From: sashiko-bot@kernel.org
To: "Rodrigo Alencar" <rodrigo.alencar@analog.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v9 15/17] iio: frequency: ad9910: show channel priority in debugfs
Date: Wed, 22 Jul 2026 16:52:27 +0000 [thread overview]
Message-ID: <20260722165227.F0FEC1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260722-ad9910-iio-driver-v9-15-459d1df5ac56@analog.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Lockless access to `indio_dev->active_scan_mask` in debugfs callbacks leads to a Time-of-Check to Time-of-Use (TOCTOU) Use-After-Free or NULL pointer dereference.
--
--- Patch [15]: [PATCH v9 15/17] iio: frequency: ad9910: show channel priority in debugfs ---
commit fd59307766b0ba216861518edba7f7cf6e5c6e92
Author: Rodrigo Alencar <rodrigo.alencar@analog.com>
iio: frequency: ad9910: show channel priority in debugfs
This commit exposes frequency, phase, and amplitude source attributes in
debugfs for the AD9910 driver. These attributes indicate which channel
is sourcing specific DDS parameters based on the device's priority table.
> diff --git a/drivers/iio/frequency/ad9910.c b/drivers/iio/frequency/ad9910.c
> index 49a70909bf5fe..32bd1e6cf14f7 100644
> --- a/drivers/iio/frequency/ad9910.c
> +++ b/drivers/iio/frequency/ad9910.c
[ ... ]
> +static inline const char *ad9910_frequency_source_get(struct iio_dev *indio_dev)
> +{
> + struct ad9910_state *st = iio_priv(indio_dev);
> + bool ram_en, mode_en;
> +
> + guard(mutex)(&st->lock);
> +
[ ... ]
> + /* Parallel data port enabled and data destination is frequency */
> + mode_en = FIELD_GET(AD9910_CFR2_PARALLEL_DATA_PORT_EN_MSK,
> + st->reg[AD9910_REG_CFR2].val32);
> + if (mode_en && indio_dev->active_scan_mask &&
> + test_bit(AD9910_SCAN_IDX_FREQ, indio_dev->active_scan_mask))
^^^^^^^^^^^^^^^^^^^^^^^^^^^
[Severity: Medium]
Is it safe to access indio_dev->active_scan_mask here without holding the
IIO core mlock?
If another thread concurrently disables buffers, could the mask be freed and
set to NULL between the if check and test_bit(), leading to a NULL pointer
dereference?
While this appears to be a latent regression since the driver currently only
sets INDIO_DIRECT_MODE, could this cause crashes if buffer support is added in
the future?
> + return ad9910_channel_str[AD9910_CHAN_IDX_PARALLEL_FREQ];
[ ... ]
> +static inline const char *ad9910_phase_source_get(struct iio_dev *indio_dev)
> +{
> + struct ad9910_state *st = iio_priv(indio_dev);
> + bool ram_en, mode_en;
> + u32 destination;
> +
> + guard(mutex)(&st->lock);
> +
[ ... ]
> + /* Parallel data port enabled and data destination is phase */
> + mode_en = FIELD_GET(AD9910_CFR2_PARALLEL_DATA_PORT_EN_MSK,
> + st->reg[AD9910_REG_CFR2].val32);
> + if (mode_en && indio_dev->active_scan_mask) {
> + if (test_bit(AD9910_SCAN_IDX_PHASE, indio_dev->active_scan_mask))
^^^^^^^^^^^^^^^^^^^^^^^^^^^
[Severity: Medium]
Could this also be affected by the same lockless access issue with
indio_dev->active_scan_mask mentioned above?
> + return ad9910_channel_str[AD9910_CHAN_IDX_PARALLEL_PHASE];
> + if (test_bit(AD9910_SCAN_IDX_POLAR_PHASE, indio_dev->active_scan_mask))
> + return ad9910_channel_str[AD9910_CHAN_IDX_PARALLEL_POLAR_PHASE];
> + }
[ ... ]
> +static inline const char *ad9910_amplitude_source_get(struct iio_dev *indio_dev)
> +{
> + struct ad9910_state *st = iio_priv(indio_dev);
> + bool ram_en, mode_en;
> + u32 destination;
> +
> + guard(mutex)(&st->lock);
> +
[ ... ]
> + /* Parallel data port enabled and data destination is amplitude */
> + mode_en = FIELD_GET(AD9910_CFR2_PARALLEL_DATA_PORT_EN_MSK,
> + st->reg[AD9910_REG_CFR2].val32);
> + if (mode_en && indio_dev->active_scan_mask) {
> + if (test_bit(AD9910_SCAN_IDX_AMP, indio_dev->active_scan_mask))
^^^^^^^^^^^^^^^^^^^^^^^^^^^
[Severity: Medium]
Does this also have the same lockless access issue with
indio_dev->active_scan_mask?
> + return ad9910_channel_str[AD9910_CHAN_IDX_PARALLEL_AMP];
> + if (test_bit(AD9910_SCAN_IDX_POLAR_AMP, indio_dev->active_scan_mask))
> + return ad9910_channel_str[AD9910_CHAN_IDX_PARALLEL_POLAR_AMP];
> + }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260722-ad9910-iio-driver-v9-0-459d1df5ac56@analog.com?part=15
next prev parent reply other threads:[~2026-07-22 16:52 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 15:50 [PATCH v9 00/17] AD9910 Direct Digital Synthesizer Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 01/17] iio: ABI: add attributes for altcurrent channels Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 02/17] iio: ABI: raw, scale and offset for frequency/phase channels Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 03/17] iio: ABI: add parent entry for iio channels Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 04/17] iio: add IIO_FREQUENCY channel type Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 05/17] iio: core: support 64-bit register through debugfs Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 06/17] iio: core: create local __iio_chan_prefix_emit() for reuse Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 07/17] iio: test: add kunit tests for channel prefix naming generation Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 16:13 ` sashiko-bot
2026-07-22 15:50 ` [PATCH v9 08/17] iio: core: add hierarchical channel relationships Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 09/17] dt-bindings: iio: frequency: add ad9910 Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 10/17] iio: frequency: ad9910: initial driver implementation Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 16:24 ` sashiko-bot
2026-07-22 15:50 ` [PATCH v9 11/17] iio: frequency: ad9910: add basic parallel port support Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 12/17] iio: frequency: ad9910: add digital ramp generator support Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 13/17] iio: frequency: ad9910: add RAM mode support Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 16:44 ` sashiko-bot
2026-07-22 15:50 ` [PATCH v9 14/17] iio: frequency: ad9910: add output shift keying support Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 15:50 ` [PATCH v9 15/17] iio: frequency: ad9910: show channel priority in debugfs Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 16:52 ` sashiko-bot [this message]
2026-07-22 15:50 ` [PATCH v9 16/17] iio: ABI: add docs for ad9910 sysfs and debugfs entries Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
2026-07-22 16:50 ` sashiko-bot
2026-07-22 15:50 ` [PATCH v9 17/17] docs: iio: add documentation for ad9910 driver Rodrigo Alencar via B4 Relay
2026-07-22 15:50 ` Rodrigo Alencar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260722165227.F0FEC1F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=rodrigo.alencar@analog.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.