From: sashiko-bot@kernel.org
To: "Andrei Stancovici" <andrei.stancovici@analog.com>
Cc: conor+dt@kernel.org, robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH 5/6] iio: adc: ltc2497: add FA/FB line-frequency rejection selection
Date: Fri, 09 Oct 2026 08:54:09 +0000 [thread overview]
Message-ID: <sashiko-outbox-165114@kernel.org> (raw)
In-Reply-To: <20261009-submission-ltc2493-support-v1-v1-5-3dad1d4b152a@analog.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] iio: adc: I2C DMA memory corruption via stack buffer in ltc2497_result_and_measure
- [Low] iio: data race on ddata->rejection in read_avail
--
commit 26aab6330d34e8191cc6202f7b5b3be69e9b0fb8
Author: Andrei Stancovici <andrei.stancovici@analog.com>
iio: adc: ltc2497: add FA/FB line-frequency rejection selection
This patch adds support for exposing the FA/FB line-frequency rejection
options of the LTC2499 through filter_mode on the voltage channels. It
allows selection of 50Hz, 60Hz, or both, and updates conversion times
accordingly.
Datasheet: https://www.analog.com/media/en/technical-documentation/data-sheets/2499fa.pdf
> diff --git a/drivers/iio/adc/ltc2497-core.c b/drivers/iio/adc/ltc2497-core.c
> index 816312bf0e90b..e5a8ab5681281 100644
> --- a/drivers/iio/adc/ltc2497-core.c
> +++ b/drivers/iio/adc/ltc2497-core.c
[ ... ]
> @@ -211,11 +218,13 @@ static int ltc2497core_read_avail(struct iio_dev *indio_dev,
> const int **vals, int *type, int *length,
> long mask)
> {
> + struct ltc2497core_driverdata *ddata = iio_priv(indio_dev);
> +
> switch (mask) {
> case IIO_CHAN_INFO_SAMP_FREQ:
> - *vals = ltc2497core_samp_freq_avail;
> + *vals = ltc2497core_samp_freq_avail[ddata->rejection];
[Severity: Low]
Does this unguarded read of ddata->rejection in ltc2497core_read_avail() race
with concurrent sysfs writes?
Concurrently, filter_mode sysfs writes can invoke
ltc2497core_set_filter_mode(), which modifies ddata->rejection while holding
the ddata->lock. While an out-of-bounds array access is structurally
prevented because the inner array size is fixed and resolved at compile time,
this unguarded read of shared mutable state violates kernel concurrency rules
and will trigger KCSAN data race warnings.
> + *type = IIO_VAL_INT_PLUS_MICRO;
> - *length = ARRAY_SIZE(ltc2497core_samp_freq_avail);
> + *length = ARRAY_SIZE(ltc2497core_samp_freq_avail[ddata->rejection]);
> return IIO_AVAIL_LIST;
>
> default:
[ ... ]
> diff --git a/drivers/iio/adc/ltc2497.c b/drivers/iio/adc/ltc2497.c
> index a655b04e2454b..0df2ad9b32437 100644
> --- a/drivers/iio/adc/ltc2497.c
> +++ b/drivers/iio/adc/ltc2497.c
[ ... ]
> @@ -86,32 +103,34 @@ static int ltc2497_result_and_measure(struct ltc2497core_driverdata *ddata,
[ ... ]
> - if (ddata->chip_info->has_temp || ddata->chip_info->has_speed_mode) {
> + if (ddata->chip_info->has_temp || ddata->chip_info->has_speed_mode ||
> + ddata->chip_info->has_rejection_mode) {
> + u8 rejection_bits = ltc2497_rejection_bits(ddata->rejection);
> u8 cmd[2];
>
> if (address == LTC2497_TEMP_ADDR) {
> cmd[0] = LTC2497_ENABLE | LTC2497_CONFIG_DEFAULT;
> - cmd[1] = LTC2499_EN2 | LTC2499_IM;
> + cmd[1] = LTC2499_EN2 | LTC2499_IM | rejection_bits;
> } else {
> cmd[0] = LTC2497_ENABLE | address;
> - cmd[1] = LTC2499_EN2;
> + cmd[1] = LTC2499_EN2 | rejection_bits;
> if (ddata->speed_2x)
> cmd[1] |= LTC2499_SPD;
> }
>
> ret = i2c_master_send(st->client, cmd, sizeof(cmd));
[Severity: High]
This problem wasn't introduced by this patch, but since the patch modifies
this exact block and relies on it, does this code pass an unaligned stack
buffer for DMA I/O?
In ltc2497_result_and_measure(), the 2-byte array cmd is allocated on the
stack and populated with configuration bits. This array is passed directly to
i2c_master_send(). If the underlying I2C master driver uses DMA for the
transfer, mapping a stack address is illegal (especially with
CONFIG_VMAP_STACK) and can lead to memory corruption, panics, or silent
failures.
The driver properly aligns its receive buffer (st->data) with
__aligned(IIO_DMA_MINALIGN), demonstrating awareness of this requirement, but
overlooks the transmit buffer.
> if (ret < 0) {
> dev_err(&st->client->dev, "i2c transfer failed: %pe\n",
> ERR_PTR(ret));
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261009-submission-ltc2493-support-v1-v1-0-3dad1d4b152a@analog.com?part=5
next prev parent reply other threads:[~2026-10-09 8:54 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 8:43 [PATCH 0/6] iio: adc: ltc2497: add LTC2493 support and line-frequency rejection Andrei Stancovici via B4 Relay
2026-10-09 8:43 ` [PATCH 1/6] dt-bindings: iio: adc: lltc,ltc2497: add LTC2493 support Andrei Stancovici via B4 Relay
2026-10-09 12:06 ` Joshua Crofts
2026-10-09 14:45 ` Conor Dooley
2026-10-09 8:43 ` [PATCH 2/6] iio: adc: ltc2497: " Andrei Stancovici via B4 Relay
2026-10-09 8:43 ` [PATCH 3/6] iio: adc: ltc2497: add LTC2493 internal temperature channel Andrei Stancovici via B4 Relay
2026-10-09 8:43 ` [PATCH 4/6] iio: adc: ltc2497: add 2x speed mode support for the LTC2493 Andrei Stancovici via B4 Relay
2026-10-09 8:43 ` [PATCH 5/6] iio: adc: ltc2497: add FA/FB line-frequency rejection selection Andrei Stancovici via B4 Relay
2026-10-09 8:54 ` sashiko-bot [this message]
2026-10-09 8:43 ` [PATCH 6/6] iio: adc: ltc2497: enable line-frequency rejection on LTC2493 Andrei Stancovici via B4 Relay
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-165114@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=andrei.stancovici@analog.com \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox