* [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show()
@ 2026-09-16 16:16 Dmitry Antipov
2026-09-16 16:16 ` [PATCH v3 2/2] leds: flash: Simplify flash_fault_show() Dmitry Antipov
` (2 more replies)
0 siblings, 3 replies; 5+ messages in thread
From: Dmitry Antipov @ 2026-09-16 16:16 UTC (permalink / raw)
To: Lee Jones, Pavel Machek; +Cc: linux-leds, Dmitry Antipov, sashiko-bot
In flash_fault_show(), address of uninitialized 'fault' variable is
passed to device-specific .fault_get callbacks. This is not a problem
if such a callback directly assigns the value like rt4505_fault_get(),
but results in an undefined behavior if callback just performs bitwise
ORs like as3645a_get_fault(). So just initialize 'fault' with zero.
Reported-by: sashiko-bot@kernel.org
Closes: https://sashiko.dev/#/patchset/20260904054437.461706-1-dmantipov@yandex.ru?part=1
Fixes: 7aea8389a77ab ("leds: Add LED Flash class extension to the LED subsystem")
Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
---
v3: unchanged since v2
v2: initial version to join the series
---
drivers/leds/led-class-flash.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/leds/led-class-flash.c b/drivers/leds/led-class-flash.c
index 165035a8826c..3bb90823de1a 100644
--- a/drivers/leds/led-class-flash.c
+++ b/drivers/leds/led-class-flash.c
@@ -187,7 +187,7 @@ static ssize_t flash_fault_show(struct device *dev,
{
struct led_classdev *led_cdev = dev_get_drvdata(dev);
struct led_classdev_flash *fled_cdev = lcdev_to_flcdev(led_cdev);
- u32 fault, mask = 0x1;
+ u32 fault = 0, mask = 0x1;
char *pbuf = buf;
int i, ret, buf_len;
--
2.55.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH v3 2/2] leds: flash: Simplify flash_fault_show()
2026-09-16 16:16 [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show() Dmitry Antipov
@ 2026-09-16 16:16 ` Dmitry Antipov
2026-09-16 16:22 ` sashiko-bot
2026-09-16 16:25 ` [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show() sashiko-bot
2026-09-22 13:27 ` Lee Jones
2 siblings, 1 reply; 5+ messages in thread
From: Dmitry Antipov @ 2026-09-16 16:16 UTC (permalink / raw)
To: Lee Jones, Pavel Machek; +Cc: linux-leds, Dmitry Antipov
Do not emit extra trailing space and use sysfs_emit_at()
over sprintf()/strcat()/strlen() in flash_fault_show().
Suggested-by: Lee Jones <lee@kernel.org>
Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
---
v3: use sysfs_emit_at() as suggested by Lee
v2: capitalize commit title
---
drivers/leds/led-class-flash.c | 19 ++++++++-----------
1 file changed, 8 insertions(+), 11 deletions(-)
diff --git a/drivers/leds/led-class-flash.c b/drivers/leds/led-class-flash.c
index 3bb90823de1a..181dfd49c6ad 100644
--- a/drivers/leds/led-class-flash.c
+++ b/drivers/leds/led-class-flash.c
@@ -188,25 +188,22 @@ static ssize_t flash_fault_show(struct device *dev,
struct led_classdev *led_cdev = dev_get_drvdata(dev);
struct led_classdev_flash *fled_cdev = lcdev_to_flcdev(led_cdev);
u32 fault = 0, mask = 0x1;
- char *pbuf = buf;
- int i, ret, buf_len;
+ int i, ret;
ret = led_get_flash_fault(fled_cdev, &fault);
if (ret < 0)
return -EINVAL;
- *buf = '\0';
-
- for (i = 0; i < LED_NUM_FLASH_FAULTS; ++i) {
- if (fault & mask) {
- buf_len = sprintf(pbuf, "%s ",
- led_flash_fault_names[i]);
- pbuf += buf_len;
- }
+ for (ret = 0, i = 0; i < LED_NUM_FLASH_FAULTS; ++i) {
+ if (fault & mask)
+ ret += sysfs_emit_at(buf, ret, "%s%s",
+ (ret ? " " : ""),
+ led_flash_fault_names[i]);
mask <<= 1;
}
- return strlen(strcat(buf, "\n"));
+ ret += sysfs_emit_at(buf, ret, "\n");
+ return ret;
}
static DEVICE_ATTR_RO(flash_fault);
--
2.55.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH v3 2/2] leds: flash: Simplify flash_fault_show()
2026-09-16 16:16 ` [PATCH v3 2/2] leds: flash: Simplify flash_fault_show() Dmitry Antipov
@ 2026-09-16 16:22 ` sashiko-bot
0 siblings, 0 replies; 5+ messages in thread
From: sashiko-bot @ 2026-09-16 16:22 UTC (permalink / raw)
To: Dmitry Antipov; +Cc: linux-leds, lee
> Do not emit extra trailing space and use sysfs_emit_at()
> over sprintf()/strcat()/strlen() in flash_fault_show().
>
> Suggested-by: Lee Jones <lee@kernel.org>
> Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916161607.90106-1-dmantipov@yandex.ru?part=2
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show()
2026-09-16 16:16 [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show() Dmitry Antipov
2026-09-16 16:16 ` [PATCH v3 2/2] leds: flash: Simplify flash_fault_show() Dmitry Antipov
@ 2026-09-16 16:25 ` sashiko-bot
2026-09-22 13:27 ` Lee Jones
2 siblings, 0 replies; 5+ messages in thread
From: sashiko-bot @ 2026-09-16 16:25 UTC (permalink / raw)
To: Dmitry Antipov; +Cc: linux-leds, lee
> In flash_fault_show(), address of uninitialized 'fault' variable is
> passed to device-specific .fault_get callbacks. This is not a problem
> if such a callback directly assigns the value like rt4505_fault_get(),
> but results in an undefined behavior if callback just performs bitwise
> ORs like as3645a_get_fault(). So just initialize 'fault' with zero.
>
> Reported-by: sashiko-bot@kernel.org
> Closes: https://sashiko.dev/#/patchset/20260904054437.461706-1-dmantipov@yandex.ru?part=1
> Fixes: 7aea8389a77ab ("leds: Add LED Flash class extension to the LED subsystem")
> Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916161607.90106-1-dmantipov@yandex.ru?part=1
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show()
2026-09-16 16:16 [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show() Dmitry Antipov
2026-09-16 16:16 ` [PATCH v3 2/2] leds: flash: Simplify flash_fault_show() Dmitry Antipov
2026-09-16 16:25 ` [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show() sashiko-bot
@ 2026-09-22 13:27 ` Lee Jones
2 siblings, 0 replies; 5+ messages in thread
From: Lee Jones @ 2026-09-22 13:27 UTC (permalink / raw)
To: Lee Jones, Pavel Machek, Dmitry Antipov; +Cc: linux-leds, sashiko-bot
On Wed, 16 Sep 2026 19:16:06 +0300, Dmitry Antipov wrote:
> In flash_fault_show(), address of uninitialized 'fault' variable is
> passed to device-specific .fault_get callbacks. This is not a problem
> if such a callback directly assigns the value like rt4505_fault_get(),
> but results in an undefined behavior if callback just performs bitwise
> ORs like as3645a_get_fault(). So just initialize 'fault' with zero.
>
>
> [...]
Applied, thanks!
[1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show()
commit: d229695f2162a41bfa614f175798fa56a5f1c969
[2/2] leds: flash: Simplify flash_fault_show()
commit: b18158f705dcff53f76f37733dea5154f1b32444
--
Lee Jones [李琼斯]
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-22 13:27 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 16:16 [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show() Dmitry Antipov
2026-09-16 16:16 ` [PATCH v3 2/2] leds: flash: Simplify flash_fault_show() Dmitry Antipov
2026-09-16 16:22 ` sashiko-bot
2026-09-16 16:25 ` [PATCH v3 1/2] leds: flash: Prevent using uninitialized variable in flash_fault_show() sashiko-bot
2026-09-22 13:27 ` Lee Jones
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox