From: sashiko-bot@kernel.org
To: "Michal Wilczynski" <m.wilczynski@samsung.com>
Cc: linux-clk@vger.kernel.org, mfd@lists.linux.dev,
linux-phy@lists.infradead.org, lee@kernel.org, olteanv@gmail.com,
robh@kernel.org, devicetree@vger.kernel.org, conor+dt@kernel.org,
vkoul@kernel.org, dri-devel@lists.freedesktop.org,
neil.armstrong@linaro.org
Subject: Re: [PATCH v4 16/20] phy: Add common Innosilicon HDMI PHY helpers
Date: Tue, 15 Sep 2026 15:42:51 +0000 [thread overview]
Message-ID: <20260915154252.0C34F1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260915-jh7110-clean-send-v4-16-f0e4fd6f2cc8@samsung.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] phy: division by zero kernel panic in recalc_rate() on register read failure
--
commit 543e5d00d9e079829f4ad47de05248c127f81d1c
Author: Michal Wilczynski <m.wilczynski@samsung.com>
phy: Add common Innosilicon HDMI PHY helpers
This commit adds a common library for the Innosilicon HDMI PHY IP, which
is used by several SoCs. It extracts the pre-PLL configuration table
format, lookups, and clock rate helpers into shared code.
> diff --git a/drivers/phy/phy-inno-hdmi.c b/drivers/phy/phy-inno-hdmi.c
> new file mode 100644
> index 0000000000000..77e745a87d22b
> --- /dev/null
> +++ b/drivers/phy/phy-inno-hdmi.c
[ ... ]
> +unsigned long
> +inno_hdmi_phy_pre_pll_recalc_rate(const struct inno_hdmi_phy_pre_pll *pll,
> + unsigned long parent_rate)
> +{
> + u8 nd, no_a, no_b, no_d;
> + unsigned long frac, rate;
> + u64 vco, vco_rate;
> + u16 nf;
> +
> + nd = inno_read(pll, INNO_PRE_PLL_DIV_1) & INNO_PRE_PLL_PRE_DIV_MASK;
> + nf = (inno_read(pll, INNO_PRE_PLL_DIV_2) &
> + INNO_PRE_PLL_FB_DIV_11_8_MASK) << 8;
> + nf |= inno_read(pll, INNO_PRE_PLL_DIV_3);
> + vco = parent_rate * nf;
[Severity: High]
This is a pre-existing issue, but does this code cause an integer overflow
on 32-bit architectures?
When inno_hdmi_phy_pre_pll_recalc_rate() executes, parent_rate * nf
multiplies two 32-bit integers, which could silently overflow before
assignment to the 64-bit vco variable.
> +
> + if (!(inno_read(pll, INNO_PRE_PLL_DIV_2) &
> + INNO_PRE_PLL_FRAC_DIV_DISABLE)) {
> + frac = inno_read(pll, INNO_PRE_PLL_FRAC_DIV_7_0) |
> + (inno_read(pll, INNO_PRE_PLL_FRAC_DIV_15_8) << 8) |
> + (inno_read(pll, INNO_PRE_PLL_FRAC_DIV_23_16) << 16);
> + vco += DIV_ROUND_CLOSEST(parent_rate * frac,
> + BIT(INNO_FRAC_DIV_WIDTH));
[Severity: High]
This isn't a bug introduced by this patch, but does parent_rate * frac
also massively overflow before rounding on 32-bit systems?
Since parent_rate is typically 24MHz and frac is a 24-bit divider, their
product exceeds the 32-bit maximum. This causes silent truncation and leads
to completely incorrect calculated VCO rates.
> + }
> +
> + vco_rate = vco;
> +
> + if (inno_read(pll, INNO_PRE_PLL_CONTROL) & INNO_PCLK_VCO_DIV_5_MASK) {
> + do_div(vco, nd * 5);
[Severity: High]
Can this result in a division by zero kernel panic?
inno_read() returns 0 if regmap_read() fails. If nd evaluates to 0 due to
an uninitialized register or a read failure, the denominator becomes 0.
> + } else {
> + no_a = inno_read(pll, INNO_PCLK_DIV_AB) & INNO_PCLK_DIV_A_MASK;
> + no_b = FIELD_GET(INNO_PCLK_DIV_B_MASK,
> + inno_read(pll, INNO_PCLK_DIV_AB)) + 2;
> + no_d = inno_read(pll, INNO_PCLK_DIV_CD) & INNO_PCLK_DIV_D_MASK;
> +
> + do_div(vco, nd * (no_a == 1 ? no_b : no_a) * no_d * 2);
[Severity: High]
Could this also trigger a division by zero crash?
If nd, no_a, or no_d evaluates to 0 due to read failures, the denominator
becomes 0.
The legacy RK3228 driver guarded against no_a being 0 with an explicit
check (if (!no_a) no_a = 1;), but it appears this protection was removed
when creating this shared code.
> + }
> +
> + rate = DIV_ROUND_CLOSEST((unsigned long)vco, 1000) * 1000;
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260915-jh7110-clean-send-v4-0-f0e4fd6f2cc8@samsung.com?part=16
next prev parent reply other threads:[~2026-09-15 15:42 UTC|newest]
Thread overview: 74+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <CGME20260915153213eucas1p148f013af239a334fc78cdc249c0f8a61@eucas1p1.samsung.com>
2026-09-15 15:32 ` [PATCH v4 00/20] drm: starfive: jh7110: Enable display subsystem Michal Wilczynski
2026-09-15 15:32 ` [PATCH v4 01/20] dt-bindings: phy: Add starfive,jh7110-inno-hdmi-phy Michal Wilczynski
2026-09-15 15:35 ` sashiko-bot
2026-09-17 6:51 ` Krzysztof Kozlowski
2026-09-18 0:34 ` Joshua Peisach
2026-09-18 6:16 ` Krzysztof Kozlowski
2026-09-18 6:21 ` Icenowy Zheng
2026-09-18 6:41 ` Krzysztof Kozlowski
2026-09-25 21:27 ` Michal Wilczynski
2026-09-25 21:05 ` Michal Wilczynski
2026-09-30 11:01 ` Krzysztof Kozlowski
2026-10-03 15:36 ` Michal Wilczynski
2026-10-03 20:45 ` Krzysztof Kozlowski
2026-10-03 22:35 ` Michal Wilczynski
2026-10-04 7:15 ` Krzysztof Kozlowski
2026-10-05 7:27 ` Icenowy Zheng
2026-09-15 15:32 ` [PATCH v4 02/20] dt-bindings: display: bridge: Add starfive,jh7110-inno-hdmi-controller Michal Wilczynski
2026-09-15 15:35 ` sashiko-bot
2026-09-15 15:32 ` [PATCH v4 03/20] dt-bindings: mfd: Add starfive,jh7110-hdmi-subsystem Michal Wilczynski
2026-09-15 15:42 ` sashiko-bot
2026-09-17 6:54 ` Krzysztof Kozlowski
2026-09-28 18:34 ` Michal Wilczynski
2026-09-15 15:32 ` [PATCH v4 04/20] dt-bindings: soc: starfive: Add starfive,jh7110-vout-syscon Michal Wilczynski
2026-09-15 15:35 ` sashiko-bot
2026-09-17 6:55 ` Krzysztof Kozlowski
2026-09-15 15:32 ` [PATCH v4 05/20] dt-bindings: display: verisilicon: Add starfive,jh7110-dc8200 Michal Wilczynski
2026-09-15 15:35 ` sashiko-bot
2026-09-18 5:58 ` Icenowy Zheng
2026-09-27 15:26 ` Michal Wilczynski
2026-09-15 15:32 ` [PATCH v4 06/20] dt-bindings: soc: starfive: Add starfive,jh7110-vout-subsystem Michal Wilczynski
2026-09-15 15:35 ` sashiko-bot
2026-09-24 15:30 ` Rob Herring (Arm)
2026-09-15 15:32 ` [PATCH v4 07/20] drm/bridge: inno-hdmi: Split probe out of bind Michal Wilczynski
2026-09-15 15:44 ` sashiko-bot
2026-09-15 15:32 ` [PATCH v4 08/20] drm/bridge: inno-hdmi: Allow the register map to come from a parent Michal Wilczynski
2026-09-15 15:42 ` sashiko-bot
2026-09-15 15:32 ` [PATCH v4 09/20] drm/bridge: inno-hdmi: Add .disable platform operation Michal Wilczynski
2026-09-15 15:43 ` sashiko-bot
2026-09-15 15:32 ` [PATCH v4 10/20] drm/bridge: inno-hdmi: Add .mode_valid " Michal Wilczynski
2026-09-15 15:37 ` sashiko-bot
2026-09-15 15:32 ` [PATCH v4 11/20] drm/bridge: inno-hdmi: Make the PHY configuration table optional Michal Wilczynski
2026-09-15 15:40 ` sashiko-bot
2026-09-15 15:32 ` [PATCH v4 12/20] soc: starfive: Add jh7110-hdmi-subsystem driver Michal Wilczynski
2026-09-15 15:44 ` sashiko-bot
2026-09-29 15:04 ` Icenowy Zheng
2026-09-15 15:32 ` [PATCH v4 13/20] soc: starfive: Add jh7110-vout-subsystem driver Michal Wilczynski
2026-09-15 15:42 ` sashiko-bot
2026-09-29 15:04 ` Icenowy Zheng
2026-09-15 15:32 ` [PATCH v4 14/20] clk: starfive: jh7110-vout: Allow pixel clock rate propagation Michal Wilczynski
2026-09-15 15:38 ` sashiko-bot
2026-09-15 15:32 ` [PATCH v4 15/20] drm/bridge: starfive: Add JH7110 HDMI controller driver Michal Wilczynski
2026-09-15 15:42 ` sashiko-bot
2026-09-29 15:03 ` Icenowy Zheng
2026-09-15 15:32 ` [PATCH v4 16/20] phy: Add common Innosilicon HDMI PHY helpers Michal Wilczynski
2026-09-15 15:42 ` sashiko-bot [this message]
2026-10-03 14:22 ` Vinod Koul
2026-09-15 15:32 ` [PATCH v4 17/20] phy: rockchip: inno-hdmi: Use the common Innosilicon " Michal Wilczynski
2026-09-15 15:44 ` sashiko-bot
2026-09-15 15:32 ` [PATCH v4 18/20] phy: starfive: Add jh7110-inno-hdmi-phy driver Michal Wilczynski
2026-09-15 15:46 ` sashiko-bot
2026-09-26 3:31 ` Dominique Belhachemi
2026-09-27 12:05 ` Michal Wilczynski
2026-09-15 15:32 ` [PATCH v4 19/20] riscv: dts: starfive: jh7110: Update DT for display subsystem Michal Wilczynski
2026-09-15 15:49 ` sashiko-bot
2026-09-29 15:06 ` Icenowy Zheng
2026-09-15 15:32 ` [PATCH v4 20/20] MAINTAINERS: Add StarFive JH7110 display subsystem entry Michal Wilczynski
2026-09-16 0:45 ` [PATCH v4 00/20] drm: starfive: jh7110: Enable display subsystem Joshua Peisach
2026-09-17 17:22 ` Michal Wilczynski
2026-09-18 15:32 ` Joshua Peisach
2026-09-27 12:24 ` Michal Wilczynski
2026-09-20 6:09 ` Byron Stanoszek
2026-09-20 7:35 ` Icenowy Zheng
2026-09-25 20:09 ` Michal Wilczynski
2026-09-25 13:55 ` (subset) " Brian Masney
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260915154252.0C34F1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=lee@kernel.org \
--cc=linux-clk@vger.kernel.org \
--cc=linux-phy@lists.infradead.org \
--cc=m.wilczynski@samsung.com \
--cc=mfd@lists.linux.dev \
--cc=neil.armstrong@linaro.org \
--cc=olteanv@gmail.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox