mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Miquel Raynal <miquel.raynal@bootlin.com>
To: Jacky Huang <ychuang3@nuvoton.com>,
	Shan-Chun Hung <schung@nuvoton.com>,
	 Stephen Boyd <sboyd@kernel.org>,
	Brian Masney <bmasney+clk@redhat.com>,
	 Jerome Brunet <jbrunet+clk@baylibre.com>,
	Rob Herring <robh@kernel.org>,
	 Krzysztof Kozlowski <krzk+dt@kernel.org>,
	 Conor Dooley <conor+dt@kernel.org>,
	Chi-Fang Li <cfli0@nuvoton.com>,  Arnd Bergmann <arnd@arndb.de>,
	Andrew Jeffery <andrew@codeconstruct.com.au>,
	 Avi Fishman <avifishman70@gmail.com>,
	Tomer Maimon <tmaimon77@gmail.com>,
	 Tali Perry <tali.perry1@gmail.com>,
	Patrick Venture <venture@google.com>,
	 Nancy Yuen <yuenn@google.com>,
	Benjamin Fair <benjaminfair@google.com>
Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com>,
	 Steam Lin <STLin2@winbond.com>,
	linux-arm-kernel@lists.infradead.org,  linux-clk@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	 Krzysztof Kozlowski <krzk@kernel.org>,
	devicetree@vger.kernel.org,  openbmc@lists.ozlabs.org,
	Miquel Raynal <miquel.raynal@bootlin.com>
Subject: [PATCH v5 7/9] clk: nuvoton: ma35d1: Avoid possible error pointer dereferencing
Date: Tue, 29 Sep 2026 16:44:50 +0200	[thread overview]
Message-ID: <20260929-perso-ma35d1-upstream-clk-v5-7-68533e935ee4@bootlin.com> (raw)
In-Reply-To: <20260929-perso-ma35d1-upstream-clk-v5-0-68533e935ee4@bootlin.com>

MA35D1 registration helpers store their parent_hw
argument straight into the parent data, without checking it first. In
case of registration failure an error pointer will be stored in the
table, which is then forwarded to the clk core, which treats any
non-NULL parent as valid handles.

Bail out early when the parent is an error pointer, instead of building
the parent data.

This issue is mostly theoretical in practice, since reaching such an
error would involve a very early -ENOMEM.

Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
---
 drivers/clk/nuvoton/clk-ma35d1-divider.c |  3 +++
 drivers/clk/nuvoton/clk-ma35d1-pll.c     |  3 +++
 drivers/clk/nuvoton/clk-ma35d1.c         | 13 +++++++++++--
 3 files changed, 17 insertions(+), 2 deletions(-)

diff --git a/drivers/clk/nuvoton/clk-ma35d1-divider.c b/drivers/clk/nuvoton/clk-ma35d1-divider.c
index e992e7c30341..57a7b4ed3b5e 100644
--- a/drivers/clk/nuvoton/clk-ma35d1-divider.c
+++ b/drivers/clk/nuvoton/clk-ma35d1-divider.c
@@ -90,6 +90,9 @@ struct clk_hw *ma35d1_reg_adc_clkdiv(struct device *dev, const char *name,
 	int ret;
 	int i;
 
+	if (IS_ERR(parent_hw))
+		return parent_hw;
+
 	div = devm_kzalloc(dev, sizeof(*div), GFP_KERNEL);
 	if (!div)
 		return ERR_PTR(-ENOMEM);
diff --git a/drivers/clk/nuvoton/clk-ma35d1-pll.c b/drivers/clk/nuvoton/clk-ma35d1-pll.c
index c7c0dc91a012..92424e9c669d 100644
--- a/drivers/clk/nuvoton/clk-ma35d1-pll.c
+++ b/drivers/clk/nuvoton/clk-ma35d1-pll.c
@@ -336,6 +336,9 @@ struct clk_hw *ma35d1_reg_clk_pll(struct device *dev, u32 id, u8 u8mode, const c
 	struct clk_hw *hw;
 	int ret;
 
+	if (IS_ERR(parent_hw))
+		return parent_hw;
+
 	pll = devm_kzalloc(dev, sizeof(*pll), GFP_KERNEL);
 	if (!pll)
 		return ERR_PTR(-ENOMEM);
diff --git a/drivers/clk/nuvoton/clk-ma35d1.c b/drivers/clk/nuvoton/clk-ma35d1.c
index 1a857f28310f..ceebcbd8c18b 100644
--- a/drivers/clk/nuvoton/clk-ma35d1.c
+++ b/drivers/clk/nuvoton/clk-ma35d1.c
@@ -130,10 +130,19 @@ static struct clk_hw *ma35d1_clk_mux(struct device *dev, const char *name,
 				     const int *parent_idx, int num_parents)
 {
 	const struct clk_hw *parent_hws[MA35D1_MUX_MAX_PARENTS] = {};
+	struct clk_hw *parent;
 	int i;
 
-	for (i = 0; i < num_parents; i++)
-		parent_hws[i] = (parent_idx[i] >= 0) ? hws[parent_idx[i]] : NULL;
+	for (i = 0; i < num_parents; i++) {
+		if (parent_idx[i] < 0)
+			continue;
+
+		parent = hws[parent_idx[i]];
+		if (IS_ERR(parent))
+			return parent;
+
+		parent_hws[i] = parent;
+	}
 
 	return clk_hw_register_mux_hws(dev, name, parent_hws, num_parents,
 				       CLK_SET_RATE_NO_REPARENT, reg, shift,

-- 
2.55.0


  parent reply	other threads:[~2026-09-29 14:45 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29 14:44 [PATCH v5 0/9] clk: nuvoton: ma35d1: Fix mux parenting and peripheral clock rates Miquel Raynal
2026-09-29 14:44 ` [PATCH v5 1/9] clk: nuvoton: ma35d1: Keep the clock count in the driver Miquel Raynal
2026-09-29 14:44 ` [PATCH v5 2/9] dt-bindings: clock: ma35d1: Document the missing crystal inputs Miquel Raynal
2026-09-30 11:55   ` Krzysztof Kozlowski
2026-09-29 14:44 ` [PATCH v5 3/9] dt-bindings: clock: ma35d1: Drop CLK_MAX_IDX define Miquel Raynal
2026-09-29 14:44 ` [PATCH v5 4/9] dt-bindings: clock: ma35d1: Add missing WDT/WWDT parent clocks Miquel Raynal
2026-09-29 14:44 ` [PATCH v5 5/9] clk: nuvoton: " Miquel Raynal
2026-09-29 14:44 ` [PATCH v5 6/9] clk: nuvoton: ma35d1: Use clk_hw pointers as mux parents Miquel Raynal
2026-09-29 14:44 ` Miquel Raynal [this message]
2026-09-29 14:44 ` [PATCH v5 8/9] clk: nuvoton: ma35d1: get HXT/LXT from DT Miquel Raynal
2026-09-29 14:44 ` [PATCH v5 9/9] arm64: dts: nuvoton: ma35d1: Add LXT crystal and correct HXT name Miquel Raynal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929-perso-ma35d1-upstream-clk-v5-7-68533e935ee4@bootlin.com \
    --to=miquel.raynal@bootlin.com \
    --cc=STLin2@winbond.com \
    --cc=andrew@codeconstruct.com.au \
    --cc=arnd@arndb.de \
    --cc=avifishman70@gmail.com \
    --cc=benjaminfair@google.com \
    --cc=bmasney+clk@redhat.com \
    --cc=cfli0@nuvoton.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=jbrunet+clk@baylibre.com \
    --cc=krzk+dt@kernel.org \
    --cc=krzk@kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-clk@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=openbmc@lists.ozlabs.org \
    --cc=robh@kernel.org \
    --cc=sboyd@kernel.org \
    --cc=schung@nuvoton.com \
    --cc=tali.perry1@gmail.com \
    --cc=thomas.petazzoni@bootlin.com \
    --cc=tmaimon77@gmail.com \
    --cc=venture@google.com \
    --cc=ychuang3@nuvoton.com \
    --cc=yuenn@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®