From: sashiko-bot@kernel.org
To: "Petko Manolov" <petko.manolov@konsulko.com>
Cc: conor+dt@kernel.org, robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v7 3/3] arm: dts: altera: add Draeger M48 CPU Module
Date: Mon, 21 Sep 2026 09:17:22 +0000 [thread overview]
Message-ID: <20260921091722.C33FF1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260921090735.3174292-4-petko.manolov@konsulko.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] dts: out-of-bounds IO read in gpio3/4 due to truncated reg size
--
commit 3110a5bc839de956f70473c018ac9b733616c145
Author: Petko Manolov <petko.manolov@konsulko.com>
arm: dts: altera: add Draeger M48 CPU Module
M48 is a heterogeneous board made by Draeger that is based on two
independent cpus, that are monitoring each other. One of them is
imx6, the other is Altera SoCFPGA Cyclone 5. The latter is booting
independently off qspi.
> diff --git a/arch/arm/boot/dts/intel/socfpga/socfpga_cyclone5_draeger_m48.dts b/arch/arm/boot/dts/intel/socfpga/socfpga_cyclone5_draeger_m48.dts
> new file mode 100644
> index 0000000000000..dae809c02adb8
> --- /dev/null
> +++ b/arch/arm/boot/dts/intel/socfpga/socfpga_cyclone5_draeger_m48.dts
> @@ -0,0 +1,123 @@
> +// SPDX-License-Identifier: GPL-2.0+
[ ... ]
> + soc {
> + gpio3: gpio@ff202000 {
> + #address-cells = <1>;
> + #size-cells = <0>;
> + compatible = "snps,dw-apb-gpio";
> + reg = <0xff202000 0x20>;
[Severity: High]
Does mapping a 0x20 byte resource window for the snps,dw-apb-gpio driver
trigger an out-of-bounds IO memory access on boot?
During probe in drivers/gpio/gpio-dwapb.c, dwapb_gpio_probe() calls
dwapb_gpio_add_port(), which passes gpio->regs + 0x50 (GPIO_EXT_PORTA)
to gpio_generic_chip_init(). This results in an unconditional read from
offset 0x50, which is outside the mapped 0x20 byte window.
On the Altera SoCFPGA's lightweight HPS-to-FPGA bridge, reading unmapped
addresses typically triggers an AXI bus error, leading to a synchronous
external abort and a kernel panic.
Is it possible the hardware here is actually an Altera PIO core
(altr,pio-1.0) given the 0x20 byte size?
> +
> + portd: gpio-controller@0 {
> + compatible = "snps,dw-apb-gpio-port";
> + gpio-controller;
> + #gpio-cells = <2>;
> + snps,nr-gpios = <2>;
> + reg = <0>;
> + };
> + };
> +
> + gpio4: gpio@ff202020 {
> + #address-cells = <1>;
> + #size-cells = <0>;
> + compatible = "snps,dw-apb-gpio";
> + reg = <0xff202020 0x20>;
[Severity: High]
Similarly, does mapping a 0x20 byte window for gpio4 at 0xff202020 cause
the same out-of-bounds IO read from offset 0x50 into unmapped MMIO space
during dwapb_gpio_add_port()?
> +
> + porte: gpio-controller@0 {
> + compatible = "snps,dw-apb-gpio-port";
> + gpio-controller;
> + #gpio-cells = <2>;
> + snps,nr-gpios = <2>;
> + reg = <0>;
> + };
> + };
> + };
> +};
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260921090735.3174292-1-petko.manolov@konsulko.com?part=3
next prev parent reply other threads:[~2026-09-21 9:17 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 9:07 [PATCH v7 0/3] arm: dts: altera: add Draeger M48 CPU board Petko Manolov
2026-09-21 9:07 ` [PATCH v7 1/3] dt-bindings: vendor-prefixes: add Draeger AG Petko Manolov
2026-09-21 9:07 ` [PATCH v7 2/3] dt-bindings: arm: altera: add Draeger M48 dual-cpu board Petko Manolov
2026-09-28 5:53 ` Krzysztof Kozlowski
2026-09-21 9:07 ` [PATCH v7 3/3] arm: dts: altera: add Draeger M48 CPU Module Petko Manolov
2026-09-21 9:17 ` sashiko-bot [this message]
2026-09-28 14:18 ` Dinh Nguyen
2026-09-29 13:38 ` Petko Manolov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921091722.C33FF1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=petko.manolov@konsulko.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox