summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorCristian Ciocaltea <cristian.ciocaltea@collabora.com>2026-08-11 18:44:44 +0300
committerVinod Koul <vkoul@kernel.org>2026-08-11 22:24:02 +0530
commit229788526ff24e0607726e93b74dd2ef157a99cd (patch)
tree090813301db68d0c079c16513deedce0a5d4dd61
parentc4fe5a9f379055ce0ec930f6495ae62aad237b89 (diff)
phy: rockchip: samsung-hdptx: Guard against clk rate integer underflow
The 'fout' subtraction in rk_hdptx_phy_clk_calc_rate_from_pll_cfg() could result in an integer underflow, if the hardware registers are misconfigured or contain uninitialized values, such that the computed sigma-delta modulator offset sdm exceeds the base frequency fout. This might lead to an absurdly high clock rate being returned to the Common Clock Framework, with unpredictable effects on downstream clk consumers. Provide the necessary sanitization to avoid trusting the hardware state. Reported-by: Sashiko <sashiko-bot@kernel.org> Closes: https://lore.kernel.org/all/20260611235702.0E9691F000E9@smtp.kernel.org/ Fixes: 3481fc04d969 ("phy: rockchip: samsung-hdptx: Compute clk rate from PLL config") Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com> Link: https://patch.msgid.link/20260811-hdptx-clk-fixes-v6-3-75bca0ee5753@collabora.com Signed-off-by: Vinod Koul <vkoul@kernel.org>
-rw-r--r--drivers/phy/rockchip/phy-rockchip-samsung-hdptx.c14
1 files changed, 12 insertions, 2 deletions
diff --git a/drivers/phy/rockchip/phy-rockchip-samsung-hdptx.c b/drivers/phy/rockchip/phy-rockchip-samsung-hdptx.c
index d67ced2bf7b2..3a65c26f3efa 100644
--- a/drivers/phy/rockchip/phy-rockchip-samsung-hdptx.c
+++ b/drivers/phy/rockchip/phy-rockchip-samsung-hdptx.c
@@ -2285,10 +2285,20 @@ static u64 rk_hdptx_phy_clk_calc_rate_from_pll_cfg(struct rk_hdptx_phy *hdptx)
sdm = div_u64(PLL_REF_CLK * ropll_hw.sdc_deno *
ropll_hw.pms_mdiv * ropll_hw.sdm_num, val);
- if (ropll_hw.sdm_num_sign)
+ if (ropll_hw.sdm_num_sign) {
+ if (sdm > fout) {
+ /*
+ * Similarly to the case above, it is expected
+ * the next .set_rate() will help with recovery.
+ */
+ dev_dbg(hdptx->dev, "Invalid ROPLL hw state: sdm > fout\n");
+ return 0;
+ }
+
fout = fout - sdm;
- else
+ } else {
fout = fout + sdm;
+ }
}
return DIV_ROUND_CLOSEST_ULL(fout * 2 * 8, ropll_hw.pms_sdiv * 10 * bpc);