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787313204; cv=none; b=bmObZ4Et55MheCj4sFVEx7lBassLa00RnVX73i7KsUP6c6v3lLGnROAVsr6xzFh94xaKoWf3ZtkXOvNjTq4p2zoXENwXYgFfr4B8TDFW2M8WBSmLD4J3D12iT9nzia7e0P4Z+KAFBOZxE8Lo7NPfrqHjALG692i4sxhIy1JKUWU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787313204; c=relaxed/simple; bh=twJtsqkg53bpD4bVrRNiLIZX920vdyn30TopGVNGaE8=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=pJl23j3UYuRZRiD40rq5BVywOTy9PDpdGz4MWyJEP/a5qmqIyiwde+fPLUSFbwj4OrNYFq4hXXpNK80GzmxpMEL+51Vx40fALIu/KBm7dPh7QcLB0ccFZlf51Qv/2JzZ7TffUogcEFStxITgoAoHwXJ85lY4+oHq/N5txephERg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FK37vJia; arc=none smtp.client-ip=209.85.128.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FK37vJia" Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-495437bb891so4577445e9.1 for ; Fri, 21 Aug 2026 04:53:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787313198; x=1787917998; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=vEGJVYFUVUAeETEsjFVbgJcz6cD970D0BMiWavG2Bfs=; b=FK37vJiaIMhcSk+PPTZx9em11EJWFlPON8S0OgCxSjxwX2kdnKQRQT0CSGFSGrrih0 hkmdJXImaXMLnwIvZSU7bEcbbTFShTKPiKmHmY/GMcW5t5bBbjCRgiYgxrpBzlLBvwPQ R7ZScjMJPkFiU8DNi/5UbaludHwjgueT/RT7/c/rmT6OLlMue1+xNF4sxk/uE/A2rqIP 2N0/7Ce9ZpAyx6xMHK1SWd+2zz9N2eKSXQFYk2MQNKeWzwoUYjCPixLBTEJ2N33tDv5K jyTt97UAuUermFxX/Sp6kt/NVAAYltouHhLDselC3lEjbM8dmH2TSWMo3KLGMkMhUyXs MaGQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787313198; x=1787917998; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=vEGJVYFUVUAeETEsjFVbgJcz6cD970D0BMiWavG2Bfs=; b=M0u3XzV2AvrTaZGXJJ68YVmWiQOQLsbH2zIQIcpdSrLmAamczeVGPJSwH8xnxFk8Gi B9LzvK7xMhUrcLUdvgPfAAGamZfwfp2zGcvoE5lttV4rw5prburnUVRqgTBBkDrhY8TU wObqUgWBhFEWbpPn4utVu8URDt56BLEwcI+Ld1V9VwXKL7lDJ0Sv1iWs12SotPbVxUMj jCfwgI32LWXcvtZfzxcMHIzBrk2G39Sqo4yhWOR8M8BlBpwqw6r6h6i++Aqtdqj28Uc7 Mnp5YM6uSJepP/DFylC/PEXx8kDcyZ6W4ipx0zyVSFweZHAlgnzp1ap1RB8pD6yGGVQg W0VA== X-Forwarded-Encrypted: i=1; AHgh+Rp+f1fL0QLNphGtZlYjHq1JgFxi+JPg+fyiGLqrH7QAzgDMKTgw+T4UrLR5ytyCxC4WWBz68JEIPvWbKY4=@vger.kernel.org X-Gm-Message-State: AOJu0YykBwxVnxRi2BqQa8/wRB/oTleZ+r9G0aG2rCPqyu8+0XfW3DmS 45RF1jF2XFuVDRnYZSS4KB7w+VaADZGT5FIWd3KYV8PitQcM/J5xGvAs X-Gm-Gg: AR+sD12flkUr9VJixV+RJXSBdAZ2xh7ZI6Y0IPu1y+hFdzxrGkS822VQqsWt/6Cd1e1 qgNgztnUHCWsRBXZwtFTLPtkSNm+/y3wfXqyRtIw25fE684UDKnlirJAp9Zk6MBAip9uxO2wq/v i+rhM1ftMwfjM9+0z2332NSoln4wgZ5kLTDvfMBNKDdm0sxU+kxkyPaBkzfxUwpsHdZz4LGMUs4 Q/wJa17iBzOKDSwbg2y8UsQ/ghbuHUAtkh9sbBlL2ZV3qBo2tVOLLx/4tplR5dK/GZrF2SHJW5z ki1YYF0AIuHpuHL/qHQQ0Cr2qJvgsRwxveCmyIoNHuB/r/UlvbOY/r0xl1cwVg8uPZC/+19AbUp CVOvuc/mjRYYSHHIiM8OMYtXohfPwZwTVE3KgQj2aAIb/N2byh8AZf6/JLuWhc/A9Y7gRZhQsv5 dA5PsISd//89hlBtCv0irP1DIpc1YvqgsV2Ut5K5UQCJqREz8xmXNXWzdB X-Received: by 2002:a05:600c:1912:b0:499:8d9b:832c with SMTP id 5b1f17b1804b1-499b9182141mr49688785e9.4.1787313197554; Fri, 21 Aug 2026 04:53:17 -0700 (PDT) Received: from localhost ([2c0f:3d00:6be:8900:ce5e:9212:ea4b:f30]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499b9b81602sm16565645e9.3.2026.08.21.04.53.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 04:53:16 -0700 (PDT) Date: Fri, 21 Aug 2026 14:53:13 +0300 From: Dan Carpenter To: hanzhijian Cc: Greg Kroah-Hartman , Viresh Kumar , Johan Hovold , Alex Elder , greybus-dev@lists.linaro.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org Subject: Re: [PATCH] staging: greybus: bootrom: fix potential NULL dereference Message-ID: References: <20260821113540.1989561-1-hanzhijian1991@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260821113540.1989561-1-hanzhijian1991@gmail.com> You're using the word "potential" but the commit message correctly explains why a NULL dereference is impossible. Don't say potentially for things which are impossible. On Fri, Aug 21, 2026 at 07:35:40PM +0800, hanzhijian wrote: > In gb_bootrom_get_firmware(), the queue_work label dereferences fw->size > on a path where fw may have been set to NULL via the "if (!fw) goto > unlock" path. This is currently masked at runtime by the !ret > short-circuit (ret is non-zero on every path where fw can be NULL), but > it relies on an implicit invariant that is fragile and hard to follow. A lot of people would argue that the original code is easy to follow. In your code, to see what is passed on error you have to scroll all the way to the top of the function to see the "next_request = NEXT_REQ_GET_FIRMWARE;" assignment. In the existing code, it's clear, this is what we pass on error, this is what we pass on success. It's not really fragile either. If we screwed up and forgot to set the error code or something then Smatch would warn about that. drivers/staging/greybus/bootrom.c:300 gb_bootrom_get_firmware() error: we previously assumed 'fw' could be null (see line 266) Or on the earlier paths, we would get an uninitialized variable warning. regards, dan carpenter