Re: [PATCH] hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
Florian Bezdeka <[email protected]>
| Newsgroups | org.kernel.vger.linux-hwmon |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 2026-07-22 at 07:28 -0700, Guenter Roeck wrote: > Unlike NCT6106, NCT6116 only has three temperature registers, and with > it only three temperature source and temperature source configuration > registers. The register addresses match those of NCT6106 and can be > re-used. > > The code used a separate array to list the temperature source registers > for NCT6116, but used the size of the NCT6106 register array to set > the number of registers. The NCT6106 register array provides six addresses, > while the temperature source register array for NCT6116 only provides three > addresses. This causes a KASAN report. > > BUG: KASAN: global-out-of-bounds in nct6775_probe+0x936/0x46f0 [nct6775] > Read of size 2 at addr ffffffffc19561a6 by task modprobe/954 > ... > Call Trace: > dump_stack+0x7d/0xa7 > print_address_description.constprop.0+0x1c/0x220 > ? __kasan_kmalloc.constprop.0+0xc9/0xd0 > ? __kmalloc_node_track_caller+0x194/0x5b0 > ? nct6775_probe+0x936/0x46f0 [nct6775] > ? nct6775_probe+0x936/0x46f0 [nct6775] > ... > > Fix the problem by hard-coding the number of temperature and temperature > configuration registers to three for NCT6116. Drop the unnecessary > NCT6116_REG_TEMP_SOURCE array and re-use NCT6106_REG_TEMP_SOURCE. Thanks a lot for taking over and the super fast response/fix. Highly appreciated! Have you checked how far we get with the auto-stable apply process? I'm expecting that 5.10 (and maybe 5.15 in addition) will need some manual backporting. Happy to help there, just let me know. > > Reported-by: Florian Bezdeka <[email protected]> > Closes: https://lore.kernel.org/linux-hwmon/[email protected]/T/#t > Fixes: 29c7cb485b32 ("hwmon: (nct6775) Integrate new model nct6116") > Cc: Björn Gerhart <[email protected]> > Signed-off-by: Guenter Roeck <[email protected]> Reviewed-by: Florian Bezdeka <[email protected]> > --- > drivers/hwmon/nct6775-core.c | 8 +++----- > 1 file changed, 3 insertions(+), 5 deletions(-) > > diff --git a/drivers/hwmon/nct6775-core.c b/drivers/hwmon/nct6775-core.c > index d668dc390def..51253acff4b0 100644 > --- a/drivers/hwmon/nct6775-core.c > +++ b/drivers/hwmon/nct6775-core.c > @@ -846,8 +846,6 @@ static const u16 NCT6116_FAN_PULSE_SHIFT[] = { 0, 2, 4, 6, 6 }; > static const u16 NCT6116_REG_PWM[] = { 0x119, 0x129, 0x139, 0x199, 0x1a9 }; > static const u16 NCT6116_REG_FAN_MODE[] = { 0x113, 0x123, 0x133, 0x193, 0x1a3 }; > static const u16 NCT6116_REG_TEMP_SEL[] = { 0x110, 0x120, 0x130, 0x190, 0x1a0 }; > -static const u16 NCT6116_REG_TEMP_SOURCE[] = { > - 0xb0, 0xb1, 0xb2 }; > > static const u16 NCT6116_REG_CRITICAL_TEMP[] = { > 0x11a, 0x12a, 0x13a, 0x19a, 0x1aa }; > @@ -3652,7 +3650,7 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data, > = NCT6106_CRITICAL_PWM_ENABLE_MASK; > data->REG_CRITICAL_PWM = NCT6116_REG_CRITICAL_PWM; > data->REG_TEMP_OFFSET = NCT6106_REG_TEMP_OFFSET; > - data->REG_TEMP_SOURCE = NCT6116_REG_TEMP_SOURCE; > + data->REG_TEMP_SOURCE = NCT6106_REG_TEMP_SOURCE; > data->REG_TEMP_SEL = NCT6116_REG_TEMP_SEL; > data->REG_WEIGHT_TEMP_SEL = NCT6106_REG_WEIGHT_TEMP_SEL; > data->REG_WEIGHT_TEMP[0] = NCT6106_REG_WEIGHT_TEMP_STEP; > @@ -3666,13 +3664,13 @@ int nct6775_probe(struct device *dev, struct nct6775_data *data, > > reg_temp = NCT6106_REG_TEMP; > reg_temp_mon = NCT6106_REG_TEMP_MON; > - num_reg_temp = ARRAY_SIZE(NCT6106_REG_TEMP); > + num_reg_temp = 3; > num_reg_temp_mon = ARRAY_SIZE(NCT6106_REG_TEMP_MON); > num_reg_tsi_temp = ARRAY_SIZE(NCT6116_REG_TSI_TEMP); > reg_temp_over = NCT6106_REG_TEMP_OVER; > reg_temp_hyst = NCT6106_REG_TEMP_HYST; > reg_temp_config = NCT6106_REG_TEMP_CONFIG; > - num_reg_temp_config = ARRAY_SIZE(NCT6106_REG_TEMP_CONFIG); > + num_reg_temp_config = 3; > reg_temp_alternate = NCT6106_REG_TEMP_ALTERNATE; > reg_temp_crit = NCT6106_REG_TEMP_CRIT; > reg_temp_crit_l = NCT6106_REG_TEMP_CRIT_L; > -- > 2.45.2