From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f171.google.com (mail-pl1-f171.google.com [209.85.214.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2EE4F1E7C02 for ; Sat, 22 Aug 2026 11:43:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787399012; cv=none; b=bXvv9QpfO4/9psObZtW0yewjZe9ftWJAFqeijatyMoUMLpC6Omvvq0o6riTEBd32Qknupmrg5/hNETsfWnkMLDKjoU/rGubuTlJfo5p4ZIrz/5RMGo+xzzgB0DYC7W05Q4bvOi2fE5JlsG8U21diG0mReVGU/8vZdf1RaujB4bo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787399012; c=relaxed/simple; bh=CN9bI5JSc4R97kTthHOYaRIf79ONlFCVPEmvKFOn3m4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=OdWiMUoh2lFbipZ8YMqQApqjk8xLuLBYlt3SrLIxqf2/jEz/IxrAhB0zH/YwP+BusIA87dcgN57nvRRb2S5P/5MWgdup1mwncuO6HKSZum4WHkwGI/qtGwins1L8WpbRprItm89U11KXLsRxg1VHl/aKTVJetcDUXCJFMd1/X7U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=E9UvHy6p; arc=none smtp.client-ip=209.85.214.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="E9UvHy6p" Received: by mail-pl1-f171.google.com with SMTP id d9443c01a7336-2cca0c5799eso16949325ad.0 for ; Sat, 22 Aug 2026 04:43:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787399010; x=1788003810; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=t2malKHbWrEiaEypSgDR5cpQ350oJBSIdozLYtaZr0U=; b=E9UvHy6pTEg9aSuc+Or0H2dYeVyWRKeUz4NLVouAJdgyYxGsBnpWpLR30lnKJaqNe5 v43U/C/mEgsJEk9Wm7DgP5JO/9h7a3+by2YTlvLhUH806TmLLUOgdN1cjlivS1Z0abDZ gMxDC3+MwIuYhVnt4tawgYKJJb95yy5wu/42jM6ZWYndKRfA74fMMrs2aXKO9o6J7JbX L6pNmy8QH/64dHAzT4LWrYQfjMMH6EPaX0NObuC55wacKuO0jMlBUyZCLmN7wX1Bmiie 62bt9N8GSWVb2PzFuFTtpJbv7GwmC5WhrnISk4Q9gnsDQGj8rFonkUJtL07CsFwiE5HI a0+g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787399010; x=1788003810; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=t2malKHbWrEiaEypSgDR5cpQ350oJBSIdozLYtaZr0U=; b=WrJvo0a+STx5jc8K8zccUDjyQdQZL4A7W/tSA9lCMgli8YPQsOPKVV7mZeX5l88+NW nXJ/V816f7xvGSb8QUy3uT1Mvqw6qFytRGBuitOIQv/fNuRa0xj7pSRumHR8FbwNbwFt zn1GldZpTHb5C86bopZYhCbsm1paa/ctXv6CmnjIGRHJecIUzjenxKDtkvCQ4S9CCmCC F4y5vb06Q0evVbl0AsWNGriuP74uIGjkU/moc7HaIGA3MkxvrXc3Ss5eqNrO8+d2iqI3 hGTeUr6hxBAoUYuyiBfy7HrfznIHyI3O1PhVSv3nBAA91tWxPILumEKk/nag1++NeBnd 2ADg== X-Gm-Message-State: AFuF++nLSYAtiKRJRWSM7IuJeAYswqoAeSSY9Q2fvnNbfVhQxQSffRM3 Q7qEqSycdk8H/CcF0f/IXpkC76Ukfg3T3tuTl8Mpy8uuco0+OkoSqwpU X-Gm-Gg: AR+sD11Z4tzEfGZevMnn0kgEv49mNr/BsSoOgSppaBTjO48Hk/PlsLYYUUZxyv3BiRu rZoX5PRZhF0swDpgP9Q9+lhpbp4/EVWeV1eHUeMRoyvjRvfP5s3lbQTM+h7TJPILE7L0hCqJt0f FkkpDuqoapnT9oa+oGerYOvo8fVKknoMQqMBSE9+nN1XYAm8rQ1gWZByQlx5EH/EuRH95Mz8LiB 2+qw32RRZc7fShr2FzZBAm1DgYcGEakC3YmUYtc5MmOUm/8q9YCUv5UlpOAKbiLLrqdDq9VPOle spp9Hg1k0wZ5K/4JCISAjqoqhIZhxMmgINGU++oMAqG1zqd75kUv8ArpZkaqH0gbch9lsm4c1aC uArtKE/JDv/Jg2zTPkoCB19BJ4Vus/Q2oIXxHNrKHfO8N4/VIg8YID4fEcbi/ep12yD684BzP88 U5yVrpjb08JU/kN/IlSeO59tjXqdqiuggBWX9VbOSnu2VJiy9V5wMunZAmqzM= X-Received: by 2002:a17:903:1206:b0:2ca:1b97:70c5 with SMTP id d9443c01a7336-2d64adaff50mr208053965ad.4.1787399010397; Sat, 22 Aug 2026 04:43:30 -0700 (PDT) Received: from gmail.com ([58.84.62.206]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327f923f2c0sm9387324eec.30.2026.08.22.04.43.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 22 Aug 2026 04:43:29 -0700 (PDT) From: Sumeet Pawnikar To: lukasz.luba@arm.com, rafael@kernel.org, daniel.lezcano@kernel.org, rui.zhang@intel.com, linux-pm@vger.kernel.org Cc: linux-kernel@vger.kernel.org, sumeet4linux@gmail.com Subject: [PATCH] thermal: gov_power_allocator: Fix NULL pointer dereference in update_tz() Date: Sat, 22 Aug 2026 17:12:36 +0530 Message-ID: <20260822114236.15998-1-sumeet4linux@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit power_allocator_update_tz() unconditionally derives the trip descriptor of params->trip_max as below, const struct thermal_trip_desc *td = trip_to_trip_desc(params->trip_max); and then walks td->thermal_instances. However, params->trip_max is allowed to be NULL and in that case the list walk dereferences a bogus pointer derived from NULL which oops the kernel. get_governor_trips() picks trip_switch_on and trip_max out of the trip table of the zone. When the zone has neither a passive nor an active trip point, last_active is NULL and params->trip_max is left NULL. This is an explicitly supported configuration, as documented in the function get_governor_trips() as below, If there are no passive or active trip points, then the governor won't do anything. In fact, its throttle function won't be called at all. Return early from power_allocator_update_tz() when params->trip_max is NULL and only compute the trip descriptor after that check. There is nothing to update in that case anyway, with no trip_max and there are no thermal instances for the governor to account for, num_actors stays zero and total_weight is irrelevant. Fixes: 912e97c67cc3 ("thermal: gov_power_allocator: Move memory allocation out of throttle()") Signed-off-by: Sumeet Pawnikar --- drivers/thermal/gov_power_allocator.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/drivers/thermal/gov_power_allocator.c b/drivers/thermal/gov_power_allocator.c index 37f2e22a999e..b5c254187628 100644 --- a/drivers/thermal/gov_power_allocator.c +++ b/drivers/thermal/gov_power_allocator.c @@ -660,10 +660,15 @@ static void power_allocator_update_tz(struct thermal_zone_device *tz, enum thermal_notify_event reason) { struct power_allocator_params *params = tz->governor_data; - const struct thermal_trip_desc *td = trip_to_trip_desc(params->trip_max); + const struct thermal_trip_desc *td; struct thermal_instance *instance; int num_actors = 0; + if (!params->trip_max) + return; + + td = trip_to_trip_desc(params->trip_max); + switch (reason) { case THERMAL_TZ_BIND_CDEV: case THERMAL_TZ_UNBIND_CDEV: -- 2.43.0