Thread (19 messages) 19 messages, 2 authors, 2026-08-27

Re: [PATCH v4 05/15] clk: qcom: clk-rpmh: Add support for Kuno RPMh clocks

From: sashiko-bot@kernel.org
Date: 2026-08-27 16:49:04
Also in: linux-clk

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] This problem wasn't introduced by this patch, but this patch adds new instances of static arrays (like `kuno_rpmh_clocks`) that are subjected to the same corruption. Global static structures and arrays in clk-rpmh are permanently mutated during probe, leading to resource address corruption and dropped clocks across unbind/rebind or probe deferrals.
--

commit 05d4af4c482cb487c2654eee526d1d872c910869
Author: Hardeep Sharma [off-list ref]

clk: qcom: clk-rpmh: Add support for Kuno RPMh clocks

Add the RPMh clock description for the Qualcomm Kuno SoC so the
qcom,kuno-rpmh-clk compatible can provide the RPMh-managed clocks to
consumers.
quoted hunk ↗ jump to hunk
diff --git a/drivers/clk/qcom/clk-rpmh.c b/drivers/clk/qcom/clk-rpmh.c
index a224a94ae2733..ec8700b6186d8 100644
--- a/drivers/clk/qcom/clk-rpmh.c
+++ b/drivers/clk/qcom/clk-rpmh.c
@@ -937,6 +937,20 @@ static const struct clk_rpmh_desc clk_rpmh_kaanapali = {
 	.num_clks = ARRAY_SIZE(kaanapali_rpmh_clocks),
 };
 
+static struct clk_hw *kuno_rpmh_clocks[] = {
+	[RPMH_CXO_CLK]		= &clk_rpmh_bi_tcxo_div2.hw,
+	[RPMH_CXO_CLK_A]	= &clk_rpmh_bi_tcxo_div2_ao.hw,
+	[RPMH_RF_CLK1]		= &clk_rpmh_rf_clk1_a.hw,
+	[RPMH_RF_CLK1_A]	= &clk_rpmh_rf_clk1_a_ao.hw,
+	[RPMH_QPIC_CLK]		= &clk_rpmh_qpic_clk.hw,
+	[RPMH_IPA_CLK]		= &clk_rpmh_ipa.hw,
+};
+
+static const struct clk_rpmh_desc clk_rpmh_kuno = {
+	.clks = kuno_rpmh_clocks,
[Severity: High]
This is a pre-existing issue, but adding this new array subjects it to a bug
in the clk-rpmh driver's probe path.

Will this statically allocated array and the clocks it points to be corrupted
during probe deferrals or driver unbind/rebind cycles?

In clk_rpmh_probe(), the globally shared static array and the structures it
references are permanently mutated:

drivers/clk/qcom/clk-rpmh.c:clk_rpmh_probe() {
    ...
		if (!has_state_changed && rpmh_clk->state) {
			hw_clks[i] = NULL;
			continue;
		}

		rpmh_clk->res_addr += res_addr;
    ...
}

Because kuno_rpmh_clocks is a static array, hw_clks[i] = NULL permanently
drops the clock for all subsequent probe attempts.

Additionally, rpmh_clk->res_addr += res_addr incorrectly accumulates the
hardware resource address multiple times across probes, which can cause the
driver to write to out-of-bounds addresses when sending RPMh commands.
+	.num_clks = ARRAY_SIZE(kuno_rpmh_clocks),
+};
-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260827-kuno-soc-support-v4-0-dd34f235fc1a@oss.qualcomm.com?part=5
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help