Thread (12 messages) flat view 12 messages, 3 authors, 3d ago

Re: [PATCH v7 3/7] mtd: spi-nor: sfdp: expose the SFDP as a read-only NVMEM device

From: sashiko-bot@kernel.org
Date: 2026-08-13 10:52:08

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Use-After-Free of device tree node in NVMEM device due to premature of_node_put().
--
--- Patch [3]: [PATCH v7 3/7] mtd: spi-nor: sfdp: expose the SFDP as a read-only NVMEM device ---
commit d892664b27bcd5da338917980297630345d51e30
Author: Manikandan Muralidharan [off-list ref]

mtd: spi-nor: sfdp: expose the SFDP as a read-only NVMEM device

This commit exposes the cached SFDP table as a read-only NVMEM device
in on-flash byte order. The NVMEM device is registered only when an
sfdp node is present in the device tree.
quoted hunk ↗ jump to hunk
diff --git a/drivers/mtd/spi-nor/core.c b/drivers/mtd/spi-nor/core.c
index ccf4396cdcd04..0425af6e898fd 100644
--- a/drivers/mtd/spi-nor/core.c
+++ b/drivers/mtd/spi-nor/core.c
[ ... ]
quoted hunk ↗ jump to hunk
@@ -3001,6 +3002,75 @@ static void spi_nor_init_fixup_flags(struct spi_nor *nor)
+static int spi_nor_register_sfdp_nvmem(struct spi_nor *nor)
+{
[ ... ]
+	config.dev = dev;
+	config.of_node = np;
+	config.name = "sfdp";
+	config.id = NVMEM_DEVID_AUTO;
+	config.owner = THIS_MODULE;
+	config.read_only = true;
+	config.word_size = 1;
+	config.stride = 1;
+	config.size = (int)(nor->sfdp->num_dwords * sizeof(*nor->sfdp->dwords));
+	config.reg_read = spi_nor_sfdp_reg_read;
+	config.priv = nor;
+
+	nvmem = devm_nvmem_register(dev, &config);
+	of_node_put(np);
[Severity: High]
Does calling of_node_put() here leave the NVMEM device with a dangling
pointer to the device tree node?

The nvmem core assigns config.of_node to the underlying device structure
but does not take an additional reference count on the node itself. 

If a device tree overlay is removed later, causing the node's reference
count to drop to zero, could this lead to a use-after-free when the nvmem
framework or sysfs subsequently accesses the node?
+	if (IS_ERR(nvmem)) {
+		/* NVMEM support is optional. */
[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260812104955.485667-1-manikandan.m@microchip.com?part=3
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help