Linux clock framework development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sascha Hauer" <s.hauer@pengutronix.de>
Cc: robh@kernel.org, linux-clk@vger.kernel.org,
	devicetree@vger.kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v9 2/2] clk: add TI CDCE6214 clock driver
Date: Mon, 21 Sep 2026 07:01:21 +0000	[thread overview]
Message-ID: <20260921070121.A33001F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260921-clk-cdce6214-v9-2-f2ea74fd38a2@pengutronix.de>

Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
- [High] clk: cdce6214: uninitialized memory used when regmap_read() fails
- [Medium] clk: cdce6214: integer overflow in pll_determine_rate() min check
- [Medium] clk: cdce6214: missing upper bound check allows silent truncation of PLL ndiv
- [Medium] clk: cdce6214: power leak in cdce6214_clk_pll_prepare() on lock timeout
- [Medium] clk: cdce6214: missing EEPROM boot delay after reset de-assertion
--

commit 3f176632480b02a9e90a4fa95363d1fa484107d5
Author: Sascha Hauer <s.hauer@pengutronix.de>
Subject: clk: add TI CDCE6214 clock driver

This commit introduces a new common clock framework driver for the TI 
CDCE6214 clock synthesizer. It registers multiple clock components including
the PLL, outputs, and dividers.

> diff --git a/drivers/clk/clk-cdce6214.c b/drivers/clk/clk-cdce6214.c
> new file mode 100644
> --- /dev/null
> +++ b/drivers/clk/clk-cdce6214.c
> @@ -0,0 +1,1594 @@
[ ... ]
> +static int cdce6214_clk_out_is_prepared(struct clk_hw *hw)
> +{
> +	struct cdce6214_clock *clock = hw_to_cdce6214_clk(hw);
> +	struct cdce6214 *priv = clock->priv;
> +	unsigned int mask = cdce6214_clk_out_mask(clock->index);
> +	unsigned int val;
> +
> +	if (!mask)
> +		return -EINVAL;
> +
> +	regmap_read(priv->regmap, R4, &val);
> +
> +	return !(val & mask);

[Severity: High]
Is it possible for I2C transfers to fail here? If regmap_read() returns an 
error, val will remain uninitialized, leading to undefined behavior when the 
mask is applied. Should the return value be checked?

[ ... ]
> +static unsigned long cdce6214_clk_pll_recalc_rate(struct clk_hw *hw,
> +						  unsigned long parent_rate)
> +{
> +	struct cdce6214_clock *clock = hw_to_cdce6214_clk(hw);
> +	struct cdce6214 *priv = clock->priv;
> +	unsigned long ndiv, num, den;
> +	unsigned int val;
> +
> +	regmap_read(priv->regmap, R30, &val);
> +	ndiv = FIELD_GET(R30_PLL_NDIV, val);

[Severity: High]
Similar to above, if this read fails, could we end up calculating the rate 
with garbage data from the stack and propagating a corrupted frequency to 
the clock framework?

[ ... ]
> +static int cdce6214_clk_pll_determine_rate(struct clk_hw *hw,
> +					   struct clk_rate_request *req)
> +{
> +	if (!req->best_parent_rate)
> +		return -EINVAL;
> +
> +	req->rate = clamp(req->rate, CDCE6214_VCO_MIN, CDCE6214_VCO_MAX);
> +
> +	if (req->rate < req->best_parent_rate * CDCE6214_PLL_NDIV_MIN)

[Severity: Medium]
Does this multiplication risk overflowing on 32-bit systems? 

If the parent rate is high (e.g., > 178.9 MHz), could the multiplication
req->best_parent_rate * CDCE6214_PLL_NDIV_MIN wrap around the 32-bit unsigned 
long, bypassing the lower bound check?

> +		return -EINVAL;
> +
> +	req->min_rate = CDCE6214_VCO_MIN;
> +	req->max_rate = CDCE6214_VCO_MAX;

[Severity: Medium]
Is an upper bound check also needed here to ensure the computed ndiv fits 
into the 15-bit hardware maximum? If the parent clock is very low, it seems 
a valid VCO rate could still result in an ndiv that is too large.

[ ... ]
> +static int cdce6214_clk_pll_prepare(struct clk_hw *hw)
> +{
> +	struct cdce6214_clock *clock = hw_to_cdce6214_clk(hw);
> +	struct cdce6214 *priv = clock->priv;
> +
> +	regmap_clear_bits(priv->regmap, R5, R5_PLL_POWER_BITS);
> +
> +	regmap_set_bits(priv->regmap, R0, RO_RECAL);
> +
> +	return cdce6214_wait_pll_lock(priv);

[Severity: Medium]
If the PLL lock times out, does this exit path leave the LDOs and VCO 
permanently active? Would it make sense to roll back the R5_PLL_POWER_BITS 
changes on error to prevent wasting power?

[ ... ]
> +static int cdce6214_clk_pll_set_rate(struct clk_hw *hw, unsigned long rate,
> +				     unsigned long parent_rate)
> +{
> +	struct cdce6214_clock *clock = hw_to_cdce6214_clk(hw);
> +	struct cdce6214 *priv = clock->priv;
> +	unsigned long ndiv, num, den;
> +	int ret;
> +
> +	ret = pll_calc_values(parent_rate, rate, &ndiv, &num, &den);
> +	if (ret < 0)
> +		return ret;
> +
> +	regmap_update_bits(priv->regmap, R34, R34_PLL_DEN_23_16,
> +			   FIELD_PREP(R34_PLL_DEN_23_16, den >> 16));
> +	regmap_update_bits(priv->regmap, R33, R33_PLL_DEN_15_0,
> +			   FIELD_PREP(R33_PLL_DEN_15_0, den & 0xffff));
> +	regmap_update_bits(priv->regmap, R32, R32_PLL_NUM_23_16,
> +			   FIELD_PREP(R32_PLL_NUM_23_16, num >> 16));
> +	regmap_update_bits(priv->regmap, R31, R31_PLL_NUM_15_0,
> +			   FIELD_PREP(R31_PLL_NUM_15_0, num & 0xffff));
> +	regmap_update_bits(priv->regmap, R30, R30_PLL_NDIV,
> +			   FIELD_PREP(R30_PLL_NDIV, ndiv));

[Severity: Medium]
If an out-of-bounds ndiv reaches this point, will it be silently truncated 
by FIELD_PREP and written to the register, breaking the frequency 
configuration?

[ ... ]
> +static int cdce6214_pinconf_get_xo_cload(struct cdce6214 *priv, unsigned int pin)
> +{
> +	unsigned int val;
> +
> +	if (pin != SECREF)
> +		return -EOPNOTSUPP;
> +
> +	regmap_read(priv->regmap, R24, &val);
> +
> +	val = FIELD_GET(R24_IP_XO_CLOAD, val);
> +
> +	if (val >= ARRAY_SIZE(ip_xo_cload))
> +		return -EINVAL;
> +
> +	return ip_xo_cload[val];

[Severity: High]
Is this another place where a failed I2C read could cause us to evaluate 
uninitialized stack memory? It seems this could lead to returning random 
elements.

[ ... ]
> +static int cdce6214_probe(struct i2c_client *client)
> +{
> +	struct device *dev = &client->dev;
> +	struct cdce6214 *priv;
> +	struct pinctrl_dev *pctl;
> +	int ret;
> +
> +	priv = devm_kzalloc(dev, sizeof(*priv), GFP_KERNEL);
> +	if (!priv)
> +		return -ENOMEM;
> +
> +	priv->client = client;
> +	priv->dev = dev;
> +	i2c_set_clientdata(client, priv);
> +	dev_set_drvdata(dev, priv);
> +
> +	priv->reset_gpio = devm_gpiod_get_optional(dev, "reset", GPIOD_OUT_LOW);
> +	if (IS_ERR(priv->reset_gpio)) {
> +		return dev_err_probe(dev, PTR_ERR(priv->reset_gpio),
> +				     "failed to get reset gpio\n");
> +	}
> +
> +	priv->regmap = devm_regmap_init_i2c(client, &cdce6214_regmap_config);
> +	if (IS_ERR(priv->regmap))
> +		return dev_err_probe(dev, PTR_ERR(priv->regmap),
> +				     "failed to init regmap\n");
> +
> +	ret = cdce6214_configure(priv);

[Severity: Medium]
Does the CDCE6214 require a brief boot delay after the reset de-assertion 
to load its EEPROM before I2C communication begins? It looks like we call 
cdce6214_configure() immediately, which might cause probe failures if the 
hardware isn't ready.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260921-clk-cdce6214-v9-0-f2ea74fd38a2@pengutronix.de?part=2

  reply	other threads:[~2026-09-21  7:01 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21  6:49 [PATCH v9 0/2] clk: add support for TI CDCE6214 Sascha Hauer
2026-09-21  6:49 ` [PATCH v9 1/2] dt-bindings: clock: add TI CDCE6214 binding Sascha Hauer
2026-09-21  6:57   ` sashiko-bot
2026-09-28  5:51   ` Krzysztof Kozlowski
2026-09-21  6:50 ` [PATCH v9 2/2] clk: add TI CDCE6214 clock driver Sascha Hauer
2026-09-21  7:01   ` sashiko-bot [this message]
2026-09-25  9:54   ` Jerome Brunet
2026-09-29 10:43     ` Sascha Hauer
2026-10-05 15:15       ` Jerome Brunet

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260921070121.A33001F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-clk@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=s.hauer@pengutronix.de \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox