From: Dan Carpenter <error27@gmail.com>
To: Stephen Boyd <swboyd@chromium.org>
Cc: Guenter Roeck <groeck@chromium.org>,
linux-gpio@vger.kernel.org, chrome-platform@lists.linux.dev
Subject: [bug report] gpio: Add ChromeOS EC GPIO driver
Date: Fri, 11 Sep 2026 15:37:28 +0300 [thread overview]
Message-ID: <aqP2CHazflMSQrfa@stanley.mountain> (raw)
Hello Stephen Boyd,
Commit f837fe1bffe6 ("gpio: Add ChromeOS EC GPIO driver") from Feb
19, 2024 (linux-next), leads to the following Smatch static checker
warning:
drivers/gpio/gpio-cros-ec.c:131 cros_ec_gpio_init_names()
warn: expected subtract in snprintf limit 'name_len'
drivers/gpio/gpio-cros-ec.c
97 static int cros_ec_gpio_init_names(struct cros_ec_device *cros_ec, struct gpio_chip *gc)
98 {
99 struct ec_params_gpio_get_v1 params = {
100 .subcmd = EC_GPIO_GET_INFO,
101 };
102 struct ec_response_gpio_get_v1 response;
103 int ret, i;
104 /* EC may not NUL terminate */
105 size_t name_len = strlen(cros_ec_gpio_prefix) + sizeof(response.get_info.name) + 1;
106 ssize_t copied;
107 const char **names;
108 char *str;
109
110 names = devm_kcalloc(gc->parent, gc->ngpio, sizeof(*names), GFP_KERNEL);
111 if (!names)
112 return -ENOMEM;
113 gc->names = names;
114
115 str = devm_kcalloc(gc->parent, gc->ngpio, name_len, GFP_KERNEL);
116 if (!str)
117 return -ENOMEM;
118
119 /* Get gpio line names one at a time */
120 for (i = 0; i < gc->ngpio; i++) {
121 params.get_info.index = i;
122 ret = cros_ec_cmd(cros_ec, 1, EC_CMD_GPIO_GET, ¶ms,
123 sizeof(params), &response, sizeof(response));
124 if (ret < 0) {
125 dev_err_probe(gc->parent, ret, "error getting gpio%d info\n", i);
126 return ret;
127 }
128
129 names[i] = str;
130 copied = scnprintf(str, name_len, "%s%s", cros_ec_gpio_prefix,
--> 131 response.get_info.name);
The name_len is wrong because that's the total length but we should
be using the remaining length.
132 if (copied < 0)
The scnprintf() function is a kernel only invention can never return
negatives. User space versions of snprintf() can return negatives but
the kernel versions cannot and the kernel relies on this behavior.
133 return copied;
134
135 str += copied + 1;
136 }
137
138 return 0;
139 }
This email is a free service from the Smatch-CI project [smatch.sf.net].
regards,
dan carpenter
reply other threads:[~2026-09-11 12:37 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aqP2CHazflMSQrfa@stanley.mountain \
--to=error27@gmail.com \
--cc=chrome-platform@lists.linux.dev \
--cc=groeck@chromium.org \
--cc=linux-gpio@vger.kernel.org \
--cc=swboyd@chromium.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox