Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] thermal: qcom: OOB write in init_8952() via under-sized #qcom,sensors 
DT property
--

commit 6a35eb56487d35e206bcac22420641583d749610
Author: Muzaffer Kadir <[email protected]>
One line subject: thermal: qcom: tsens: Add support for MSM8952 tsens

This commit adds tsens support for MSM8952, introducing initialization
and calibration offsets.

> diff --git a/drivers/thermal/qcom/tsens-v1.c b/drivers/thermal/qcom/tsens-v1.c
> index faa5d00788ca6..f4201748ea297 100644
> --- a/drivers/thermal/qcom/tsens-v1.c
> +++ b/drivers/thermal/qcom/tsens-v1.c
> @@ -145,6 +145,37 @@ static const struct reg_field 
> tsens_v1_regfields[MAX_REGFIELDS] = {
>       [TRDY] = REG_FIELD(TM_TRDY_OFF, 0, 0),
>  };
>  
> +static int __init init_8952(struct tsens_priv *priv)
> +{
> +     for (int i = 0; i < priv->num_sensors; ++i)
> +             priv->sensor[i].slope = 3200;
> +
> +     priv->sensor[0].p1_calib_offset = 2;
> +     priv->sensor[0].p2_calib_offset = -1;
> +     priv->sensor[1].p1_calib_offset = -4;

[Severity: High]
In tsens_probe(), priv->sensor is dynamically allocated based on num_sensors,
which can be overridden by the #qcom,sensors device tree property:

        priv = devm_kzalloc(dev,
                             struct_size(priv, sensor, num_sensors),
                             GFP_KERNEL);

If the device tree property limits num_sensors to a smaller value (for
example, 2), would these hardcoded assignments overwrite memory beyond the
allocated array bounds?

[ ... ]

> +     priv->sensor[10].p1_calib_offset = -3;
> +     priv->sensor[10].p2_calib_offset = -2;
> +
> +     return init_common(priv);
> +}

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/20260916-msm8952-initial-support-v2-0-798c2602d...@mainlining.org?part=16

Reply via email to