]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
of/address: Fix NULL bus dereference in of_pci_range_parser_one()
authorCarlo Caione <ccaione@baylibre.com>
Mon, 27 Jul 2026 08:36:59 +0000 (10:36 +0200)
committerRob Herring (Arm) <robh@kernel.org>
Tue, 28 Jul 2026 15:34:37 +0000 (10:34 -0500)
The bus matching rework made of_match_bus() return NULL for nodes with
ranges/dma-ranges but no local #address-cells. parser_init() stored that
NULL bus, and the range iterator later dereferenced it.

Reject such nodes in parser_init(), leaving an explicit empty
iterator for callers that ignore the init return, and make
of_dma_get_max_cpu_address() honour the init failure so a rejected node
cannot clamp the DMA limit.

Fixes: 64ee3cf096ac ("of/address: Rework bus matching to avoid warnings")
Cc: stable@vger.kernel.org
Signed-off-by: Carlo Caione <ccaione@baylibre.com>
Link: https://patch.msgid.link/20260727-of-range-parser-null-bus-v3-1-be01b708a4ce@baylibre.com
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
drivers/of/address.c

index cf4aab11e9b1f1e6085101c35c31550f47265f8b..499d37ceae210ac844eef853aeecbfabaaa5e138 100644 (file)
@@ -753,6 +753,7 @@ EXPORT_SYMBOL(of_property_read_reg);
 static int parser_init(struct of_pci_range_parser *parser,
                        struct device_node *node, const char *name)
 {
+       const __be32 *range;
        int rlen;
 
        parser->node = node;
@@ -761,12 +762,20 @@ static int parser_init(struct of_pci_range_parser *parser,
        parser->ns = of_bus_n_size_cells(node);
        parser->dma = !strcmp(name, "dma-ranges");
        parser->bus = of_match_bus(node);
+       parser->range = NULL;
+       parser->end = NULL;
 
-       parser->range = of_get_property(node, name, &rlen);
-       if (parser->range == NULL)
+       range = of_get_property(node, name, &rlen);
+       if (!range)
                return -ENOENT;
 
-       parser->end = parser->range + rlen / sizeof(__be32);
+       if (!parser->bus ||
+           !OF_CHECK_COUNTS(parser->na, parser->ns) ||
+           !OF_CHECK_ADDR_COUNT(parser->pna))
+               return -EINVAL;
+
+       parser->range = range;
+       parser->end = range + rlen / sizeof(__be32);
 
        return 0;
 }
@@ -792,7 +801,7 @@ struct of_pci_range *of_pci_range_parser_one(struct of_pci_range_parser *parser,
        int na = parser->na;
        int ns = parser->ns;
        int np = parser->pna + na + ns;
-       int busflag_na = parser->bus->flag_cells;
+       int busflag_na;
 
        if (!range)
                return NULL;
@@ -800,6 +809,8 @@ struct of_pci_range *of_pci_range_parser_one(struct of_pci_range_parser *parser,
        if (!parser->range || parser->range + np > parser->end)
                return NULL;
 
+       busflag_na = parser->bus->flag_cells;
+
        range->flags = parser->bus->get_flags(parser->range);
 
        range->bus_addr = of_read_number(parser->range + busflag_na, na - busflag_na);
@@ -976,8 +987,7 @@ phys_addr_t __init of_dma_get_max_cpu_address(struct device_node *np)
                np = of_root;
 
        ranges = of_get_property(np, "dma-ranges", &len);
-       if (ranges && len) {
-               of_dma_range_parser_init(&parser, np);
+       if (ranges && len && !of_dma_range_parser_init(&parser, np)) {
                for_each_of_range(&parser, &range)
                        if (range.cpu_addr + range.size > cpu_end)
                                cpu_end = range.cpu_addr + range.size - 1;