mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Miquel Raynal" <miquel.raynal@bootlin.com>,
	"Michael Walle" <mwalle@kernel.org>,
	"Takahiro Kuwano" <takahiro.kuwano@infineon.com>,
	"Pratyush Yadav" <pratyush@kernel.org>,
	"Richard Weinberger" <richard@nod.at>,
	"Vignesh Raghavendra" <vigneshr@ti.com>
Cc: linux-mtd@lists.infradead.org,
	"Thomas Petazzoni" <thomas.petazzoni@bootlin.com>,
	linux-kernel@vger.kernel.org, "Steam Lin" <STLin2@winbond.com>
Subject: Re: [PATCH 13/15] mtd: spi-nor: winbond: Add support for W35T51NW-C/E
Date: Fri, 02 Oct 2026 12:32:04 +0000	[thread overview]
Message-ID: <20261002123205.0A1791F00898@smtp.kernel.org> (raw)
In-Reply-To: <20261002-winbond-master-spi-nor-w35t-v1-13-a22a2f95c26e@bootlin.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] mtd: spi-nor: uninitialized memory read in write_sr1_and_sr2_and_check_careful()
--

commit db0463242c1b895f1a8729e983049e5010571c6d
Author: Miquel Raynal <miquel.raynal@bootlin.com>

mtd: spi-nor: winbond: Add support for W35T51NW-C/E

This commit adds support for the Winbond W35T51NW-C/E SPI-NOR flash
devices. It defines their JEDEC ID and configures features like block
protection and locking by setting SPI_NOR_HAS_LOCK and related flags.

> diff --git a/drivers/mtd/spi-nor/winbond.c b/drivers/mtd/spi-nor/winbond.c
> index 05a80af3a6b93..0e350dcfbb755 100644
> --- a/drivers/mtd/spi-nor/winbond.c
> +++ b/drivers/mtd/spi-nor/winbond.c
[ ... ]
> @@ -633,6 +633,11 @@ static const struct flash_info winbond_nor_parts[] = {
>  		.id = SNOR_ID(0xef, 0x5b, 0x19),
>  		.flags = SPI_NOR_HAS_LOCK | SPI_NOR_HAS_TB | SPI_NOR_TB_SR_BIT6 |
>  			 SPI_NOR_4BIT_BP,
> +	}, {
> +		/* W35T51NW-C/E */
> +		.id = SNOR_ID(0xef, 0x5b, 0x1a),
> +		.flags = SPI_NOR_HAS_LOCK | SPI_NOR_HAS_TB | SPI_NOR_TB_SR_BIT6 |
> +			 SPI_NOR_4BIT_BP,

[Severity: High]
Does enabling SPI_NOR_HAS_LOCK on this chip lead to an uninitialized memory
read and random failures during lock/unlock operations?

Since W35T chips disable reading SR2 via winbond_w35txxnw_nor_late_init()
by setting nor->params->opcodes.read_sr2 = 0, lock operations eventually reach
spi_nor_write_sr1_and_sr2_and_check_careful() with an uninitialized buffer:

drivers/mtd/spi-nor/swp.c:spi_nor_write_sr1_and_sr2_and_check_careful() {
	u8 tmp[2];
	int ret;
	...
	ret = spi_nor_read_sr1_and_sr2_careful(nor, tmp);
	if (ret)
		return ret;

	if (sr[0] != tmp[0] || sr[1] != tmp[1])
		return -EIO;
}

Because read_sr2 is 0, spi_nor_read_sr2_careful() safely returns 0 but leaves
tmp[1] completely uninitialized.

When the code unconditionally evaluates if (sr[1] != tmp[1]), tmp[1] contains
stack garbage, which will randomly not match sr[1]. Can this cause spurious
-EIO failures for lock and unlock functionality on these chips?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002-winbond-master-spi-nor-w35t-v1-0-a22a2f95c26e@bootlin.com?part=13

  reply	other threads:[~2026-10-02 12:32 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 12:21 [PATCH 00/15] mtd: spi-nor: winbond: Add support for the W35TxxNW family Miquel Raynal
2026-10-02 12:21 ` [PATCH 01/15] mtd: spi-nor: Only switch to ODTR if the chip has a callback for it Miquel Raynal
2026-10-02 12:21 ` [PATCH 02/15] mtd: spi-nor: Fix spacing between arguments Miquel Raynal
2026-10-02 12:21 ` [PATCH 03/15] mtd: spi-nor: Fix comment indentation to clarify the intent Miquel Raynal
2026-10-02 12:21 ` [PATCH 04/15] mtd: spi-nor: sfdp: Enhance a comment Miquel Raynal
2026-10-02 12:21 ` [PATCH 05/15] mtd: spi-nor: Drop stale values Miquel Raynal
2026-10-02 12:21 ` [PATCH 06/15] mtd: spi-nor: Fix WRSR with ODTR chips Miquel Raynal
2026-10-02 12:34   ` sashiko-bot
2026-10-02 12:21 ` [PATCH 07/15] mtd: spi-nor: Allow configuring the actual number of dummy cycles Miquel Raynal
2026-10-02 12:34   ` sashiko-bot
2026-10-02 12:21 ` [PATCH 08/15] mtd: spi-nor: Fix SWP for octal DTR chips Miquel Raynal
2026-10-02 12:29   ` sashiko-bot
2026-10-02 12:21 ` [PATCH 09/15] mtd: spi-nor: winbond: Prepare the introduction of W35TxxNW parts Miquel Raynal
2026-10-02 12:45   ` sashiko-bot
2026-10-02 12:21 ` [PATCH 10/15] mtd: spi-nor: winbond: Add support for W35T64NW-C Miquel Raynal
2026-10-02 12:21 ` [PATCH 11/15] mtd: spi-nor: winbond: Add support for W35T12NW-C Miquel Raynal
2026-10-02 12:21 ` [PATCH 12/15] mtd: spi-nor: winbond: Add support for W35T25NW-C/E Miquel Raynal
2026-10-02 12:21 ` [PATCH 13/15] mtd: spi-nor: winbond: Add support for W35T51NW-C/E Miquel Raynal
2026-10-02 12:32   ` sashiko-bot [this message]
2026-10-02 12:21 ` [PATCH 14/15] mtd: spi-nor: winbond: Add support for W35T01NW-C/E Miquel Raynal
2026-10-02 12:21 ` [PATCH 15/15] mtd: spi-nor: winbond: Add support for W35T02NW-C/E Miquel Raynal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002123205.0A1791F00898@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=STLin2@winbond.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mtd@lists.infradead.org \
    --cc=miquel.raynal@bootlin.com \
    --cc=mwalle@kernel.org \
    --cc=pratyush@kernel.org \
    --cc=richard@nod.at \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=takahiro.kuwano@infineon.com \
    --cc=thomas.petazzoni@bootlin.com \
    --cc=vigneshr@ti.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®