From: sashiko-bot@kernel.org
To: "Varshini Rajendran" <varshini.rajendran@microchip.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v4 03/16] iio: adc: at91-sama5d2_adc: rework temp calibration layout handling
Date: Mon, 27 Jul 2026 12:39:59 +0000 [thread overview]
Message-ID: <20260727124000.909C91F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260727122633.117435-4-varshini.rajendran@microchip.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] The `DEFINE_FREE` wrapper for `nvmem_cell_put` incorrectly handles error pointers, leading to a kernel crash when `nvmem_cell_get()` fails.
- [Medium] The introduced temperature calibration tag index and expected tag macro are never used to validate the NVMEM packet.
--
--- Patch [3]: [PATCH v4 03/16] iio: adc: at91-sama5d2_adc: rework temp calibration layout handling ---
commit 859125ad776a3a3f2a744e65f324ef58a384982e
Author: Varshini Rajendran <varshini.rajendran@microchip.com>
iio: adc: at91-sama5d2_adc: rework temp calibration layout handling
Extend support to handle different temperature calibration layouts.
Add a temperature calibration data layout structure to describe indexes
of the factors P1, P4, P6, tag, minimum length of the packet and the
scaling factors for P1 (p1_scale) which are SoC-specific instead of the
older non scalable id structure. This helps handle the differences in the
same function flow and prepare the calibration data to be applied.
> diff --git a/drivers/iio/adc/at91-sama5d2_adc.c b/drivers/iio/adc/at91-sama5d2_adc.c
> index 4a4a25f3c715a..798e4d60bf697 100644
> --- a/drivers/iio/adc/at91-sama5d2_adc.c
> +++ b/drivers/iio/adc/at91-sama5d2_adc.c
[ ... ]
> @@ -2251,11 +2271,18 @@ static int at91_adc_temp_sensor_init(struct at91_adc_state *st,
> struct device *dev)
> {
> struct at91_adc_temp_sensor_clb *clb = &st->soc_info.temp_sensor_clb;
> + const struct at91_adc_temp_calib_layout *layout;
> size_t len;
>
> if (!st->soc_info.platform->temp_sensor)
> return 0;
>
> + layout = st->soc_info.platform->temp_calib_layout;
> + if (!layout)
> + return -ENODEV;
> + if (!layout->p1_scale.denominator)
> + return -EINVAL;
> +
> /* Get the calibration data from NVMEM. */
> struct nvmem_cell *temp_calib __free(nvmem_cell_put) =
> nvmem_cell_get(dev, "temperature_calib");
[Severity: High]
Does the DEFINE_FREE() wrapper for nvmem_cell_put() properly handle error
pointers?
If nvmem_cell_get() returns an ERR_PTR (e.g. if the NVMEM cell is missing
or defers probe), the error pointer will be truthy. If the custom
DEFINE_FREE(nvmem_cell_put) wrapper only checks "if (_T)" instead of
using IS_ERR_OR_NULL(), the truthy ERR_PTR can bypass the guard and be
passed to nvmem_cell_put(). This would unconditionally dereference the
error pointer and cause a kernel panic.
[ ... ]
> @@ -2270,20 +2297,23 @@ static int at91_adc_temp_sensor_init(struct at91_adc_state *st,
> return dev_err_probe(dev, PTR_ERR(buf),
> "Failed to read calibration data!\n");
>
> - if (len < AT91_ADC_TS_CLB_IDX_MAX * sizeof(*buf)) {
> + if (len < layout->min_len * sizeof(*buf)) {
> dev_err(dev, "Invalid calibration data!\n");
> return -EINVAL;
> }
[Severity: Medium]
Are we missing the expected packet tag validation here?
The commit introduces the AT91_TEMP_CALIB_TAG_ACST macro and the tag_idx field
specifically to validate the NVMEM cell content, but the actual validation
check seems omitted.
This might allow the driver to accept corrupted or invalid NVMEM calibration
data as long as it meets the minimum length requirement.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260727122633.117435-1-varshini.rajendran@microchip.com?part=3
next prev parent reply other threads:[~2026-07-27 12:40 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 12:26 [PATCH v4 00/16] Add thermal management support for sama7d65 Varshini Rajendran
2026-07-27 12:26 ` [PATCH v4 01/16] dt-bindings: iio: adc: at91-sama5d2: document sama7d65 Varshini Rajendran
2026-07-27 12:26 ` [PATCH v4 02/16] iio: adc: at91-sama5d2_adc: use cleanup.h for NVMEM buffer Varshini Rajendran
2026-07-27 12:36 ` sashiko-bot
2026-07-27 12:26 ` [PATCH v4 03/16] iio: adc: at91-sama5d2_adc: rework temp calibration layout handling Varshini Rajendran
2026-07-27 12:39 ` sashiko-bot [this message]
2026-07-27 12:26 ` [PATCH v4 04/16] iio: adc: at91-sama5d2_adc: add condition to validate calibration data Varshini Rajendran
2026-07-27 12:42 ` sashiko-bot
2026-07-27 12:26 ` [PATCH v4 05/16] iio: adc: at91-sama5d2_adc: remove unnecessary casts in of_device_id Varshini Rajendran
2026-07-27 12:26 ` [PATCH v4 06/16] iio: adc: at91-sama5d2_adc: adapt the driver for sama7d65 Varshini Rajendran
2026-07-27 12:41 ` sashiko-bot
2026-07-27 12:26 ` [PATCH v4 07/16] dt-bindings: nvmem: microchip,sama7g5-otpc: add sama7d65 and dt node example Varshini Rajendran
2026-07-27 12:41 ` sashiko-bot
2026-07-27 12:26 ` [PATCH v4 08/16] nvmem: microchip-otpc: nvmem: microchip-otpc: add tag-based packet lookup Varshini Rajendran
2026-07-27 12:44 ` sashiko-bot
2026-07-27 12:26 ` [PATCH v4 09/16] nvmem: microchip-otpc: nvmem: add emulation mode and OTP access validation Varshini Rajendran
2026-07-27 12:39 ` sashiko-bot
2026-07-27 12:26 ` [PATCH v4 10/16] ARM: dts: microchip: sama7d65: add cpu opps Varshini Rajendran
2026-07-27 12:26 ` [PATCH v4 11/16] ARM: dts: microchip: sama7d65: Add ADC node Varshini Rajendran
2026-07-27 12:26 ` [PATCH v4 12/16] ARM: dts: microchip: sama7d65_curiosity: Enable ADC, DVFS Varshini Rajendran
2026-07-27 12:26 ` [PATCH v4 13/16] ARM: dts: microchip: sama7d65: add otpc node Varshini Rajendran
2026-07-27 12:44 ` sashiko-bot
2026-07-27 12:26 ` [PATCH v4 14/16] ARM: dts: microchip: sama7d65: add cells for temperature calibration Varshini Rajendran
2026-07-27 12:50 ` sashiko-bot
2026-07-27 12:26 ` [PATCH v4 15/16] ARM: dts: microchip: sama7d65: add temperature sensor Varshini Rajendran
2026-07-27 12:45 ` sashiko-bot
2026-07-27 12:26 ` [PATCH v4 16/16] ARM: dts: microchip: sama7d65: add thermal zones node Varshini Rajendran
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260727124000.909C91F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=varshini.rajendran@microchip.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox