From nobody Sun Jul 26 11:52:32 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782718974979747.8049795382852; Mon, 29 Jun 2026 00:42:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1we6d5-0004G7-Hv; Mon, 29 Jun 2026 03:42:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1we6d0-0004FU-0G; Mon, 29 Jun 2026 03:42:03 -0400 Received: from mailgw.kylinos.cn ([124.126.103.232]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1we6cx-0007GV-2d; Mon, 29 Jun 2026 03:42:01 -0400 Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1800238053; Mon, 29 Jun 2026 15:41:36 +0800 X-UUID: f5059c7e738d11f1aa26b74ffac11d73-20260629 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12, REQID:e890ac4f-4b6d-4885-8d0f-3ce5a5abc933, IP:0, U RL:0,TC:0,Content:0,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION :release,TS:25 X-CID-META: VersionHash:e7bac3a, CLOUDID:8889d078cea4805edcf846487ebbdc80, BulkI D:nil,BulkQuantity:0,Recheck:0,SF:102|850|865|898,TC:nil,Content:0|15|50,E DM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI:0,OSA: 0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: f5059c7e738d11f1aa26b74ffac11d73-20260629 X-User: yujun@kylinos.cn From: yujun To: Glenn Miles Cc: qemu-ppc@nongnu.org, qemu-arm@nongnu.org, qemu-devel@nongnu.org Subject: [PATCH] hw/gpio/pca9552: fix off-by-one in QOM led index validation Date: Mon, 29 Jun 2026 15:41:33 +0800 Message-Id: <20260629074133.187549-1-yujun@kylinos.cn> X-Mailer: git-send-email 2.25.1 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=124.126.103.232; envelope-from=yujun@kylinos.cn; helo=mailgw.kylinos.cn X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1782718978954158500 Content-Type: text/plain; charset="utf-8" pca955x_get_led() and pca955x_set_led() accept led indices equal to pin_count, but valid indices are 0..pin_count-1. For a 16-pin device, led16 passes the current check and then accesses an LS register past max_reg. Use the same >=3D pin_count bounds check as pca9554_set_pin() and the gpio input handler assert in this file. Fixes: a90d8f84674 ("misc/pca9552: Add qom set and get") Signed-off-by: yujun Reviewed-by: Glenn Miles Reviewed-by: Peter Maydell --- hw/gpio/pca9552.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/hw/gpio/pca9552.c b/hw/gpio/pca9552.c index 472d8ad957..b13ac9fd9c 100644 --- a/hw/gpio/pca9552.c +++ b/hw/gpio/pca9552.c @@ -311,8 +311,8 @@ static void pca955x_get_led(Object *obj, Visitor *v, co= nst char *name, error_setg(errp, "%s: error reading %s", __func__, name); return; } - if (led < 0 || led > k->pin_count) { - error_setg(errp, "%s invalid led %s", __func__, name); + if (led < 0 || led >=3D k->pin_count) { + error_setg(errp, "%s: invalid led %s", __func__, name); return; } /* @@ -352,8 +352,8 @@ static void pca955x_set_led(Object *obj, Visitor *v, co= nst char *name, error_setg(errp, "%s: error reading %s", __func__, name); return; } - if (led < 0 || led > k->pin_count) { - error_setg(errp, "%s invalid led %s", __func__, name); + if (led < 0 || led >=3D k->pin_count) { + error_setg(errp, "%s: invalid led %s", __func__, name); return; } =20 --=20 2.25.1