From: Jay Buddhabhatti <jay.buddhabhatti@amd.com>
To: <sudeep.holla@kernel.org>, <cristian.marussi@arm.com>
Cc: <arm-scmi@vger.kernel.org>,
<linux-arm-kernel@lists.infradead.org>,
<linux-kernel@vger.kernel.org>, <git@amd.com>,
Jay Buddhabhatti <jay.buddhabhatti@amd.com>
Subject: [RFC PATCH] firmware: arm_scmi: skip empty CLOCK_DESCRIBE_RATES replies
Date: Thu, 1 Oct 2026 04:45:38 -0700 [thread overview]
Message-ID: <20261001114538.671755-1-jay.buddhabhatti@amd.com> (raw)
Some platforms advertise reserved or uninstantiated clock IDs that still
succeed CLOCK_DESCRIBE_RATES with zero rates. After dynamic rate
allocation, kcalloc(0) returns ZERO_SIZE_PTR and protocol init then
dereferences rates[0], which panics.
Do not allocate or index the rate array when the firmware reports an
empty list, so unused IDs are skipped instead of taking down the SCMI
clock provider.
Fixes: 62ba967595e0 ("firmware: arm_scmi: Make clock rates allocation dynamic")
Signed-off-by: Jay Buddhabhatti <jay.buddhabhatti@amd.com>
---
The SCMI server is the source of this zero rate and successful response
and it should be fixed in SCMI server. This defensive check in Linux is
still useful because firmware responses must be validated before
de-referencing dynamically allocated data, The panic is a Linux
regression introduced by dynamic rate allocation; previous fixed array
tolerated the same response and other SCMI implementations could return
the same unexpected response.
---
drivers/firmware/arm_scmi/clock.c | 18 ++++++++++++++++++
1 file changed, 18 insertions(+)
diff --git a/drivers/firmware/arm_scmi/clock.c b/drivers/firmware/arm_scmi/clock.c
index 0278705d809e..8934a95527e2 100644
--- a/drivers/firmware/arm_scmi/clock.c
+++ b/drivers/firmware/arm_scmi/clock.c
@@ -8,6 +8,7 @@
#include <linux/math64.h>
#include <linux/module.h>
#include <linux/limits.h>
+#include <linux/slab.h>
#include <linux/sort.h>
#include "protocols.h"
@@ -484,6 +485,13 @@ iter_clk_describe_update_state(struct scmi_iterator_state *st,
if (!st->max_resources) {
unsigned int tot_rates = st->num_returned + st->num_remaining;
+ /*
+ * Unused/reserved clock IDs return 0 rates. kmalloc(0)
+ * returns ZERO_SIZE_PTR and must not be dereferenced.
+ */
+ if (!tot_rates)
+ return 0;
+
p->clkd->r.rates = devm_kcalloc(p->dev, tot_rates,
sizeof(*p->clkd->r.rates), GFP_KERNEL);
if (!p->clkd->r.rates)
@@ -505,6 +513,9 @@ iter_clk_describe_process_response(const struct scmi_protocol_handle *ph,
struct scmi_clk_ipriv *p = priv;
const struct scmi_msg_resp_clock_describe_rates *r = response;
+ if (ZERO_OR_NULL_PTR(p->clkd->r.rates))
+ return -EPROTO;
+
p->clkd->r.rates[p->clkd->r.num_rates] = RATE_TO_U64(r->rate[st->loop_idx]);
/* Count only effectively discovered rates */
@@ -622,6 +633,13 @@ scmi_clock_describe_rates_get(const struct scmi_protocol_handle *ph,
if (ret)
return ret;
+ /*
+ * Some platforms expose reserved clock IDs with an empty
+ * CLOCK_DESCRIBE_RATES reply. Do not dereference rates[].
+ */
+ if (!clkd->r.num_rates || ZERO_OR_NULL_PTR(clkd->r.rates))
+ return 0;
+
clkd->info.min_rate = clkd->r.rates[RATE_MIN];
if (!clkd->r.rate_discrete) {
clkd->info.max_rate = clkd->r.rates[RATE_MAX];
--
2.34.1
next reply other threads:[~2026-10-01 11:46 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 11:45 Jay Buddhabhatti [this message]
2026-10-01 14:44 ` Sudeep Holla
2026-10-05 12:36 ` Jay Buddhabhatti
2026-10-05 15:31 ` Sudeep Holla
2026-10-07 11:25 ` Jay Buddhabhatti
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001114538.671755-1-jay.buddhabhatti@amd.com \
--to=jay.buddhabhatti@amd.com \
--cc=arm-scmi@vger.kernel.org \
--cc=cristian.marussi@arm.com \
--cc=git@amd.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=sudeep.holla@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®