* [PATCH] clk: airoha: fix off-by-one in clock ID boundary check
@ 2026-07-08 4:06 Wayen Yan
2026-07-18 0:07 ` Tom Rini
0 siblings, 1 reply; 2+ messages in thread
From: Wayen Yan @ 2026-07-08 4:06 UTC (permalink / raw)
To: Tom Rini; +Cc: u-boot, Christian Marangi, Mikhail Kshevetskiy, Lukasz Majewski
The boundary checks in airoha_clk_enable(), airoha_clk_get_rate(), and
airoha_clk_set_rate() use "id > data->num_clocks" which allows id equal
to num_clocks to pass. Since data->descs[] has exactly num_clocks entries
(indices 0 to num_clocks-1), id=num_clocks results in an out-of-bounds
array access.
This is currently not triggered because the device tree clock IDs are
within bounds, but the check should be defensive. Fix by changing the
comparison from ">" to ">=".
Fixes: d0b81afb5ec9 ("clk: airoha: Add support for Airoha AN7581 SoC clock")
Signed-off-by: Wayen Yan <win847@gmail.com>
---
drivers/clk/airoha/clk-airoha.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/clk/airoha/clk-airoha.c b/drivers/clk/airoha/clk-airoha.c
index 49dbca82135..89a8b4cb1cf 100644
--- a/drivers/clk/airoha/clk-airoha.c
+++ b/drivers/clk/airoha/clk-airoha.c
@@ -327,7 +327,7 @@ static int airoha_clk_enable(struct clk *clk)
struct airoha_clk_soc_data *data = priv->data;
int id = clk->id;
- if (id > data->num_clocks)
+ if (id >= data->num_clocks)
return -EINVAL;
return 0;
@@ -349,7 +349,7 @@ static ulong airoha_clk_get_rate(struct clk *clk)
ulong rate;
int ret;
- if (id > data->num_clocks) {
+ if (id >= data->num_clocks) {
dev_err(clk->dev, "Invalid clk ID %d\n", id);
return 0;
}
@@ -412,7 +412,7 @@ static ulong airoha_clk_set_rate(struct clk *clk, ulong rate)
int div;
int ret;
- if (id > data->num_clocks) {
+ if (id >= data->num_clocks) {
dev_err(clk->dev, "Invalid clk ID %d\n", id);
return 0;
}
--
2.51.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH] clk: airoha: fix off-by-one in clock ID boundary check
2026-07-08 4:06 [PATCH] clk: airoha: fix off-by-one in clock ID boundary check Wayen Yan
@ 2026-07-18 0:07 ` Tom Rini
0 siblings, 0 replies; 2+ messages in thread
From: Tom Rini @ 2026-07-18 0:07 UTC (permalink / raw)
To: Wayen Yan; +Cc: u-boot, Christian Marangi, Mikhail Kshevetskiy, Lukasz Majewski
On Wed, 08 Jul 2026 12:06:08 +0800, Wayen Yan wrote:
> The boundary checks in airoha_clk_enable(), airoha_clk_get_rate(), and
> airoha_clk_set_rate() use "id > data->num_clocks" which allows id equal
> to num_clocks to pass. Since data->descs[] has exactly num_clocks entries
> (indices 0 to num_clocks-1), id=num_clocks results in an out-of-bounds
> array access.
>
> This is currently not triggered because the device tree clock IDs are
> within bounds, but the check should be defensive. Fix by changing the
> comparison from ">" to ">=".
>
> [...]
Applied to u-boot/main, thanks!
[1/1] clk: airoha: fix off-by-one in clock ID boundary check
commit: fdfe2ec48d5c1c2ed03073d73edd3fdd3fe1ffa1
--
Tom
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-07-18 0:08 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-08 4:06 [PATCH] clk: airoha: fix off-by-one in clock ID boundary check Wayen Yan
2026-07-18 0:07 ` Tom Rini
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox