Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [High] thermal: qcom: OOB write in init_8952() via under-sized #qcom,sensors DT property --
commit 6a35eb56487d35e206bcac22420641583d749610 Author: Muzaffer Kadir <[email protected]> One line subject: thermal: qcom: tsens: Add support for MSM8952 tsens This commit adds tsens support for MSM8952, introducing initialization and calibration offsets. > diff --git a/drivers/thermal/qcom/tsens-v1.c b/drivers/thermal/qcom/tsens-v1.c > index faa5d00788ca6..f4201748ea297 100644 > --- a/drivers/thermal/qcom/tsens-v1.c > +++ b/drivers/thermal/qcom/tsens-v1.c > @@ -145,6 +145,37 @@ static const struct reg_field > tsens_v1_regfields[MAX_REGFIELDS] = { > [TRDY] = REG_FIELD(TM_TRDY_OFF, 0, 0), > }; > > +static int __init init_8952(struct tsens_priv *priv) > +{ > + for (int i = 0; i < priv->num_sensors; ++i) > + priv->sensor[i].slope = 3200; > + > + priv->sensor[0].p1_calib_offset = 2; > + priv->sensor[0].p2_calib_offset = -1; > + priv->sensor[1].p1_calib_offset = -4; [Severity: High] In tsens_probe(), priv->sensor is dynamically allocated based on num_sensors, which can be overridden by the #qcom,sensors device tree property: priv = devm_kzalloc(dev, struct_size(priv, sensor, num_sensors), GFP_KERNEL); If the device tree property limits num_sensors to a smaller value (for example, 2), would these hardcoded assignments overwrite memory beyond the allocated array bounds? [ ... ] > + priv->sensor[10].p1_calib_offset = -3; > + priv->sensor[10].p2_calib_offset = -2; > + > + return init_common(priv); > +} -- Sashiko AI review ยท https://sashiko.dev/#/patchset/20260916-msm8952-initial-support-v2-0-798c2602d...@mainlining.org?part=16
