718-v6.9-net-phy-qcom-at803x-fix-kernel-panic-with-at8031_pro.patch 1.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445
  1. From 6a4aee277740d04ac0fd54cfa17cc28261932ddc Mon Sep 17 00:00:00 2001
  2. From: Christian Marangi <[email protected]>
  3. Date: Mon, 25 Mar 2024 20:06:19 +0100
  4. Subject: [PATCH] net: phy: qcom: at803x: fix kernel panic with at8031_probe
  5. On reworking and splitting the at803x driver, in splitting function of
  6. at803x PHYs it was added a NULL dereference bug where priv is referenced
  7. before it's actually allocated and then is tried to write to for the
  8. is_1000basex and is_fiber variables in the case of at8031, writing on
  9. the wrong address.
  10. Fix this by correctly setting priv local variable only after
  11. at803x_probe is called and actually allocates priv in the phydev struct.
  12. Reported-by: William Wortel <[email protected]>
  13. Cc: <[email protected]>
  14. Fixes: 25d2ba94005f ("net: phy: at803x: move specific at8031 probe mode check to dedicated probe")
  15. Signed-off-by: Christian Marangi <[email protected]>
  16. Reviewed-by: Andrew Lunn <[email protected]>
  17. Link: https://lore.kernel.org/r/[email protected]
  18. Signed-off-by: Paolo Abeni <[email protected]>
  19. ---
  20. drivers/net/phy/qcom/at803x.c | 4 +++-
  21. 1 file changed, 3 insertions(+), 1 deletion(-)
  22. --- a/drivers/net/phy/qcom/at803x.c
  23. +++ b/drivers/net/phy/qcom/at803x.c
  24. @@ -797,7 +797,7 @@ static int at8031_parse_dt(struct phy_de
  25. static int at8031_probe(struct phy_device *phydev)
  26. {
  27. - struct at803x_priv *priv = phydev->priv;
  28. + struct at803x_priv *priv;
  29. int mode_cfg;
  30. int ccr;
  31. int ret;
  32. @@ -806,6 +806,8 @@ static int at8031_probe(struct phy_devic
  33. if (ret)
  34. return ret;
  35. + priv = phydev->priv;
  36. +
  37. /* Only supported on AR8031/AR8033, the AR8030/AR8035 use strapping
  38. * options.
  39. */