Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Muzaffer Kadir" <muzafferkadir@mainlining.org>
Cc: devicetree@vger.kernel.org, linux-input@vger.kernel.org,
	dmitry.torokhov@gmail.com, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH v4 4/7] thermal: qcom: tsens: Add support for MSM8952 tsens
Date: Tue, 06 Oct 2026 12:25:14 +0000	[thread overview]
Message-ID: <20261006122515.276E51F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261006-msm8952-initial-support-v4-4-ecdcc1ac620c@mainlining.org>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] thermal: qcom: tsens: heap out-of-bounds write in init_8952() due to unvalidated #qcom,sensors
- [High] thermal: qcom: tsens: use-after-free in tsens_probe() when executing __init init_8952()
--

commit 485835aa537dd437aeac92e15ded8ca82d079ba0
Author: Muzaffer Kadir <muzafferkadir@mainlining.org>

thermal: qcom: tsens: Add support for MSM8952 tsens

Add support for tsens v1 block that exists on MSM8952 with 11 tsens
sensors. Sensor Offsets and slope values are taken from downstream.

Link: https://android.googlesource.com/kernel/msm.git/+/refs/tags/android-wear-7.0.0_r0.3/drivers/thermal/msm-tsens.c#1621

> diff --git a/drivers/thermal/qcom/tsens-v1.c b/drivers/thermal/qcom/tsens-v1.c
> --- a/drivers/thermal/qcom/tsens-v1.c
> +++ b/drivers/thermal/qcom/tsens-v1.c
[ ... ]
> +static int __init init_8952(struct tsens_priv *priv)

[Severity: High]
Is it safe to mark init_8952() with __init?

The pointer to this function is stored in the ops_8952 structure below,
which is non-init data. If tsens_probe() is deferred due to calibration
nvmem cell returning -EPROBE_DEFER, or if the device is manually unbound
and rebound via sysfs after boot, it will eventually execute
priv->ops->init(priv).

Could this result in a use-after-free regression by dereferencing
discarded init memory during a later probe?

> +{
> +	for (int i = 0; i < priv->num_sensors; ++i)
> +		priv->sensor[i].slope = 3200;
> +
> +	priv->sensor[0].p1_calib_offset = 2;
> +	priv->sensor[0].p2_calib_offset = -1;
[ ... ]
> +	priv->sensor[10].p1_calib_offset = -3;
> +	priv->sensor[10].p2_calib_offset = -2;

[Severity: High]
Does this sequence unconditionally access up to 11 sensors?

In tsens_probe(), the priv->sensor array is dynamically allocated based
on the num_sensors value, which can be restricted by the device tree:

drivers/thermal/qcom/tsens.c:tsens_probe() {
    ...
    priv = devm_kzalloc(dev,
                 struct_size(priv, sensor, num_sensors),
                 GFP_KERNEL);
    ...
}

If a device tree provides a #qcom,sensors property with a value less
than 11, could these assignments overwrite heap memory and cause a
corruption regression during driver load?

> +
> +	return init_common(priv);
> +}
[ ... ]
> +static const struct tsens_ops ops_8952 = {
> +	.init		= init_8952,
> +	.calibrate	= tsens_calibrate_common,
> +	.get_temp	= get_temp_tsens_valid,
> +};

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261006-msm8952-initial-support-v4-0-ecdcc1ac620c@mainlining.org?part=4

  reply	other threads:[~2026-10-06 12:25 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 12:15 [PATCH v4 0/7] Add Initial Support For MSM8952, Add General Mobile Shamrock Muzaffer Kadir via B4 Relay
2026-10-06 12:15 ` [PATCH v4 1/7] dt-bindings: nvmem: Add compatible for MSM8952 Muzaffer Kadir via B4 Relay
2026-10-06 12:15 ` [PATCH v4 2/7] dt-bindings: iommu: qcom,iommu: Add MSM8952 IOMMU to SMMUv2 compatibles Muzaffer Kadir via B4 Relay
2026-10-06 12:15 ` [PATCH v4 3/7] dt-bindings: thermal: tsens: Add MSM8952 Muzaffer Kadir via B4 Relay
2026-10-06 12:15 ` [PATCH v4 4/7] thermal: qcom: tsens: Add support for MSM8952 tsens Muzaffer Kadir via B4 Relay
2026-10-06 12:25   ` sashiko-bot [this message]
2026-10-06 13:19   ` Dmitry Baryshkov
2026-10-06 13:49     ` Muzaffer Kadir
2026-10-07  7:03       ` Dmitry Baryshkov
2026-10-06 12:15 ` [PATCH v4 5/7] arm64: dts: qcom: Add initial support for MSM8952 Muzaffer Kadir via B4 Relay
2026-10-06 12:29   ` sashiko-bot
2026-10-06 12:15 ` [PATCH v4 6/7] dt-bindings: input: touchscreen: goodix: Add binding for GT970 Muzaffer Kadir via B4 Relay
2026-10-06 12:15 ` [PATCH v4 7/7] arm64: dts: qcom: generalmobile-shamrock: new device Muzaffer Kadir via B4 Relay
2026-10-06 12:27   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006122515.276E51F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dmitry.torokhov@gmail.com \
    --cc=linux-input@vger.kernel.org \
    --cc=muzafferkadir@mainlining.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox