From nobody Fri Jul 24 23:33:42 2026 Received: from mail-pf1-f174.google.com (mail-pf1-f174.google.com [209.85.210.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 50449374186 for ; Wed, 22 Jul 2026 07:14:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.174 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704453; cv=none; b=QsR3r0IbvCyyoyRu0tc6vQ5uiRkeUDbpBFrNo/ziV0Jj2W9pqIX4HW4vmCnd/CUntpWV+EHhZrA2WwUQlDMqw8AF6cQudXHY9YhAPrBuV/hm+FkAnSQYZ+bAevq/QsE1J0XLf5rhCdpQzPguMLGfP7PbDEFGCBomdh3hS6MDG9I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704453; c=relaxed/simple; bh=CzglU0PG4T/1tAP+1ean7yfZy/UcG1CF1h1xLRBZt5s=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=FruXsWC4KzyI7OXr5gWc3jyesDLkIisUobXXMAgvs0qt3YDgXIQA7Mbqng8rtNNSxLisLzKxIePsrl1FDwXFXzpv6pw4UFMeFeoCkkIwbRuf3s5vZtTct8F1KLTQa+e9180gxaOSXj+uTGx8gi053Rvi/nMIF3FP1Ev22I19LtY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=DbSOjXlI; arc=none smtp.client-ip=209.85.210.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="DbSOjXlI" Received: by mail-pf1-f174.google.com with SMTP id d2e1a72fcca58-84e04df8c46so1605491b3a.2 for ; Wed, 22 Jul 2026 00:14:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1784704451; x=1785309251; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KnTWoZ5wDGxUlUNB0qU2s5na487tWVd5E/ewSvf8uj0=; b=DbSOjXlImTJcmR5Bj8hAaJGBFCMSC3n46LiIhlMitY76wiWK28YR1rMkNc4uWZ/KBf gaR57Z+wJCxZVXt/yPwsxCD88k8LHhLXxgnRQdCzAOvpH12WSuACMvifH6ylmuna8M7E uUK7bwsrJlR0LG2CVZeMA6kY7tNeOxkVqzQ6UG1ZEZA+DgRz65dV79wlxy6sc0oAT2TG 3cxBSbVXtb0sZDMW5RS4B/3mS5D2q1PNcagHacknTIF8R0dTJSAvlYbUR9oC+d50PluA PgBywXyHlYAuC6whwaa040YqEp/rNsHSJ7IX9bEnaqiryG8e0KZsz9cQc1rDJ/KL2OYZ D/5g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784704451; x=1785309251; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=KnTWoZ5wDGxUlUNB0qU2s5na487tWVd5E/ewSvf8uj0=; b=I74PRanFFk+S9TtJTBEc3z+No9bwop7Egxx3mdaGu06r5YYSSGfFF3SbhrKaH07gPA O288jeRuMWrYt4ehaLCEEvHDmnXSmzB4tFwHsa5PMb2EFp1pIVpSohWWTOI2O6qJ9TzM QvohL5uoIIcg66TlM8rajnNNOjCIGMBr1bl7a5ILli694/LyEMWLqRoWqrMSM2xH204W E6R7Hbud85LXuH1q2hvLMWkpEbjEj4OJP5jKKRAW/+UfM1XzvDusZi1LKWs/fmDm1CBf RGPQ/Pyj/UqzFVzNB5gzLSZlEcxBiG/7NXSH+iaocIZTn6JpM85YcPMaESN9d2MjoLKH 9rxQ== X-Forwarded-Encrypted: i=1; AHgh+Rr5UpgldCYGonOPi0AZY4hNJ8CZuuVHza7YJsmRuYMkzMuwyGFtw2Wgh5sR596ZQqs7WmII09wtELkAbAY=@vger.kernel.org X-Gm-Message-State: AOJu0Ywn8WTl4xOygaX9BU2PFLSRxU+uRncJOpXW1Smqu7tP+wOeAm1t pnwlOG/fq7k4YKWvsNhD3EBi8hi7zxV0gsXMywpRa3YJ+MbbDAZA6ESMjOBujXrci/c= X-Gm-Gg: AR+sD12W5/pr0COSdkOH/Ra+Lr74DnfyJ08mBTHgrMVqA4nDHZ3b4RS+W+hpeJ8U3Cq aYokWLmGSyuSAgONOA0GeQS8AZ7DDmpfyQqDzyX1YoF9rv7vutMEiqsyUmFxSMjkrp+it2WIgQl 4mRq3YWdpaO4iXxRSEWQZ4GO0eKD2kCUvmdP7yrFTzC1ZvYO5eq+/wAPSNdTblX4qJT4e9qH6pm Qj47v6O5ea2E9lMpKw3x19cxGwFCaJfufXq3hcEC2ttTFVhADz9vcDgxLu7PtbxkNvr2XA7+aH+ UKe9La6SX1A6Gd/UwX1rXJrs9u5CckhxmWIHZA3i/nu2adoOdSLLvVY/WLGcw14OCqszx4orY9q L9CpR754iyjHYSHZkua2DafS2eN/yVb4iI+r6rPFFJKCaFu6BX08XMtBCaTarZJaPRwOB2LHDDu vx5tu/ X-Received: by 2002:a05:6a00:288d:b0:845:d650:b75f with SMTP id d2e1a72fcca58-84c29270e93mr22915892b3a.8.1784704450541; Wed, 22 Jul 2026 00:14:10 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e175f3180sm843890b3a.56.2026.07.22.00.14.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 00:14:10 -0700 (PDT) From: Abdurrahman Hussain Date: Wed, 22 Jul 2026 00:14:06 -0700 Subject: [PATCH v4 1/7] of: resolve alias-prefixed paths under devtree_lock Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-nh-of-alias-overlay-v4-1-fc96a40d2761@nexthop.ai> References: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> In-Reply-To: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> To: Rob Herring , Saravana Kannan Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784704448; l=4803; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=CzglU0PG4T/1tAP+1ean7yfZy/UcG1CF1h1xLRBZt5s=; b=arj9uEEBYDPV0UiCINKd+TuGUtNG6b5H5R/rN3UsRrbaUsE5QtcxLhpTg1W4uNO7ffnqgvgUi r3l/1NsKGRiCXRL27qgFs2ZSaj1ThcZQOXIDFkdBLelqabpspoZOK6Z X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= of_find_node_opts_by_path() resolves an alias-prefixed path by walking the property list of the of_aliases node with no lock held and no reference taken on the node. Property surgery on /aliases =E2=80=94 of_add_property(), of_remove_property(), changeset apply/revert =E2=80=94 mutates that list under devtree_lock, so the lockless walk can step into a property that is being unlinked. Nothing keeps the node itself alive across the walk either: detaching /aliases and dropping the last reference frees the node and its property list mid-iteration. The race has existed since the walk was introduced, but is hard to hit with a boot-FDT /aliases node that nothing ever detaches. The rest of this series makes /aliases dynamic =E2=80=94 overlays can add and remove properties, and create and destroy the node itself =E2=80=94 so close it first: find the matching property under devtree_lock with a reference held on of_aliases, and keep that reference across the of_find_node_by_path() call that resolves the value. The reference is what keeps the value string valid outside the lock: a concurrently removed property moves to the node's deadprops list and is only freed when the node itself is released. While here, validate the value's shape before handing it to of_find_node_by_path(): /aliases contents can now come from overlays and from raw changeset/of_add_property() callers, and only the overlay path validates at the producer. of_alias_value_ok() (shared with the alias tracking added later in this series) rejects values that are not non-empty C strings NUL-terminated within the property length, so the consumer no longer trusts any producer. This also covers the empty property (NULL value) that previously crashed in strchr(). of_alias_value_ok() also requires the value to be an absolute path =E2=80= =94 the DT spec defines alias values as full node paths. A relative value that names another alias, including itself, would otherwise send of_find_node_by_path() into unbounded mutual recursion with the alias resolution here: `loop =3D "loop"` exhausts the kernel stack on the first lookup. Both consumers (this reader and of_alias_create()) share the helper, so one check closes the recursion everywhere. The name match is folded into one bounded strncmp plus a check of the terminating NUL instead of strlen + strncmp, halving the string traversal now done with interrupts disabled. Assisted-by: Claude:claude-fable-5 [Claude Code] Signed-off-by: Abdurrahman Hussain --- drivers/of/base.c | 26 ++++++++++++++++++-------- drivers/of/of_private.h | 8 ++++++++ 2 files changed, 26 insertions(+), 8 deletions(-) diff --git a/drivers/of/base.c b/drivers/of/base.c index 6e7a42dedad3..9c2770823889 100644 --- a/drivers/of/base.c +++ b/drivers/of/base.c @@ -995,6 +995,8 @@ struct device_node *of_find_node_opts_by_path(const cha= r *path, const char **opt =20 /* The path could begin with an alias */ if (*path !=3D '/') { + struct device_node *aliases; + const char *value =3D NULL; int len; const char *p =3D strchrnul(path, '/'); =20 @@ -1002,16 +1004,24 @@ struct device_node *of_find_node_opts_by_path(const= char *path, const char **opt p =3D separator; len =3D p - path; =20 - /* of_aliases must not be NULL */ - if (!of_aliases) - return NULL; - - for_each_property_of_node(of_aliases, pp) { - if (strlen(pp->name) =3D=3D len && !strncmp(pp->name, path, len)) { - np =3D of_find_node_by_path(pp->value); - break; + raw_spin_lock_irqsave(&devtree_lock, flags); + aliases =3D of_node_get(of_aliases); + if (aliases) { + for_each_property_of_node(aliases, pp) { + if (!strncmp(pp->name, path, len) && + !pp->name[len]) { + if (of_alias_value_ok(pp)) + value =3D pp->value; + break; + } } } + raw_spin_unlock_irqrestore(&devtree_lock, flags); + + /* the reference on @aliases keeps @value alive */ + if (value) + np =3D of_find_node_by_path(value); + of_node_put(aliases); if (!np) return NULL; path =3D p; diff --git a/drivers/of/of_private.h b/drivers/of/of_private.h index 0ae16da066e2..9bba999f0bf8 100644 --- a/drivers/of/of_private.h +++ b/drivers/of/of_private.h @@ -215,6 +215,14 @@ static inline bool is_pseudo_property(const char *prop= _name) !of_prop_cmp(prop_name, "linux,phandle"); } =20 +/* alias values must be absolute paths NUL-terminated within length */ +static inline bool of_alias_value_ok(const struct property *pp) +{ + return pp->value && pp->length >=3D 2 && + *(const char *)pp->value =3D=3D '/' && + strnlen(pp->value, pp->length) < pp->length; +} + #if IS_ENABLED(CONFIG_KUNIT) int __of_address_resource_bounds(struct resource *r, u64 start, u64 size); #endif --=20 2.54.0 From nobody Fri Jul 24 23:33:42 2026 Received: from mail-pf1-f169.google.com (mail-pf1-f169.google.com [209.85.210.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4A61C3C1961 for ; Wed, 22 Jul 2026 07:14:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704454; cv=none; b=hsgP6x4RmblDwRh3GIC6f5eviPu93qgA00KdDo12mW4bqEuoMZqBpRtvNluypxi40lvIKOOxlGolK7uG61PgDF9zIFfS4E47jLo1DesAXibB6jejkDWUMzEzrpCJNCf3J20Y/5kSutXjobDTxHlYwDn1mCA/SEQ4GRHcG/uXcXU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704454; c=relaxed/simple; bh=QOHHKqluyNzXaY0MgQDsZynbut0broBYRsoS7lqv22I=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=s9b/gyw+ab74aFw0ErmfnQgCE7EakdfP5WuQyRtZo/aro38PgTB+at3tVLtjsnPZUA9aegiSeK5lW7fxoW2m+5meAOreML/B5k/jtpxb3z5ocNn/aEyKJwHZtxDBlctYii0a0O373TqucLFYNSwTFiX9/40sxv1nXwZQIiS5Dlk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=ZBRb4UpI; arc=none smtp.client-ip=209.85.210.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="ZBRb4UpI" Received: by mail-pf1-f169.google.com with SMTP id d2e1a72fcca58-8453427d3f4so11374410b3a.3 for ; Wed, 22 Jul 2026 00:14:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1784704452; x=1785309252; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8RrJTPdpDV+xxTsg977zOfxZbcmNaMztUMTalxEC9Mc=; b=ZBRb4UpIQILHWKLNwjryaivhrNXg3kq8UOXXO/YTIRrdoUrsUSSYD6AtSCbD8+A9/H D0PryIZCH0Uhr8dP0mERO3a343PwAfz1eN1GYLJXF/du3OIzXdetK2u/8tPJ5VnXNwpj cqG2YsXPv0uuHEu5eiWdggd9mTh6QINcauu+zZS4D6PixY+zGKrFHPC47FAIy23wJ8fg /y+QBdxH7GE19japMP9uDq48sxZ1KghJRIQS6PY/0tFbi85hX3ANbMWYB/j1NQ6Buf6l ac8UgcVTstlOVzWWn5yqrAxcjZu/UfzX+M5PZE5bQzH+r2x3SyWYiNuCthhhU7EcEZ19 kxVg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784704452; x=1785309252; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=8RrJTPdpDV+xxTsg977zOfxZbcmNaMztUMTalxEC9Mc=; b=V+KqPrrw07RXpWmEoCFlEkXUl7cD/0nXZBm1UgNaFFq88sbhHtvMHnb0JE4O6fzJIm lX2dZhJPwHBtO0OOp2ABm5DYvBwN+7ioBKS2/aGHCpFA912SJjKkKFvxwUCHqpWF5jX3 GNRPdHZoQsCUVqzQ9iBT5HHqQDb063gwIHDBJhspbB7YoN43JMWB9ox1AEo5hUxE3fEF AeP0Z431yKs15hBS9Xdq011mSdklW0iej1laIGYQltlY/Ao0hxy6ApT++JCJ/SNWMH26 oPU7UkKLhvabsfqyfANmj/LW4v5OTIaQ9dBCEVENowRYPYZeHKx1ukNFJ7LL9da7tsYp xejQ== X-Forwarded-Encrypted: i=1; AHgh+RpLDThb1vSRtkNT0thkQHDYDZc06fSG5nEfQtUtddR9+8XtDL/yZ/bS+Bd+G+LH4xLXRTHT9KKTEnSvwag=@vger.kernel.org X-Gm-Message-State: AOJu0YyMxeCmXix3rfit2mNgl9OyCMsvgB0NHOWzl+/iKNVkglfuHJSQ RU9PCoSF2df/g8KHKWqcH4rcUNhxcApGHLXJ920o7Ae56gnDUdBlZV4Mp+JuPaH8EVIBfsQUfVl tT21ES7w= X-Gm-Gg: AR+sD10cK9sfZUdVXnYk2dZfA1GwR228kOP4yrmrvhLoKi93vFDem056gZq9me95oPf unK7C+ETGrR+nYsAmZZXkJ/O92O9ouHEIgDm9ue+AHqYhn/15Lz8OzjPI7cYVWBdyewO5ER7R/f GGwFLbPfH1dpMyeDZ/0q5XA1WoGdPil85TCs4v/IaEPzRWF10Kpavo/nidWbfRgCx8QQQLSleI9 GIRJEz3nASg1uBM/Fl+GzD4iR0w++v72cxwEesN3EUhuu5TBO9IYLOXQiFk4SRwfrV56QAYmRZL Paz1swP/v1qgmn9nh4mNDMzeIXSGpysU5wnZDQynULJBQIDqCoqGZXV0KzvZ8LOP8PyPNqMn/oA 66OU11P6wvo0ypYnUGwc3jqEI8yCqKZBX6uJURf9xAth7q5NPwyGxynOwvSkLREiW+ucgooLopo KRll8l4TpaEjPYsh0= X-Received: by 2002:a05:6a00:1d8a:b0:848:727f:2c8b with SMTP id d2e1a72fcca58-84c294eb4demr21763992b3a.68.1784704451504; Wed, 22 Jul 2026 00:14:11 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e175f3180sm843890b3a.56.2026.07.22.00.14.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 00:14:11 -0700 (PDT) From: Abdurrahman Hussain Date: Wed, 22 Jul 2026 00:14:07 -0700 Subject: [PATCH v4 2/7] of: incrementally update /aliases lookup on reconfig notifications Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-nh-of-alias-overlay-v4-2-fc96a40d2761@nexthop.ai> References: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> In-Reply-To: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> To: Rob Herring , Saravana Kannan Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784704448; l=16428; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=QOHHKqluyNzXaY0MgQDsZynbut0broBYRsoS7lqv22I=; b=8XaxTQvAIGf5bkaMyt6EOedt4LkW/9pOZ8Gw819RelDDO91wZP1sSY1CXaYsjbQI4wlwykEDf MiBYTwKExp1B2DMtSrm3T9NLhAk3Z4c17LzjfNokBPzZBgzDcwdsx0r X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= /aliases entries added by a device-tree overlay are stored in the live tree but never enter the global aliases_lookup list that of_alias_scan() builds at boot. As a result, of_alias_get_id() returns -ENODEV for aliases declared inside overlays, and any driver that relies on alias-based numbering (i2c-xiic, spi, tty, mmc, ...) silently loses its pinned id and falls back to auto-assignment. Fix by registering an internal OF reconfig notifier that mirrors /aliases changes into aliases_lookup. Registration happens at core_initcall_sync time, safely after the boot-time of_alias_scan(), which runs pre-initcall from unflatten_device_tree() (or of_pdt_build_devicetree() on OF-real platforms): OF_RECONFIG_ADD_PROPERTY -> of_alias_create() OF_RECONFIG_REMOVE_PROPERTY -> of_alias_destroy() OF_RECONFIG_UPDATE_PROPERTY -> destroy + create OF_RECONFIG_ATTACH_NODE -> adopt the node as of_aliases OF_RECONFIG_DETACH_NODE -> drop every aliases_lookup entry The reconfig notifier chain fires from both direct changesets and overlay apply/revert, so the same code path covers runtime dt modifications and overlay-declared aliases without any overlay- specific hook in drivers/of/overlay.c. Grant Likely suggested this shape on Geert Uytterhoeven's 2015 RFC [1]; Geert's original hook was in dynamic.c directly. Match the /aliases target node structurally (exact name "aliases", parent =3D=3D root, via the shared of_node_is_aliases()) rather than by pointer against the of_aliases global. A system with no boot-time /aliases has of_aliases =3D=3D NULL, so an overlay that creates /aliases from scratch would otherwise be missed from the first ATTACH_NODE onward. The name compare is exact rather than of_node_name_eq(): the latter ignores unit addresses and would also match a root node named "aliases@1", which neither path lookup nor the DT spec treats as the aliases node. ATTACH publishes the adopted node in of_aliases with a reference held; DETACH clears the pointer and drops that reference again. Both pointer updates happen under devtree_lock, pairing with the locked reader in of_find_node_opts_by_path() from the previous patch =E2=80=94 a reader eith= er observes NULL or takes its own reference before the notifier's put can be the last one. Dropping the reference at DETACH also keeps the node at refcount 1 by the time an overlay changeset that created /aliases is destroyed, which __of_changeset_entry_destroy() insists on before it lets the node be freed. Only per-property notifications populate aliases_lookup =E2=80=94 the notifier does not walk the attached node's property list, which would race with devtree_lock-protected property mutations. A direct of_attach_node() caller that pre-populates /aliases is not tracked, matching pre-series behavior. DETACH_NODE conversely drops every aliases_lookup entry =E2=80=94 but only when the detached node is the tracked of_aliases. __of_attach_node() has no duplicate-name check, so a stray second root node named "aliases" can exist; detaching it must not wipe entries backed by the real node. Walking aliases_lookup itself (under aliases_mutex) avoids the same property-list race. Overlay revert additionally emits per- property REMOVE events beforehand; the sweep catches direct of_detach_node() callers that don't. The per-entry teardown is factored into __of_alias_del(), shared by the single-name destroy and the detach-time sweep. One ordering caveat is inherent to the notification architecture: within a single changeset, a device created by an earlier ATTACH entry can be probed by of_platform_notify() before a later /aliases ADD_PROPERTY entry reaches this notifier. Overlays that declare an alias for a node they also create should order the /aliases fragment first if the target bus is populated with a bound driver at apply time. The notifier machinery is built only for CONFIG_OF_DYNAMIC kernels: without it no reconfig notifications exist and of_reconfig_notifier_register() is a stub returning -EINVAL, so an unconditional registration would fail the initcall on every non-dynamic DT kernel. Factor the per-property loop body of of_alias_scan() into of_alias_create() so the boot-time scan and the runtime notifier share one code path. Owned (runtime) entries kstrdup the alias name so the alias_prop survives the property that spawned it =E2=80=94 required for the overlay revert path where the source property is freed. A one-bit @owned flag on struct alias_prop distinguishes kmalloc'd entries from memblock-backed ones so the destroy path kfree()s the right ones. Every entry, boot-time or runtime, holds the target-node reference that of_find_node_by_path() returned at create time; destroy drops it symmetrically. The destroy path unlinks matching entries regardless of ownership (freeing storage only for owned ones) so an overlay UPDATE against a boot-time alias leaves at most one entry per stem+id. This addresses the allocator-mismatch worry Grant flagged on the 2015 series [2] and the duplicate-mapping side effect that would otherwise leak through. Serialize aliases_lookup on a dedicated aliases_mutex: readers (of_alias_get_id, of_alias_get_highest_id, of_device_uevent) and the reconfig notifier hold it around every access. Boot-time of_alias_scan() runs single-threaded during init and stays lockless. This is preferable to piggy-backing on of_mutex because the reconfig notifier is called both under of_mutex (overlay apply path) and outside of it (direct of_add_property() path from dynamic.c), so a nested acquisition would deadlock on some callers. Validate the property value before feeding it to of_find_node_by_path(): pp->value must be non-empty and null-terminated within pp->length. An overlay that hasn't been through /aliases fixup can otherwise present a fragment-internal string that isn't a valid live-tree path or a malformed non-terminated value, and of_find_node_by_path() derefs it as a C string =E2=80=94 an OOB read on the malformed case. The refactor also fixes a pre-existing one-byte out-of-bounds read in the stem parser: the old loop tested isdigit(*(end - 1)) before checking end > start, reading one byte before the property name when the name is empty or all digits. of_alias_create() checks the bound first and rejects a zero-length stem. Naming builds on Geert's original series: - "of: Extract of_alias_create()" [3] - "of: Add of_alias_destroy()" [4] - "of/dynamic: Update list of aliases on aliases changes" [5] Link: https://lore.kernel.org/lkml/1435675876-2159-1-git-send-email-geert+r= enesas@glider.be/ [1] Link: https://lore.kernel.org/lkml/20150630172131.D4E6CC4041A@trevor.secret= lab.ca/ [2] Link: https://lore.kernel.org/lkml/1435675876-2159-2-git-send-email-geert+r= enesas@glider.be/ [3] Link: https://lore.kernel.org/lkml/1435675876-2159-3-git-send-email-geert+r= enesas@glider.be/ [4] Link: https://lore.kernel.org/lkml/1435675876-2159-4-git-send-email-geert+r= enesas@glider.be/ [5] Assisted-by: Claude:claude-fable-5 [Claude Code] Signed-off-by: Abdurrahman Hussain --- drivers/of/base.c | 210 +++++++++++++++++++++++++++++++++++++++-----= ---- drivers/of/device.c | 4 +- drivers/of/of_private.h | 14 ++++ 3 files changed, 186 insertions(+), 42 deletions(-) diff --git a/drivers/of/base.c b/drivers/of/base.c index 9c2770823889..669eed7d03cf 100644 --- a/drivers/of/base.c +++ b/drivers/of/base.c @@ -1925,6 +1925,170 @@ static void of_alias_add(struct alias_prop *ap, str= uct device_node *np, ap->alias, ap->stem, ap->id, np); } =20 +/* + * Protects aliases_lookup and of_aliases. of_alias_scan() runs single- + * threaded at init and skips it; every other reader/writer must hold it. + */ +DEFINE_MUTEX(aliases_mutex); + +/* Callers other than of_alias_scan() must hold @aliases_mutex. */ +static void of_alias_create(const struct property *pp, + void *(*dt_alloc)(u64 size, u64 align), + bool owned) +{ + const char *start =3D pp->name; + const char *end; + struct device_node *np; + struct alias_prop *ap; + const char *dup; + int id, len; + + if (is_pseudo_property(pp->name)) + return; + + if (!of_alias_value_ok(pp)) + return; + + np =3D of_find_node_by_path(pp->value); + if (!np) + return; + + end =3D start + strlen(start); + while (end > start && isdigit(*(end - 1))) + end--; + len =3D end - start; + if (len =3D=3D 0) + goto out_put; + + if (kstrtoint(end, 10, &id) < 0) + goto out_put; + + ap =3D dt_alloc(sizeof(*ap) + len + 1, __alignof__(*ap)); + if (!ap) + goto out_put; + memset(ap, 0, sizeof(*ap) + len + 1); + + if (owned) { + dup =3D kstrdup(pp->name, GFP_KERNEL); + if (!dup) { + kfree(ap); + goto out_put; + } + } else { + dup =3D start; + } + ap->alias =3D dup; + ap->owned =3D owned; + of_alias_add(ap, np, id, start, len); + return; + +out_put: + of_node_put(np); +} + +#ifdef CONFIG_OF_DYNAMIC +/* Unlink @ap; free its storage if it was runtime-allocated. */ +static void __of_alias_del(struct alias_prop *ap) +{ + list_del(&ap->link); + of_node_put(ap->np); + if (ap->owned) { + kfree(ap->alias); + kfree(ap); + } +} + +/* Callers must hold @aliases_mutex. */ +static void of_alias_destroy(const char *name) +{ + struct alias_prop *ap, *tmp; + + list_for_each_entry_safe(ap, tmp, &aliases_lookup, link) { + if (strcmp(ap->alias, name) !=3D 0) + continue; + __of_alias_del(ap); + return; + } +} + +static void *alias_alloc(u64 size, u64 align) +{ + return kzalloc(size, GFP_KERNEL); +} + +/* Callers must hold @aliases_mutex. */ +static void of_aliases_forget_all(void) +{ + struct alias_prop *ap, *tmp; + + list_for_each_entry_safe(ap, tmp, &aliases_lookup, link) + __of_alias_del(ap); +} + +static int of_aliases_reconfig_notifier(struct notifier_block *nb, + unsigned long action, void *arg) +{ + struct of_reconfig_data *rd =3D arg; + struct device_node *put =3D NULL; + unsigned long flags; + + /* of_aliases may still be NULL when an overlay creates the node */ + if (!rd->dn || !of_node_is_aliases(rd->dn)) + return NOTIFY_DONE; + + mutex_lock(&aliases_mutex); + switch (action) { + case OF_RECONFIG_ATTACH_NODE: + /* of_aliases is read under devtree_lock by alias path lookup */ + raw_spin_lock_irqsave(&devtree_lock, flags); + if (!of_aliases) + of_aliases =3D of_node_get(rd->dn); + raw_spin_unlock_irqrestore(&devtree_lock, flags); + break; + case OF_RECONFIG_DETACH_NODE: + raw_spin_lock_irqsave(&devtree_lock, flags); + if (of_aliases =3D=3D rd->dn) { + of_aliases =3D NULL; + put =3D rd->dn; + } + raw_spin_unlock_irqrestore(&devtree_lock, flags); + if (put) { + of_aliases_forget_all(); + /* may free the node, so must sit outside devtree_lock */ + of_node_put(put); + } + break; + case OF_RECONFIG_ADD_PROPERTY: + of_alias_create(rd->prop, alias_alloc, true); + break; + case OF_RECONFIG_REMOVE_PROPERTY: + of_alias_destroy(rd->prop->name); + break; + case OF_RECONFIG_UPDATE_PROPERTY: + if (rd->old_prop) + of_alias_destroy(rd->old_prop->name); + of_alias_create(rd->prop, alias_alloc, true); + break; + default: + break; + } + mutex_unlock(&aliases_mutex); + return NOTIFY_OK; +} + +static struct notifier_block of_aliases_nb =3D { + .notifier_call =3D of_aliases_reconfig_notifier, +}; + +static int __init of_aliases_reconfig_init(void) +{ + return of_reconfig_notifier_register(&of_aliases_nb); +} + +/* of_alias_scan() runs pre-initcall, so the boot-time scan is complete */ +core_initcall_sync(of_aliases_reconfig_init); +#endif /* CONFIG_OF_DYNAMIC */ + /** * of_alias_scan - Scan all properties of the 'aliases' node * @dt_alloc: An allocator that provides a virtual address to memory @@ -1960,42 +2124,8 @@ void of_alias_scan(void * (*dt_alloc)(u64 size, u64 = align)) if (!of_aliases) return; =20 - for_each_property_of_node(of_aliases, pp) { - const char *start =3D pp->name; - const char *end =3D start + strlen(start); - struct device_node *np; - struct alias_prop *ap; - int id, len; - - /* Skip those we do not want to proceed */ - if (is_pseudo_property(pp->name)) - continue; - - np =3D of_find_node_by_path(pp->value); - if (!np) - continue; - - /* walk the alias backwards to extract the id and work out - * the 'stem' string */ - while (isdigit(*(end-1)) && end > start) - end--; - len =3D end - start; - - if (kstrtoint(end, 10, &id) < 0) { - of_node_put(np); - continue; - } - - /* Allocate an alias_prop with enough space for the stem */ - ap =3D dt_alloc(sizeof(*ap) + len + 1, __alignof__(*ap)); - if (!ap) { - of_node_put(np); - continue; - } - memset(ap, 0, sizeof(*ap) + len + 1); - ap->alias =3D start; - of_alias_add(ap, np, id, start, len); - } + for_each_property_of_node(of_aliases, pp) + of_alias_create(pp, dt_alloc, false); } =20 /** @@ -2013,7 +2143,7 @@ int of_alias_get_id(const struct device_node *np, con= st char *stem) struct alias_prop *app; int id =3D -ENODEV; =20 - mutex_lock(&of_mutex); + mutex_lock(&aliases_mutex); list_for_each_entry(app, &aliases_lookup, link) { if (strcmp(app->stem, stem) !=3D 0) continue; @@ -2023,7 +2153,7 @@ int of_alias_get_id(const struct device_node *np, con= st char *stem) break; } } - mutex_unlock(&of_mutex); + mutex_unlock(&aliases_mutex); =20 return id; } @@ -2041,7 +2171,7 @@ int of_alias_get_highest_id(const char *stem) struct alias_prop *app; int id =3D -ENODEV; =20 - mutex_lock(&of_mutex); + mutex_lock(&aliases_mutex); list_for_each_entry(app, &aliases_lookup, link) { if (strcmp(app->stem, stem) !=3D 0) continue; @@ -2049,7 +2179,7 @@ int of_alias_get_highest_id(const char *stem) if (app->id > id) id =3D app->id; } - mutex_unlock(&of_mutex); + mutex_unlock(&aliases_mutex); =20 return id; } diff --git a/drivers/of/device.c b/drivers/of/device.c index b3dc78f2fa3a..fa0cc8129ab0 100644 --- a/drivers/of/device.c +++ b/drivers/of/device.c @@ -237,7 +237,7 @@ void of_device_uevent(const struct device *dev, struct = kobj_uevent_env *env) add_uevent_var(env, "OF_COMPATIBLE_N=3D%d", seen); =20 seen =3D 0; - mutex_lock(&of_mutex); + mutex_lock(&aliases_mutex); list_for_each_entry(app, &aliases_lookup, link) { if (dev->of_node =3D=3D app->np) { add_uevent_var(env, "OF_ALIAS_%d=3D%s", seen, @@ -245,7 +245,7 @@ void of_device_uevent(const struct device *dev, struct = kobj_uevent_env *env) seen++; } } - mutex_unlock(&of_mutex); + mutex_unlock(&aliases_mutex); } EXPORT_SYMBOL_GPL(of_device_uevent); =20 diff --git a/drivers/of/of_private.h b/drivers/of/of_private.h index 9bba999f0bf8..731b606ae3e3 100644 --- a/drivers/of/of_private.h +++ b/drivers/of/of_private.h @@ -17,6 +17,11 @@ * @alias: Alias property name * @np: Pointer to device_node that the alias stands for * @id: Index value from end of alias name + * @owned: True for runtime entries, where the struct and @alias are + * kmalloc'd/kstrdup'd and freed on removal. False for boot-time + * entries, which live in memblock (@alias points into the FDT) + * and are only unlinked. Every entry holds a reference on @np; + * removal drops it regardless of @owned. * @stem: Alias string without the index * * The structure represents one alias property of 'aliases' node as @@ -27,6 +32,7 @@ struct alias_prop { const char *alias; struct device_node *np; int id; + bool owned; char stem[]; }; =20 @@ -40,6 +46,7 @@ struct alias_prop { =20 extern struct mutex of_mutex; extern raw_spinlock_t devtree_lock; +extern struct mutex aliases_mutex; extern struct list_head aliases_lookup; extern struct kset *of_kset; =20 @@ -223,6 +230,13 @@ static inline bool of_alias_value_ok(const struct prop= erty *pp) strnlen(pp->value, pp->length) < pp->length; } =20 +/* the /aliases node: root child with the exact name "aliases" */ +static inline bool of_node_is_aliases(const struct device_node *np) +{ + return of_node_is_root(np->parent) && + !strcmp(kbasename(np->full_name), "aliases"); +} + #if IS_ENABLED(CONFIG_KUNIT) int __of_address_resource_bounds(struct resource *r, u64 start, u64 size); #endif --=20 2.54.0 From nobody Fri Jul 24 23:33:42 2026 Received: from mail-pf1-f182.google.com (mail-pf1-f182.google.com [209.85.210.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 09A2B284880 for ; Wed, 22 Jul 2026 07:14:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704454; cv=none; b=K+v5dWlxNRyN5Cjmxo0q7Wu7YvibSpDZUT+zrXkq11hPky10qDupnjxHLnRPLvBoAOZqztisGsL9Q/oZnjzRvsD8iYHq78Kw6l9V5ByfdJVPojH8z3uhYrRBCwkaTogW++IQ3ZCdAAxpxY9FSKz++QAjHYso+90WhgHb/V8byTQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704454; c=relaxed/simple; bh=kRpIeIkOBNbm/VqI0BkoZECW2QHfP+btpWk4Ns3ReaI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=fXbfSxR/HfGH0Muw/z/+f5hfPMLvfEJBVdkXZl+BCHqKInivwWRkGOhQSBymLx5kWhJKKQk0VPlWr13HUKjt7JqUH0MonP9R9jgCrROSN76lq/bAZibmrrAiY7+LFaIJuFA+pKzZw3bEjB5OZ4a+dUyc+FMrXkR/aQ027/YR1N4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=OjwfnqzO; arc=none smtp.client-ip=209.85.210.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="OjwfnqzO" Received: by mail-pf1-f182.google.com with SMTP id d2e1a72fcca58-8487214ad2bso11540079b3a.1 for ; Wed, 22 Jul 2026 00:14:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1784704452; x=1785309252; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1dw4LW8kSdGmcldnGWhnWc2M/cNC9RFM1UCRX4bcCtw=; b=OjwfnqzOak06zzN9FemLuld38DStyz/hNiP5E8G3FE3kEoQZxSVonULli1M9ClqNMB VqGHDrJChspNphhJvCW0b9CBZ/eAhveawXm5uNUWRubzjBg2delMM19IDCbC2eS+7ZKQ L+HIwuyIZDo3Eel/BnqthkVK3ybJMdFmDPm0KJAXTA0BY+wFTAquF/bHT0q5TIwEOKMg PuC3kWtg4mMJ9TwciWwzxRy21srQ7yW+y0LgmbJCZRBpzAtw5sEAwSzKyBl8DOerQhnJ 4nWGv4tuyUED7tkc6zlo/ihwFug434FenZQs0yKeX3v/Oe8jjwsk09bk8C38QpDE+Asp oaZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784704452; x=1785309252; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=1dw4LW8kSdGmcldnGWhnWc2M/cNC9RFM1UCRX4bcCtw=; b=HzrHeUzpu6hFOwqKXtBEmmtWLaff0PnF0wO7IAroZ4Hv5H0L8MDIJf5trnzEgkLmOx 1dIWdIvXXG6uk+7AC+wjZaHKx54aZdtNDTDOI0HcpWbqVA6RfM/PZFGEE5EtiMetkQA5 DBsiTrM2y0knolCiVHxcmVM2V8imroY01aRSDrELqxsEQS5OFKQM6lzkedsDVJP0JJw1 Dg8RBleAwegDeGu57+tiKCXe8wwAW1k57tDUVRaK4FmE/e4V95WwuTzeTc2rqwQsYytD +YcktDqk/bWTGek1+PU3OWX8gO5/O5A3DBHABHTKMFFczTdx9a+cW9Ryl5ueec7dIKrP 9WOA== X-Forwarded-Encrypted: i=1; AHgh+RrR3rciwn/gK/Oq+u3EYBkYPKA2URJz1a8ghK0SeNubmlI0v2gb8bl6zp8n/s6n6kHviXqFKIhARjutYr0=@vger.kernel.org X-Gm-Message-State: AOJu0YwTu40o5fEeF0k0Pe49sMIllJlHZmcUwxIJkvr3adkEraQ1RoGo w1WEakRPhcqVaAlNms2ZZIRzLlPAFy15o4oUmlMIP/4YhmuO51+6BE6bwQhTQpOBsd4= X-Gm-Gg: AR+sD10E+4d4eM8fCjOb1gcOSvTGiZbBsFFkQAq5RtZsPO4phpV6Q1sQL8wUH6l5cud B5+nm1J+s02u7cRPTZfF+LCQfwxim7V4omlsgh/+6Opp/f/Km4BqKP83ABYyVTqPdJuc8Qc34kk txKoyCQirmiFCHgo7ZaYcQzAun/rxKZllG06iL7WdbYS/8suRM1rBU/Go/Lhs/Gpsp7a1LeAKa2 +QZ0B0j/3WKCcUqyz2HzpI5/oojcMWAEFgMzkB6de0q4aTvWuo7IqajPfBtYR1D5DlDLiUj1nGC dKzbn2F4w6LNERFUfWR2pf7XeBISs3uX9wjn4rvbzPOSawpE2/gDnBbHbMLgU9MWhRzOWNcAYlS ipXAcDvLQcuPEjoD3jDUr1A1Kjveq202UkL1ZxRKIdUltjXAuRBfnHkFrIWhUBqtGxCQSg6kHRp nLPo3e X-Received: by 2002:a05:6a00:a253:b0:84a:6e0d:692d with SMTP id d2e1a72fcca58-84c294d4bdfmr22264981b3a.46.1784704452418; Wed, 22 Jul 2026 00:14:12 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e175f3180sm843890b3a.56.2026.07.22.00.14.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 00:14:11 -0700 (PDT) From: Abdurrahman Hussain Date: Wed, 22 Jul 2026 00:14:08 -0700 Subject: [PATCH v4 3/7] of/overlay: look up absolute target-paths absolutely Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-nh-of-alias-overlay-v4-3-fc96a40d2761@nexthop.ai> References: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> In-Reply-To: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> To: Rob Herring , Saravana Kannan Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784704448; l=4474; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=kRpIeIkOBNbm/VqI0BkoZECW2QHfP+btpWk4Ns3ReaI=; b=5knW5jjfI3OWoYNxxiYknjtFAvioJZ6zfPSzSD5HXNv+ixHw5NaMxUWPtAhqCJiDmEQYuqkjQ MFxlQG+eFdHCQ+l121Y7ejnfIZ38oyIU7+GBUCyW9+XK6BxIeK2MUyD X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= When of_overlay_fdt_apply() is called with a non-NULL target base, find_target() currently concatenates the base's full path with every fragment's target-path via "%pOF%s" =E2=80=94 so target-path=3D"" resolves = to the base itself (the intended common case), but target-path=3D"/foo" resolves to "/foo" (never the DT root) and target-path=3D"/" to "/" (never a valid node at all). That makes it impossible for a two-fragment overlay to modify one subtree under the base and one node at the DT root =E2=80=94 a shape that arises naturally when a PCI-attached device wants to declare its peripherals under dev_of_node(&pdev->dev) AND add /aliases entries so alias-aware drivers (i2c-xiic, spi, tty, ...) can pin bus numbers. Treat target-path as absolute whenever it is non-empty. An empty target-path continues to mean "the target base itself", preserving the existing shape used by drivers/misc/lan966x_pci.c and its dtso (the only in-tree of_overlay_fdt_apply() caller today that passes a non-NULL base). Spell the new contract out in the kernel-doc for @base and @target_base and in find_target()'s strategy comment, so out-of-tree callers that modeled a base-relative target-path on the old concatenation behavior have a documented signal that the semantics changed. Assisted-by: Claude:claude-fable-5 [Claude Code] Signed-off-by: Abdurrahman Hussain --- drivers/of/overlay.c | 38 ++++++++++++++++++-------------------- 1 file changed, 18 insertions(+), 20 deletions(-) diff --git a/drivers/of/overlay.c b/drivers/of/overlay.c index 08d5351746be..74aea704835a 100644 --- a/drivers/of/overlay.c +++ b/drivers/of/overlay.c @@ -688,12 +688,15 @@ static int build_changeset(struct overlay_changeset *= ovcs) * * 1) "target" property containing the phandle of the target * 2) "target-path" property containing the path of the target + * + * With a non-NULL @target_base, an empty "target-path" means + * @target_base itself; any non-empty "target-path" is resolved + * absolutely from the live-tree root. */ static struct device_node *find_target(const struct device_node *info_node, const struct device_node *target_base) { struct device_node *node; - char *target_path; const char *path; u32 val; int ret; @@ -709,23 +712,14 @@ static struct device_node *find_target(const struct d= evice_node *info_node, =20 ret =3D of_property_read_string(info_node, "target-path", &path); if (!ret) { - if (target_base) { - target_path =3D kasprintf(GFP_KERNEL, "%pOF%s", target_base, path); - if (!target_path) - return NULL; - node =3D of_find_node_by_path(target_path); - if (!node) { - pr_err("find target, node: %pOF, path '%s' not found\n", - info_node, target_path); - } - kfree(target_path); - } else { - node =3D of_find_node_by_path(path); - if (!node) { - pr_err("find target, node: %pOF, path '%s' not found\n", - info_node, path); - } - } + /* an empty target-path means the target base itself */ + if (target_base && path[0] =3D=3D '\0') + return of_node_get((struct device_node *)target_base); + + node =3D of_find_node_by_path(path); + if (!node) + pr_err("find target, node: %pOF, path '%s' not found\n", + info_node, path); return node; } =20 @@ -737,7 +731,9 @@ static struct device_node *find_target(const struct dev= ice_node *info_node, /** * init_overlay_changeset() - initialize overlay changeset from overlay tr= ee * @ovcs: Overlay changeset to build - * @target_base: Point to the target node to apply overlay + * @target_base: Target for fragments with an empty "target-path"; + * fragments with a non-empty "target-path" resolve + * absolutely and ignore @target_base * * Initialize @ovcs. Populate @ovcs->fragments with node information from * the top level of @overlay_root. The relevant top level nodes are the @@ -982,7 +978,9 @@ static int of_overlay_apply(struct overlay_changeset *o= vcs, * @overlay_fdt: pointer to overlay FDT * @overlay_fdt_size: number of bytes in @overlay_fdt * @ret_ovcs_id: pointer for returning created changeset id - * @base: pointer for the target node to apply overlay + * @base: target for fragments with an empty "target-path"; + * fragments with a non-empty "target-path" resolve + * absolutely and ignore @base * * Creates and applies an overlay changeset. * --=20 2.54.0 From nobody Fri Jul 24 23:33:42 2026 Received: from mail-pg1-f181.google.com (mail-pg1-f181.google.com [209.85.215.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1A8173DA5AE for ; Wed, 22 Jul 2026 07:14:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704455; cv=none; b=ZhucPaAlNSEdGWvOSuMhgOxilOa1nABBRzJ7fh66ZIJu/+BH49eeY+APIYZt4iB7a3ViM0tZpmkrfjvTtnx0BnRaFqHrvV/r5P6JLwlXOme+05IvA1uMd+fj/Hv6vmYoq+2Y1Jb9+wP6RS7tlWSIBawgM4AtijfQPPJxs0FDVu8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704455; c=relaxed/simple; bh=AB5Ed4fodLCRymlKclDBO+9rLTYghZ/tdB5y6s3AQQg=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=cYKkBKpF76oVwND4gERAOlTml9HsUKuEILLYQvwprkaB5B5Qf2GXCR6dQhj0Pyqe6bI4c3klgEXKEkYl6pFbQmpfXCa9nXmGwjaDbni9lAoXESGfxHnMiidd6dVRKJjQmaoWGWI2Z7zfWMmyCiH9G6N55uBHH4jqgACLf5NbpSk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=ECZlTj61; arc=none smtp.client-ip=209.85.215.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="ECZlTj61" Received: by mail-pg1-f181.google.com with SMTP id 41be03b00d2f7-ca766c1c9ccso7315487a12.0 for ; Wed, 22 Jul 2026 00:14:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1784704453; x=1785309253; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ROWj2nRa0GLCu+9OGXMhneBFv3OXk9O/to00GwrjIbo=; b=ECZlTj6181bPMnAr/Pb+LmkJj93XeVL7HtQxTcOrgB1Dt+Xi2obVfKa17W/6vTiq0X dUI0xr5Iwez2stYYyQIzkAEaTt2VGvKeMO8xuwBqXCLREBoKFjWULj6ZKMbB/yD+Gui+ PsT6EW6s00lujHPHFf5fIGOuTBOYdBKv8gP4zNIWWE3hf9sGGBMfnGGpKJhR4cJp/THg KT8akIQMZan80tSWi45p7DOc8G4Aepfvema9NxcWtRU+MpL3ACU2+IUC4kRQpuZwaspJ cNQIsuJFkpVmnmmH0uclmdQskLJG7LbwryXCkWtVZJ2MrzmUX+y2ItQVkiqRcBtPeZBU cOaA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784704453; x=1785309253; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ROWj2nRa0GLCu+9OGXMhneBFv3OXk9O/to00GwrjIbo=; b=JO/1m/h8W/XPbCBCBoTIXAsOOsntiqH+KSRhGEaxVMvvVZpT0ZxRR13JRZxWF21MBA jhEj9luKSgKE5rnjV2Cc+p5eH/mA2bleYWP/evvYrZ3cvmrSodCZlOwV5NZG0VzRE3gH Ogdq3pnxrdPBMLc/dhutPp8ATUkuN1aroaZBGHqGBq3u9a1zLBnNANGPjo8fThiQW9CO 98TyEAYRHtHbCZ/LGMKe3EBLYa/gNQrZMnEv7UVNrRAwRXbipA+Yyg8/1Pd57Fwb6B0e y4DNS5/3h1quxKiX/eGZlYBgIQzbR8jH5vZywg/C56pPGNFp7LYYHy+u+jKroVzyZaVf cCSw== X-Forwarded-Encrypted: i=1; AHgh+RrXECvpUN26PyE0ufln5lGSuDgRJsLrZTiAnip6nFF5Y/jgvf4stz+QuA6jzUXLSZdX1lVl0ulkx9Gs3BY=@vger.kernel.org X-Gm-Message-State: AOJu0YzHxav3tyijxIOH2OYeQQyaTOmaULRNiYO9UV/vyJT2V5NhWg6X DpUUmT1KUhcBp/gXU1sn6Qyc6fzfP3LkW3HhLNinHTQllkZBRSy4KgRhgwomnr+0wtA= X-Gm-Gg: AR+sD12h7visUFCu+a8zhu/F+8XFB+HxN1hu1eeSQgU+YTbxIpieHg0+epr4VMviHbV qg45GIWqosbTlzVbbfwz0R6601HPx93NVbis4Ctd7m2S2ZvfX3ZP8MUgM6BaaBQsCH5MnFcn2qN s8yGNEbIAkBIvMg7RoOeBxVg9xgs1in0zNFDL0bzOJa75rutMFIn/IdOdKTAU+JDwvLCBjiXz+i Vc0njLzqCSsDFfCnnKu8gpwL6ti0WC176n6B2pbtJ08NVobdLKOhYHrW+jV2vWyZ4Lf3KCfNpJo 3oRoEh6tCGvXnoM2qMDw4WDi/Q3C9tir44CxgWFBbTFglSxESZp67z1h/sJEJNqyl4ZM/qUkk0L eLcgyh8tWd3gZdQVfkS9J1REVH111GT5Gplj3No6PtgHz5o2g3BurJICvjpat6QWSyqEd9y2qO7 Q3jXXx X-Received: by 2002:a05:6a00:8008:b0:848:767c:452f with SMTP id d2e1a72fcca58-84c29501a69mr22295483b3a.48.1784704453394; Wed, 22 Jul 2026 00:14:13 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e175f3180sm843890b3a.56.2026.07.22.00.14.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 00:14:12 -0700 (PDT) From: Abdurrahman Hussain Date: Wed, 22 Jul 2026 00:14:09 -0700 Subject: [PATCH v4 4/7] of/overlay: put property on deadprops only after changeset add succeeds Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-nh-of-alias-overlay-v4-4-fc96a40d2761@nexthop.ai> References: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> In-Reply-To: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> To: Rob Herring , Saravana Kannan Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784704448; l=1786; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=AB5Ed4fodLCRymlKclDBO+9rLTYghZ/tdB5y6s3AQQg=; b=BYa7Zu9dCUDbUP3nOajIh4PjrvleUwyzBC7YnmaDfwHJ2+zlJGnGqOR1g1xjn8Bvss7mKm4Ad zBf6VcVdIEyDDnuJtQMn/hmCmCyPhdk7utPWGpULsJ1UZ1H5g329TmW X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= add_changeset_property() links a new property of a not-yet-live target node into the node's deadprops list before handing it to of_changeset_add_property(). If that fails, the error path frees the property with __of_prop_free() but leaves the freed pointer linked in deadprops. When the aborted overlay's node is later released, of_node_release() walks deadprops and frees the property a second time =E2=80=94 a use-after-free followed by a double-free. Record the changeset entry first and link the property into deadprops only on success. of_changeset_add_property() only allocates and queues the changeset entry =E2=80=94 it never looks at the node's property lists =E2=80=94 so the order of the two steps is otherwise immaterial, and the error path is left freeing a property that nothing references. Assisted-by: Claude:claude-fable-5 [Claude Code] Signed-off-by: Abdurrahman Hussain --- drivers/of/overlay.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/drivers/of/overlay.c b/drivers/of/overlay.c index 74aea704835a..284c9bc6c9cf 100644 --- a/drivers/of/overlay.c +++ b/drivers/of/overlay.c @@ -358,12 +358,13 @@ static int add_changeset_property(struct overlay_chan= geset *ovcs, return -ENOMEM; =20 if (!prop) { - if (!target->in_livetree) { + ret =3D of_changeset_add_property(&ovcs->cset, target->np, + new_prop); + /* the detached node owns the property until the apply */ + if (!ret && !target->in_livetree) { new_prop->next =3D target->np->deadprops; target->np->deadprops =3D new_prop; } - ret =3D of_changeset_add_property(&ovcs->cset, target->np, - new_prop); } else { ret =3D of_changeset_update_property(&ovcs->cset, target->np, new_prop); --=20 2.54.0 From nobody Fri Jul 24 23:33:42 2026 Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E7E783C5546 for ; Wed, 22 Jul 2026 07:14:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.179 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704456; cv=none; b=Su4MnjVwPnOW5PGEMAM7UpWAYupr/pQD/oyzNl0ielpxfI22kwMTaYpBqOViYSu0/RHKtnH0es2zu78yUjZ3G7xsHeEJ8OcOwadHn22VqeZdlLUN/SXt3vpCCNGZ4KNBztjREFThb9URPNfvvW9+zrs8E44vo6K1zJkCT3tUS70= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704456; c=relaxed/simple; bh=56EaOWu081VTlPQJyGRihYZBiu5C/z9UW7OFVNQGU1c=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=A66Qkn4t1HcEmRljATicyTzzIkv+rWejZE3Y6igVI9MvqOTXGamqz4yRMIKGqoto9Ra/1x6raPKtuVSwiMGZxJRNTI6dWTB5NFXllpC2yg48lh3P4O4Eh1wy1Iz82ZWl3TDSyBSuWCD26M3v77YDYt9amPoLVb1jpuNlqSgp6Bg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=ijxmvbWh; arc=none smtp.client-ip=209.85.210.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="ijxmvbWh" Received: by mail-pf1-f179.google.com with SMTP id d2e1a72fcca58-8487b7b3fc8so12373159b3a.3 for ; Wed, 22 Jul 2026 00:14:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1784704454; x=1785309254; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ZzDaZAsTcNrLrR0gCV37X/IPnoIRBp6UhmD6467PjVk=; b=ijxmvbWhhl+nnoU0OJIGFM0rmt6+7EDcA0cm9HsGJC4LOp5hR0g/7GtjCX+6qLHtTj HunHFuINTNldLu0/tk8yqZ4Utu4r3vhXnfQXQf0+7tW6BT3sWK1cIlxXo+bv6GeKINc5 bukCgj6GK+dmsZmm8zbgke9xSALsYL72g2OnpCRVNIRX2cgiekFwJmCai48MxTN6LxUK gKu/HR8wOw6u44bOnRHWBbt0WnMisf60LclfA1ZNnwRpe+2Wl+ML1t3yATVLUldNe+4T tsMeT9qOEdNjNNfxHL3+VJrJsjaq0sMBs3qGpCRArzNefPdP+fHEH7FaxuchTR0ZzjLx mcxA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784704454; x=1785309254; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ZzDaZAsTcNrLrR0gCV37X/IPnoIRBp6UhmD6467PjVk=; b=EcWtzIKqOTprw4Gwy/rAxE7H2uQdO3+67NJah8ODfpeDvPoTPYX5kSrHGDrZgEe4x0 rLVp2sY0bSvgq3qi+pQioxh9P3jso86zQrfhetdoQRZxJz9uoawyW+wZVKMrb10yKq/3 GpN5/R6SRgoiemaE6LXJjfphVxaev0Oj6jtCGnEQlPPh5ukvw3XLPXiZrBKy+SQAAyjH iMFN5Rwk1p2N1CpYiBd4bwJpApNwkK7fKfgD+keODbwTnbMl8NYTfv0fA00nQ5TetD+m SaU16hHT8JHeIhhbqDrvBgiZzdmv9Q8r2WvtBrmh3dXLQASGxBzmaOP+hyypW55sOnO7 +y9A== X-Forwarded-Encrypted: i=1; AHgh+RpKXGVOq0ytqpPTbyckLH4l0rl5VwwtjQtOJ+4SYbhVZgxjEruABzyhpZ2/WDkbk56nyVPATJcRbCy8B4g=@vger.kernel.org X-Gm-Message-State: AOJu0YydvzZdJu1idzl6taSIHdes5D/zvoIbIiSfleqgQdUeE8fYNcYl HXfcJFQZtbTVQCu3agX8Pa85ECF6qlhD0kS/aHaFVh7y6zXhPImcjkBTcKpiRHEjcpw= X-Gm-Gg: AR+sD12kaYDY4qI60b2eqZVXoMaqgXv5A2I8t0Vmt7WJZxr4oocOrF75JhbuxKWIKts sBoJ8Si+OeKcjNvpMI3Ej4qZTTxWjs+U95tGiwkW4brpcLrpQBuQjxPe1qN9fBYc9Uz6quQKGq6 dDQBBEmNbSxJhzuTVHFHguD9K7rGzh9UtrnJ5k7ylWD1RCvrcBZrPGi2A46aJt11CVcMB1SsWP4 a0aPIvtqYgb2rSOUhs45Ai37XkNuodQOHrSN4+N5W7MVK918sPCulGZeF6J/7d9wOtQjoAZNSbV wYh2RvXDHX68wSB4KTfX3hbywTk6We/ojmBkx3MT1xzrSZ/BBkQ7S6kfm9RSWjh72b9fYl5bCJ2 U8+l4qGDqAKzalIXtXHxFnc/h/1JAS+fALED3Pfja5UFsGZh96YpTnxicxooDPMAK5syGjrTGk2 ArXTNz X-Received: by 2002:a05:6a00:928f:b0:847:9367:e054 with SMTP id d2e1a72fcca58-84c2950185amr21414583b3a.57.1784704454284; Wed, 22 Jul 2026 00:14:14 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e175f3180sm843890b3a.56.2026.07.22.00.14.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 00:14:13 -0700 (PDT) From: Abdurrahman Hussain Date: Wed, 22 Jul 2026 00:14:10 -0700 Subject: [PATCH v4 5/7] of/overlay: return ERR_PTR from dup_and_fixup_symbol_prop() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-nh-of-alias-overlay-v4-5-fc96a40d2761@nexthop.ai> References: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> In-Reply-To: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> To: Rob Herring , Saravana Kannan Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784704448; l=4996; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=56EaOWu081VTlPQJyGRihYZBiu5C/z9UW7OFVNQGU1c=; b=Ufc1sozpdFdWAt07dAHXiTNVa9LBYKpx58iwYkv2MmrwuzUkdtXciJVER66cMd7wp+jk9aLIT ojJ2maXobb7C+xBZxG7A3shgh4WgZL/3j1HUEr7Bwpq+8P/zxIr1lNv X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= dup_and_fixup_symbol_prop() returns NULL for three very different reasons: the property value is not a valid non-empty C string (malformed input), the value does not resolve to a node inside one of the overlay's fragments (not an overlay-internal path), and memory allocation failure. Its only caller today reports every NULL as -ENOMEM, so structural problems in an overlay's /__symbols__ node are diagnosed as memory exhaustion. The next patch reuses the helper for /aliases values, where the distinction is load-bearing: a value that doesn't resolve inside the overlay is a legacy alias that must be copied verbatim, a malformed value must be admitted inertly with a warning, and only a real allocation failure may fail the overlay apply. Return ERR_PTR instead: -EINVAL for malformed values, -ENODEV when the value is not a path into one of the overlay's fragments, -ENOMEM for allocation failures. The /__symbols__ caller now propagates the distinct errno instead of collapsing everything to -ENOMEM. Also verify textually that the value descends through the matched fragment's __overlay__ node before slicing it. The old code resolved only the first path component inside overlay_root and then cut the value at the length of the __overlay__ node's rendered path on faith: a value like "/soc/serial@1234" in an overlay that also carries a hand-named fragment "soc" =E2=80=94 or a /__symbols__ value with a bogus tail =E2=80=94 was sliced mid-string and rewritten to garbage. A prefix mismatch is -ENODEV (not an overlay-internal path), as is a value shorter than the fragment's __overlay__ path. Assisted-by: Claude:claude-fable-5 [Claude Code] Signed-off-by: Abdurrahman Hussain --- drivers/of/overlay.c | 35 ++++++++++++++++++++++++++--------- 1 file changed, 26 insertions(+), 9 deletions(-) diff --git a/drivers/of/overlay.c b/drivers/of/overlay.c index 284c9bc6c9cf..d4d2591e735a 100644 --- a/drivers/of/overlay.c +++ b/drivers/of/overlay.c @@ -206,6 +206,10 @@ static void overlay_fw_devlink_refresh(struct overlay_= changeset *ovcs) * The duplicated property value will be modified by replacing the * "/fragment_name/__overlay/" portion of the value with the target * path from the fragment node. + * + * Return: the fixed-up property, or ERR_PTR: -EINVAL if @prop's value + * is not a valid non-empty C string, -ENODEV if it is not a path into + * one of @ovcs's fragments, -ENOMEM on allocation failure. */ static struct property *dup_and_fixup_symbol_prop( struct overlay_changeset *ovcs, const struct property *prop) @@ -217,6 +221,8 @@ static struct property *dup_and_fixup_symbol_prop( const char *path; const char *path_tail; const char *target_path; + char *overlay_name; + bool mismatch; int k; int overlay_name_len; int path_len; @@ -224,14 +230,14 @@ static struct property *dup_and_fixup_symbol_prop( int target_path_len; =20 if (!prop->value) - return NULL; + return ERR_PTR(-EINVAL); if (strnlen(prop->value, prop->length) >=3D prop->length) - return NULL; + return ERR_PTR(-EINVAL); path =3D prop->value; path_len =3D strlen(path); =20 if (path_len < 1) - return NULL; + return ERR_PTR(-EINVAL); fragment_node =3D __of_find_node_by_path(ovcs->overlay_root, path + 1); overlay_node =3D __of_find_node_by_path(fragment_node, "__overlay__/"); of_node_put(fragment_node); @@ -243,18 +249,27 @@ static struct property *dup_and_fixup_symbol_prop( break; } if (k >=3D ovcs->count) - return NULL; + return ERR_PTR(-ENODEV); + + overlay_name =3D kasprintf(GFP_KERNEL, "%pOF", fragment->overlay); + if (!overlay_name) + return ERR_PTR(-ENOMEM); + overlay_name_len =3D strlen(overlay_name); =20 - overlay_name_len =3D snprintf(NULL, 0, "%pOF", fragment->overlay); + /* @path must descend through this fragment's __overlay__ node */ + mismatch =3D overlay_name_len > path_len || + strncmp(path, overlay_name, overlay_name_len) !=3D 0 || + (path[overlay_name_len] !=3D '/' && path[overlay_name_len]); + kfree(overlay_name); + if (mismatch) + return ERR_PTR(-ENODEV); =20 - if (overlay_name_len > path_len) - return NULL; path_tail =3D path + overlay_name_len; path_tail_len =3D strlen(path_tail); =20 target_path =3D kasprintf(GFP_KERNEL, "%pOF", fragment->target); if (!target_path) - return NULL; + return ERR_PTR(-ENOMEM); target_path_len =3D strlen(target_path); =20 new_prop =3D kzalloc_obj(*new_prop); @@ -281,7 +296,7 @@ static struct property *dup_and_fixup_symbol_prop( err_free_target_path: kfree(target_path); =20 - return NULL; + return ERR_PTR(-ENOMEM); } =20 /** @@ -350,6 +365,8 @@ static int add_changeset_property(struct overlay_change= set *ovcs, if (prop) return -EINVAL; new_prop =3D dup_and_fixup_symbol_prop(ovcs, overlay_prop); + if (IS_ERR(new_prop)) + return PTR_ERR(new_prop); } else { new_prop =3D __of_prop_dup(overlay_prop, GFP_KERNEL); } --=20 2.54.0 From nobody Fri Jul 24 23:33:42 2026 Received: from mail-pf1-f169.google.com (mail-pf1-f169.google.com [209.85.210.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C84CF3E2AD6 for ; Wed, 22 Jul 2026 07:14:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704460; cv=none; b=DhpiX7HCLYaPFgBtRwzc69/nS0z/2dwKm2uKizen/6VS+NM5zmsKm+pHG4cmCuE3WfbyyTcfSexyv/wkLRhRWGIau22VlbDMLOFx6UidJYmb+gK8f9I4+MeMvpGxUnKmVMf6jo3ywwHaIiRa3udHnGH2aUpTsNkuehOAwZgb9qA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704460; c=relaxed/simple; bh=zybjIXFHNavrw8uY4Okis92bt3g9zNjWZIZ9RQh5a8c=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=K8Oaajq/svwLR/tjQxTO2syf5CcFs1H3ytorjT/QGBw48mwGqmjlWmfElHRYWHwcFNa41ZVzGHhDfhyMr8ZOkyU6p3v3zwnJQysP5usuNN17RrEGmCMbDUvPi1G76L3Y9RMQOXLUR59DHnw37TRuZKKPECT60vmBnTV2NiRBk3c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=k2PqF/MD; arc=none smtp.client-ip=209.85.210.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="k2PqF/MD" Received: by mail-pf1-f169.google.com with SMTP id d2e1a72fcca58-8485bd28dd0so14042768b3a.2 for ; Wed, 22 Jul 2026 00:14:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1784704455; x=1785309255; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=fbAB56al18SncLTES8Sq3tgbthMQkR3WWR1QBsCKMJw=; b=k2PqF/MDDkLXJu+oGaeNO+BFeNVVh/sD+kxjCInZ2H1ztWSX9FWQ5BzmeCZuZAmyys Vg1wgaL1hQm8i3i3cODqJDNyot+ksvxKVpW3Mfoaz2bAqtWZ8y/f1hyAu5VDw8GIbO38 AXNNeKnzBNRP8EzEaRbckg3V+2VdqT4WvJsEsr0SSVlV+m6zKQpt2rXt49MhsewxQ6Pk R93PTZyxtjEej7jkZ6tZPD3uymSvpWJwhrvNkIMiJG6lAIus91LiphnCVfIswI9ydX8F QLkSdadyb+6HYX+Ye7wDJUa3897xrbCmqzXui6wnsQABIxBiFRnGwu+J6I6aSMsMy7DN W8dg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784704455; x=1785309255; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=fbAB56al18SncLTES8Sq3tgbthMQkR3WWR1QBsCKMJw=; b=mepjEJKtIDc4EAGVo1ZQ0FyeDRGf6JJpL+YuESz0BvYyTwd6QndXNvUk6YN1skUpHd 3BFrC9ouD+T3ZBNmP7U8/9YsoQszU0TYhdCgzWo2M7MxRh+UBxIQgkNR5rQoazS4A4EE i3jKOSCC07niOOKq6eboskBOXw0RDQTQ2SogzSeX9NKCMNmn5rq9B2/HI9euZhMoxBWJ AbyrvIKQhEu9h6vlAnZXJDhU2nsMg9z2RKwbcHQ+hdOtCx7pnIId8xgDCNy7W9/YE+kq cGEqINmirCFWGXXzuMsKVMBnKMl7EZil59xhDSjkdXNMLuTYVKL+UCNQkezugxzm0Xfk JdhQ== X-Forwarded-Encrypted: i=1; AHgh+Rp3Xom5BsSzsijodbhbdOsGhvcUn99cBx07JsCay8RRAXZxuX0pwVRmn6CDlFDzbsO6h7Y3IGfjghJ6w1c=@vger.kernel.org X-Gm-Message-State: AOJu0YyY2d1OrXLrWejii3vCEk32oMwX68rjIcxtDQkBKuB5j12GNScM 3PdcWysxOjncAowkev6AxH3S/ewxo03x3WyQjHnTPHP6vBkK+ZXdiSuFezfZ051jQvg= X-Gm-Gg: AR+sD12mDuSgZc3GJVgOq2CUVPxsWnXcGiDOG+QXtWjuv5MjZ2iH6gxAD/AfQwi7zCw 16p6ur4IFCQI5m2rTE8eo4f9m0geqc5LkEgiUpkfBzfSklY0qmNbpX5fVRPyBn936UVghcs5Neq 2jMZxZsVP+CYox5IRFFiqxzVTrvNG8jDJ7Pp3IzCDGc0eAwpjwU1c8cSHjgGBKeHZw961iBLbVW Lnn+XZry4KMi6CICpeoZpYw1kcFtr/KUgaDQ1t8ErkHe6hWcPiKTo0kAY9ZmgMZmHmfjesuNqPJ FllEPXys7JUq7za2AQfvCak66pGaFxNwAo0V/wOY51AqiJhf1BO+U0l1VsoD/UUubIdRtsAeTen n2/bqPFR3TpO7pMPG17aAmmZ5xCCF5eo8ngGScOe7ncPlOU0rmktbcCJ5TmU6ziFIq8coXKgJJl KhcD4e X-Received: by 2002:a05:6a00:4215:b0:848:5ed6:9d27 with SMTP id d2e1a72fcca58-84c294d4401mr22091120b3a.36.1784704455221; Wed, 22 Jul 2026 00:14:15 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e175f3180sm843890b3a.56.2026.07.22.00.14.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 00:14:14 -0700 (PDT) From: Abdurrahman Hussain Date: Wed, 22 Jul 2026 00:14:11 -0700 Subject: [PATCH v4 6/7] of/overlay: rewrite /aliases path values to live-tree paths Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-nh-of-alias-overlay-v4-6-fc96a40d2761@nexthop.ai> References: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> In-Reply-To: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> To: Rob Herring , Saravana Kannan Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784704448; l=3894; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=zybjIXFHNavrw8uY4Okis92bt3g9zNjWZIZ9RQh5a8c=; b=WIAtCu8rho7K3VrHV14+snVW/Rk0fqMEHbPqG5ikYK3bjGoby/692T6YIslCHOWHn908VGKH6 cTpr+1KTH68DB/oDjSOY24ZDM6Q+Pn8F4o3p8JR2756dkQOIiTU7EeN X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= /aliases entries added by an overlay reference labeled nodes inside the overlay via '&label' in the .dtso. dtc renders those references as string paths at compile time, but the paths encode the overlay's internal fragment layout (e.g. "/fragment@1/__overlay__/fpga@0/i2c@40000") rather than the location where the node will live after apply. Currently only /__symbols__ has its property values rewritten from overlay-internal paths to live-tree paths by dup_and_fixup_symbol_prop(). /aliases values fall through the plain __of_prop_dup() path and are copied byte-for-byte, so of_find_node_by_path() on such a value returns NULL, of_alias_get_id() reports -ENODEV =E2=80=94 and the reconfig notifier added earlier in this series sees uninterpretable paths and can't populate aliases_lookup for overlay-declared aliases. The values in /aliases follow the same textual convention as /__symbols__, so we can reuse the existing rewriter. Detect the /aliases target node (of_node_is_aliases(), the same predicate the reconfig notifier uses) and offer every non-pseudo property to dup_and_fixup_symbol_prop(); the previous patch made its return value carry the distinction this needs. A value that resolves inside one of the overlay's fragments is stored rewritten. -ENODEV means the value is not a path into this overlay =E2=80=94 legacy string aliases like "ttyS0= ", or absolute live-tree paths =E2=80=94 and is copied verbatim, as before this series. -EINVAL means the value is not a valid non-empty C string; it is also copied verbatim, but with a warning: consumers (of_alias_create() and the alias path lookup) validate before dereferencing, so a malformed alias is inert rather than a reason to reject an otherwise-valid overlay that applied cleanly before this series. Only -ENOMEM fails the apply. Matching on where the value resolves rather than on a "/fragment@" name prefix matters: init_overlay_changeset() accepts fragments with any node name, and dtc emits the actual fragment name into the alias value, so a prefix test would silently leave a hand-named fragment's alias unrewritten (and misroute a live-tree path that happens to start with "/fragment@"). Pseudo-properties (name, phandle, linux,phandle) are exempt from the /aliases handling: the is_pseudo_property() skip at the top of add_changeset_property() only covers targets already in the live tree, so a phandle of a newly created /aliases node would otherwise reach the rewriter =E2=80=94 and a phandle value is a raw cell, not a C string. Such properties take the plain __of_prop_dup() path as before this patch; of_alias_create() skips them at notifier time. Assisted-by: Claude:claude-fable-5 [Claude Code] Signed-off-by: Abdurrahman Hussain --- drivers/of/overlay.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/drivers/of/overlay.c b/drivers/of/overlay.c index d4d2591e735a..aabe8c8bea4b 100644 --- a/drivers/of/overlay.c +++ b/drivers/of/overlay.c @@ -367,6 +367,19 @@ static int add_changeset_property(struct overlay_chang= eset *ovcs, new_prop =3D dup_and_fixup_symbol_prop(ovcs, overlay_prop); if (IS_ERR(new_prop)) return PTR_ERR(new_prop); + } else if (!is_pseudo_property(overlay_prop->name) && + of_node_is_aliases(target->np)) { + /* rewrite overlay-internal alias values to live-tree paths */ + new_prop =3D dup_and_fixup_symbol_prop(ovcs, overlay_prop); + if (new_prop =3D=3D ERR_PTR(-ENOMEM)) + return -ENOMEM; + if (IS_ERR(new_prop)) { + if (new_prop =3D=3D ERR_PTR(-EINVAL)) + pr_warn("%pOF/%s is not a valid string; alias will be inert\n", + target->np, overlay_prop->name); + /* not overlay-internal: copy verbatim, consumers validate */ + new_prop =3D __of_prop_dup(overlay_prop, GFP_KERNEL); + } } else { new_prop =3D __of_prop_dup(overlay_prop, GFP_KERNEL); } --=20 2.54.0 From nobody Fri Jul 24 23:33:42 2026 Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EC2633E63AE for ; Wed, 22 Jul 2026 07:14:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.179 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704463; cv=none; b=cFSZUX4pRYFny9gpatuYKREaGkbePRADKr0qLZr01pdSkeYKzhWnXnJB6HteB1zZO0EWHnuEpjJ6n7RkXEZctjI8KPHTAzYiDKSHoXEnT47A8xJrhXyjsKQjErZlj971Y3mQOSi74HbpFGTu7KZxMxtlLNYqzh/8xVPbuFx6wvo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784704463; c=relaxed/simple; bh=GiQ8QmcT52eeZQ8hU0W7klQyaak1qO4zuG4S19GZ1Eo=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=kx4ragSgVVPUjygddMIhBvv4Oqe2xi31aiadY5DOBi5VTbxy9wKjNIpjMbwD3EABVdysHkPiCT4TWy0fQgTIhQvY4EmyHLQA6WpxW0arNWVw1vJNBwj3idn/ffctWpwkifz7k1Cgiv1uWad1LVdMaT0zc8WIIU6U0IOcbIF4coA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=RhaQZjh0; arc=none smtp.client-ip=209.85.210.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="RhaQZjh0" Received: by mail-pf1-f179.google.com with SMTP id d2e1a72fcca58-845b6d9bf39so5595599b3a.1 for ; Wed, 22 Jul 2026 00:14:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1784704456; x=1785309256; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=E3gS4IFrL1u/fKDkWRYURGH9FqMyDvXnOF4aO0ajrY4=; b=RhaQZjh08GgLVleoKE9JifepJdZeR5UZ7Y23vwAwtSO40h3Wn07IfJwRPCyVcinU00 RZZXO1JNdzbSQ7okTGgoE0sIZSJgek5tTd5vVmQcAjCtPrG1O5FCa4uCvgTfiC07Y9o4 R8Y8qdntyeZYdVf33+c7zGouOoJevQvzN1JXUg1UpBR2EKTFRRN7dYAfewKCp4ZR2yoI 5Tm0EMh2EsyOuJJ3TdjPWoh7qNVk7kea1Akwmdh+XF5n4FLiX4aPjPtfAuiv+BvPE2fG wf2SO6Udb4xgFfuNu/oZLYpbsQ83WnSjADC+Mvj1Zbh2VfOvZI4QZskY5ENb1trKke5k t0JQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784704456; x=1785309256; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=E3gS4IFrL1u/fKDkWRYURGH9FqMyDvXnOF4aO0ajrY4=; b=PEND5Se/SQBxSoM+sqTOTm9Ot8I087ufpn6N5QVYzqA4Qj1W5ES1UNVsAkn5TrrCIw SRTNXQ93zEvlpwKtLeEijTfk1wlt6zf2ZirmqSQQayKqAlERUzDreEzRL/dPAvbsBWFH NelTcIIWvGryynq0D3klmH4NOVg1HqZOBg+QO96unkntKPi9qhGzOfhsVZxBm9/IqNYD HKG1MKS6FQb4nOB379JDv5p9xrZ1I5Tg5QP2hWQ1D+N3chPVS32fNNJpyqwTrg+UN+sz uQmR/QLP6sXvtAWdBbtmTXrAY712LKMEQakwoOtsLyfAV5rc2MKMBuvLY1AnU84a05n+ q9YQ== X-Forwarded-Encrypted: i=1; AHgh+RpcYnAGMGvQLPKCJb0WFZL1WZddCYpRzMdFXm7oiVKojO9FRB0bBhrAliRqkZIshRqcSQMST89LQYc/sqc=@vger.kernel.org X-Gm-Message-State: AOJu0YxmIjfE9UCWOsl7w6X3X6MyMrt3F2+xCX0IV3NLeTgPExeEhyEN 8CvKCjYaNaqXz85ca8ledkaMCeLp5to4rT3Q9Dz/g6ZYFu2rzG3l5VJQZbYFvJD6/fY= X-Gm-Gg: AR+sD10f8SMFMIhHSZTNXX1TOY5eXnoKMG0YlmrYskuBcH1XuYdLEz/CaSysak1R8g4 it+SiG4CLcPEYCykztV2sux4TwaVvBGgTIL2jkCVJ9piKRuU3tYHykaEiGXbIhnX6/Nq7XW00gV bBQNSfA2DIn5XvawtzzhaZU6TMoEslSmnpaCS+lx425xyPwkADsn244EcxgJsl07TwH4YwXD3CJ G0pQw+bK509mPucpUwGvd+tgqWmEN0EhwTz5oZuMbuO9/4O/h2forTd6lD5oZ7lrxdwGUZDoDm5 EG4cO0Vw+AWxDJ97cKcXz/G2dDiXz5QrUZ3G9It7sHN276x+EiOxK0v2fv4+OV2xOoK0UIm0SjX uychCzxzSn6ZnP08vOr7YTPurhql6bsa7fY4hs1PbsYJ/TXNviYc+fFYwxX5CYI+mZQ6R5NHZZ+ TIbK1V1BKJbyKG8N0= X-Received: by 2002:a05:6a00:8382:b0:84e:242:4bb2 with SMTP id d2e1a72fcca58-84e15f63738mr2216369b3a.4.1784704456218; Wed, 22 Jul 2026 00:14:16 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e175f3180sm843890b3a.56.2026.07.22.00.14.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 00:14:15 -0700 (PDT) From: Abdurrahman Hussain Date: Wed, 22 Jul 2026 00:14:12 -0700 Subject: [PATCH v4 7/7] of: unittest: cover /aliases updates from overlay apply/revert Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-nh-of-alias-overlay-v4-7-fc96a40d2761@nexthop.ai> References: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> In-Reply-To: <20260722-nh-of-alias-overlay-v4-0-fc96a40d2761@nexthop.ai> To: Rob Herring , Saravana Kannan Cc: devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784704448; l=6951; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=GiQ8QmcT52eeZQ8hU0W7klQyaak1qO4zuG4S19GZ1Eo=; b=T0W7eLKQIoliJGMM3fe/VSdz5oI4Ld5EAvhtEdOlb0u/CNx2YQpUw3fvBcM0gWduSj8bAjTQ1 LImdpuaLJORCt+eTirRtDyaLUilgyeWtWHAaRHNJ+WdPwitM05PWMgZ X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= Add overlay_alias.dtso plus of_unittest_overlay_alias() to cover the "aliases inside an overlay" flow end-to-end. The overlay has two fragments: fragment@0: target-path=3D"" grafts a labeled node under target_base. fragment@1: target-path=3D"/aliases" adds `testcase-alias99 =3D &