Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Liviu Stan" <liviu.stan@analog.com>
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v4 9/9] iio: temperature: ltc2983: Add support for ADT7604
Date: Mon, 25 May 2026 19:06:14 +0000	[thread overview]
Message-ID: <20260525190616.272A41F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260525164013.118614-10-liviu.stan@analog.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Integer truncation of `num_channels` leads to an out-of-bounds write on the heap when parsing device tree children.
--

commit 482bc8c51e04185002511817885173bd265542d8
Author: Liviu Stan <liviu.stan@analog.com>

iio: temperature: ltc2983: Add support for ADT7604

This commit adds support for the ADT7604 sensor, repurposing custom RTD
and thermistor sensor types as copper trace and leak detectors. It
introduces new structs, parser functions, and hardware register mappings
to handle these new types.

> diff --git a/drivers/iio/temperature/ltc2983.c b/drivers/iio/temperature/ltc2983.c
> index 130ab7fddc2fe..fc65d8352d120 100644
> --- a/drivers/iio/temperature/ltc2983.c
> +++ b/drivers/iio/temperature/ltc2983.c

[ ... ]

> @@ -1348,7 +1672,7 @@ static int ltc2983_parse_fw(struct ltc2983_data *st)
>  	if (!st->sensors)
>  		return -ENOMEM;
>  
> -	st->iio_channels = st->num_channels;
> +	st->iio_channels = 0;

[Severity: High]
This is a pre-existing issue, but does st->num_channels silently truncate
the number of child nodes since it is defined as a u8?

If a device tree is provided with 256 or more child nodes (e.g., 257
nodes via DT overlays), device_get_child_node_count() returns 257, but
st->num_channels truncates this to 1. This causes devm_kcalloc() to
allocate only a 1-element array for st->sensors.

The device_for_each_child_node_scoped() loop directly following this will
then iterate over the children and write into st->sensors[chan], resulting
in out-of-bounds writes on the heap. Could num_channels be changed to an
unsigned int to prevent this memory corruption?

>  	device_for_each_child_node_scoped(dev, child) {
>  		struct ltc2983_sensor sensor;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260525164013.118614-1-liviu.stan@analog.com?part=9

  reply	other threads:[~2026-05-25 19:06 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-25 16:39 [PATCH v4 0/9] iio: temperature: ltc2983: Add support for ADT7604 Liviu Stan
2026-05-25 16:39 ` [PATCH v4 1/9] iio: temperature: ltc2983: Fix n_wires default bypassing rotation check Liviu Stan
2026-05-27 16:11   ` Jonathan Cameron
2026-05-25 16:39 ` [PATCH v4 2/9] iio: temperature: ltc2983: Fix reinit_completion() called after conversion start Liviu Stan
2026-05-27 16:13   ` Jonathan Cameron
2026-05-25 16:39 ` [PATCH v4 3/9] iio: temperature: ltc2983: Fix macro parenthesization and rename Liviu Stan
2026-05-27 16:13   ` Jonathan Cameron
2026-05-25 16:39 ` [PATCH v4 4/9] iio: temperature: ltc2983: Use local device pointer consistently Liviu Stan
2026-05-27 16:18   ` Jonathan Cameron
2026-06-02 23:25     ` Andy Shevchenko
2026-06-03 14:08       ` Jonathan Cameron
2026-05-25 16:39 ` [PATCH v4 5/9] iio: temperature: ltc2983: Fix inconsistent channel wording in messages Liviu Stan
2026-05-27 16:19   ` Jonathan Cameron
2026-05-25 16:39 ` [PATCH v4 6/9] iio: temperature: ltc2983: Use fwnode_property_present() for optional properties Liviu Stan
2026-05-27 16:19   ` Jonathan Cameron
2026-06-02 23:26     ` Andy Shevchenko
2026-06-03 14:01       ` Jonathan Cameron
2026-05-25 16:39 ` [PATCH v4 7/9] iio: core: Add IIO_COVERAGE channel type Liviu Stan
2026-05-27 16:51   ` Jonathan Cameron
2026-05-25 16:39 ` [PATCH v4 8/9] dt-bindings: iio: temperature: Add ADT7604 support to adi,ltc2983 Liviu Stan
2026-05-25 18:28   ` sashiko-bot
2026-05-26 16:55   ` Conor Dooley
2026-05-27 15:59     ` Liviu Stan
2026-05-27 16:51     ` Jonathan Cameron
2026-05-25 16:39 ` [PATCH v4 9/9] iio: temperature: ltc2983: Add support for ADT7604 Liviu Stan
2026-05-25 19:06   ` sashiko-bot [this message]
2026-05-26  8:47   ` Liviu Stan
2026-05-27 16:49     ` Jonathan Cameron
2026-06-02  6:38       ` Liviu Stan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260525190616.272A41F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=liviu.stan@analog.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox