[PATCH 0/3] mtd: rawnand: sunxi: harden protected OOB handling

James Hilliard posted 3 patches 1 month, 2 weeks ago
drivers/mtd/nand/raw/sunxi_nand.c | 32 +++++++++++++++++++++-----------
1 file changed, 21 insertions(+), 11 deletions(-)
[PATCH 0/3] mtd: rawnand: sunxi: harden protected OOB handling
Posted by James Hilliard 1 month, 2 weeks ago
The H6/H616 variable protected-OOB implementation has three related
failure cases around its per-step user-data lengths.

First, propagate failures while allocating the per-step length array.
Then reserve an encodable four-byte first section for the bad block
marker and reject layouts which cannot provide it. Finally, replace the
per-write heap allocation used for BBM compensation with the
controller's bounded 32-byte stack buffer.

These fixes keep the calculated, advertised and programmed OOB layouts
consistent and prevent zero-sized sections from reaching the BBM path.

Assisted-by: OpenAI Codex (gpt-5.6-sol, max)
Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
---
James Hilliard (3):
      mtd: rawnand: sunxi: propagate user-data allocation errors
      mtd: rawnand: sunxi: reserve a full user-data word for BBM
      mtd: rawnand: sunxi: use a stack buffer for BBM randomization

 drivers/mtd/nand/raw/sunxi_nand.c | 32 +++++++++++++++++++++-----------
 1 file changed, 21 insertions(+), 11 deletions(-)
---
base-commit: 15a3cbce32994141252bb4ecfe3ff3a5d22d0b4f
change-id: 20260810-sunxi-nand-protected-oob-fixes-15db4368a8ae

Best regards,
--  
James Hilliard <james.hilliard1@gmail.com>
Re: [PATCH 0/3] mtd: rawnand: sunxi: harden protected OOB handling
Posted by Miquel Raynal 3 weeks, 3 days ago
On Tue, 11 Aug 2026 00:01:58 -0600, James Hilliard wrote:
> The H6/H616 variable protected-OOB implementation has three related
> failure cases around its per-step user-data lengths.
> 
> First, propagate failures while allocating the per-step length array.
> Then reserve an encodable four-byte first section for the bad block
> marker and reject layouts which cannot provide it. Finally, replace the
> per-write heap allocation used for BBM compensation with the
> controller's bounded 32-byte stack buffer.
> 
> [...]

Applied to nand/next, thanks!

[1/3] mtd: rawnand: sunxi: propagate user-data allocation errors
      commit: 8696502b0aa96bcbb1f1e78ae117726378823ae8
[2/3] mtd: rawnand: sunxi: reserve a full user-data word for BBM
      commit: bde8fd880d84627072c224729c818306c4b30d58
[3/3] mtd: rawnand: sunxi: use a stack buffer for BBM randomization
      commit: a8596bb7148136b9e83980900d508d0ef86507ef

Patche(s) should be available on mtd/linux.git and will be
part of the next PR (provided that no robot complains by then).

Kind regards,
Miquèl