Re: [PATCH net-next v3 2/2] net: pcs: rzn1-miic: Validate dtb configuration values
From: Simon Horman
Date: Fri Oct 09 2026 - 10:35:06 EST
On Tue, Oct 06, 2026 at 09:48:12AM -0700, Kyle Hendry via B4 Relay wrote:
> From: Kyle Hendry <khendry@xxxxxxxxxxxxxxxxxxxx>
>
> Bad configuration values from the dtb could result in out of bounds array
> access. Verify parsed values are within range for the SoC and fail the
> probe if invalid.
>
> Signed-off-by: Kyle Hendry <khendry@xxxxxxxxxxxxxxxxxxxx>
> ---
> drivers/net/pcs/pcs-rzn1-miic.c | 29 +++++++++++++++++++++++++++--
> 1 file changed, 27 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/net/pcs/pcs-rzn1-miic.c b/drivers/net/pcs/pcs-rzn1-miic.c
> index 31716241b58f..10622eb654d2 100644
> --- a/drivers/net/pcs/pcs-rzn1-miic.c
> +++ b/drivers/net/pcs/pcs-rzn1-miic.c
> @@ -693,16 +693,40 @@ static int miic_parse_dt(struct miic *miic, u32 *mode_cfg)
> memset(dt_val, MIIC_MODCTRL_CONF_NONE,
> sizeof(*dt_val) * miic->of_data->conf_conv_count);
>
> - if (of_property_read_u32(np, "renesas,miic-switch-portin", &conf) == 0)
> - dt_val[0] = conf;
> + if (of_property_read_u32(np, "renesas,miic-switch-portin", &conf) == 0) {
> + if (conf >= miic->of_data->conf_to_string_count) {
> + dev_err(miic->dev, "Port input configuration out of range: %d\n",
> + conf);
> + ret = -EINVAL;
> + goto err;
> + } else {
> + dt_val[0] = conf;
> + }
> + }
Hi Kyle,
Please drop the else arm here, it is unnecessary.
Doing so will move the code into the preferred style
of handling errors conditionally while keeping
the main thread of execution outside (extra) conditions.
(Completely untested, but I mean like this.)
if (of_property_read_u32(np, "renesas,miic-switch-portin", &conf) == 0) {
if (conf >= miic->of_data->conf_to_string_count) {
dev_err(miic->dev, "Port input configuration out of range: %d\n",
conf);
ret = -EINVAL;
goto err;
}
dt_val[0] = conf;
}
With that change, feel free to add:
Reviewed-by: Simon Horman <horms@xxxxxxxxxx>
--
pw-bot: changes-requested