All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tom Rini <trini@konsulko.com>
To: u-boot@lists.u-boot-project.org
Cc: Rasmus Villemoes <ravi@prevas.dk>,
	James Hilliard <james.hilliard1@gmail.com>,
	Jordi Trepat Mur <yordy1902@gmail.com>,
	Igor Opaniuk <igor.opaniuk@gmail.com>
Subject: Fwd: New Defects reported by Coverity Scan for Das U-Boot
Date: Mon, 10 Aug 2026 17:14:48 -0600	[thread overview]
Message-ID: <20260810231448.GH1160436@bill-the-cat> (raw)

[-- Attachment #1: Type: text/plain, Size: 5407 bytes --]

Here's the latest report

---------- Forwarded message ---------
From: <scan-admin@coverity.com>
Date: Mon, Aug 10, 2026 at 5:06 PM
Subject: New Defects reported by Coverity Scan for Das U-Boot
To: <tom.rini@gmail.com>


Hi,

Please find the latest report on new defect(s) introduced to *Das U-Boot*
found with Coverity Scan.

   - *New Defects Found:* 5
   - 1 defect(s), reported by Coverity Scan earlier, were marked fixed in
   the recent build analyzed by Coverity Scan.
   - *Defects Shown:* Showing 5 of 5 defect(s)

Defect Details

** CID 652911:       Resource leaks  (RESOURCE_LEAK)
/drivers/pinctrl/pinctrl-single.c: 579           in single_add_gpio_func()


_____________________________________________________________________________________________
*** CID 652911:         Resource leaks  (RESOURCE_LEAK)
/drivers/pinctrl/pinctrl-single.c: 579             in single_add_gpio_func()
573     			break;
574
575     		list_add_tail(&range->node, &priv->gpiofuncs);
576     		range++;
577     	}
578
>>>     CID 652911:         Resource leaks  (RESOURCE_LEAK)
>>>     Variable "range" going out of scope leaks the storage it points to.
579     	return 0;
580     }
581
582     static int single_probe(struct udevice *dev)
583     {
584     	struct single_pdata *pdata = dev_get_plat(dev);

** CID 652910:       Memory - illegal accesses  (UNINIT)


_____________________________________________________________________________________________
*** CID 652910:         Memory - illegal accesses  (UNINIT)
/lib/libavb/avb_cmdline.c: 342             in avb_append_options()
336             break;
337           case AVB_HASHTREE_ERROR_MODE_PANIC:
338             verity_mode = "panicking";
339             dm_verity_mode = "panic_on_corruption";
340             break;
341         }
>>>     CID 652910:         Memory - illegal accesses  (UNINIT)
>>>     Using uninitialized value "dm_verity_mode" when calling "avb_replace".
342         new_ret = avb_replace(
343             slot_data->cmdline, "$(ANDROID_VERITY_MODE)", dm_verity_mode);
344         avb_free(slot_data->cmdline);
345         slot_data->cmdline = new_ret;
346         if (slot_data->cmdline == NULL) {
347           ret = AVB_SLOT_VERIFY_RESULT_ERROR_OOM;

** CID 652909:       Control flow issues  (DEADCODE)
/boot/bootretry.c: 32           in bootretry_parse()


_____________________________________________________________________________________________
*** CID 652909:         Control flow issues  (DEADCODE)
/boot/bootretry.c: 32             in bootretry_parse()
26     	if (s != NULL)
27     		retry_time = (int)simple_strtol(s, NULL, 10);
28     	else
29     		retry_time = CONFIG_BOOT_RETRY_TIME;
30
31     	if (retry_time >= 0 && retry_time < CONFIG_BOOT_RETRY_MIN)
>>>     CID 652909:         Control flow issues  (DEADCODE)
>>>     Execution cannot reach this statement: "retry_time = 0;".
32     		retry_time = CONFIG_BOOT_RETRY_MIN;
33     }
34
35     void bootretry_init_cmd_timeout(void)
36     {
37     	bootretry_parse(env_get("bootretry"));

** CID 652908:       Error handling issues  (NEGATIVE_RETURNS)
/test/dm/hash.c: 35           in hash_test_success()


_____________________________________________________________________________________________
*** CID 652908:         Error handling issues  (NEGATIVE_RETURNS)
/test/dm/hash.c: 35             in hash_test_success()
29
30     static int hash_test_success(struct udevice *dev, enum HASH_ALGO algo,
31     			     const void *ibuf, const uint32_t ilen,
32     			     void *obuf, uint32_t chunk_sz)
33     {
34     	success_calls++;
>>>     CID 652908:         Error handling issues  (NEGATIVE_RETURNS)
>>>     "hash_algo_digest_size(algo)" is passed to a parameter that cannot be negative. [Note: The source code implementation of the function has been overridden by a builtin model.]
35     	memset(obuf, 0x5a, hash_algo_digest_size(algo));
36
37     	return 0;
38     }
39
40     static int hash_test_hard_error(struct udevice *dev, enum HASH_ALGO algo,

** CID 652907:       Memory - corruptions  (OVERRUN)
/test/dm/hash.c: 35           in hash_test_success()


_____________________________________________________________________________________________
*** CID 652907:         Memory - corruptions  (OVERRUN)
/test/dm/hash.c: 35             in hash_test_success()
29
30     static int hash_test_success(struct udevice *dev, enum HASH_ALGO algo,
31     			     const void *ibuf, const uint32_t ilen,
32     			     void *obuf, uint32_t chunk_sz)
33     {
34     	success_calls++;
>>>     CID 652907:         Memory - corruptions  (OVERRUN)
>>>     Calling "memset" with "obuf" and "hash_algo_digest_size(algo)" is suspicious because of the very large index, 18446744073709551594. The index may be due to a negative parameter being interpreted as unsigned. [Note: The source code implementation of the function has been overridden by a builtin model.]
35     	memset(obuf, 0x5a, hash_algo_digest_size(algo));
36
37     	return 0;
38     }
39
40     static int hash_test_hard_error(struct udevice *dev, enum HASH_ALGO algo,



View Defects in Coverity Scan
<https://scan.coverity.com/projects/das-u-boot?tab=overview>

Best regards,

The Coverity Scan Admin Team

----- End forwarded message -----

-- 
Tom

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

             reply	other threads:[~2026-08-10 23:14 UTC|newest]

Thread overview: 120+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-10 23:14 Tom Rini [this message]
  -- strict thread matches above, loose matches on Subject: below --
2026-07-29 17:07 Fwd: New Defects reported by Coverity Scan for Das U-Boot Tom Rini
2026-07-07 18:58 Tom Rini
2026-06-22 22:43 Tom Rini
2026-06-26 18:28 ` Quentin Schulz
2026-06-26 18:32   ` Dario Binacchi
2026-06-26 21:53   ` Tom Rini
2026-05-11 22:35 Tom Rini
2026-05-08 23:42 Tom Rini
2026-05-14 15:39 ` Lucien.Jheng
2026-04-28 14:04 Tom Rini
2026-04-29  6:31 ` Michal Simek
2026-05-01 22:51   ` Raymond Mao
2026-05-12  8:44 ` Christian Pötzsch
2026-05-12 18:38   ` Tom Rini
2026-04-06 19:12 Tom Rini
2026-03-09 21:23 Tom Rini
2026-03-09 22:05 ` Raphaël Gallais-Pou
2026-03-09 22:13   ` Tom Rini
2026-02-23 19:51 Tom Rini
2026-02-13 22:09 Tom Rini
2026-02-18 23:02 ` Chris Morgan
2026-02-20 16:11   ` Tom Rini
2026-02-20 16:23     ` Chris Morgan
2026-01-16 19:43 Tom Rini
2026-02-09 11:05 ` Guillaume La Roque
2026-02-20 16:11   ` Tom Rini
2026-01-06 20:36 Tom Rini
2026-01-05 23:58 Tom Rini
2026-01-06  9:37 ` Mattijs Korpershoek
2026-01-06 17:15   ` Tom Rini
2026-01-06 10:03 ` Heiko Schocher
2025-12-08 19:38 Tom Rini
2025-11-23 19:03 Tom Rini
2025-11-10 18:55 Tom Rini
2025-10-11 18:06 Tom Rini
2025-10-12 14:22 ` Mikhail Kshevetskiy
2025-10-12 19:07   ` Tom Rini
2025-11-01  6:32     ` Mikhail Kshevetskiy
2025-11-03 15:17       ` Tom Rini
2025-11-03 15:24         ` Michael Nazzareno Trimarchi
2025-08-06 18:35 Tom Rini
2025-08-07  9:17 ` Heiko Schocher
2025-08-08  3:37   ` Maniyam, Dinesh
2025-08-08  4:01     ` Heiko Schocher
2025-07-29 16:32 Tom Rini
2025-07-25 13:26 Tom Rini
2025-07-25 13:34 ` Michal Simek
2025-08-04  9:11 ` Alexander Dahl
2025-07-14 23:29 Tom Rini
2025-07-15 13:45 ` Rasmus Villemoes
2025-07-08 14:10 Tom Rini
2025-04-28 21:59 Tom Rini
2025-04-29 12:07 ` Jerome Forissier
2025-04-30 16:50 ` Marek Vasut
2025-04-30 17:01   ` Tom Rini
2025-04-30 18:23 ` Heinrich Schuchardt
2025-04-30 19:14   ` Tom Rini
2025-03-11  1:49 Tom Rini
2025-02-25  2:39 Tom Rini
2025-02-25  6:06 ` Heiko Schocher
2025-02-25 10:48   ` Quentin Schulz
2025-02-25 10:54     ` Heiko Schocher
2025-02-10 22:26 Tom Rini
2025-02-11  6:14 ` Heiko Schocher
2025-02-11 22:30   ` Tom Rini
2024-12-31 13:55 Tom Rini
2024-12-24 17:14 Tom Rini
2024-11-15 13:27 Tom Rini
2024-11-12  2:11 Tom Rini
2024-10-28  3:11 Tom Rini
2024-10-19 16:16 Tom Rini
2024-10-16  3:47 Tom Rini
2024-10-16  5:56 ` Tudor Ambarus
2024-10-07 17:15 Tom Rini
2024-07-23 14:18 Tom Rini
2024-07-24  9:21 ` Mattijs Korpershoek
2024-07-24  9:45   ` Heinrich Schuchardt
2024-07-24  9:56     ` Mattijs Korpershoek
2024-07-24 10:06       ` Heinrich Schuchardt
2024-07-24 22:40         ` Tom Rini
2024-07-25  8:04           ` Mattijs Korpershoek
2024-07-25 17:16             ` Tom Rini
2024-07-24  9:53   ` Mattijs Korpershoek
2024-04-22 21:48 Tom Rini
2024-01-29 23:55 Tom Rini
2024-01-30  8:14 ` Heinrich Schuchardt
     [not found] <20240127154018.GC785631@bill-the-cat>
2024-01-27 20:56 ` Heinrich Schuchardt
2024-01-28  8:51   ` Heinrich Schuchardt
2024-01-22 23:52 Tom Rini
2024-01-22 23:30 Tom Rini
2024-01-23  8:15 ` Hugo Cornelis
     [not found] <65a933ab652b3_da12cbd3e77f998728e5@prd-scan-dashboard-0.mail>
2024-01-19  8:47 ` Heinrich Schuchardt
2024-01-18 14:35 Tom Rini
2024-01-08 17:45 Tom Rini
2024-01-09  5:26 ` Sean Anderson
2024-01-09 22:18   ` Tom Rini
2023-08-21 21:09 Tom Rini
2023-08-24  9:27 ` Abdellatif El Khlifi
2023-08-28 16:09   ` Alvaro Fernando García
2023-08-28 16:11     ` Tom Rini
2023-10-20 11:57 ` Abdellatif El Khlifi
2023-10-25 14:57   ` Tom Rini
2023-10-25 15:12     ` Abdellatif El Khlifi
2023-10-25 15:15       ` Tom Rini
2023-10-31 14:21         ` Abdellatif El Khlifi
2023-05-08 20:20 Tom Rini
2023-05-15 21:59 ` Ehsan Mohandesi
2023-05-18 21:04 ` Sean Edmond
2023-02-14 14:26 Tom Rini
2022-11-21 19:43 Tom Rini
2022-11-09 15:40 Tom Rini
     [not found] <62df3a0cb9fd2_30ed5f2acd4da7b9a431758@prd-scan-dashboard-0.mail>
2022-07-26  4:22 ` Heinrich Schuchardt
     [not found] <611aaf735d268_21438d2b07184e399c79439@prd-scan-dashboard-0.mail>
2021-08-17  5:21 ` Heinrich Schuchardt
2021-08-17 15:17   ` Tom Rini
     [not found] <6082f7faa423_5762a2b148d4af9a86820@prd-scan-dashboard-0.mail>
2021-04-24  4:52 ` Heinrich Schuchardt
     [not found] <5ecd3c8249d1_d6f562acb748daf5820386@appnode-2.mail>
     [not found] ` <CA+M6bX=AmT+SyM0Snt2POLy0-vpD__6CD4j6ifqMqh63yYJBLA@mail.gmail.com>
     [not found]   ` <8ea1ca2f-2826-58f2-4b6b-ed5cfe977467@gmx.de>
     [not found]     ` <20200526184027.GJ12717@bill-the-cat>
2020-05-26 20:02       ` Heinrich Schuchardt
2020-05-26 20:10         ` Tom Rini
2020-05-26 20:36           ` Heinrich Schuchardt
2020-05-26 20:48             ` Tom Rini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260810231448.GH1160436@bill-the-cat \
    --to=trini@konsulko.com \
    --cc=igor.opaniuk@gmail.com \
    --cc=james.hilliard1@gmail.com \
    --cc=ravi@prevas.dk \
    --cc=u-boot@lists.u-boot-project.org \
    --cc=yordy1902@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.