From: "Nuno Sá" <noname.nuno@gmail.com>
To: Guenter Roeck <linux@roeck-us.net>
Cc: Hardware Monitoring <linux-hwmon@vger.kernel.org>,
Nuno Sa <nuno.sa@analog.com>, Sashiko <sashiko-bot@kernel.org>
Subject: Re: [PATCH 2/3] hwmon: (ltc4282) Clamp negative current limits
Date: Wed, 5 Aug 2026 10:22:28 +0100 [thread overview]
Message-ID: <anMAcWIbE7_wOjIv@nsa> (raw)
In-Reply-To: <20260805005721.1566034-3-linux@roeck-us.net>
On Tue, Aug 04, 2026 at 05:57:20PM -0700, Guenter Roeck wrote:
> When a negative value is passed to ltc4282_write_curr(), the signed long
> val is cast directly to u64:
>
> drivers/hwmon/ltc4282.c:ltc4282_write_curr() {
> /* need to pass it in millivolt */
> u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO);
> ...
> }
>
> This cast converts negative inputs into large positive values. The
> subsequent division result overflows the u32 in variable, truncating
> to a pseudo-random positive value. When this is passed to
> ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead
> of zero.
>
> Clamp val to 0 and to the maximum supported upper limit before the cast
> and assign the result to a 64-bit temporary variable before the division
> to avoid the underflow and an also possible overflow.
>
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Fixes: cbc29538dbf7d ("hwmon: Add driver for LTC4282")
> Cc: Nuno Sa <nuno.sa@analog.com>
> Signed-off-by: Guenter Roeck <linux@roeck-us.net>
> ---
> drivers/hwmon/ltc4282.c | 6 +++++-
> 1 file changed, 5 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/hwmon/ltc4282.c b/drivers/hwmon/ltc4282.c
> index bb7f6727c44d..bb1bcb369016 100644
> --- a/drivers/hwmon/ltc4282.c
> +++ b/drivers/hwmon/ltc4282.c
> @@ -14,6 +14,7 @@
> #include <linux/hwmon.h>
> #include <linux/i2c.h>
> #include <linux/math.h>
> +#include <linux/math64.h>
> #include <linux/minmax.h>
> #include <linux/module.h>
> #include <linux/regmap.h>
> @@ -929,8 +930,11 @@ static int ltc4282_curr_reset_hist(struct ltc4282_state *st)
> static int ltc4282_write_curr(struct ltc4282_state *st, u32 attr,
> long val)
> {
> + s32 ulimit = min_t(u64, INT_MAX,
> + div_u64((u64)INT_MAX * DECA * MICRO, st->rsense));
I guess we can do the same as in ltc4283 instead of just assuming
INT_MAX:
https://elixir.bootlin.com/linux/v7.2-rc5/source/drivers/hwmon/ltc4283.c#L765
And so we just account for isense_max
- Nuno Sá
next prev parent reply other threads:[~2026-08-05 9:21 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-05 0:57 [PATCH 0/3] hwmon: (ltc4282) Fix issues reported by Sashiko Guenter Roeck
2026-08-05 0:57 ` [PATCH 1/3] hwmon: (ltc4282) Avoid overflow in maximum power calculation Guenter Roeck
2026-08-05 1:07 ` sashiko-bot
2026-08-05 0:57 ` [PATCH 2/3] hwmon: (ltc4282) Clamp negative current limits Guenter Roeck
2026-08-05 1:04 ` sashiko-bot
2026-08-05 9:22 ` Nuno Sá [this message]
2026-08-05 15:41 ` Guenter Roeck
2026-08-05 16:14 ` Nuno Sá
2026-08-05 17:19 ` Guenter Roeck
2026-08-05 0:57 ` [PATCH 3/3] hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt Guenter Roeck
2026-08-05 1:08 ` sashiko-bot
2026-08-05 9:26 ` [PATCH 0/3] hwmon: (ltc4282) Fix issues reported by Sashiko Nuno Sá
2026-08-05 14:28 ` Guenter Roeck
2026-08-05 16:15 ` Nuno Sá
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=anMAcWIbE7_wOjIv@nsa \
--to=noname.nuno@gmail.com \
--cc=linux-hwmon@vger.kernel.org \
--cc=linux@roeck-us.net \
--cc=nuno.sa@analog.com \
--cc=sashiko-bot@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox