Somewhen between 6.10 and 6.11 the driver started to crash on my MacBookPro14,3. The property doesn't exist and 'tmp' remains uninitialized, so we pass a random pointer to devm_kstrdup(). The crash I am getting looks like this: BUG: unable to handle page fault for address: 00007f033c669379 PF: supervisor read access in kernel mode PF: error_code(0x0001) - permissions violation PGD 8000000101341067 P4D 8000000101341067 PUD 101340067 PMD 1013bb067 PTE 800000010aee9025 Oops: Oops: 0001 [#1] SMP PTI CPU: 4 UID: 0 PID: 827 Comm: (udev-worker) Not tainted 6.11.8-gentoo #1 Hardware name: Apple Inc. MacBookPro14,3/Mac-551B86E5744E2388, BIOS 529.140.2.0.0 06/23/2024 RIP: 0010:strlen+0x4/0x30 Code: f7 75 ec 31 c0 c3 cc cc cc cc 48 89 f8 c3 cc cc cc cc 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa <80> 3f 00 74 14 48 89 f8 48 83 c0 01 80 38 00 75 f7 48 29 f8 c3 cc RSP: 0018:ffffb4aac0683ad8 EFLAGS: 00010202 RAX: 00000000ffffffea RBX: 00007f033c669379 RCX: 0000000000000001 RDX: 0000000000000cc0 RSI: 00007f033c669379 RDI: 00007f033c669379 RBP: 00000000ffffffea R08: 0000000000000000 R09: 00000000c0ba916a R10: ffffffffffffffff R11: ffffffffb61ea260 R12: ffff91f7815b50c8 R13: 0000000000000cc0 R14: ffff91fafefffe30 R15: ffffb4aac0683b30 FS: 00007f033ccbe8c0(0000) GS:ffff91faeed00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f033c669379 CR3: 0000000107b1e004 CR4: 00000000003706f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> ? __die+0x23/0x70 ? page_fault_oops+0x149/0x4c0 ? raw_spin_rq_lock_nested+0xe/0x20 ? sched_balance_newidle+0x22b/0x3c0 ? update_load_avg+0x78/0x770 ? exc_page_fault+0x6f/0x150 ? asm_exc_page_fault+0x26/0x30 ? __pfx_pci_conf1_write+0x10/0x10 ? strlen+0x4/0x30 devm_kstrdup+0x25/0x70 brcmf_of_probe+0x273/0x350 [brcmfmac] Signed-off-by: Stefan Dösinger <stefan@codeweavers.com> Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com> Signed-off-by: Kalle Valo <kvalo@kernel.org> Link: https://patch.msgid.link/20250106170958.3595-1-stefan@codeweavers.com
156 lines
3.8 KiB
C
156 lines
3.8 KiB
C
// SPDX-License-Identifier: ISC
|
|
/*
|
|
* Copyright (c) 2014 Broadcom Corporation
|
|
*/
|
|
#include <linux/init.h>
|
|
#include <linux/of.h>
|
|
#include <linux/of_irq.h>
|
|
#include <linux/of_net.h>
|
|
#include <linux/clk.h>
|
|
|
|
#include <defs.h>
|
|
#include "debug.h"
|
|
#include "core.h"
|
|
#include "common.h"
|
|
#include "of.h"
|
|
|
|
static int brcmf_of_get_country_codes(struct device *dev,
|
|
struct brcmf_mp_device *settings)
|
|
{
|
|
struct device_node *np = dev->of_node;
|
|
struct brcmfmac_pd_cc_entry *cce;
|
|
struct brcmfmac_pd_cc *cc;
|
|
int count;
|
|
int i;
|
|
|
|
count = of_property_count_strings(np, "brcm,ccode-map");
|
|
if (count < 0) {
|
|
/* If no explicit country code map is specified, check whether
|
|
* the trivial map should be used.
|
|
*/
|
|
settings->trivial_ccode_map =
|
|
of_property_read_bool(np, "brcm,ccode-map-trivial");
|
|
|
|
/* The property is optional, so return success if it doesn't
|
|
* exist. Otherwise propagate the error code.
|
|
*/
|
|
return (count == -EINVAL) ? 0 : count;
|
|
}
|
|
|
|
cc = devm_kzalloc(dev, struct_size(cc, table, count), GFP_KERNEL);
|
|
if (!cc)
|
|
return -ENOMEM;
|
|
|
|
cc->table_size = count;
|
|
|
|
for (i = 0; i < count; i++) {
|
|
const char *map;
|
|
|
|
cce = &cc->table[i];
|
|
|
|
if (of_property_read_string_index(np, "brcm,ccode-map",
|
|
i, &map))
|
|
continue;
|
|
|
|
/* String format e.g. US-Q2-86 */
|
|
if (sscanf(map, "%2c-%2c-%d", cce->iso3166, cce->cc,
|
|
&cce->rev) != 3)
|
|
brcmf_err("failed to read country map %s\n", map);
|
|
else
|
|
brcmf_dbg(INFO, "%s-%s-%d\n", cce->iso3166, cce->cc,
|
|
cce->rev);
|
|
}
|
|
|
|
settings->country_codes = cc;
|
|
|
|
return 0;
|
|
}
|
|
|
|
int brcmf_of_probe(struct device *dev, enum brcmf_bus_type bus_type,
|
|
struct brcmf_mp_device *settings)
|
|
{
|
|
struct brcmfmac_sdio_pd *sdio = &settings->bus.sdio;
|
|
struct device_node *root, *np = dev->of_node;
|
|
struct of_phandle_args oirq;
|
|
struct clk *clk;
|
|
const char *prop;
|
|
int irq;
|
|
int err;
|
|
u32 irqf;
|
|
u32 val;
|
|
|
|
/* Apple ARM64 platforms have their own idea of board type, passed in
|
|
* via the device tree. They also have an antenna SKU parameter
|
|
*/
|
|
err = of_property_read_string(np, "brcm,board-type", &prop);
|
|
if (!err)
|
|
settings->board_type = prop;
|
|
|
|
if (!of_property_read_string(np, "apple,antenna-sku", &prop))
|
|
settings->antenna_sku = prop;
|
|
|
|
/* The WLAN calibration blob is normally stored in SROM, but Apple
|
|
* ARM64 platforms pass it via the DT instead.
|
|
*/
|
|
prop = of_get_property(np, "brcm,cal-blob", &settings->cal_size);
|
|
if (prop && settings->cal_size)
|
|
settings->cal_blob = prop;
|
|
|
|
/* Set board-type to the first string of the machine compatible prop */
|
|
root = of_find_node_by_path("/");
|
|
if (root && err) {
|
|
char *board_type = NULL;
|
|
const char *tmp;
|
|
|
|
/* get rid of '/' in the compatible string to be able to find the FW */
|
|
if (!of_property_read_string_index(root, "compatible", 0, &tmp))
|
|
board_type = devm_kstrdup(dev, tmp, GFP_KERNEL);
|
|
|
|
if (!board_type) {
|
|
of_node_put(root);
|
|
return 0;
|
|
}
|
|
strreplace(board_type, '/', '-');
|
|
settings->board_type = board_type;
|
|
}
|
|
of_node_put(root);
|
|
|
|
clk = devm_clk_get_optional_enabled_with_rate(dev, "lpo", 32768);
|
|
if (IS_ERR(clk))
|
|
return PTR_ERR(clk);
|
|
|
|
brcmf_dbg(INFO, "%s LPO clock\n", clk ? "enable" : "no");
|
|
|
|
if (!np || !of_device_is_compatible(np, "brcm,bcm4329-fmac"))
|
|
return 0;
|
|
|
|
err = brcmf_of_get_country_codes(dev, settings);
|
|
if (err)
|
|
brcmf_err("failed to get OF country code map (err=%d)\n", err);
|
|
|
|
of_get_mac_address(np, settings->mac);
|
|
|
|
if (bus_type != BRCMF_BUSTYPE_SDIO)
|
|
return 0;
|
|
|
|
if (of_property_read_u32(np, "brcm,drive-strength", &val) == 0)
|
|
sdio->drive_strength = val;
|
|
|
|
/* make sure there are interrupts defined in the node */
|
|
if (of_irq_parse_one(np, 0, &oirq))
|
|
return 0;
|
|
|
|
irq = irq_create_of_mapping(&oirq);
|
|
if (!irq) {
|
|
brcmf_err("interrupt could not be mapped\n");
|
|
return 0;
|
|
}
|
|
irqf = irq_get_trigger_type(irq);
|
|
|
|
sdio->oob_irq_supported = true;
|
|
sdio->oob_irq_nr = irq;
|
|
sdio->oob_irq_flags = irqf;
|
|
|
|
return 0;
|
|
}
|