mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>
To: Hui Peng <benquike@gmail.com>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	 Jiri Slaby <jirislaby@kernel.org>,
	John Ogness <john.ogness@linutronix.de>,
	 Andy Shevchenko <andriy.shevchenko@linux.intel.com>,
	 Hugo Villeneuve <hugo@hugovil.com>,
	 linux-serial <linux-serial@vger.kernel.org>,
	 LKML <linux-kernel@vger.kernel.org>,
	stable@vger.kernel.org
Subject: Re: [PATCH v8 1/2] serial: core: fix baud rate fallback in uart_get_baud_rate()
Date: Wed, 7 Oct 2026 13:43:52 +0300 (EEST)	[thread overview]
Message-ID: <9b6de039-6db5-35c8-b3f6-104521e1d09f@linux.intel.com> (raw)
In-Reply-To: <20261007094719.1362769-2-benquike@gmail.com>

[-- Attachment #1: Type: text/plain, Size: 3189 bytes --]

On Wed, 7 Oct 2026, Hui Peng wrote:

> When uart_get_baud_rate() evaluates a requested baud rate against a port's
> supported limits [min, max], the retry loop operates as follows:
> 
>   try == 0: Evaluates the requested baud rate. If out of range and an old
>             termios is available, it switches termios to old.
>   try == 1: If old is also out of range

> (or unavailable)

This is not equal to the case where old is out of range because try == 0 
didn't use continue if that's the case so baud is within bounds.

But as suggested by Hugo in the older version thread, the better approach 
would be to prevent "old" from getting invalid in the first place so 
please look into that instead.

-- 
 i.

> , the fallback rule
>             at the end of the loop clips baud to [min, max - 1] and encodes
>             it into termios via tty_termios_encode_baud_rate(termios, baud,
>             baud).
>   try == 2: Evaluates baud = tty_termios_baud_rate(termios) for the newly
>             encoded clipped rate, which now satisfies min <= baud && baud
>             <= max and returns baud from within the loop body.
> 
> However, because the current loop bound is for (try = 0; try < 2; try++),
> the loop terminates immediately after try == 1 without executing try == 2 to
> re-evaluate the clipped rate. Upon loop exit, the function hits WARN_ON(1)
> and returns 0, which triggers a fatal divide-by-zero (Oops: divide error)
> in uart_get_divisor():
> 
>   WARNING: drivers/tty/serial/serial_core.c:548 at uart_get_baud_rate+0x136/0x260
>   [ ... ]
>   divide error: 0000 [#1] PREEMPT SMP KASAN
> 
> Increase the loop retry limit in uart_get_baud_rate() from 2 to 3 iterations
> (try < 3) so that clipped fallback baud rates are re-evaluated in try == 2.
> 
> Tested in QEMU against Linux 7.3.0-rc3 by setting B4000000 on /dev/ttyS0 via
> tcsetattr(): on the unfixed kernel it triggers WARN_ON(1) and divide-by-zero
> Oops, whereas with this fix applied uart_get_baud_rate() smoothly falls back
> to 115200 without error.
> 
> Fixes: 091ea8e5d34e ("serial: core: prevent division by zero by always returning non-zero baud rate")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Hui Peng <benquike@gmail.com>
> ---
> Changes in v8:
> - Rewrote commit description to detail the step-by-step loop iteration
>   progression (try == 0, try == 1, try == 2) as requested by Ilpo Järvinen
>   and Greg Kroah-Hartman.
> 
>  drivers/tty/serial/serial_core.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/tty/serial/serial_core.c b/drivers/tty/serial/serial_core.c
> index f91bcfa30113..6ed0195e6912 100644
> --- a/drivers/tty/serial/serial_core.c
> +++ b/drivers/tty/serial/serial_core.c
> @@ -470,7 +470,7 @@ unsigned int uart_get_baud_rate(struct uart_port *port, struct ktermios *termi
>  	 * Ask the low level driver to verify the baud rate if it can't
>  	 * then it will have encode_baud_rate set the Closet else .
>  	 */
> -	for (try = 0; try < 2; try++) {
> +	for (try = 0; try < 3; try++) {
>  		baud = tty_termios_baud_rate(termios);
> 
>  		/*
> 

  reply	other threads:[~2026-10-07 10:44 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07  9:47 [PATCH v8 0/2] serial: core: fix baud rate fallback loop and baud_base overflow Hui Peng
2026-10-07  9:47 ` [PATCH v8 1/2] serial: core: fix baud rate fallback in uart_get_baud_rate() Hui Peng
2026-10-07 10:43   ` Ilpo Järvinen [this message]
2026-10-07 14:13   ` Hugo Villeneuve
2026-10-07  9:47 ` [PATCH v8 2/2] serial: core: reject baud_base values that overflow port->uartclk in uart_set_info() Hui Peng

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=9b6de039-6db5-35c8-b3f6-104521e1d09f@linux.intel.com \
    --to=ilpo.jarvinen@linux.intel.com \
    --cc=andriy.shevchenko@linux.intel.com \
    --cc=benquike@gmail.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=hugo@hugovil.com \
    --cc=jirislaby@kernel.org \
    --cc=john.ogness@linutronix.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-serial@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®