[PATCH] pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()

Karl Mehltretter posted 1 patch 1 month, 3 weeks ago
drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH] pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()
Posted by Karl Mehltretter 1 month, 3 weeks ago
mtk_mfg_attach_dev() reads prev_o on the first iteration of its loop,
in "if (prev_o && prev_o->freq == o->freq)", before prev_o is assigned
at the end of the loop body. On that first iteration, evaluating prev_o
reads an indeterminate value. If it is non-NULL, the condition
dereferences a stale or invalid pointer, potentially faulting or
incorrectly skipping the first OPP.

Initialize prev_o to NULL. This matches the intent as well: there is no
previous OPP to compare against on the first iteration.

Found with Clang's -Wconditional-uninitialized.

Fixes: f08e7a4e8d6ac ("pmdomain: mediatek: Add support for MFlexGraphics")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
---
 drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c b/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c
index 53bdab66cf157..9a8a38d98cce7 100644
--- a/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c
+++ b/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c
@@ -657,7 +657,7 @@ static int mtk_mfg_attach_dev(struct generic_pm_domain *pd, struct device *dev)
 	struct mtk_mfg *mfg = mtk_mfg_from_genpd(pd);
 	struct dev_pm_opp_data *so = mfg->stack_opps;
 	struct dev_pm_opp_data *go = mfg->gpu_opps;
-	struct dev_pm_opp_data *prev_o;
+	struct dev_pm_opp_data *prev_o = NULL;
 	struct dev_pm_opp_data *o;
 	int i, ret;
 
-- 
2.53.0
Re: [PATCH] pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()
Posted by Ulf Hansson 1 month, 2 weeks ago
On Sat, Aug 8, 2026 at 5:06 PM Karl Mehltretter <kmehltretter@gmail.com> wrote:
>
> mtk_mfg_attach_dev() reads prev_o on the first iteration of its loop,
> in "if (prev_o && prev_o->freq == o->freq)", before prev_o is assigned
> at the end of the loop body. On that first iteration, evaluating prev_o
> reads an indeterminate value. If it is non-NULL, the condition
> dereferences a stale or invalid pointer, potentially faulting or
> incorrectly skipping the first OPP.
>
> Initialize prev_o to NULL. This matches the intent as well: there is no
> previous OPP to compare against on the first iteration.
>
> Found with Clang's -Wconditional-uninitialized.
>
> Fixes: f08e7a4e8d6ac ("pmdomain: mediatek: Add support for MFlexGraphics")
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>

Applied for fixes and by adding a stable tag, thanks!

Kind regards
Uffe


> ---
>  drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c b/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c
> index 53bdab66cf157..9a8a38d98cce7 100644
> --- a/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c
> +++ b/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c
> @@ -657,7 +657,7 @@ static int mtk_mfg_attach_dev(struct generic_pm_domain *pd, struct device *dev)
>         struct mtk_mfg *mfg = mtk_mfg_from_genpd(pd);
>         struct dev_pm_opp_data *so = mfg->stack_opps;
>         struct dev_pm_opp_data *go = mfg->gpu_opps;
> -       struct dev_pm_opp_data *prev_o;
> +       struct dev_pm_opp_data *prev_o = NULL;
>         struct dev_pm_opp_data *o;
>         int i, ret;
>
> --
> 2.53.0
Re: [PATCH] pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()
Posted by Nicolas Frattaroli 1 month, 2 weeks ago
On Saturday, 8 August 2026 17:05:06 Central European Summer Time Karl Mehltretter wrote:
> mtk_mfg_attach_dev() reads prev_o on the first iteration of its loop,
> in "if (prev_o && prev_o->freq == o->freq)", before prev_o is assigned
> at the end of the loop body. On that first iteration, evaluating prev_o
> reads an indeterminate value. If it is non-NULL, the condition
> dereferences a stale or invalid pointer, potentially faulting or
> incorrectly skipping the first OPP.
> 
> Initialize prev_o to NULL. This matches the intent as well: there is no
> previous OPP to compare against on the first iteration.
> 
> Found with Clang's -Wconditional-uninitialized.
> 
> Fixes: f08e7a4e8d6ac ("pmdomain: mediatek: Add support for MFlexGraphics")
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
> ---
>  drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c b/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c
> index 53bdab66cf157..9a8a38d98cce7 100644
> --- a/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c
> +++ b/drivers/pmdomain/mediatek/mtk-mfg-pmdomain.c
> @@ -657,7 +657,7 @@ static int mtk_mfg_attach_dev(struct generic_pm_domain *pd, struct device *dev)
>  	struct mtk_mfg *mfg = mtk_mfg_from_genpd(pd);
>  	struct dev_pm_opp_data *so = mfg->stack_opps;
>  	struct dev_pm_opp_data *go = mfg->gpu_opps;
> -	struct dev_pm_opp_data *prev_o;
> +	struct dev_pm_opp_data *prev_o = NULL;
>  	struct dev_pm_opp_data *o;
>  	int i, ret;
>  
> 

Reviewed-by: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>