From: Junjie Cao <junjie.cao@intel.com>
To: Lee Jones <lee@kernel.org>, Daniel Thompson <danielt@kernel.org>,
Jingoo Han <jingoohan1@gmail.com>
Cc: dri-devel@lists.freedesktop.org, linux-leds@vger.kernel.org,
linux-kernel@vger.kernel.org, Pengyu Luo <mitltlatltl@gmail.com>,
Junjie Cao <junjie.cao@linux.dev>
Subject: [PATCH v3 2/3] backlight: aw99706: Validate all DT property values consistently
Date: Tue, 4 Aug 2026 11:02:54 +0800 [thread overview]
Message-ID: <20260804030255.1934470-3-junjie.cao@intel.com> (raw)
In-Reply-To: <20260804030255.1934470-1-junjie.cao@intel.com>
From: Junjie Cao <junjie.cao@linux.dev>
The lookup helpers for dim-mode and ramp-ctl take a shortcut when
lookup_tbl is NULL: they accept any u32 value without range-checking
and return success unconditionally. Out-of-range values get silently
truncated by regmap_update_bits instead of triggering the dev_warn +
default-fallback path that the other properties use.
Add a field-width check for the NULL-table case so that values
exceeding the register field maximum are rejected the same way a
table-lookup miss is.
The switching frequency table has a second hole: reserved slots use 0
as their marker, so "awinic,sw-freq-hz = <0>" matches slot 0 and
programs a reserved encoding. Make the reserved marker U32_MAX and
skip such slots during lookup.
While here, also switch the error returns to -EINVAL for consistency.
Fixes: 147b38a5ad06 ("backlight: aw99706: Add support for Awinic AW99706 backlight")
Signed-off-by: Junjie Cao <junjie.cao@linux.dev>
---
drivers/video/backlight/aw99706.c | 15 ++++++++++-----
1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/drivers/video/backlight/aw99706.c b/drivers/video/backlight/aw99706.c
index e130f164303a..6ec49b6cb14c 100644
--- a/drivers/video/backlight/aw99706.c
+++ b/drivers/video/backlight/aw99706.c
@@ -60,7 +60,7 @@
#define AW99706_MTPLDOSEL_REG 0x1E
#define AW99706_MTPRUN_REG 0x1F
-#define RESV 0
+#define RESV U32_MAX
/* Boost switching frequency table, in Hz */
static const u32 aw99706_sw_freq_tbl[] = {
@@ -94,17 +94,19 @@ static int aw99706_dt_property_lookup(const struct aw99706_dt_prop *prop,
int i;
if (!prop->lookup_tbl) {
+ if (dt_val > (prop->mask >> __ffs(prop->mask)))
+ return -EINVAL;
*val = dt_val;
return 0;
}
for (i = 0; i < prop->tbl_size; i++)
- if (prop->lookup_tbl[i] == dt_val)
+ if (prop->lookup_tbl[i] != RESV && prop->lookup_tbl[i] == dt_val)
break;
*val = i;
- return i == prop->tbl_size ? -1 : 0;
+ return i == prop->tbl_size ? -EINVAL : 0;
}
#define MIN_ILED_MAX 5000
@@ -116,11 +118,14 @@ aw99706_dt_property_iled_max_convert(const struct aw99706_dt_prop *prop,
u32 dt_val, u8 *val)
{
if (dt_val > MAX_ILED_MAX || dt_val < MIN_ILED_MAX)
- return -1;
+ return -EINVAL;
+
+ if ((dt_val - MIN_ILED_MAX) % STEP_ILED_MAX)
+ return -EINVAL;
*val = (dt_val - MIN_ILED_MAX) / STEP_ILED_MAX;
- return (dt_val - MIN_ILED_MAX) % STEP_ILED_MAX;
+ return 0;
}
static const struct aw99706_dt_prop aw99706_dt_props[] = {
--
2.43.0
next prev parent reply other threads:[~2026-08-04 3:04 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 3:02 [PATCH v3 0/3] backlight: aw99706: DT parsing and blank state fixes Junjie Cao
2026-08-04 3:02 ` [PATCH v3 1/3] backlight: aw99706: Fix DT property names to match binding Junjie Cao
2026-08-04 3:28 ` sashiko-bot
2026-08-10 10:29 ` Daniel Thompson
2026-08-04 3:02 ` Junjie Cao [this message]
2026-08-04 3:14 ` [PATCH v3 2/3] backlight: aw99706: Validate all DT property values consistently sashiko-bot
2026-08-10 10:32 ` Daniel Thompson
2026-08-04 3:02 ` [PATCH v3 3/3] backlight: aw99706: Honor the core blank state in update_status() Junjie Cao
2026-08-04 3:15 ` sashiko-bot
2026-08-10 10:32 ` Daniel Thompson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260804030255.1934470-3-junjie.cao@intel.com \
--to=junjie.cao@intel.com \
--cc=danielt@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=jingoohan1@gmail.com \
--cc=junjie.cao@linux.dev \
--cc=lee@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-leds@vger.kernel.org \
--cc=mitltlatltl@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.