Re: [PATCH 3/3] MIPS: Octeon: flash: use the simple map accessors without a shared eMMC

From: sashiko-bot

Date: Sat Oct 10 2026 - 13:32:15 EST


Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] mips: cavium-octeon: global state corruption on multiple flash probes
--

commit 9e242ec4162d9c7c06bd10d98f2bbfb32869d150
Author: Orgad Shaneh <orgads@xxxxxxxxx>

MIPS: Octeon: flash: use the simple map accessors without a shared eMMC

This patch updates the Cavium Octeon flash setup to use simple map accessors
when there is no shared eMMC host on the boot bus. It also changes the flash
bank width check to fail and unmap the memory if unsupported, rather than
just warning.

> diff --git a/arch/mips/cavium-octeon/flash_setup.c b/arch/mips/cavium-octeon/flash_setup.c
> index 3395acde4d60a..28fbe3d15c956 100644
> --- a/arch/mips/cavium-octeon/flash_setup.c
> +++ b/arch/mips/cavium-octeon/flash_setup.c
[ ... ]
> @@ -102,11 +113,26 @@ static int octeon_flash_probe(struct platform_device *pdev)
> flash_map.virt = ioremap(flash_map.phys, flash_map.size);
> pr_notice("Bootbus flash: Setting flash for %luMB flash at "
> "0x%08llx\n", flash_map.size >> 20, flash_map.phys);
> - WARN_ON(!map_bankwidth_supported(flash_map.bankwidth));
> - flash_map.read = octeon_flash_map_read;
> - flash_map.write = octeon_flash_map_write;
> - flash_map.copy_from = octeon_flash_map_copy_from;
> - flash_map.copy_to = octeon_flash_map_copy_to;
> + if (!map_bankwidth_supported(flash_map.bankwidth)) {
> + pr_err("Unsupported flash bank width %d\n",
> + flash_map.bankwidth);
> + iounmap(flash_map.virt);
> + return -EINVAL;
> + }

[Severity: High]
Since flash_map is a static global structure, what happens if there are
multiple flash devices probed sequentially?

The line just above this block unconditionally overwrites flash_map.virt
with a new ioremap() on each probe, which appears to leak the previous
mapping and corrupt the state of any already-registered MTD device.

If octeon_flash_probe() executes a second time and fails the bank width check
here, it calls iounmap(flash_map.virt) and returns an error. Does this unmap
operation turn the first successfully probed MTD device's shared reference
into a dangling pointer, leading to an invalid memory access when the first
device is accessed?

--
Sashiko AI review · https://sashiko.dev/#/patchset/20261010172142.2138956-1-orgads@xxxxxxxxx?part=3