From: Salah Triki <salah.triki@gmail.com>
To: "Michael Hennerich" <michael.hennerich@analog.com>,
"Nuno Sá" <nuno.sa@analog.com>,
"Jonathan Cameron" <jic23@kernel.org>,
"David Lechner" <dlechner@baylibre.com>,
"Andy Shevchenko" <andy@kernel.org>,
linux-iio@vger.kernel.org, linux@analog.com,
linux-kernel@vger.kernel.org
Cc: Salah Triki <salah.triki@gmail.com>
Subject: [PATCH v2] iio: adc: ad4030: fix invalid oversampling_ratio validation
Date: Sun, 23 Aug 2026 05:52:05 +0100 [thread overview]
Message-ID: <20260823045205.25554-1-salah.triki@gmail.com> (raw)
ad4030_set_avg_frame_len() computes avg_log2 = ilog2(avg_val) before
validating avg_val, and the subsequent range check only rejects
negative values or values above the maximum supported OSR. It does
not reject avg_val == 0, nor values that are not exact powers of 2.
- avg_val == 0 passes the check (0 is not < 0 and not > max), so
ilog2(0) is called with an undefined/garbage result.
- Non-power-of-2 values (e.g. avg_val == 3) also pass the check and
silently get rounded down by ilog2() to the nearest lower power of
2, so userspace can write a value to the oversampling_ratio sysfs
attribute that does not match what actually gets programmed into
hardware, without any error being reported.
Only powers of 2 in [1, 65536] are valid OSR values, as listed in
ad4030_average_modes[]. Validate avg_val fully before computing its
log2, using is_power_of_2() and requiring avg_val > 0.
This issue was identified with assistance from Claude AI and manually
verified against the code.
Fixes: 949abd1ca5a4 ("iio: adc: ad4030: add averaging support")
Signed-off-by: Salah Triki <salah.triki@gmail.com>
---
Changes since v1:
- Added note stating the issue was identified with assistance from
Claude AI and verified manually.
- Removed initialization of avg_log2 at declaration.
drivers/iio/adc/ad4030.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/iio/adc/ad4030.c b/drivers/iio/adc/ad4030.c
index 9c5f19321e3b..20911cc55873 100644
--- a/drivers/iio/adc/ad4030.c
+++ b/drivers/iio/adc/ad4030.c
@@ -746,14 +746,16 @@ static int ad4030_set_chan_calibbias(struct iio_dev *indio_dev,
static int ad4030_set_avg_frame_len(struct iio_dev *dev, int avg_val)
{
struct ad4030_state *st = iio_priv(dev);
- unsigned int avg_log2 = ilog2(avg_val);
+ unsigned int avg_log2;
unsigned int last_avg_idx = ARRAY_SIZE(ad4030_average_modes) - 1;
int freq_hz;
int ret;
- if (avg_val < 0 || avg_val > ad4030_average_modes[last_avg_idx])
+ if (avg_val <= 0 || avg_val > ad4030_average_modes[last_avg_idx] || !is_power_of_2(avg_val))
return -EINVAL;
+ avg_log2 = ilog2(avg_val);
+
if (st->offload_trigger) {
/*
* The sample averaging and sampling frequency configurations
--
2.43.0
next reply other threads:[~2026-08-23 4:52 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-23 4:52 Salah Triki [this message]
2026-08-23 18:29 ` [PATCH v2] iio: adc: ad4030: fix invalid oversampling_ratio validation David Lechner
2026-08-23 21:31 ` Jonathan Cameron
2026-08-24 9:04 ` Andy Shevchenko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260823045205.25554-1-salah.triki@gmail.com \
--to=salah.triki@gmail.com \
--cc=andy@kernel.org \
--cc=dlechner@baylibre.com \
--cc=jic23@kernel.org \
--cc=linux-iio@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@analog.com \
--cc=michael.hennerich@analog.com \
--cc=nuno.sa@analog.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.