From: sashiko-bot@kernel.org
To: "Radu Sabau" <radu.sabau@analog.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v2 6/6] iio: imu: adis16607: Add calibration bias support for gyro/accel
Date: Thu, 08 Oct 2026 08:43:14 +0000 [thread overview]
Message-ID: <sashiko-outbox-163849@kernel.org> (raw)
In-Reply-To: <20261008-adis16607-v2-6-7c94df80878a@analog.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] iio: missing bounds check in adis16607_write_raw() causes integer truncation
--
commit e23feabbd136bcd6fd30e2609a83f094ba9326fc
Author: Radu Sabau <radu.sabau@analog.com>
iio: imu: adis16607: Add calibration bias support for gyro/accel
This commit adds IIO_CHAN_INFO_CALIBBIAS support for the gyroscope and
accelerometer axes. It backs the new attribute using the device's per-axis
bias registers.
> diff --git a/drivers/iio/imu/adis16607.c b/drivers/iio/imu/adis16607.c
> index 0147eba0b1737..d4b3a8a9fd08a 100644
> --- a/drivers/iio/imu/adis16607.c
> +++ b/drivers/iio/imu/adis16607.c
[ ... ]
> @@ -1000,6 +1026,7 @@ static int adis16607_write_raw(struct iio_dev *indio_dev,
> int val, int val2, long info)
> {
> struct adis16607 *st = iio_priv(indio_dev);
> + const int idx = chan->scan_index;
> u32 tmp;
>
> switch (info) {
> @@ -1007,6 +1034,9 @@ static int adis16607_write_raw(struct iio_dev *indio_dev,
> tmp = val * 1000 + val2 / 1000;
> return adis16607_set_freq(st, tmp);
>
> + case IIO_CHAN_INFO_CALIBBIAS:
> + return adis_write_reg_16(&st->adis, adis16607_calib_bias[idx], val);
[Severity: Medium]
Does this code silently truncate out-of-bounds user inputs? The `val`
parameter in adis16607_write_raw() is a 32-bit signed integer provided by
userspace, but adis_write_reg_16() expects a 16-bit integer.
Because there is no bounds check on `val` before passing it down, out-of-range
values (values outside the 16-bit signed range [-32768, 32767]) could be
implicitly cast and wrapped. For example, 65536 would become 0, leading to
unintended calibration bias being applied to the device instead of rejecting
the write and returning an error to userspace.
> +
> default:
> return -EINVAL;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261008-adis16607-v2-0-7c94df80878a@analog.com?part=6
prev parent reply other threads:[~2026-10-08 8:43 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 8:31 [PATCH v2 0/6] iio: imu: Add support for the ADI ADIS16607 Radu Sabau via B4 Relay
2026-10-08 8:31 ` [PATCH v2 1/6] iio: imu: adis: Add optional self_test callback and fix custom reset dispatch Radu Sabau via B4 Relay
2026-10-08 8:45 ` sashiko-bot
2026-10-08 8:31 ` [PATCH v2 2/6] dt-bindings: iio: imu: Add bindings for ADI ADIS16607 Radu Sabau via B4 Relay
2026-10-08 8:37 ` sashiko-bot
2026-10-08 10:14 ` Conor Dooley
2026-10-08 8:31 ` [PATCH v2 3/6] iio: imu: Add driver for the " Radu Sabau via B4 Relay
2026-10-08 8:31 ` [PATCH v2 4/6] iio: imu: adis16607: Add FIFO-based buffered/triggered capture Radu Sabau via B4 Relay
2026-10-08 8:45 ` sashiko-bot
2026-10-08 8:31 ` [PATCH v2 5/6] iio: imu: adis16607: Add external clock sync support Radu Sabau via B4 Relay
2026-10-08 8:42 ` sashiko-bot
2026-10-08 8:31 ` [PATCH v2 6/6] iio: imu: adis16607: Add calibration bias support for gyro/accel Radu Sabau via B4 Relay
2026-10-08 8:43 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-163849@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=radu.sabau@analog.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox