Linux clock framework development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Joey Lu" <a0987203069@gmail.com>
Cc: linux-clk@vger.kernel.org
Subject: Re: [PATCH 1/1] clk: nuvoton: ma35d1-divider: use direct formula instead of divider table
Date: Tue, 29 Sep 2026 07:29:16 +0000	[thread overview]
Message-ID: <20260929072916.E46231F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929072106.175202-2-a0987203069@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] clk: nuvoton: rate mismatch and missing bounds check in determine_rate
- [High] clk: nuvoton: divide by zero due to integer overflow in rate multiplication
--

commit 434b92fcdb326fe48e43db4fafe0804d04aee387
Author: Joey Lu <a0987203069@gmail.com>

    clk: nuvoton: ma35d1-divider: use direct formula instead of divider table

This patch replaces the table-based clock divider with a direct formula in the
Nuvoton MA35D1 ADC clock divider driver. It drops the mask bit mechanism and
computes the divisor explicitly in the recalc, determine, and set rate
callbacks.

> diff --git a/drivers/clk/nuvoton/clk-ma35d1-divider.c b/drivers/clk/nuvoton/clk-ma35d1-divider.c
> index e992e7c303419..03fcf87caae18 100644
> --- a/drivers/clk/nuvoton/clk-ma35d1-divider.c
> +++ b/drivers/clk/nuvoton/clk-ma35d1-divider.c
[ ... ]
> @@ -29,44 +27,60 @@ static inline struct ma35d1_adc_clk_div *to_ma35d1_adc_clk_div(struct clk_hw *_h
[ ... ]
>  static int ma35d1_clkdiv_determine_rate(struct clk_hw *hw,
>  					struct clk_rate_request *req)
>  {
>  	struct ma35d1_adc_clk_div *dclk = to_ma35d1_adc_clk_div(hw);
> +	unsigned int val;
> +
> +	if (!req->rate)
> +		return -EINVAL;
>  
> -	return divider_determine_rate(hw, req, dclk->table, dclk->width,
> -				      CLK_DIVIDER_ROUND_CLOSEST);
> +	val = DIV_ROUND_UP(req->best_parent_rate, 2 * req->rate);

[Severity: High]
Does this code divide by zero due to integer overflow in rate multiplication?

If a caller or untrusted user (via debugfs) requests a rate such that
2 * req->rate overflows a 32-bit or 64-bit unsigned integer (for example,
rate = 1UL << (BITS_PER_LONG - 1)), the denominator 2 * req->rate wraps to 0.

This would cause DIV_ROUND_UP(req->best_parent_rate, 0) to evaluate to a
division by zero panic.

[Severity: High]
Can this create a rate mismatch between ma35d1_clkdiv_determine_rate() and
ma35d1_clkdiv_set_rate()?

This calculates the divider using a strict ceiling instead of closest match,
and also fails to check rate boundaries against req->min_rate and
req->max_rate.

> +	if (val == 0)
> +		val = 1;
> +	if (val > (unsigned int)clk_div_mask(dclk->width) + 1)
> +		val = clk_div_mask(dclk->width) + 1;
> +
> +	req->rate = DIV_ROUND_CLOSEST_ULL((u64)req->best_parent_rate, 2 * val);

It then promises a closest-rounded integer rate to the clock framework here.
When ma35d1_clkdiv_set_rate() is called later, the recomputation will yield a
different divisor.

> +
> +	return 0;
>  }
>  
>  static int ma35d1_clkdiv_set_rate(struct clk_hw *hw, unsigned long rate, unsigned long parent_rate)
>  {
> -	int value;
> -	unsigned long flags = 0;
> -	u32 data;
>  	struct ma35d1_adc_clk_div *dclk = to_ma35d1_adc_clk_div(hw);
> +	unsigned long flags;
> +	unsigned int val;
> +	u32 data;
> +
> +	if (!rate)
> +		return -EINVAL;
>  
> -	value = divider_get_val(rate, parent_rate, dclk->table,
> -				dclk->width, CLK_DIVIDER_ROUND_CLOSEST);
> +	val = DIV_ROUND_UP(parent_rate, 2 * rate);

[Severity: High]
Could this identical integer overflow cause division by zero here as well?

Also, because the rate was rounded in ma35d1_clkdiv_determine_rate(),
recalculating the divider using DIV_ROUND_UP(parent_rate, 2 * rate) can yield
a completely different divisor.

For example, with parent_rate=1000 and an original val=6,
ma35d1_clkdiv_determine_rate() promises rate=83.

Then ma35d1_clkdiv_set_rate() calculates DIV_ROUND_UP(1000, 166) = 7, applying
a divider of 7 instead of 6 (which results in an actual rate of 71 instead of
83).

> +	if (val == 0)
> +		val = 1;
> +	if (val > (unsigned int)clk_div_mask(dclk->width) + 1)
> +		val = clk_div_mask(dclk->width) + 1;
>  
>  	spin_lock_irqsave(dclk->lock, flags);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929072106.175202-1-a0987203069@gmail.com?part=1

      reply	other threads:[~2026-09-29  7:29 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  7:21 [PATCH 0/1] clk: nuvoton: ma35d1-divider: use direct formula instead of divider table Joey Lu
2026-09-29  7:21 ` [PATCH 1/1] " Joey Lu
2026-09-29  7:29   ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929072916.E46231F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=a0987203069@gmail.com \
    --cc=linux-clk@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox