Here is the outcome of researching if the result of clk_get_rate() was directly
used as a divisor without checking if it is 0. Inspired by a Coverity report.
Wolfram Sang (6):
ide: palm_bk3710: test clock rate to avoid division by 0
net: ethernet: renesas: ravb_main: test clock rate to avoid division
by 0
pwm: pwm-img: test clock rate to avoid division by 0
pwm: pwm-lpc18xx-sct: test clock rate to avoid division by 0
watchdog: atlas7_wdt: test clock rate to avoid division by 0
watchdog: tangox_wdt: test clock rate to avoid division by 0
drivers/ide/palm_bk3710.c | 2 ++
drivers/net/ethernet/renesas/ravb_main.c | 3 +++
drivers/pwm/pwm-img.c | 5 +++++
drivers/pwm/pwm-lpc18xx-sct.c | 2 ++
drivers/watchdog/atlas7_wdt.c | 5 +++++
drivers/watchdog/tangox_wdt.c | 2 ++
6 files changed, 19 insertions(+)
--
2.7.0
From: Wolfram Sang <wsa+renesas@sang-engineering.com>
The clk API may return 0 on clk_get_rate, so we should check the result before
using it as a divisor.
Signed-off-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
---
Should go individually via subsystem tree.
drivers/pwm/pwm-lpc18xx-sct.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/pwm/pwm-lpc18xx-sct.c b/drivers/pwm/pwm-lpc18xx-sct.c
index 9163085101bc94..6487962c355c03 100644
--- a/drivers/pwm/pwm-lpc18xx-sct.c
+++ b/drivers/pwm/pwm-lpc18xx-sct.c
@@ -360,6 +360,8 @@ static int lpc18xx_pwm_probe(struct platform_device *pdev)
}
lpc18xx_pwm->clk_rate = clk_get_rate(lpc18xx_pwm->pwm_clk);
+ if (!lpc18xx_pwm->clk_rate)
+ return -EINVAL;
mutex_init(&lpc18xx_pwm->res_lock);
mutex_init(&lpc18xx_pwm->period_lock);
--
2.7.0
Hi Wolfram,
On 2 March 2016 at 23:33, Wolfram Sang [off-list ref] wrote:
quoted hunk
From: Wolfram Sang <wsa+renesas@sang-engineering.com>
The clk API may return 0 on clk_get_rate, so we should check the result before
using it as a divisor.
Signed-off-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
---
Should go individually via subsystem tree.
drivers/pwm/pwm-lpc18xx-sct.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/pwm/pwm-lpc18xx-sct.c b/drivers/pwm/pwm-lpc18xx-sct.c
index 9163085101bc94..6487962c355c03 100644
--- a/drivers/pwm/pwm-lpc18xx-sct.c
+++ b/drivers/pwm/pwm-lpc18xx-sct.c
@@ -360,6 +360,8 @@ static int lpc18xx_pwm_probe(struct platform_device *pdev)
}
lpc18xx_pwm->clk_rate = clk_get_rate(lpc18xx_pwm->pwm_clk);
+ if (!lpc18xx_pwm->clk_rate)
+ return -EINVAL;
This needs to be:
if (!lpc18xx_pwm->clk_rate) {
ret = -EINVAL;
goto disable_pwmclk;
}
I would also prefer an explicit check against 0 here. ie.:
'lpc18xx_pwm->clk_rate == 0'
A dev_err() message would also be nice to have.
regards,
Joachim Eastwood
On Wed, Mar 02, 2016 at 11:44:02PM +0100, Joachim Eastwood wrote:
Hi Wolfram,
On 2 March 2016 at 23:33, Wolfram Sang [off-list ref] wrote:
quoted
From: Wolfram Sang <wsa+renesas@sang-engineering.com>
The clk API may return 0 on clk_get_rate, so we should check the result before
using it as a divisor.
Signed-off-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
---
Should go individually via subsystem tree.
drivers/pwm/pwm-lpc18xx-sct.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/pwm/pwm-lpc18xx-sct.c b/drivers/pwm/pwm-lpc18xx-sct.c
index 9163085101bc94..6487962c355c03 100644
--- a/drivers/pwm/pwm-lpc18xx-sct.c
+++ b/drivers/pwm/pwm-lpc18xx-sct.c
@@ -360,6 +360,8 @@ static int lpc18xx_pwm_probe(struct platform_device *pdev)
}
lpc18xx_pwm->clk_rate = clk_get_rate(lpc18xx_pwm->pwm_clk);
+ if (!lpc18xx_pwm->clk_rate)
+ return -EINVAL;
This needs to be:
if (!lpc18xx_pwm->clk_rate) {
ret = -EINVAL;
goto disable_pwmclk;
}
Yes, that slipped through. Thanks!
I would also prefer an explicit check against 0 here. ie.:
Well, I like the reading "if not rate then error"
Will send V2 now...
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: not available
URL: <http://lists.infradead.org/pipermail/linux-arm-kernel/attachments/20160302/e24b2786/attachment.sig>