From: Antonio Quartulli <antonio@mandelbit.com>
To: linux-spi@vger.kernel.org
Cc: linux-stm32@st-md-mailman.stormreply.com,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org,
"Clément Le Goffic" <clement.legoffic@foss.st.com>,
"Alexandre Torgue" <alexandre.torgue@foss.st.com>,
"Maxime Coquelin" <mcoquelin.stm32@gmail.com>,
"Mark Brown" <broonie@kernel.org>,
"Alain Volmat" <alain.volmat@foss.st.com>,
"Antonio Quartulli" <antonio@mandelbit.com>
Subject: [PATCH] spi: stm32: fix NULL check on pointer-to-pointer variable
Date: Sat, 28 Jun 2025 02:02:27 +0200 [thread overview]
Message-ID: <20250628000227.22895-1-antonio@mandelbit.com> (raw)
In stm32_spi_prepare_rx_dma_mdma_chaining() both rx_dma_desc
and rx_mdma_desc are passed as pointer-to-pointer arguments.
The goal is to pass back to the caller the value returned
by dmaengine_prep_slave_sg(), when it is not NULL.
However, the NULL check on the result is erroneously
performed without dereferencing the pointer.
Add the proper dereference operator to both checks.
Fixes: d17dd2f1d8a1 ("spi: stm32: use STM32 DMA with STM32 MDMA to enhance DDR use")
Addresses-Coverity-ID: 1644715 ("Null pointer dereferences (REVERSE_INULL)")
Signed-off-by: Antonio Quartulli <antonio@mandelbit.com>
---
drivers/spi/spi-stm32.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/spi/spi-stm32.c b/drivers/spi/spi-stm32.c
index 3d20f09f1ae7..e9fa17e52fb0 100644
--- a/drivers/spi/spi-stm32.c
+++ b/drivers/spi/spi-stm32.c
@@ -1529,7 +1529,7 @@ static int stm32_spi_prepare_rx_dma_mdma_chaining(struct stm32_spi *spi,
DMA_PREP_INTERRUPT);
sg_free_table(&dma_sgt);
- if (!rx_dma_desc)
+ if (!*rx_dma_desc)
return -EINVAL;
/* Prepare MDMA slave_sg transfer MEM_TO_MEM (SRAM>DDR) */
@@ -1563,8 +1563,8 @@ static int stm32_spi_prepare_rx_dma_mdma_chaining(struct stm32_spi *spi,
DMA_PREP_INTERRUPT);
sg_free_table(&mdma_sgt);
- if (!rx_mdma_desc) {
- rx_dma_desc = NULL;
+ if (!*rx_mdma_desc) {
+ *rx_dma_desc = NULL;
return -EINVAL;
}
--
2.49.0
next reply other threads:[~2025-06-28 0:02 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-06-28 0:02 Antonio Quartulli [this message]
2025-06-30 7:34 ` Clement LE GOFFIC
2025-06-30 7:48 ` Antonio Quartulli
2025-06-30 8:12 ` [PATCH v2] spi: stm32: fix pointer-to-pointer variables usage Antonio Quartulli
2025-06-30 8:28 ` Clement LE GOFFIC
2025-06-30 11:20 ` Mark Brown
2025-06-30 12:00 ` Clement LE GOFFIC
2025-06-30 11:40 ` Alain Volmat
2025-06-30 11:58 ` Clement LE GOFFIC
2025-07-01 22:15 ` Mark Brown
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250628000227.22895-1-antonio@mandelbit.com \
--to=antonio@mandelbit.com \
--cc=alain.volmat@foss.st.com \
--cc=alexandre.torgue@foss.st.com \
--cc=broonie@kernel.org \
--cc=clement.legoffic@foss.st.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-spi@vger.kernel.org \
--cc=linux-stm32@st-md-mailman.stormreply.com \
--cc=mcoquelin.stm32@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®