Thread (3 messages) 3 messages, 3 authors, 2025-06-27

Re: [PATCH] The sun50i_iommu_of_xlate() function didn't properly handle the case where of_find_device_by_node() returns NULL. This could lead to a NULL pointer dereference when accessing platform_get_drvdata(iommu_pdev) if the device node couldn't be found.

From: Robin Murphy <robin.murphy@arm.com>
Date: 2025-06-25 10:42:14
Also in: linux-iommu, linux-sunxi, lkml

On 2025-06-24 9:35 am, Zhang Shurong wrote:
Add a WARN_ON() check to detect this condition and return -ENODEV when it
occurs. This ensures proper error handling and helps diagnose incorrect
device tree configurations at runtime.
Please look at how this op is called in of_iommu_xlate(), then at how 
the ops are registered by sun50i_iommu_probe(), and then clarify how you 
think the driver could ever be bound to a device which does not exist.

Thanks,
Robin.
quoted hunk ↗ jump to hunk
Fixes: 4100b8c229b3 ("iommu: Add Allwinner H6 IOMMU driver")
Signed-off-by: Zhang Shurong <redacted>
---
  drivers/iommu/sun50i-iommu.c | 3 +++
  1 file changed, 3 insertions(+)
diff --git a/drivers/iommu/sun50i-iommu.c b/drivers/iommu/sun50i-iommu.c
index 76c9620af4bb..0f85850269ae 100644
--- a/drivers/iommu/sun50i-iommu.c
+++ b/drivers/iommu/sun50i-iommu.c
@@ -833,6 +833,9 @@ static int sun50i_iommu_of_xlate(struct device *dev,
  				 const struct of_phandle_args *args)
  {
  	struct platform_device *iommu_pdev = of_find_device_by_node(args->np);
+	if (WARN_ON(!iommu_pdev))
+		return -ENODEV;
+
  	unsigned id = args->args[0];
  
  	dev_iommu_priv_set(dev, platform_get_drvdata(iommu_pdev));
  
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help