Linux Input/HID development
 help / color / mirror / Atom feed
* [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196
@ 2026-09-05 13:09 Breno Rodrigues Alves
  2026-09-05 13:09 ` [PATCH v9 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316 Breno Rodrigues Alves
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Breno Rodrigues Alves @ 2026-09-05 13:09 UTC (permalink / raw)
  To: gregkh
  Cc: torvalds, linux-kernel, arnd, linux-clk, linux-input, linux-media,
	linux-pci, linux-usb, linux-sound, linux-staging, linux-fbdev,
	linux-security-module, Breno Rodrigues Alves

Correct a copy-paste typo in the MediaTek interconnect Makefile that
mapped mt8196.o to CONFIG_INTERCONNECT_MTK_MT8195 instead of MT8196.

Assisted-by: OpenCode AI
Signed-off-by: Breno Rodrigues Alves <breno3011alves@gmail.com>
---
 drivers/interconnect/mediatek/Makefile | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/interconnect/mediatek/Makefile b/drivers/interconnect/mediatek/Makefile
index 6bd656668..64170ab16 100644
--- a/drivers/interconnect/mediatek/Makefile
+++ b/drivers/interconnect/mediatek/Makefile
@@ -3,4 +3,4 @@
 obj-$(CONFIG_INTERCONNECT_MTK_DVFSRC_EMI) += icc-emi.o
 obj-$(CONFIG_INTERCONNECT_MTK_MT8183) += mt8183.o
 obj-$(CONFIG_INTERCONNECT_MTK_MT8195) += mt8195.o
-obj-$(CONFIG_INTERCONNECT_MTK_MT8195) += mt8196.o
+obj-$(CONFIG_INTERCONNECT_MTK_MT8196) += mt8196.o
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* [PATCH v9 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316
  2026-09-05 13:09 [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196 Breno Rodrigues Alves
@ 2026-09-05 13:09 ` Breno Rodrigues Alves
  2026-09-05 13:11   ` sashiko-bot
  2026-09-05 13:09 ` [PATCH v9 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block Breno Rodrigues Alves
  2026-09-05 13:11 ` [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196 sashiko-bot
  2 siblings, 1 reply; 6+ messages in thread
From: Breno Rodrigues Alves @ 2026-09-05 13:09 UTC (permalink / raw)
  To: gregkh
  Cc: torvalds, linux-kernel, arnd, linux-clk, linux-input, linux-media,
	linux-pci, linux-usb, linux-sound, linux-staging, linux-fbdev,
	linux-security-module, Breno Rodrigues Alves

Fix a Makefile typo that incorrectly placed the mt6316-regulator object
under the old CONFIG_REGULATOR_MT6315 configuration flag.

Assisted-by: OpenCode AI
Signed-off-by: Breno Rodrigues Alves <breno3011alves@gmail.com>
---
 drivers/regulator/Makefile | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/regulator/Makefile b/drivers/regulator/Makefile
index 5a764cec8..f81d1f31a 100644
--- a/drivers/regulator/Makefile
+++ b/drivers/regulator/Makefile
@@ -107,7 +107,7 @@ obj-$(CONFIG_REGULATOR_MP886X) += mp886x.o
 obj-$(CONFIG_REGULATOR_MPQ7920) += mpq7920.o
 obj-$(CONFIG_REGULATOR_MT6311) += mt6311-regulator.o
 obj-$(CONFIG_REGULATOR_MT6315) += mt6315-regulator.o
-obj-$(CONFIG_REGULATOR_MT6315)  += mt6316-regulator.o
+obj-$(CONFIG_REGULATOR_MT6316)  += mt6316-regulator.o
 obj-$(CONFIG_REGULATOR_MT6323)	+= mt6323-regulator.o
 obj-$(CONFIG_REGULATOR_MT6331)	+= mt6331-regulator.o
 obj-$(CONFIG_REGULATOR_MT6332)	+= mt6332-regulator.o
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* [PATCH v9 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block
  2026-09-05 13:09 [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196 Breno Rodrigues Alves
  2026-09-05 13:09 ` [PATCH v9 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316 Breno Rodrigues Alves
@ 2026-09-05 13:09 ` Breno Rodrigues Alves
  2026-09-05 13:19   ` sashiko-bot
  2026-09-05 13:11 ` [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196 sashiko-bot
  2 siblings, 1 reply; 6+ messages in thread
From: Breno Rodrigues Alves @ 2026-09-05 13:09 UTC (permalink / raw)
  To: gregkh
  Cc: torvalds, linux-kernel, arnd, linux-clk, linux-input, linux-media,
	linux-pci, linux-usb, linux-sound, linux-staging, linux-fbdev,
	linux-security-module, Breno Rodrigues Alves

Completely purge the unmaintained DVB_ULE_DEBUG code block from
dvb_net.c and its Kconfig definition to eliminate severe lockless race
conditions and clean up unused function parameters.

Assisted-by: OpenCode AI
Signed-off-by: Breno Rodrigues Alves <breno3011alves@gmail.com>
---
 drivers/media/dvb-core/Kconfig   | 11 --------
 drivers/media/dvb-core/dvb_net.c | 46 --------------------------------
 2 files changed, 57 deletions(-)

diff --git a/drivers/media/dvb-core/Kconfig b/drivers/media/dvb-core/Kconfig
index 8b3f2d53c..c6a97add8 100644
--- a/drivers/media/dvb-core/Kconfig
+++ b/drivers/media/dvb-core/Kconfig
@@ -67,14 +67,3 @@ config DVB_DEMUX_SECTION_LOSS_LOG
 
 	  If you are unsure about this, say N here.
 
-config DVB_ULE_DEBUG
-	bool "Enable DVB net ULE packet debug messages"
-	depends on DVB_CORE
-	help
-	  Enable extra log messages meant to detect problems while
-	  handling DVB network ULE packet loss inside the Kernel.
-
-	  Should not be enabled on normal cases, as logs can
-	  be very verbose.
-
-	  If you are unsure about this, say N here.
diff --git a/drivers/media/dvb-core/dvb_net.c b/drivers/media/dvb-core/dvb_net.c
index a2159b2bc..29f99dfe2 100644
--- a/drivers/media/dvb-core/dvb_net.c
+++ b/drivers/media/dvb-core/dvb_net.c
@@ -68,19 +68,6 @@ static inline __u32 iov_crc32( __u32 c, struct kvec *iov, unsigned int cnt )
 
 #define DVB_NET_MULTICAST_MAX 10
 
-#ifdef DVB_ULE_DEBUG
-/*
- * The code inside DVB_ULE_DEBUG keeps a history of the
- * last 100 TS cells processed.
- */
-static unsigned char ule_hist[100*TS_SZ] = { 0 };
-static unsigned char *ule_where = ule_hist, ule_dump;
-
-static void hexdump(const unsigned char *buf, unsigned short len)
-{
-	print_hex_dump_debug("", DUMP_PREFIX_OFFSET, 16, 1, buf, len, true);
-}
-#endif
 
 struct dvb_net_priv {
 	int in_use;
@@ -320,16 +307,6 @@ static int dvb_net_ule_new_ts_cell(struct dvb_net_ule_handle *h)
 {
 	/* We are about to process a new TS cell. */
 
-#ifdef DVB_ULE_DEBUG
-	if (ule_where >= &ule_hist[100*TS_SZ])
-		ule_where = ule_hist;
-	memcpy(ule_where, h->ts, TS_SZ);
-	if (ule_dump) {
-		hexdump(ule_where, TS_SZ);
-		ule_dump = 0;
-	}
-	ule_where += TS_SZ;
-#endif
 
 	/*
 	 * Check TS h->error conditions: sync_byte, transport_error_indicator,
@@ -659,23 +636,6 @@ static void dvb_net_ule_check_crc(struct dvb_net_ule_handle *h,
 			h->ts_remain > 2 ?
 				*(unsigned short *)h->from_where : 0);
 
-	#ifdef DVB_ULE_DEBUG
-		hexdump(iov[0].iov_base, iov[0].iov_len);
-		hexdump(iov[1].iov_base, iov[1].iov_len);
-		hexdump(iov[2].iov_base, iov[2].iov_len);
-
-		if (ule_where == ule_hist) {
-			hexdump(&ule_hist[98*TS_SZ], TS_SZ);
-			hexdump(&ule_hist[99*TS_SZ], TS_SZ);
-		} else if (ule_where == &ule_hist[TS_SZ]) {
-			hexdump(&ule_hist[99*TS_SZ], TS_SZ);
-			hexdump(ule_hist, TS_SZ);
-		} else {
-			hexdump(ule_where - TS_SZ - TS_SZ, TS_SZ);
-			hexdump(ule_where - TS_SZ, TS_SZ);
-		}
-		ule_dump = 1;
-	#endif
 
 		h->dev->stats.rx_errors++;
 		h->dev->stats.rx_crc_errors++;
@@ -823,12 +783,6 @@ static void dvb_net_ule(struct net_device *dev, const u8 *buf, size_t buf_len)
 			__be16 ulen = htons(h.priv->ule_sndu_len);
 			__be16 utype = htons(h.priv->ule_sndu_type);
 			const u8 *tail;
-			struct kvec iov[3] = {
-				{ &ulen, sizeof ulen },
-				{ &utype, sizeof utype },
-				{ h.priv->ule_skb->data,
-				  h.priv->ule_skb->len - 4 }
-			};
 			u32 ule_crc = ~0L, expected_crc;
 			if (h.priv->ule_dbit) {
 				/* Set D-bit for CRC32 verification,
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [PATCH v9 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316
  2026-09-05 13:09 ` [PATCH v9 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316 Breno Rodrigues Alves
@ 2026-09-05 13:11   ` sashiko-bot
  0 siblings, 0 replies; 6+ messages in thread
From: sashiko-bot @ 2026-09-05 13:11 UTC (permalink / raw)
  To: Breno Rodrigues Alves
  Cc: linux-pci, dmitry.torokhov, linux-clk, media-ci, linux-input

> Fix a Makefile typo that incorrectly placed the mt6316-regulator object
> under the old CONFIG_REGULATOR_MT6315 configuration flag.
> 
> Assisted-by: OpenCode AI
> Signed-off-by: Breno Rodrigues Alves <breno3011alves@gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260905130925.7115-1-breno3011alves@gmail.com?part=2


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196
  2026-09-05 13:09 [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196 Breno Rodrigues Alves
  2026-09-05 13:09 ` [PATCH v9 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316 Breno Rodrigues Alves
  2026-09-05 13:09 ` [PATCH v9 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block Breno Rodrigues Alves
@ 2026-09-05 13:11 ` sashiko-bot
  2 siblings, 0 replies; 6+ messages in thread
From: sashiko-bot @ 2026-09-05 13:11 UTC (permalink / raw)
  To: Breno Rodrigues Alves
  Cc: linux-pci, dmitry.torokhov, media-ci, linux-clk, linux-input

> Correct a copy-paste typo in the MediaTek interconnect Makefile that
> mapped mt8196.o to CONFIG_INTERCONNECT_MTK_MT8195 instead of MT8196.
> 
> Assisted-by: OpenCode AI
> Signed-off-by: Breno Rodrigues Alves <breno3011alves@gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260905130925.7115-1-breno3011alves@gmail.com?part=1


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH v9 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block
  2026-09-05 13:09 ` [PATCH v9 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block Breno Rodrigues Alves
@ 2026-09-05 13:19   ` sashiko-bot
  0 siblings, 0 replies; 6+ messages in thread
From: sashiko-bot @ 2026-09-05 13:19 UTC (permalink / raw)
  To: Breno Rodrigues Alves
  Cc: linux-clk, media-ci, linux-pci, linux-input, dmitry.torokhov

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:

New issues:
- [Low] Removal of the `iov` array declaration breaks compilation because it is still required for CRC32 computation.
- [Low] The `iov` parameter in `dvb_net_ule_check_crc()` is left entirely unused, contradicting the commit message claim.

Pre-existing issues:
- [High] Missing length checks in ULE extension header parsing allows an arbitrary out-of-bounds heap memory read.
--

commit 8bbfcd7d5129e4e8e1d24fd8e69989a6dcdf34d2
Author: Breno Rodrigues Alves <breno3011alves@gmail.com>

media: dvb-core: extirpate defective and unsafe ULE debug block

Completely purge the unmaintained DVB_ULE_DEBUG code block from
dvb_net.c and its Kconfig definition to eliminate severe lockless race
conditions and clean up unused function parameters.

> diff --git a/drivers/media/dvb-core/dvb_net.c b/drivers/media/dvb-core/dvb_net.c
> index a2159b2bc1766..29f99dfe282a3 100644
> --- a/drivers/media/dvb-core/dvb_net.c
> +++ b/drivers/media/dvb-core/dvb_net.c
[ ... ]
> @@ -659,23 +636,6 @@ static void dvb_net_ule_check_crc(struct dvb_net_ule_handle *h,
>  			h->ts_remain > 2 ?
>  				*(unsigned short *)h->from_where : 0);
>  
> -	#ifdef DVB_ULE_DEBUG
> -		hexdump(iov[0].iov_base, iov[0].iov_len);
> -		hexdump(iov[1].iov_base, iov[1].iov_len);
> -		hexdump(iov[2].iov_base, iov[2].iov_len);
> -
> -		if (ule_where == ule_hist) {
> -			hexdump(&ule_hist[98*TS_SZ], TS_SZ);
> -			hexdump(&ule_hist[99*TS_SZ], TS_SZ);
> -		} else if (ule_where == &ule_hist[TS_SZ]) {
> -			hexdump(&ule_hist[99*TS_SZ], TS_SZ);
> -			hexdump(ule_hist, TS_SZ);
> -		} else {
> -			hexdump(ule_where - TS_SZ - TS_SZ, TS_SZ);
> -			hexdump(ule_where - TS_SZ, TS_SZ);
> -		}
> -		ule_dump = 1;
> -	#endif
>  
>  		h->dev->stats.rx_errors++;
>  		h->dev->stats.rx_crc_errors++;

[Severity: Low]
Does the iov parameter in dvb_net_ule_check_crc() need to be kept in the
function signature?

The commit message mentions cleaning up unused function parameters, but
iov remains in the signature while being entirely unused inside the function
now that the debug code is removed.

[ ... ]

> @@ -823,12 +783,6 @@ static void dvb_net_ule(struct net_device *dev, const u8 *buf, size_t buf_len)
>  			__be16 ulen = htons(h.priv->ule_sndu_len);
>  			__be16 utype = htons(h.priv->ule_sndu_type);
>  			const u8 *tail;
> -			struct kvec iov[3] = {
> -				{ &ulen, sizeof ulen },
> -				{ &utype, sizeof utype },
> -				{ h.priv->ule_skb->data,
> -				  h.priv->ule_skb->len - 4 }
> -			};
>  			u32 ule_crc = ~0L, expected_crc;
>  			if (h.priv->ule_dbit) {
>  				/* Set D-bit for CRC32 verification,

[Severity: Low]
Does the removal of the iov array break compilation?

Looking further down in dvb_net_ule(), iov is still passed to both
iov_crc32() and dvb_net_ule_check_crc():

			ule_crc = iov_crc32(ule_crc, iov, 3);
			...
			dvb_net_ule_check_crc(&h, iov, ule_crc, expected_crc);

Removing the declaration causes a compile error.

[Severity: High]
This is a pre-existing issue, but can the ULE extension header parsing enter
an infinite out-of-bounds read?

When handle_ule_extensions() iteratively calls handle_one_ule_extension()
on incoming packets:

drivers/media/dvb-core/dvb_net.c:handle_ule_extensions() {
	...
	do {
		l = handle_one_ule_extension( p );
		if (l < 0)
			return l;
		...
	} while (p->ule_sndu_type < ETH_P_802_3_MIN);
	...
}

Inside handle_one_ule_extension(), p->ule_next_hdr is advanced without
verifying if the pointer exceeds the bounds of the skb->data payload:

drivers/media/dvb-core/dvb_net.c:handle_one_ule_extension() {
	...
	} else {
		/* Optional extension header.  Calculate the length. */
		ext_len = hlen << 1;
		...
		p->ule_next_hdr += ext_len;
		p->ule_sndu_type = ntohs( *(__be16 *)(p->ule_next_hdr-2) );
	...
}

Could a malicious DVB stream payload with untrusted lengths force the kernel
to continuously read past the skb->data payload until a non-extension header
type is found or a panic occurs?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260905130925.7115-1-breno3011alves@gmail.com?part=3

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-05 13:20 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-05 13:09 [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196 Breno Rodrigues Alves
2026-09-05 13:09 ` [PATCH v9 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316 Breno Rodrigues Alves
2026-09-05 13:11   ` sashiko-bot
2026-09-05 13:09 ` [PATCH v9 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block Breno Rodrigues Alves
2026-09-05 13:19   ` sashiko-bot
2026-09-05 13:11 ` [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196 sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox