mailbox: mtk-cmdq: Fix local clock ID usage
authorFei Shao <fshao@chromium.org>
Thu, 14 Oct 2021 12:03:52 +0000 (20:03 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 18 Nov 2021 18:16:35 +0000 (19:16 +0100)
[ Upstream commit 0a5ad4322927ee4aaba6facc0e4faf1ab6c0d48e ]

In the probe function, the clock IDs were pointed to local variables
which should only be used in the same code block, and any access to them
after the probing stage becomes an use-after-free case.

Since there are only limited variants of the gce clock names so far, we
can just declare them as static constants to fix the issue.

Fixes: 85dfdbfc13ea ("mailbox: cmdq: add multi-gce clocks support for mt8195")
Signed-off-by: Fei Shao <fshao@chromium.org>
Reviewed-by: Tzung-Bi Shih <tzungbi@google.com>
Signed-off-by: Jassi Brar <jaswinder.singh@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/mailbox/mtk-cmdq-mailbox.c

index 9b0cc3bb5b23a24b3dc3223a105dc5f815d1e794..bb4793c7b38fd18aeaec1987be60a41d85eba448 100644 (file)
@@ -531,7 +531,8 @@ static int cmdq_probe(struct platform_device *pdev)
        struct device_node *phandle = dev->of_node;
        struct device_node *node;
        int alias_id = 0;
-       char clk_name[4] = "gce";
+       static const char * const clk_name = "gce";
+       static const char * const clk_names[] = { "gce0", "gce1" };
 
        cmdq = devm_kzalloc(dev, sizeof(*cmdq), GFP_KERNEL);
        if (!cmdq)
@@ -569,12 +570,9 @@ static int cmdq_probe(struct platform_device *pdev)
 
        if (cmdq->gce_num > 1) {
                for_each_child_of_node(phandle->parent, node) {
-                       char clk_id[8];
-
                        alias_id = of_alias_get_id(node, clk_name);
                        if (alias_id >= 0 && alias_id < cmdq->gce_num) {
-                               snprintf(clk_id, sizeof(clk_id), "%s%d", clk_name, alias_id);
-                               cmdq->clocks[alias_id].id = clk_id;
+                               cmdq->clocks[alias_id].id = clk_names[alias_id];
                                cmdq->clocks[alias_id].clk = of_clk_get(node, 0);
                                if (IS_ERR(cmdq->clocks[alias_id].clk)) {
                                        dev_err(dev, "failed to get gce clk: %d\n", alias_id);