From: sashiko-bot@kernel.org
To: "Kanak Shilledar" <kanak.shilledar@axis.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v5 5/6] iio: imu: inv_icm42607: Implement MREGx register access
Date: Fri, 02 Oct 2026 12:03:50 +0000 [thread overview]
Message-ID: <20261002120351.5CA7E1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261002-b4-inv_icm42370p-v5-5-c65281b745c9@axis.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] iio: imu: inv_icm42607: error codes clobbered in mreg read/write
--
commit e8858e48c698c3e653b91adc09876f8bc8ccd389
Author: Kanak Shilledar <kanak.shilledar@axis.com>
iio: imu: inv_icm42607: Implement MREGx register access
This commit implements indirect register access for MREG banks via a 16-bit
virtual regmap layered on top of the 8-bit bus regmap. It sets up the bank
switching sequence for MREG accesses while forwarding Bank 0 accesses
directly to the bus regmap.
> diff --git a/drivers/iio/imu/inv_icm42607/inv_icm42607_core.c b/drivers/iio/imu/inv_icm42607/inv_icm42607_core.c
> index 87b1499a3689f..ea0d50237817b 100644
> --- a/drivers/iio/imu/inv_icm42607/inv_icm42607_core.c
> +++ b/drivers/iio/imu/inv_icm42607/inv_icm42607_core.c
[ ... ]
> +static int inv_icm42607_mreg_read(struct regmap *map, unsigned int reg,
> + u8 *data, size_t count)
> +{
[ ... ]
> + ret = regmap_read(map, INV_ICM42607_REG_M_R, &val);
> + if (ret)
> + goto out;
> +
> + fsleep(INV_ICM42607_MREG_ACCESS_DELAY_US);
> +
> + *data = val;
> +out:
> + /* Restore direct access. */
> + ret = regmap_write(map, INV_ICM42607_REG_BLK_SEL_R, 0);
[Severity: High]
Does this overwrite the primary read error code in ret?
If the function jumps to the out label due to a bus error, and the cleanup
regmap_write succeeds (returning 0), it masks the original failure.
This causes the caller to receive a success code while operating on
uninitialized memory.
Since these values can be transformed and exposed to userspace, such as via
IIO sysfs attributes, could this lead to a kernel stack information leak?
> + inv_icm42607_mclk_put(map, idle_set);
> +
> + return ret;
> +}
> +
> +static int inv_icm42607_mreg_write(struct regmap *map, unsigned int reg,
> + const u8 *data, size_t count)
> +{
[ ... ]
> + ret = regmap_write(map, INV_ICM42607_REG_M_W, *data);
> + if (ret)
> + goto out;
> +
> + fsleep(INV_ICM42607_MREG_ACCESS_DELAY_US);
> +
> +out:
> + /* Restore direct access. */
> + ret = regmap_write(map, INV_ICM42607_REG_BLK_SEL_W, 0);
[Severity: High]
Similarly, does this overwrite the write error code?
If an I2C or SPI bus error happens earlier in the function and causes a jump
to the out label, a successful cleanup write will overwrite the error code
and falsely report success to the caller.
> + inv_icm42607_mclk_put(map, idle_set);
> +
> + return ret;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261002-b4-inv_icm42370p-v5-0-c65281b745c9@axis.com?part=5
next prev parent reply other threads:[~2026-10-02 12:03 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 11:54 [PATCH v5 0/6] Add support for InvenSense ICM-42370-P accelerometer Kanak Shilledar
2026-10-02 11:54 ` [PATCH v5 1/6] dt-bindings: iio: imu: icm42600: Add ICM-42670-P Kanak Shilledar
2026-10-02 12:01 ` sashiko-bot
2026-10-02 17:11 ` Conor Dooley
2026-10-02 17:11 ` Conor Dooley
2026-10-02 11:54 ` [PATCH v5 2/6] iio: imu: inv_icm42607: Simplify IIO channel macros Kanak Shilledar
2026-10-05 0:25 ` Marcelo Schmitt
2026-10-02 11:54 ` [PATCH v5 3/6] iio: imu: inv_icm42607: Initialize gyro based on chip_info Kanak Shilledar
2026-10-02 13:03 ` Andy Shevchenko
2026-10-05 0:39 ` Marcelo Schmitt
2026-10-02 11:54 ` [PATCH v5 4/6] iio: imu: inv_icm42607: Add support for ICM-42370-P Kanak Shilledar
2026-10-02 13:04 ` Andy Shevchenko
2026-10-05 0:43 ` Marcelo Schmitt
2026-10-02 11:54 ` [PATCH v5 5/6] iio: imu: inv_icm42607: Implement MREGx register access Kanak Shilledar
2026-10-02 12:03 ` sashiko-bot [this message]
2026-10-02 13:12 ` Andy Shevchenko
2026-10-02 14:25 ` Kanak Shilledar
2026-10-03 15:02 ` andriy.shevchenko
2026-10-05 15:02 ` Kanak Shilledar
2026-10-02 11:54 ` [PATCH v5 6/6] iio: imu: inv_icm42607: Add accelerometer calibbias support Kanak Shilledar
2026-10-02 13:18 ` Andy Shevchenko
2026-10-02 14:03 ` Kanak Shilledar
2026-10-03 14:57 ` andriy.shevchenko
2026-10-05 0:51 ` Marcelo Schmitt
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002120351.5CA7E1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=kanak.shilledar@axis.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.