Re: [PATCH v4 05/15] clk: qcom: clk-rpmh: Add support for Kuno RPMh clocks
From: sashiko-bot@kernel.org
Date: 2026-08-27 16:49:04
Also in:
linux-clk
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: Pre-existing issues: - [High] This problem wasn't introduced by this patch, but this patch adds new instances of static arrays (like `kuno_rpmh_clocks`) that are subjected to the same corruption. Global static structures and arrays in clk-rpmh are permanently mutated during probe, leading to resource address corruption and dropped clocks across unbind/rebind or probe deferrals. -- commit 05d4af4c482cb487c2654eee526d1d872c910869 Author: Hardeep Sharma [off-list ref] clk: qcom: clk-rpmh: Add support for Kuno RPMh clocks Add the RPMh clock description for the Qualcomm Kuno SoC so the qcom,kuno-rpmh-clk compatible can provide the RPMh-managed clocks to consumers.
quoted hunk ↗ jump to hunk
diff --git a/drivers/clk/qcom/clk-rpmh.c b/drivers/clk/qcom/clk-rpmh.c index a224a94ae2733..ec8700b6186d8 100644 --- a/drivers/clk/qcom/clk-rpmh.c +++ b/drivers/clk/qcom/clk-rpmh.c@@ -937,6 +937,20 @@ static const struct clk_rpmh_desc clk_rpmh_kaanapali = { .num_clks = ARRAY_SIZE(kaanapali_rpmh_clocks), }; +static struct clk_hw *kuno_rpmh_clocks[] = { + [RPMH_CXO_CLK] = &clk_rpmh_bi_tcxo_div2.hw, + [RPMH_CXO_CLK_A] = &clk_rpmh_bi_tcxo_div2_ao.hw, + [RPMH_RF_CLK1] = &clk_rpmh_rf_clk1_a.hw, + [RPMH_RF_CLK1_A] = &clk_rpmh_rf_clk1_a_ao.hw, + [RPMH_QPIC_CLK] = &clk_rpmh_qpic_clk.hw, + [RPMH_IPA_CLK] = &clk_rpmh_ipa.hw, +}; + +static const struct clk_rpmh_desc clk_rpmh_kuno = { + .clks = kuno_rpmh_clocks,
[Severity: High]
This is a pre-existing issue, but adding this new array subjects it to a bug
in the clk-rpmh driver's probe path.
Will this statically allocated array and the clocks it points to be corrupted
during probe deferrals or driver unbind/rebind cycles?
In clk_rpmh_probe(), the globally shared static array and the structures it
references are permanently mutated:
drivers/clk/qcom/clk-rpmh.c:clk_rpmh_probe() {
...
if (!has_state_changed && rpmh_clk->state) {
hw_clks[i] = NULL;
continue;
}
rpmh_clk->res_addr += res_addr;
...
}
Because kuno_rpmh_clocks is a static array, hw_clks[i] = NULL permanently
drops the clock for all subsequent probe attempts.
Additionally, rpmh_clk->res_addr += res_addr incorrectly accumulates the
hardware resource address multiple times across probes, which can cause the
driver to write to out-of-bounds addresses when sending RPMh commands.
+ .num_clks = ARRAY_SIZE(kuno_rpmh_clocks), +};
-- Sashiko AI review · https://sashiko.dev/#/patchset/20260827-kuno-soc-support-v4-0-dd34f235fc1a@oss.qualcomm.com?part=5