* [PATCH net-next v2 0/3] net: pcs: rzn1-miic: Validate dtb configuration values
@ 2026-09-28 21:19 Kyle Hendry via B4 Relay
2026-09-28 21:19 ` [PATCH net-next v2 1/3] net: pcs: rzn1-miic: Fix port numbering on RZ/T2H Kyle Hendry via B4 Relay
` (3 more replies)
0 siblings, 4 replies; 6+ messages in thread
From: Kyle Hendry via B4 Relay @ 2026-09-28 21:19 UTC (permalink / raw)
To: Clément Léger, Andrew Lunn, Heiner Kallweit,
Russell King, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Lad Prabhakar
Cc: linux-renesas-soc, netdev, linux-kernel, Kyle Hendry
This series addresses issues found when reviewing another fix:
https://lore.kernel.org/netdev/20260915-rzn1-miic-fix-array-v5-1-b7173fd5b97d@reliablecontrols.com/
Invalid values from the dtb could cause out of bounds array access. Checking
the values as they're parsed should prevent this.
Signed-off-by: Kyle Hendry <khendry@reliablecontrols.com>
---
Changes in v2:
- Simplify fixes by making miic_port_max the last documented port number
- Add fixes tags
- Link to v1: https://lore.kernel.org/r/20260925-miic-validate-dtb-v1-0-3a6db9bb75ec@reliablecontrols.com
---
Kyle Hendry (3):
net: pcs: rzn1-miic: Fix port numbering on RZ/T2H
net: pcs: rzn1-miic: Fix miic register initialization loop
net: pcs: rzn1-miic: Validate dtb configuration values
drivers/net/pcs/pcs-rzn1-miic.c | 25 +++++++++++++++++++++++--
1 file changed, 23 insertions(+), 2 deletions(-)
---
base-commit: 014d795c73837ea2339a4ea8e8f82c6e959b845d
change-id: 20260924-miic-validate-dtb-bfc4b380b782
Best regards,
--
Kyle Hendry <khendry@reliablecontrols.com>
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH net-next v2 1/3] net: pcs: rzn1-miic: Fix port numbering on RZ/T2H
2026-09-28 21:19 [PATCH net-next v2 0/3] net: pcs: rzn1-miic: Validate dtb configuration values Kyle Hendry via B4 Relay
@ 2026-09-28 21:19 ` Kyle Hendry via B4 Relay
2026-09-28 21:19 ` [PATCH net-next v2 2/3] net: pcs: rzn1-miic: Fix miic register initialization loop Kyle Hendry via B4 Relay
` (2 subsequent siblings)
3 siblings, 0 replies; 6+ messages in thread
From: Kyle Hendry via B4 Relay @ 2026-09-28 21:19 UTC (permalink / raw)
To: Clément Léger, Andrew Lunn, Heiner Kallweit,
Russell King, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Lad Prabhakar
Cc: linux-renesas-soc, netdev, linux-kernel, Kyle Hendry
From: Kyle Hendry <khendry@reliablecontrols.com>
The port numbers on the RZ/T2H are documented as 0 to 3. Update the info
structure to reflect this.
Fixes: 08f89e42121d421b ("net: pcs: rzn1-miic: Add RZ/T2H MIIC support")
Signed-off-by: Kyle Hendry <khendry@reliablecontrols.com>
---
drivers/net/pcs/pcs-rzn1-miic.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/pcs/pcs-rzn1-miic.c b/drivers/net/pcs/pcs-rzn1-miic.c
index cb74861e823c..df70309c2d97 100644
--- a/drivers/net/pcs/pcs-rzn1-miic.c
+++ b/drivers/net/pcs/pcs-rzn1-miic.c
@@ -838,7 +838,7 @@ static struct miic_of_data rzt2h_miic_of_data = {
.index_to_string = rzt2h_index_to_string,
.index_to_string_count = ARRAY_SIZE(rzt2h_index_to_string),
.miic_port_start = 0,
- .miic_port_max = 4,
+ .miic_port_max = 3,
.sw_mode_mask = GENMASK(2, 0),
.reset_ids = rzt2h_reset_ids,
.reset_count = ARRAY_SIZE(rzt2h_reset_ids),
--
2.43.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH net-next v2 2/3] net: pcs: rzn1-miic: Fix miic register initialization loop
2026-09-28 21:19 [PATCH net-next v2 0/3] net: pcs: rzn1-miic: Validate dtb configuration values Kyle Hendry via B4 Relay
2026-09-28 21:19 ` [PATCH net-next v2 1/3] net: pcs: rzn1-miic: Fix port numbering on RZ/T2H Kyle Hendry via B4 Relay
@ 2026-09-28 21:19 ` Kyle Hendry via B4 Relay
2026-09-28 21:19 ` [PATCH net-next v2 3/3] net: pcs: rzn1-miic: Validate dtb configuration values Kyle Hendry via B4 Relay
2026-09-28 21:25 ` [PATCH net-next v2 0/3] " netdev-bot+sinfo
3 siblings, 0 replies; 6+ messages in thread
From: Kyle Hendry via B4 Relay @ 2026-09-28 21:19 UTC (permalink / raw)
To: Clément Léger, Andrew Lunn, Heiner Kallweit,
Russell King, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Lad Prabhakar
Cc: linux-renesas-soc, netdev, linux-kernel, Kyle Hendry
From: Kyle Hendry <khendry@reliablecontrols.com>
The function to write default values to miic registers was looping from
zero to miic_port_max, which might not cover all ports depending on SoC
numbering. Determine the port count from SoC data and loop over that.
Fixes: c112520de041758e ("net: pcs: rzn1-miic: move port range handling into SoC data")
Signed-off-by: Kyle Hendry <khendry@reliablecontrols.com>
---
drivers/net/pcs/pcs-rzn1-miic.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/net/pcs/pcs-rzn1-miic.c b/drivers/net/pcs/pcs-rzn1-miic.c
index df70309c2d97..9e830932ce49 100644
--- a/drivers/net/pcs/pcs-rzn1-miic.c
+++ b/drivers/net/pcs/pcs-rzn1-miic.c
@@ -520,6 +520,7 @@ EXPORT_SYMBOL(miic_destroy);
static int miic_init_hw(struct miic *miic, u32 cfg_mode)
{
u8 sw_mode_mask = miic->of_data->sw_mode_mask;
+ int num_ports;
int port;
/* Unlock write access to accessory registers (cf datasheet). If this
@@ -535,7 +536,10 @@ static int miic_init_hw(struct miic *miic, u32 cfg_mode)
miic_reg_writel(miic, MIIC_MODCTRL,
((cfg_mode << __ffs(sw_mode_mask)) & sw_mode_mask));
- for (port = 0; port < miic->of_data->miic_port_max; port++) {
+ num_ports = miic->of_data->miic_port_max -
+ miic->of_data->miic_port_start + 1;
+
+ for (port = 0; port < num_ports; port++) {
miic_converter_enable(miic, port, 0);
/* Disable speed/duplex control from these registers, datasheet
* says switch registers should be used to setup switch port
--
2.43.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH net-next v2 3/3] net: pcs: rzn1-miic: Validate dtb configuration values
2026-09-28 21:19 [PATCH net-next v2 0/3] net: pcs: rzn1-miic: Validate dtb configuration values Kyle Hendry via B4 Relay
2026-09-28 21:19 ` [PATCH net-next v2 1/3] net: pcs: rzn1-miic: Fix port numbering on RZ/T2H Kyle Hendry via B4 Relay
2026-09-28 21:19 ` [PATCH net-next v2 2/3] net: pcs: rzn1-miic: Fix miic register initialization loop Kyle Hendry via B4 Relay
@ 2026-09-28 21:19 ` Kyle Hendry via B4 Relay
2026-09-28 21:25 ` [PATCH net-next v2 0/3] " netdev-bot+sinfo
3 siblings, 0 replies; 6+ messages in thread
From: Kyle Hendry via B4 Relay @ 2026-09-28 21:19 UTC (permalink / raw)
To: Clément Léger, Andrew Lunn, Heiner Kallweit,
Russell King, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Lad Prabhakar
Cc: linux-renesas-soc, netdev, linux-kernel, Kyle Hendry
From: Kyle Hendry <khendry@reliablecontrols.com>
Bad configuration values from the dtb could result in out of bounds array
access. Verify parsed values are within range for the SoC and fail the
probe if invalid.
Signed-off-by: Kyle Hendry <khendry@reliablecontrols.com>
---
drivers/net/pcs/pcs-rzn1-miic.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/drivers/net/pcs/pcs-rzn1-miic.c b/drivers/net/pcs/pcs-rzn1-miic.c
index 9e830932ce49..9a4c6d3b7d42 100644
--- a/drivers/net/pcs/pcs-rzn1-miic.c
+++ b/drivers/net/pcs/pcs-rzn1-miic.c
@@ -697,9 +697,25 @@ static int miic_parse_dt(struct miic *miic, u32 *mode_cfg)
if (of_property_read_u32(conv, "reg", &port))
continue;
+ if (port < miic->of_data->miic_port_start ||
+ port > miic->of_data->miic_port_max) {
+ dev_err(miic->dev, "Port number out of range: %d\n", port);
+ of_node_put(conv);
+ ret = -EINVAL;
+ goto err;
+ }
+
if (of_property_read_u32(conv, "renesas,miic-input", &conf))
continue;
+ if (conf >= miic->of_data->conf_to_string_count) {
+ dev_err(miic->dev, "Port %d configuration out of range: %d\n",
+ port, conf);
+ of_node_put(conv);
+ ret = -EINVAL;
+ goto err;
+ }
+
/* Adjust for 0 based index */
dt_val[port + !miic->of_data->miic_port_start] = conf;
@@ -709,6 +725,7 @@ static int miic_parse_dt(struct miic *miic, u32 *mode_cfg)
}
ret = miic_match_dt_conf(miic, dt_val, mode_cfg);
+err:
kfree(dt_val);
return ret;
--
2.43.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH net-next v2 0/3] net: pcs: rzn1-miic: Validate dtb configuration values
2026-09-28 21:19 [PATCH net-next v2 0/3] net: pcs: rzn1-miic: Validate dtb configuration values Kyle Hendry via B4 Relay
` (2 preceding siblings ...)
2026-09-28 21:19 ` [PATCH net-next v2 3/3] net: pcs: rzn1-miic: Validate dtb configuration values Kyle Hendry via B4 Relay
@ 2026-09-28 21:25 ` netdev-bot+sinfo
2026-09-29 18:13 ` Kyle Hendry
3 siblings, 1 reply; 6+ messages in thread
From: netdev-bot+sinfo @ 2026-09-28 21:25 UTC (permalink / raw)
To: khendry
Cc: Clément Léger, Andrew Lunn, Heiner Kallweit,
Russell King, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Lad Prabhakar, linux-renesas-soc, netdev,
linux-kernel
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH net-next v2 0/3] net: pcs: rzn1-miic: Validate dtb configuration values
2026-09-28 21:25 ` [PATCH net-next v2 0/3] " netdev-bot+sinfo
@ 2026-09-29 18:13 ` Kyle Hendry
0 siblings, 0 replies; 6+ messages in thread
From: Kyle Hendry @ 2026-09-29 18:13 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: Clément Léger, Andrew Lunn, Heiner Kallweit,
Russell King, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Lad Prabhakar, linux-renesas-soc, netdev,
linux-kernel
On 28-Sep-26 14:25, netdev-bot+sinfo@kernel.org wrote:
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
>
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
>
> The evaluation is done by an LLM so it may be wrong, if you think
> that is the case please reply and explain.
On the RZ/N1D I can trigger a KASAN slab-out-of-bounds error by defining
miic 6 in the dts. I can also trigger a KASAN global-out-of-bounds error
by configuring a miic input with a value outside the defined range.
I don't have a RZ/T2H to test with, but after investigating the sashiko
reviews [1], [2] I agree that there is still a bug when checking for
miic_port_max. If the value in rzt2h_miic_of_data is correct and being
used as intended I can resubmit the patch using conf_conv_count instead.
If the fixes tags were added inappropriately, I can remove them and
resubmit this series.
[1]
https://lore.kernel.org/all/178955899323.22033.2372714834297554596@kernel.org/
[2]
https://lore.kernel.org/all/178955899447.22033.5754427139793967412@kernel.org/
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-29 18:13 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 21:19 [PATCH net-next v2 0/3] net: pcs: rzn1-miic: Validate dtb configuration values Kyle Hendry via B4 Relay
2026-09-28 21:19 ` [PATCH net-next v2 1/3] net: pcs: rzn1-miic: Fix port numbering on RZ/T2H Kyle Hendry via B4 Relay
2026-09-28 21:19 ` [PATCH net-next v2 2/3] net: pcs: rzn1-miic: Fix miic register initialization loop Kyle Hendry via B4 Relay
2026-09-28 21:19 ` [PATCH net-next v2 3/3] net: pcs: rzn1-miic: Validate dtb configuration values Kyle Hendry via B4 Relay
2026-09-28 21:25 ` [PATCH net-next v2 0/3] " netdev-bot+sinfo
2026-09-29 18:13 ` Kyle Hendry
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®