From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f171.google.com (mail-oi1-f171.google.com [209.85.167.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 941F137E5E5 for ; Tue, 11 Aug 2026 06:07:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786428433; cv=none; b=k4qiGHXf5rO+p4xlThQ2RXczAvEwIpyFglO7JAhNpihUZMFSHVzBrAn9ee/osBbhbuFg6fjJOX0VmytHDRzIa7xSn4GdhObAbPVI3FFu1+VioRevWp/lkA1snAjSzZYp64dgIMxvMvUq/xaDpmrpG+54IfgMZP1bsmsYX3vnDtU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786428433; c=relaxed/simple; bh=cO0EPT1bPIG49AtzxircCgFULQ+dKdZXtNn1BWqEQV0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=IVVDUx3NaVHzx/SXrTLg39RgKZkEu+3YvUAF6zJgMxm0yGD/n5ZudrnYvCXtF2NUWCllCtJd8gRHOdh8KNJV1iCpOmvptWKBl7687Wd0UJDHZRAPA7d6teeWYuS5D9w2Hkgb1GmXRuPywGePVS5inJTkzJ5dNjWjagg8RnwqWb4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=QxXjjnby; arc=none smtp.client-ip=209.85.167.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="QxXjjnby" Received: by mail-oi1-f171.google.com with SMTP id 5614622812f47-4ab89cff9c7so663738b6e.2 for ; Mon, 10 Aug 2026 23:07:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786428430; x=1787033230; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=PQogJxVcWHF2/s1gpFEzMjsDacnUmvO1LDzMrn00kZM=; b=QxXjjnbyzSdnSXtArAg7R8hZ4Sl14ExWbYqeXhkPW9j4LJs+cDK0sZ5VJsAMEIo64f QdAVbC3tuDuK4bcc1WjpnvO7sN957ibsBqDWmC7kBMDnf6nnkuRJKNXScMCgA1S30aPp ghUVHMmjiOD4LI7Dxr8/9RVjEoSeQnBUiOwjc5BLSUeHbErQbHv/7fqedvrLJja8msmO 8lzzMULVLo65ac8fyfl7KUqfJXWmMGfOWBXIbvkSCdw1J/0JiIU/u16+AgsxLE3IgD2e se+HGaNE8SEFzja0l8QWQazrkFDjjT2853T9HcCqewrVvjo7J4K0Rz6+hk3w9QTYcnt7 4fNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786428430; x=1787033230; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PQogJxVcWHF2/s1gpFEzMjsDacnUmvO1LDzMrn00kZM=; b=cb8rxEH+imgYNzNI3wNdMtBoGE3yuNYF7RyzsI3B2MTM7l+hGCZHPmf8alBZPMBrgY z97dUoI8kfowQlPo0waTVNtXB6r5JfgfaLliVSHfk/8v/QSfHtSf2LmsFZU1WHWAQkig I+/9N1luPixFAyvPuHuCdNUyg9WLqFzAvMcqXYP4mACszploQqEaCeMjYWZjF1HoKT+Z HzUbObGpyCxCKUIB4d19+zaRpoKWFjAh1wnJ7UgwOzu4OtWu6DtVZ8DdNH70yPF3QspW pJfuz8VL2ACXxUoLuw2jz8tZ6w1Tiw/sBrWkVRiVrFs8mV+yDoML57bZZFtBeJMVW2h0 l6fg== X-Forwarded-Encrypted: i=1; AHgh+RoRUghhOi1xzkucZzJmIF6r82xDgO+gdDz2Um4gD1Htt370T+Mrm/CgrIsgOBKRqVFDSwbsyxR8cv87Zrs=@vger.kernel.org X-Gm-Message-State: AOJu0Yyb7giTrNjn//bOdopu974njmLxa3WG61TN+0erLtDw/n7X4FCs mVDW5IOslbjxBHd/ceT489TzOIs+Ynh5MWDJE95DSGERlkZljNhi3+5v X-Gm-Gg: AR+sD11tdJFZ9bM/eckumgfBPQZCIAcSrJf3cDptxvZzRCidBEDPuJf7iL+Cc4Xgp6G 5q+4vj/0bCQ/2yuUcqX8us4MWGPSVZuCF/tn5Tkbv2J+87a52IR8dExwLsu44ygw4BDTcKkijvY O5rxUVTZaxa88uKjysmgFIouFoKfTy/SyA65TOu+ewAQVK1dqTx71qutJd41ABXYKeReiAKoBnu Q5oQ3KAtBMF1Vei66x+lAjsxgjIdnm1UFUwxUQk/YkJKdq2W685QxYj3xYsWjSikgzE4ZgE+70O 3rWvMxNdEf7Dchrbxpc84sJFvnq8jxWcZ8P1QV1LLfnx4b1PVvGnWDtOG+RYmUSAp1+IB+qA/Fv xeTdZ6YF7oyRcSqFX+XcbfJM4+nA5CSV9BqoyJRwP+vx1mQlDOchHRd01TLSgJfz7m3qYF88ND/ pd90TDPZT0iUZaeF/M9QV0L8UzwvMgNqSEqkCt/7Bxpsm/ngVFrnwOJocgCxW4wEDEuM3myGI2T pvHaZZh/6EPCC/oYI5Gjj6uYw6IR2w8cqktGM7qnULyJBNawqBnn6YpI6RNreLpK352uCEluJxc Lq9mrI89ktOQQRCT8urTWxgraXSQkhegVy8umCpXxslD0jEYwXuB9ZhhH/fYKtPAmww1YPd0Ops CYJHp9ZFbrQ+0oaP7t1gVoUvD/crv5x3bchvBKQ== X-Received: by 2002:a05:6808:f01:b0:496:2b3:ae71 with SMTP id 5614622812f47-4b1fd9d2e1amr577795b6e.18.1786428430385; Mon, 10 Aug 2026 23:07:10 -0700 (PDT) Received: from james-x399.tailafd1a.ts.net (184-96-154-59.hlrn.qwest.net. [184.96.154.59]) by smtp.gmail.com with ESMTPSA id 5614622812f47-4b2001331d2sm98211b6e.11.2026.08.10.23.07.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 23:07:08 -0700 (PDT) From: James Hilliard To: linux-mtd@lists.infradead.org, linux-sunxi@lists.linux.dev Cc: James Hilliard , stable@vger.kernel.org, Miquel Raynal , Richard Weinberger , Vignesh Raghavendra , Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Richard Genoud , Geert Uytterhoeven , Boris Brezillon , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH] mtd: rawnand: sunxi: reject invalid ECC step sizes Date: Tue, 11 Aug 2026 00:06:48 -0600 Message-ID: <20260811060651.227431-1-james.hilliard1@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit ECC maximization forces a 1024-byte ECC step and divides the available OOB bytes by the number of steps. A NAND with a smaller page therefore produces zero steps and a division by zero. An explicitly configured ECC step which is larger than, or does not divide, the page also produces an unusable step count before the NAND core can diagnose the configuration. Validate the step size at both points where the driver derives the number of sectors and reject invalid geometries. Fixes: 4796d8655915 ("mtd: nand: sunxi: Support ECC maximization") Cc: stable@vger.kernel.org Signed-off-by: James Hilliard --- drivers/mtd/nand/raw/sunxi_nand.c | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/drivers/mtd/nand/raw/sunxi_nand.c b/drivers/mtd/nand/raw/sunxi_nand.c index 45ccbce91551..ad314c0e30b2 100644 --- a/drivers/mtd/nand/raw/sunxi_nand.c +++ b/drivers/mtd/nand/raw/sunxi_nand.c @@ -2032,6 +2032,15 @@ static void sunxi_nand_detach_chip(struct nand_chip *nand) sunxi_nand->user_data_bytes = NULL; } +static int sunxi_nfc_ecc_steps(struct mtd_info *mtd, unsigned int step_size) +{ + if (!step_size || mtd->writesize < step_size || + mtd->writesize % step_size) + return -EINVAL; + + return mtd->writesize / step_size; +} + static int sunxi_nfc_maximize_user_data(struct nand_chip *nand, uint32_t oobsize, int ecc_bytes, int nsectors) { @@ -2078,7 +2087,9 @@ static int sunxi_nand_hw_ecc_ctrl_init(struct nand_chip *nand, int bytes = mtd->oobsize; ecc->size = 1024; - nsectors = mtd->writesize / ecc->size; + nsectors = sunxi_nfc_ecc_steps(mtd, ecc->size); + if (nsectors < 0) + return nsectors; if (!nfc->caps->reg_user_data_len) { /* @@ -2163,7 +2174,9 @@ static int sunxi_nand_hw_ecc_ctrl_init(struct nand_chip *nand, /* HW ECC always work with even numbers of ECC bytes */ ecc->bytes = ALIGN(ecc->bytes, 2); - nsectors = mtd->writesize / ecc->size; + nsectors = sunxi_nfc_ecc_steps(mtd, ecc->size); + if (nsectors < 0) + return nsectors; /* * The rationale for variable data length is to prioritize maximum ECC -- 2.53.0