Thread (22 messages) flat view 22 messages, 3 authors, 5d ago

Re: [PATCH v9 7/9] pinctrl: mediatek: mt6397: Add MediaTek MT6392

From: sashiko-bot@kernel.org
Date: 2026-08-20 12:51:31
Also in: linux-input

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Unbinding the pinctrl driver leads to a Use-After-Free of the gpiochip structure because it is never unregistered.
--
--- Patch [7]: [PATCH v9 7/9] pinctrl: mediatek: mt6397: Add MediaTek MT6392 ---
commit 8de420548b885f3f527c1ef77d05dce6a4500878
Author: Luca Leonardo Scorcia [off-list ref]

pinctrl: mediatek: mt6397: Add MediaTek MT6392
    
This commit adds support for the MT6392 pinctrl device by introducing its pins
definition and updating the MT6397 driver to retrieve device data from the
match table.
quoted hunk ↗ jump to hunk
diff --git a/drivers/pinctrl/mediatek/pinctrl-mt6397.c b/drivers/pinctrl/mediatek/pinctrl-mt6397.c
index 03d0f65d7bcc1..8ba02e70595ce 100644
--- a/drivers/pinctrl/mediatek/pinctrl-mt6397.c
+++ b/drivers/pinctrl/mediatek/pinctrl-mt6397.c
[ ... ]
quoted hunk ↗ jump to hunk
@@ -40,13 +62,24 @@ static const struct mtk_pinctrl_devdata mt6397_pinctrl_data = {
 static int mt6397_pinctrl_probe(struct platform_device *pdev)
 {
 	struct mt6397_chip *mt6397;
+	const struct mtk_pinctrl_devdata *data;
+
+	data = device_get_match_data(&pdev->dev);
+	if (!data)
+		return -ENOENT;
 
 	mt6397 = dev_get_drvdata(pdev->dev.parent);
-	return mtk_pctrl_init(pdev, &mt6397_pinctrl_data, mt6397->regmap);
+	return mtk_pctrl_init(pdev, data, mt6397->regmap);
 }
[Severity: High]
This is a pre-existing issue, but does unbinding this driver lead to a
use-after-free of the gpiochip structure?

Looking at mtk_pctrl_init() in drivers/pinctrl/mediatek/pinctrl-mtk-common.c,
the pctl->chip memory is allocated using devm_kzalloc() but registered using
the unmanaged gpiochip_add_data() function:

drivers/pinctrl/mediatek/pinctrl-mtk-common.c:mtk_pctrl_init() {
    ...
    pctl->chip = devm_kzalloc(&pdev->dev, sizeof(*pctl->chip), GFP_KERNEL);
    ...
    ret = gpiochip_add_data(pctl->chip, pctl);
    ...
}

Since the MT6397 platform driver lacks a .remove callback to explicitly call
gpiochip_remove(), unbinding the driver via sysfs causes devres to free
pctl->chip while it remains registered in the global gpiolib lists.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260820122242.120039-1-l.scorcia@gmail.com?part=7
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help