Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

clk: samsung: exynos-clkout: Assign .num before accessing .hws

Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with
__counted_by") annotated the hws member of 'struct clk_hw_onecell_data'
with __counted_by, which informs the bounds sanitizer (UBSAN_BOUNDS)
about the number of elements in .hws[], so that it can warn when .hws[]
is accessed out of bounds. As noted in that change, the __counted_by
member must be initialized with the number of elements before the first
array access happens, otherwise there will be a warning from each access
prior to the initialization because the number of elements is zero. This
occurs in exynos_clkout_probe() due to .num being assigned after .hws[]
has been accessed:

UBSAN: array-index-out-of-bounds in drivers/clk/samsung/clk-exynos-clkout.c:178:18
index 0 is out of range for type 'clk_hw *[*]'

Move the .num initialization to before the first access of .hws[],
clearing up the warning.

Cc: stable@vger.kernel.org
Fixes: f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by")
Reported-by: Jochen Sprickerhof <jochen@sprickerhof.de>
Closes: https://lore.kernel.org/aSIYDN5eyKFKoXKL@eldamar.lan/
Tested-by: Jochen Sprickerhof <jochen@sprickerhof.de>
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Reviewed-by: Kees Cook <kees@kernel.org>
Reviewed-by: Sam Protsenko <semen.protsenko@linaro.org>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Stephen Boyd <sboyd@kernel.org>

authored by

Nathan Chancellor and committed by
Stephen Boyd
cf33f0b7 17490011

+1 -1
+1 -1
drivers/clk/samsung/clk-exynos-clkout.c
··· 175 175 clkout->mux.shift = EXYNOS_CLKOUT_MUX_SHIFT; 176 176 clkout->mux.lock = &clkout->slock; 177 177 178 + clkout->data.num = EXYNOS_CLKOUT_NR_CLKS; 178 179 clkout->data.hws[0] = clk_hw_register_composite(NULL, "clkout", 179 180 parent_names, parent_count, &clkout->mux.hw, 180 181 &clk_mux_ops, NULL, NULL, &clkout->gate.hw, ··· 186 185 goto err_unmap; 187 186 } 188 187 189 - clkout->data.num = EXYNOS_CLKOUT_NR_CLKS; 190 188 ret = of_clk_add_hw_provider(clkout->np, of_clk_hw_onecell_get, &clkout->data); 191 189 if (ret) 192 190 goto err_clk_unreg;