Commit b4ce102b2cd8 for kernel

commit b4ce102b2cd88424c5860fbbb20b9eb343a93bf4
Author: Daniel Golle <daniel@makrotopia.org>
Date:   Tue Jul 28 05:52:14 2026 +0100

    net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend

    bus->read() returns a negative errno on failure, but
    mt7530_regmap_read() assigns it to a u16, truncating e.g. -ETIMEDOUT
    into 0xff92, and returns success. The garbage word is then consumed as
    register data, and read-modify-write cycles write it back to the
    switch. Check both reads and propagate their errors.

    The same defect existed in mt7530_mii_read() since the driver was
    introduced and moved into the regmap backend unchanged.

    Fixes: b8f126a8d543 ("net-next: dsa: add dsa support for Mediatek MT7530 switch")
    Signed-off-by: Daniel Golle <daniel@makrotopia.org>
    Reviewed-by: Andrew Lunn <andrew@lunn.ch>
    Link: https://patch.msgid.link/3c628e48276c2e5522c8795a6be60d11c7a76a7d.1785213071.git.daniel@makrotopia.org
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>

diff --git a/drivers/net/dsa/mt7530-mdio.c b/drivers/net/dsa/mt7530-mdio.c
index 11ea924a9f35..784dd58a7158 100644
--- a/drivers/net/dsa/mt7530-mdio.c
+++ b/drivers/net/dsa/mt7530-mdio.c
@@ -55,8 +55,15 @@ mt7530_regmap_read(void *context, unsigned int reg, unsigned int *val)
 	if (ret < 0)
 		return ret;

-	lo = bus->read(bus, priv->mdiodev->addr, r);
-	hi = bus->read(bus, priv->mdiodev->addr, 0x10);
+	ret = bus->read(bus, priv->mdiodev->addr, r);
+	if (ret < 0)
+		return ret;
+	lo = ret;
+
+	ret = bus->read(bus, priv->mdiodev->addr, 0x10);
+	if (ret < 0)
+		return ret;
+	hi = ret;

 	*val = (hi << 16) | (lo & 0xffff);