Here's the latest report

---------- Forwarded message ---------
From: <[email protected]>
Date: Mon, Aug 10, 2026 at 5:06 PM
Subject: New Defects reported by Coverity Scan for Das U-Boot
To: <[email protected]>


Hi,

Please find the latest report on new defect(s) introduced to *Das U-Boot*
found with Coverity Scan.

   - *New Defects Found:* 5
   - 1 defect(s), reported by Coverity Scan earlier, were marked fixed in
   the recent build analyzed by Coverity Scan.
   - *Defects Shown:* Showing 5 of 5 defect(s)

Defect Details

** CID 652911:       Resource leaks  (RESOURCE_LEAK)
/drivers/pinctrl/pinctrl-single.c: 579           in single_add_gpio_func()


_____________________________________________________________________________________________
*** CID 652911:         Resource leaks  (RESOURCE_LEAK)
/drivers/pinctrl/pinctrl-single.c: 579             in single_add_gpio_func()
573                             break;
574
575                     list_add_tail(&range->node, &priv->gpiofuncs);
576                     range++;
577             }
578
>>>     CID 652911:         Resource leaks  (RESOURCE_LEAK)
>>>     Variable "range" going out of scope leaks the storage it points to.
579             return 0;
580     }
581
582     static int single_probe(struct udevice *dev)
583     {
584             struct single_pdata *pdata = dev_get_plat(dev);

** CID 652910:       Memory - illegal accesses  (UNINIT)


_____________________________________________________________________________________________
*** CID 652910:         Memory - illegal accesses  (UNINIT)
/lib/libavb/avb_cmdline.c: 342             in avb_append_options()
336             break;
337           case AVB_HASHTREE_ERROR_MODE_PANIC:
338             verity_mode = "panicking";
339             dm_verity_mode = "panic_on_corruption";
340             break;
341         }
>>>     CID 652910:         Memory - illegal accesses  (UNINIT)
>>>     Using uninitialized value "dm_verity_mode" when calling "avb_replace".
342         new_ret = avb_replace(
343             slot_data->cmdline, "$(ANDROID_VERITY_MODE)", dm_verity_mode);
344         avb_free(slot_data->cmdline);
345         slot_data->cmdline = new_ret;
346         if (slot_data->cmdline == NULL) {
347           ret = AVB_SLOT_VERIFY_RESULT_ERROR_OOM;

** CID 652909:       Control flow issues  (DEADCODE)
/boot/bootretry.c: 32           in bootretry_parse()


_____________________________________________________________________________________________
*** CID 652909:         Control flow issues  (DEADCODE)
/boot/bootretry.c: 32             in bootretry_parse()
26      if (s != NULL)
27              retry_time = (int)simple_strtol(s, NULL, 10);
28      else
29              retry_time = CONFIG_BOOT_RETRY_TIME;
30
31      if (retry_time >= 0 && retry_time < CONFIG_BOOT_RETRY_MIN)
>>>     CID 652909:         Control flow issues  (DEADCODE)
>>>     Execution cannot reach this statement: "retry_time = 0;".
32              retry_time = CONFIG_BOOT_RETRY_MIN;
33     }
34
35     void bootretry_init_cmd_timeout(void)
36     {
37      bootretry_parse(env_get("bootretry"));

** CID 652908:       Error handling issues  (NEGATIVE_RETURNS)
/test/dm/hash.c: 35           in hash_test_success()


_____________________________________________________________________________________________
*** CID 652908:         Error handling issues  (NEGATIVE_RETURNS)
/test/dm/hash.c: 35             in hash_test_success()
29
30     static int hash_test_success(struct udevice *dev, enum HASH_ALGO algo,
31                           const void *ibuf, const uint32_t ilen,
32                           void *obuf, uint32_t chunk_sz)
33     {
34      success_calls++;
>>>     CID 652908:         Error handling issues  (NEGATIVE_RETURNS)
>>>     "hash_algo_digest_size(algo)" is passed to a parameter that cannot be 
>>> negative. [Note: The source code implementation of the function has been 
>>> overridden by a builtin model.]
35      memset(obuf, 0x5a, hash_algo_digest_size(algo));
36
37      return 0;
38     }
39
40     static int hash_test_hard_error(struct udevice *dev, enum HASH_ALGO algo,

** CID 652907:       Memory - corruptions  (OVERRUN)
/test/dm/hash.c: 35           in hash_test_success()


_____________________________________________________________________________________________
*** CID 652907:         Memory - corruptions  (OVERRUN)
/test/dm/hash.c: 35             in hash_test_success()
29
30     static int hash_test_success(struct udevice *dev, enum HASH_ALGO algo,
31                           const void *ibuf, const uint32_t ilen,
32                           void *obuf, uint32_t chunk_sz)
33     {
34      success_calls++;
>>>     CID 652907:         Memory - corruptions  (OVERRUN)
>>>     Calling "memset" with "obuf" and "hash_algo_digest_size(algo)" is 
>>> suspicious because of the very large index, 18446744073709551594. The index 
>>> may be due to a negative parameter being interpreted as unsigned. [Note: 
>>> The source code implementation of the function has been overridden by a 
>>> builtin model.]
35      memset(obuf, 0x5a, hash_algo_digest_size(algo));
36
37      return 0;
38     }
39
40     static int hash_test_hard_error(struct udevice *dev, enum HASH_ALGO algo,



View Defects in Coverity Scan
<https://scan.coverity.com/projects/das-u-boot?tab=overview>

Best regards,

The Coverity Scan Admin Team

----- End forwarded message -----

-- 
Tom

Attachment: signature.asc
Description: PGP signature

Reply via email to