Linux kernel staging patches
 help / color / mirror / Atom feed
* [PATCH] staging: sm750fb: do not program the PLL from an uninitialized value
@ 2026-08-17  9:13 Junrui Luo via B4 Relay
  2026-08-17  9:59 ` Dan Carpenter
  0 siblings, 1 reply; 5+ messages in thread
From: Junrui Luo via B4 Relay @ 2026-08-17  9:13 UTC (permalink / raw)
  To: Sudip Mukherjee, Teddy Wang, Greg Kroah-Hartman
  Cc: linux-fbdev, linux-staging, linux-kernel, Yuhao Jiang, stable,
	Junrui Luo

From: Junrui Luo <moonafterrain@outlook.com>

sm750_calc_pll_value() writes pll->M, N, OD and POD only when its search
loop finds a divider combination with 0 < M < 256, and returns 0 when
there is none. ddk750_set_mode_timing() discards that return value and
calls program_mode_registers() regardless, so sm750_format_pll_reg()
reads the four members uninitialized and pokes them into PANEL_PLL_CTRL
or CRT_PLL_CTRL. Nothing bounds var->pixclock on the way in, so a mode
set can ask for a clock the loop cannot represent.

Consume the return value and reject the mode; hw_sm750_crtc_set_mode()
already propagates a non-zero return. Initialize the structure as well:
sm750_calc_pll_value() returns early for SM750LE without writing the
members, and returns non-zero on that path.

Fixes: 81dee67e215b ("staging: sm750fb: add sm750 to staging")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Assisted-by: Claude:claude-opus-5
Cc: stable@vger.kernel.org
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
---
 drivers/staging/sm750fb/ddk750_mode.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/staging/sm750fb/ddk750_mode.c b/drivers/staging/sm750fb/ddk750_mode.c
index 7163232c0701..5ff5226fe77a 100644
--- a/drivers/staging/sm750fb/ddk750_mode.c
+++ b/drivers/staging/sm750fb/ddk750_mode.c
@@ -205,12 +205,14 @@ static void program_mode_registers(struct mode_parameter *mode_param,
 
 int ddk750_set_mode_timing(struct mode_parameter *parm, enum clock_type clock)
 {
-	struct pll_value pll;
+	struct pll_value pll = {};
 
 	pll.input_freq = DEFAULT_INPUT_CLOCK;
 	pll.clock_type = clock;
 
-	sm750_calc_pll_value(parm->pixel_clock, &pll);
+	if (!sm750_calc_pll_value(parm->pixel_clock, &pll))
+		return -EINVAL;
+
 	if (sm750_get_chip_type() == SM750LE) {
 		/* set graphic mode via IO method */
 		outb_p(0x88, 0x3d4);

---
base-commit: f5bbbfec59b4e2fb7520a91de3df8a6174325d6a
change-id: 20260817-sm750-fixes-466849daffec

Best regards,
-- 
Junrui Luo <moonafterrain@outlook.com>



^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-08-17 11:27 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-17  9:13 [PATCH] staging: sm750fb: do not program the PLL from an uninitialized value Junrui Luo via B4 Relay
2026-08-17  9:59 ` Dan Carpenter
2026-08-17 10:49   ` Yuhao Jiang
2026-08-17 11:13     ` Dan Carpenter
2026-08-17 11:27       ` Yuhao Jiang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox