[PATCH v3] hwmon: (cros_ec) Avoid threshold temperature conversion overflows

Thomas Weißschuh <[email protected]> Thu, 30 Jul 2026 17:12:26 +0200
Newsgroups dev.linux.lists.chrome-platform,org.kernel.vger.linux-hwmon,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
If the EC returns non-sensical values the temperature conversions might
overflow on 32-bit systems.

As these values wouldn't make sense, clamp them to 255 degrees celsius.
The machine would die before reaching that limit anyways.

Suggested-by: Guenter Roeck <[email protected]>
Link: https://lore.kernel.org/lkml/[email protected]/
Signed-off-by: Thomas Weißschuh <[email protected]>
---
Changes in v3:
- Drop the overflow handling and instead clamp the value sent by the EC
- Link to v2: https://patch.msgid.link/[email protected]

Changes in v2:
- Drop already applied patch 1.
- Also handle overflow of u32 -> long.
- Clarify commit message wrt compiler optimizations.
- Use __always_inline over __flatten to allow the compiler to optimize
  away more unnecessary overflow checks.
- Link to v1: https://patch.msgid.link/[email protected]
---
 drivers/hwmon/cros_ec_hwmon.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/hwmon/cros_ec_hwmon.c b/drivers/hwmon/cros_ec_hwmon.c
index 1337b646e022..27af13f0941c 100644
--- a/drivers/hwmon/cros_ec_hwmon.c
+++ b/drivers/hwmon/cros_ec_hwmon.c
@@ -236,8 +236,13 @@ static int cros_ec_hwmon_read(struct device *dev, enum hwmon_sensor_types type,
 			ret = cros_ec_hwmon_read_temp_threshold(priv->cros_ec, channel,
 								cros_ec_hwmon_attr_to_thres(attr),
 								&threshold);
-			if (ret == 0)
-				*val = cros_ec_hwmon_kelvin_to_millicelsius(threshold);
+			if (ret == 0) {
+				/* Limit to sensible, non-overflowing values. */
+				if (threshold > 255 + 273)
+					*val = 255000;
+				else
+					*val = cros_ec_hwmon_kelvin_to_millicelsius(threshold);
+			}
 		}
 	}
 

---
base-commit: 8a98254c65f629dcdc50a1046f58c5c87c72ef67
change-id: 20260630-cros_ec-hwmon-overflow-0381c8509df3

Best regards,
--  
Thomas Weißschuh <[email protected]>