Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

clk: s2mps11: initialise clk_hw_onecell_data::num before accessing ::hws[] in probe()

With UBSAN enabled, we're getting the following trace:

UBSAN: array-index-out-of-bounds in .../drivers/clk/clk-s2mps11.c:186:3
index 0 is out of range for type 'struct clk_hw *[] __counted_by(num)' (aka 'struct clk_hw *[]')

This is because commit f316cdff8d67 ("clk: Annotate struct
clk_hw_onecell_data with __counted_by") annotated the hws member of
that struct with __counted_by, which informs the bounds sanitizer about
the number of elements in hws, so that it can warn when hws is accessed
out of bounds.

As noted in that change, the __counted_by member must be initialised
with the number of elements before the first array access happens,
otherwise there will be a warning from each access prior to the
initialisation because the number of elements is zero. This occurs in
s2mps11_clk_probe() due to ::num being assigned after ::hws access.

Move the assignment to satisfy the requirement of assign-before-access.

Cc: stable@vger.kernel.org
Fixes: f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by")
Signed-off-by: André Draszik <andre.draszik@linaro.org>
Link: https://lore.kernel.org/r/20250326-s2mps11-ubsan-v1-1-fcc6fce5c8a9@linaro.org
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Signed-off-by: Stephen Boyd <sboyd@kernel.org>

authored by

André Draszik and committed by
Stephen Boyd
3e14c720 2bc3ada0

+2 -1
+2 -1
drivers/clk/clk-s2mps11.c
··· 137 137 if (!clk_data) 138 138 return -ENOMEM; 139 139 140 + clk_data->num = S2MPS11_CLKS_NUM; 141 + 140 142 switch (hwid) { 141 143 case S2MPS11X: 142 144 s2mps11_reg = S2MPS11_REG_RTC_CTRL; ··· 188 186 clk_data->hws[i] = &s2mps11_clks[i].hw; 189 187 } 190 188 191 - clk_data->num = S2MPS11_CLKS_NUM; 192 189 of_clk_add_hw_provider(s2mps11_clks->clk_np, of_clk_hw_onecell_get, 193 190 clk_data); 194 191