All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "James Hilliard" <james.hilliard1@gmail.com>
Cc: linux-sunxi@lists.linux.dev, robh@kernel.org,
	devicetree@vger.kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v3 10/15] mtd: rawnand: sunxi: support randomized OOB formats
Date: Wed, 09 Sep 2026 08:44:52 +0000	[thread overview]
Message-ID: <20260909084453.26C591F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260909-submit-sunxi-nand-vendor-oob-layout-v1-v3-10-838cb0ba1547@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] A divide by zero occurs when maximizing ECC strength for a 512-byte page NAND.
--

commit b0b5203da9f471c1f78c9b3ee0393b943af5ad6f
Author: James Hilliard <james.hilliard1@gmail.com>

    mtd: rawnand: sunxi: support randomized OOB formats

This commit adds support for randomized out-of-band (OOB) data formats on
Allwinner NAND controllers. It honors the allwinner,randomized-oob property
to keep the bad block marker in the randomizer data stream during normal
hardware-ECC transfers.

> diff --git a/drivers/mtd/nand/raw/sunxi_nand.c b/drivers/mtd/nand/raw/sunxi_nand.c
> index 51d01f7f539e8..138a141edbe4d 100644
> --- a/drivers/mtd/nand/raw/sunxi_nand.c
> +++ b/drivers/mtd/nand/raw/sunxi_nand.c

[ ... ]

> @@ -2234,6 +2462,10 @@ static int sunxi_nand_hw_ecc_ctrl_init(struct nand_chip *nand,
>  		ecc->strength *= 2;
>  	}
>  
> +	/* This format requires an ECC step that fits in the page. */
> +	if (sunxi_nand->randomized_oob && mtd->writesize < ecc->size)
> +		return -EINVAL;
> +

[Severity: High]
This isn't a bug introduced by this patch, but earlier in
sunxi_nand_hw_ecc_ctrl_init() there appears to be a divide-by-zero risk
when probing a NAND device with a 512-byte page size while the
nand-ecc-maximize device tree property is set:

	if (nanddev->ecc.user_conf.flags & NAND_ECC_MAXIMIZE_STRENGTH) {
		int bytes = mtd->oobsize;

		ecc->size = 1024;
		nsectors = mtd->writesize / ecc->size;

		...

		/*
		 * Once all user data has been subtracted, the rest can be used
		 * for ECC bytes
		 */
		bytes /= nsectors;

Since ecc->size is hardcoded to 1024, nsectors evaluates to 0 if
mtd->writesize is 512. Does this cause a division by zero kernel panic
during device probe?

>  	/* Add ECC info retrieval from DT */
>  	for (ecc_mode = 0; ecc_mode < nfc->caps->nstrengths; ecc_mode++) {
>  		if (ecc->strength <= strengths[ecc_mode]) {

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260909-submit-sunxi-nand-vendor-oob-layout-v1-v3-0-838cb0ba1547@gmail.com?part=10

  reply	other threads:[~2026-09-09  8:44 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09  8:30 [PATCH v3 00/15] mtd: rawnand: sunxi: support the Allwinner randomized OOB format James Hilliard
2026-09-09  8:30 ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 01/15] mtd: rawnand: sunxi: use the logical step's OOB length in PIO James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 02/15] mtd: rawnand: sunxi: propagate page-setup and erased-check errors James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 03/15] mtd: rawnand: sunxi: stop failed program operations and disable ECC James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 04/15] mtd: rawnand: sunxi: select the pattern ID for the current ECC step James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 05/15] mtd: rawnand: sunxi: propagate buffer and column transfer errors James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 06/15] mtd: rawnand: sunxi: avoid a second program confirm for OOB writes James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 07/15] mtd: rawnand: sunxi: avoid redundant column changes for extra OOB James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 08/15] mtd: rawnand: sunxi: clarify OOB register and step handling James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 09/15] dt-bindings: mtd: sunxi: Add randomized OOB flag James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 10/15] mtd: rawnand: sunxi: support randomized OOB formats James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:44   ` sashiko-bot [this message]
2026-09-09  8:30 ` [PATCH v3 11/15] mtd: rawnand: sunxi: select the packed H6/H616 OOB layout James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:51   ` sashiko-bot
2026-09-09  8:30 ` [PATCH v3 12/15] mtd: rawnand: sunxi: combine contiguous unprotected OOB reads James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 13/15] mtd: rawnand: sunxi: avoid duplicate chip setup before page commands James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:54   ` sashiko-bot
2026-09-09  8:30 ` [PATCH v3 14/15] mtd: rawnand: sunxi: reduce user-data length register accesses James Hilliard
2026-09-09  8:30   ` James Hilliard
2026-09-09  8:30 ` [PATCH v3 15/15] mtd: rawnand: sunxi: reuse ECC status within each DMA read James Hilliard
2026-09-09  8:30   ` James Hilliard

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909084453.26C591F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=james.hilliard1@gmail.com \
    --cc=linux-sunxi@lists.linux.dev \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.