linux-rtc.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Antoni Pokusinski" <apokusinski01@gmail.com>
Cc: "Alexandre Belloni" <alexandre.belloni@bootlin.com>,
	robh@kernel.org, linux-rtc@vger.kernel.org, conor+dt@kernel.org,
	devicetree@vger.kernel.org
Subject: Re: [PATCH v5 2/9] rtc: abx80x: fix error check after i2c_smbus_read in read_alarm()
Date: Tue, 11 Aug 2026 19:55:19 +0000	[thread overview]
Message-ID: <20260811195520.3EFDD1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260811194034.28937-3-apokusinski01@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

New issues:
- [Medium] Uninitialized Stack Memory Use on short I2C reads

Pre-existing issues:
- [Medium] Incomplete Bug Fix / Unintended Return Value breaking hardware alarm initialization
--

--- Patch [2]: [PATCH v5 2/9] rtc: abx80x: fix error check after i2c_smbus_read in read_alarm() ---
commit 111542521cef97450110e2dc7483bce8d88f644f
Author: Antoni Pokusinski <apokusinski01@gmail.com>

    rtc: abx80x: fix error check after i2c_smbus_read in read_alarm()
    
    The patch relaxes the error check for i2c_smbus_read_i2c_block_data()
    in abx80x_read_alarm(). It now only returns on negative errors, allowing
    the function to proceed if the read is successful and returns the number
    of bytes read.

> diff --git a/drivers/rtc/rtc-abx80x.c b/drivers/rtc/rtc-abx80x.c
> index 5486d9d0b1e5d..fdf9664ebb6f0 100644
> --- a/drivers/rtc/rtc-abx80x.c
> +++ b/drivers/rtc/rtc-abx80x.c
> @@ -294,7 +294,7 @@ static int abx80x_read_alarm(struct device *dev, struct rtc_wkalrm *t)
>  
>  	err = i2c_smbus_read_i2c_block_data(client, ABX8XX_REG_ASC,
>  					    sizeof(buf), buf);
> -	if (err)
> +	if (err < 0)

[Severity: Medium]
Since the error check now only stops on negative values, could a short
read cause issues here?

If the adapter returns fewer bytes than sizeof(buf) (e.g. 1 to 6 bytes), err
will be positive but less than 7. The function will proceed to parse the
buffer, but since the stack allocated buf is uninitialized, wouldn't it end
up reading uninitialized stack memory later when checking buf[6]?

drivers/rtc/rtc-abx80x.c:abx80x_read_alarm() {
    ...
    t->pending = (buf[6] & ABX8XX_STATUS_AF) && t->enabled;
    ...
}

>  		return err;
>  
>  	irq_mask = i2c_smbus_read_byte_data(client, ABX8XX_REG_IRQ);

[Severity: Medium]
This is a pre-existing issue, but does returning err at the end of this
function cause problems with alarm initialization?

Since err holds the positive byte count on success, abx80x_read_alarm()
returns 7 instead of 0:

drivers/rtc/rtc-abx80x.c:abx80x_read_alarm() {
    ...
    err = i2c_smbus_read_i2c_block_data(...);
    ...
    return err;
}

Looking at how the rtc core handles this, __rtc_read_alarm() treats any
non-zero return as an error. Would this cause __devm_rtc_register_device()
to skip calling rtc_initialize_alarm() at boot?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260811194034.28937-1-apokusinski01@gmail.com?part=2

  reply	other threads:[~2026-08-11 19:55 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-11 19:40 [PATCH v5 0/9] rtc: abx80x: add support for abx81x Antoni Pokusinski
2026-08-11 19:40 ` [PATCH v5 1/9] dt-bindings: rtc: abx80x: document ABX81X RTCs Antoni Pokusinski
2026-08-11 19:48   ` sashiko-bot
2026-08-11 19:40 ` [PATCH v5 2/9] rtc: abx80x: fix error check after i2c_smbus_read in read_alarm() Antoni Pokusinski
2026-08-11 19:55   ` sashiko-bot [this message]
2026-08-11 19:40 ` [PATCH v5 3/9] rtc: abx80x: add mutex protection for register writes Antoni Pokusinski
2026-08-11 19:56   ` sashiko-bot
2026-08-11 19:40 ` [PATCH v5 4/9] rtc: abx80x: properly handle shared IRQs Antoni Pokusinski
2026-08-11 19:53   ` sashiko-bot
2026-08-11 19:40 ` [PATCH v5 5/9] rtc: abx80x: add irq to struct abx80x_priv Antoni Pokusinski
2026-08-11 19:51   ` sashiko-bot
2026-08-11 19:40 ` [PATCH v5 6/9] rtc: abx80x: use regmap instead of I2C specific API Antoni Pokusinski
2026-08-11 19:55   ` sashiko-bot
2026-08-11 19:40 ` [PATCH v5 7/9] rtc: abx80x: replace read-modify-write pattern with regmap helpers Antoni Pokusinski
2026-08-11 19:56   ` sashiko-bot
2026-08-11 19:40 ` [PATCH v5 8/9] rtc: abx80x: create abx80x_i2c_probe() Antoni Pokusinski
2026-08-11 19:54   ` sashiko-bot
2026-08-11 19:40 ` [PATCH v5 9/9] rtc: abx80x: add support for ABX81X Antoni Pokusinski
2026-08-11 20:03   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260811195520.3EFDD1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=alexandre.belloni@bootlin.com \
    --cc=apokusinski01@gmail.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-rtc@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).