From nobody Tue Sep 29 07:48:13 2026 Received: from mail-oo1-f53.google.com (mail-oo1-f53.google.com [209.85.161.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EC0A735F619 for ; Tue, 11 Aug 2026 06:02:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786428131; cv=none; b=oShLVBW/0muLdx1RoWuUUuRyKEUbt6n26kAlyQ5XKnEVr7hGFLfa5Rw43X9vYSVYSUFSNG5N8sz4+13QkRy+shqb0yVB/GdlQwo3sfwKVmypC4Kj8rd+F9qT6ydMsRT1gxsyQcfLi5OWY4xn8RL0WBUUP9UMSRY+m2lLA7AaEfw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786428131; c=relaxed/simple; bh=a+rvHOFZ/RlMQKFoJxRxWN/30vRhfT5kdAtQoaSfUx0=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=QhFfgKEd5IYeqIZj5haKtuQeFdwPiVdDtyQahsy8MhFAZGnNmNieEcwvTBwg83fSawY28coUwUPYkHLgoEH2I9YtzGrDMaJBmdsoV38U8Ydehls3/YM9zCw54zWOhMPAuBhsEEq1ZZA6NBYMQaRMOiNU7yDLAjAocjPIIOPdR0A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=lLNFhpCF; arc=none smtp.client-ip=209.85.161.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="lLNFhpCF" Received: by mail-oo1-f53.google.com with SMTP id 006d021491bc7-6acc15016f1so1541686eaf.3 for ; Mon, 10 Aug 2026 23:02:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786428129; x=1787032929; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=nvW+vlkykLKhHUV+ggRmJqGjwZhBqy5a9qXoHb1/+wE=; b=lLNFhpCF3ttoQ52wyFi9yG4gC9tEwv8ETaF3BiQze1OfDajY0tsUXwpn4QTqTEkq4I Aavrs7Y/PcYIHcY+1fQBX2iNF2gB8LDrVp8E1AUfN9oLfTQQyvK8qwc4FugqVq871/j3 cdc+Tw5z/1GbgFCmofCHU1rx0wGi1G30GlrQLe11HFNUR6/rUbqQZvdYPHAeXQqTGrFa 1J6CXJVtvAwfNS85aM1PjZWrj7FIs1ZT51WJEI2lKN+PQl0BOiAt4NIwODjdaEyk1Hed fT3qy07Lw54FKelogi0Jg1R3S7iPFrtiZMTAuy8mYnoGSXvmUtsr717LLnwkAHyGabaK fSHQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786428129; x=1787032929; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=nvW+vlkykLKhHUV+ggRmJqGjwZhBqy5a9qXoHb1/+wE=; b=oPvVMfzaZWSg/QE+FXqLmmLh2VZuip8UBhGRGLXQh/R+w2w/uNGAVvPicgASVdvNB/ HrlYJmpCrpZYMZAr1Fc6RBLwUz/rFvxgEGNQeA8/QBJaVz7hDJcbfM8co5hhwL3C1Vxc 2x/hjIASlQqjC/Cxjnmy2tMzR72CTK0zxKz+Q3HzmsdlHmtSrpfR5Ss4zj83HtXPcCdr FjPZS9pFJpyHm4YQjqthNCAvbRN6+/zAjPiKKw1Tk4pXIqk4FmpXhKumHfSo4+R32lSP Xi+Zh7EAmq3jDvI0LWesCMKHkqUlm8VNu+pucdBH0oZ61Pd6RO2KXeZkvwPtjp84kW55 /Opg== X-Forwarded-Encrypted: i=1; AHgh+RrJeYOEi/3SbPYhDg/0PTsIA0A8V1NBONiidXA9XE76RcbZaVIs5CG5rVAgaqM0xwjG4QXF0f0izCVXGLI=@vger.kernel.org X-Gm-Message-State: AOJu0Yy+DO0iEbQ8hjHQUh1p2lZ/nixuuE7/0cCj3ZW28IVhCQNAhuL1 U8ES0FA0IIuQa0YyD04uFTWlnQVseUKgF2lhQ9JDUaOa6igaDIjq3gXg X-Gm-Gg: AR+sD12QMMOAzdLvAPPKcIHtYRDpaLrGQCVK3dWLNX86eodisAbQTpPaUygmBslzzJH sbdpWn/Z56Ltxm6n8KYl4ygPlDFILD2Xm2ynNQJAlfuIKXeBXoYZAus9GPL1Vgjcxbj8YKQd9Is XgtXPSpM2qKdzz3Z4L2NyR9H0pcQ1U7BpjP4sxfrGxr30jRMw8+LSa1P4MkaVUysALraNfJNtSA tBASJCbyxLQzxF0M78DqAzSJ4bfb7ZptLOL+qLmA/5c5Q/K3pUJYfdYFnru1PZ7Y4W2dUCd2Kyu xGGrYKyz4/Q6X6bxLKqhw262xVx80W7dXo1rQcN8Yrj8H4Ae614ZoJ5YBy03dqL6EbFClDJZEn0 aP5BsxWQ5aNBX0lr5tipWmeixW4LQhk9JtdxJar9UUP7h1RPSTrjV++MSRhFHyHcb1ojvvUNhkv /7GUHGyzZWOF2l7Q6PomzEo7kSSIGS/ieeSg16kBPXRgZs5tGbJVsquKEcX7HOBwA/eOKSdWOGV I6Un01MxAY9OB4aBUNZ6ZsPv5/n6UJ8YX14wFRjronAfsoLqbdIYdf4MZllkE3dF5gdqv26o41A yOJ0pBofNEPo03eR44x6oVcAe8VR4gUJAue3bkQVimLpTuaGfacR8Hhb6mZJBJH0zzv6oinCtFK T3RZEppL/0F97YIm2i7ZEXGE7ttU= X-Received: by 2002:a05:6820:2015:b0:6b0:4d2c:1bf1 with SMTP id 006d021491bc7-6b0a2ff070amr388872eaf.11.1786428128806; Mon, 10 Aug 2026 23:02:08 -0700 (PDT) Received: from [127.0.1.1] (184-96-154-59.hlrn.qwest.net. [184.96.154.59]) by smtp.gmail.com with ESMTPSA id 006d021491bc7-6b09fa1ef9esm676004eaf.0.2026.08.10.23.02.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 23:02:07 -0700 (PDT) From: James Hilliard Date: Tue, 11 Aug 2026 00:01:59 -0600 Subject: [PATCH 1/3] mtd: rawnand: sunxi: propagate user-data allocation errors Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-sunxi-nand-protected-oob-fixes-v1-1-412e50444673@gmail.com> References: <20260811-sunxi-nand-protected-oob-fixes-v1-0-412e50444673@gmail.com> In-Reply-To: <20260811-sunxi-nand-protected-oob-fixes-v1-0-412e50444673@gmail.com> To: Miquel Raynal , Richard Weinberger , Vignesh Raghavendra , Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Richard Genoud Cc: linux-mtd@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, James Hilliard X-Mailer: b4 0.15.2 sunxi_nfc_maximize_user_data() returns -ENOMEM when its per-step length array cannot be allocated, but the caller ignores that error. The NULL array then makes sunxi_nfc_user_data_sz() report the fixed four-byte fallback, which is not the layout that the variable-length setup calculated. Return the setup error so an allocation failure cannot silently select and validate a different OOB layout. Fixes: 54dcd6aa69db ("mtd: rawnand: sunxi: introduce maximize variable user= data length") Signed-off-by: James Hilliard --- drivers/mtd/nand/raw/sunxi_nand.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/drivers/mtd/nand/raw/sunxi_nand.c b/drivers/mtd/nand/raw/sunxi= _nand.c index 45ccbce91551..108161fe10cb 100644 --- a/drivers/mtd/nand/raw/sunxi_nand.c +++ b/drivers/mtd/nand/raw/sunxi_nand.c @@ -2072,6 +2072,7 @@ static int sunxi_nand_hw_ecc_ctrl_init(struct nand_ch= ip *nand, int total_user_data_sz =3D 0; int nsectors; int ecc_mode; + int ret; int i; =20 if (nanddev->ecc.user_conf.flags & NAND_ECC_MAXIMIZE_STRENGTH) { @@ -2169,9 +2170,12 @@ static int sunxi_nand_hw_ecc_ctrl_init(struct nand_c= hip *nand, * The rationale for variable data length is to prioritize maximum ECC * strength, and then use the remaining space for user data. */ - if (nfc->caps->reg_user_data_len) - sunxi_nfc_maximize_user_data(nand, mtd->oobsize, ecc->bytes, - nsectors); + if (nfc->caps->reg_user_data_len) { + ret =3D sunxi_nfc_maximize_user_data(nand, mtd->oobsize, + ecc->bytes, nsectors); + if (ret) + return ret; + } =20 if (total_user_data_sz =3D=3D 0) for (i =3D 0; i < nsectors; i++) --=20 2.53.0 From nobody Tue Sep 29 07:48:13 2026 Received: from mail-oo1-f41.google.com (mail-oo1-f41.google.com [209.85.161.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 00EA833F8AD for ; Tue, 11 Aug 2026 06:02:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786428135; cv=none; b=AJpXX/xGnk/26TzcK7pwRexuLTNnnLnhbcbXWAxppDEqvtgmhUY8a6DChSmyqlG5UhAtt3OY42H40cImJk0RlOpNQ4SMGp6WM0MrONlvjxIb+QNbAR6yg0ZDRo2YO4po8tMQfZI9yxUeO2PbTaYDAemm8/lO2FdPSDxmGcJkwOI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786428135; c=relaxed/simple; bh=4KZsUTIpMXmhBOS4m3R6yvkvdE17tCSS42Tb/E/j4vs=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=QaMFMaVT8l9iJKS+71tecRg1aedw8iZosdNztV02gAiDiLYuWgPX3+pOyGu1jsZIGfRljPTo+9bnQ+UqCBQNB0MDex4fbMRY7+HzHmtM5qRRpHdp9hyCx1qJ2tXo60JoGtpeaR6nYA7lhs0GeOvWNz0/rjMz+ZnnDa/xk2LKSlk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=GJyn7q8f; arc=none smtp.client-ip=209.85.161.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="GJyn7q8f" Received: by mail-oo1-f41.google.com with SMTP id 006d021491bc7-6b04c0b9159so1506533eaf.3 for ; Mon, 10 Aug 2026 23:02:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786428132; x=1787032932; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=l0tAM+5Cw0fi8Tu1hyOveYDdch8B43Cz5ASbfygeqT0=; b=GJyn7q8fIEtnehx9Ia4AoNjyMtR7LMHu+CEoZMZM9QrzZ/cxPaKp+k9taNsALcTL+c pIep48dFEYPgdBXUv1XZaHvYWQEJINnurkKnqo+QMA8FaMbVIl7rwCLK8kXkmpnNQYQ+ veIgf8VicuYdUeRh9vNo7kI0ucY/whRb9XpJuaMZBXhJtazyczW2jYrrkBAjfp74RvOB G/O6mJekfEZFCSypRT+Z1OAR+8pnCLvhSMQU5np4/dp4zLEeMFlM7LJngTp9JJgtcsZI +QN34gBTRJpq5RfEWLZF5Fe15nzfK7ykm9luPhB2675/GyFib60pV6sppzQZNJCNQcCl xsFA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786428132; x=1787032932; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=l0tAM+5Cw0fi8Tu1hyOveYDdch8B43Cz5ASbfygeqT0=; b=fj9s5SDnbrlICb6w0XkQUcJEJsda5hHczsPmFWPyT/TyzpHjS8GuIYxUT4mBsjb4zl OP9duOgnq30pLoglKAnkS+jGSmaitFk5fEfnnlqmI8FgRG0eq2/vAyrv2+Vagvrda54j 8Hto6Szw+TM6A3kFtYYsv3UPy1wveIrlmzyVHaKD/tT/gnVF3CqH5d1jp10/A0NLE3Al 0sObfJ4lgEWvPBD6gIeHNXJF8awg1wRsEpWsYlip6Jij6F/4GY3JRsx3xXK4xl2nFxfh 27uTkT4nJBQQjf6bsD/i/TY59TOqh3QAaxjnq+ELMfHxADeeO7F0UIO66TPr9Lpyog9O 4s/w== X-Forwarded-Encrypted: i=1; AHgh+RoO0tL+h+v1tKOVihGeE933k4i8LqMZps4RBs2BDvu5YQsUtqvtM9S0cp0NDI/4eYmgMTXTh5EXOCEUADA=@vger.kernel.org X-Gm-Message-State: AOJu0Ywc+oDTojsWj5jm0pg+vBNvBXf1cO7MAVltCyB7AuO1wH2peyuu Tngq1qu/dRr4yOdtUfNfnSQaA5QyTyRBiVuub49nyynYlJw7DtsfsKpJ X-Gm-Gg: AR+sD10P/XiacBxIa7WwK6rGVpQTvzO283MpdaMKU///wDwI9GPkOnvoDGzXEree19t GZ4fKiMq1o8F77Qf+ukfqXD+Ffs3r+hbbo31GXxQFa/f3V45xSLv8Br6r2Ag9ArUCtiY+R9Y+96 cMpS6XXprNo7UhurPk8ty09ZDn6AGueNlCQyCNyVhbMsWulGdEY+cg8yuBPZEfTEI3ewzvhG1BJ /dkqPlC0A2hnwPto84Q5Gm9VvEkxHbbwliThR9A/ZGc1h9y/11eLxbkV2AIx5w1T6Urv5ZFggbU spi6fRkkFJfVgjZ7GHPh1JoMQgi7LewU34pr/AJ33XhhYzAL1IG3EEowgL396tjVd+FvSwPSVlX ZGXeoW+aqPHO1Xv0S9McSIs+nqSbQFPGdWwgYA9TTkrpRXRdqCCvqGkz3SlTfZNcryi6+6U5X0p MJsj1z5bnXmCglx/2yPOuXhYMsHLGOYuCG1zt4ynNeWhCV7bRg5Bxq4pI8YilsdcCRUFyjxfHEN ArXJAgE8DC/JSx3xhvBJXJ/e+sd3KifDN3mxuLCQ45si4Dx5NoORbgimkplE7n/7HE0qUYux3B7 vRHFeJLLA0PdlUPPKgQ5Ps33u0EVW4FzInwQTC0eyRDTGX93hOpGJPxG2Ufxifhig1O3KgMdOhD LkhMPbPAU9M0Gcd1v X-Received: by 2002:a05:6820:826:b0:6ac:a45e:ff84 with SMTP id 006d021491bc7-6b0a31724c1mr316204eaf.13.1786428132448; Mon, 10 Aug 2026 23:02:12 -0700 (PDT) Received: from [127.0.1.1] (184-96-154-59.hlrn.qwest.net. [184.96.154.59]) by smtp.gmail.com with ESMTPSA id 006d021491bc7-6b09fa1ef9esm676004eaf.0.2026.08.10.23.02.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 23:02:10 -0700 (PDT) From: James Hilliard Date: Tue, 11 Aug 2026 00:02:00 -0600 Subject: [PATCH 2/3] mtd: rawnand: sunxi: reserve a full user-data word for BBM Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-sunxi-nand-protected-oob-fixes-v1-2-412e50444673@gmail.com> References: <20260811-sunxi-nand-protected-oob-fixes-v1-0-412e50444673@gmail.com> In-Reply-To: <20260811-sunxi-nand-protected-oob-fixes-v1-0-412e50444673@gmail.com> To: Miquel Raynal , Richard Weinberger , Vignesh Raghavendra , Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Richard Genoud Cc: linux-mtd@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, James Hilliard X-Mailer: b4 0.15.2 H6/H616 protected user-data lengths are encoded in four-byte units, but ECC maximization reserves only the two bad block marker bytes. A strength leaving fewer than four bytes therefore selects a zero-byte first user-data section. The OOB layout then subtracts the two marker bytes from that unsigned zero length, and the controller has no protected user-data word in which to store the marker. Reserve one complete user-data word while maximizing ECC, reject configurations which produce no ECC sectors or a shorter first section, and make the OOB iterator bounds-safe. Fixes: 54dcd6aa69db ("mtd: rawnand: sunxi: introduce maximize variable user= data length") Signed-off-by: James Hilliard --- drivers/mtd/nand/raw/sunxi_nand.c | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/drivers/mtd/nand/raw/sunxi_nand.c b/drivers/mtd/nand/raw/sunxi= _nand.c index 108161fe10cb..01a0d0fa7b62 100644 --- a/drivers/mtd/nand/raw/sunxi_nand.c +++ b/drivers/mtd/nand/raw/sunxi_nand.c @@ -1991,7 +1991,7 @@ static int sunxi_nand_ooblayout_free(struct mtd_info = *mtd, int section, struct nand_chip *nand =3D mtd_to_nand(mtd); struct nand_ecc_ctrl *ecc =3D &nand->ecc; struct sunxi_nand_chip *sunxi_nand =3D to_sunxi_nand(nand); - unsigned int user_data_sz =3D sunxi_nfc_user_data_sz(sunxi_nand, section); + unsigned int user_data_sz; =20 /* * The controller does not provide access to OOB bytes @@ -2000,6 +2000,8 @@ static int sunxi_nand_ooblayout_free(struct mtd_info = *mtd, int section, if (section >=3D ecc->steps) return -ERANGE; =20 + user_data_sz =3D sunxi_nfc_user_data_sz(sunxi_nand, section); + /* * The first 2 bytes are used for BB markers, hence we * only have user_data_sz - 2 bytes available in the first user data @@ -2007,7 +2009,7 @@ static int sunxi_nand_ooblayout_free(struct mtd_info = *mtd, int section, */ if (section =3D=3D 0) { oobregion->offset =3D 2; - oobregion->length =3D user_data_sz - 2; + oobregion->length =3D user_data_sz > 2 ? user_data_sz - 2 : 0; =20 return 0; } @@ -2041,6 +2043,9 @@ static int sunxi_nfc_maximize_user_data(struct nand_c= hip *nand, uint32_t oobsize int remaining_bytes =3D oobsize - (ecc_bytes * nsectors); int i, step; =20 + if (nsectors <=3D 0) + return -EINVAL; + sunxi_nand->user_data_bytes =3D devm_kzalloc(nfc->dev, nsectors, GFP_KERNEL); if (!sunxi_nand->user_data_bytes) @@ -2056,6 +2061,8 @@ static int sunxi_nfc_maximize_user_data(struct nand_c= hip *nand, uint32_t oobsize if (sunxi_nand->user_data_bytes[step] =3D=3D 0) break; } + if (sunxi_nand->user_data_bytes[0] < USER_DATA_SZ) + return -EINVAL; =20 return 0; } @@ -2103,10 +2110,10 @@ static int sunxi_nand_hw_ecc_ctrl_init(struct nand_= chip *nand, bytes -=3D total_user_data_sz; } else { /* - * remove at least the BBM size before computing the - * max ECC + * User-data lengths are encoded in four-byte units. Reserve + * the first word because it contains the two BBM bytes. */ - bytes -=3D 2; + bytes -=3D USER_DATA_SZ; } =20 /* --=20 2.53.0 From nobody Tue Sep 29 07:48:13 2026 Received: from mail-ot1-f51.google.com (mail-ot1-f51.google.com [209.85.210.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B94135F619 for ; Tue, 11 Aug 2026 06:02:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786428139; cv=none; b=siTvdMblf0mMihv3vkLSBvVC9TCauMzryOKjy9O+8YYlHlAi01ck0INZdeurb/ibd0LIlxqqETp9pUazMrCzny6NF4HXTblUGYIdJ9kqB9blJbSt+/7tCgNaAll8BCD77I0o7cQ3ryWW+oqOll5eB/glU0naRmpop+xpuhr4mM8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786428139; c=relaxed/simple; bh=vJd7EmY2JpLzx1z3MXo9S+yfJV2YZqsQoVfHJSu+EAw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=eMF80SyalrLiY7Cb6jY6CP+6vZ0onyhK17JfuxhF4EbF0xhSZhzZeNEwAWy8JCw3rqpYXLbc+vflQ6UIB7xJ8dSFd5rTGO2nd+Nwh5nO/PM4ciAeskT/stfVKPFefv1Jdziv+cuxcTzLFtRvUXzCgKMfE/w0aWC+p3OIvUP4xq8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=IlfNKSnV; arc=none smtp.client-ip=209.85.210.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="IlfNKSnV" Received: by mail-ot1-f51.google.com with SMTP id 46e09a7af769-7e6b5737bb2so2779718a34.1 for ; Mon, 10 Aug 2026 23:02:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786428137; x=1787032937; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NhlS5DCvXMRcCc3UaPNyrbXwvBz9PYUN+5lwYOhBUzE=; b=IlfNKSnVEOww7SqXZuJ+zwGqmObqYk9DKDKveDjl/uun9cldVFGLCNe6xdvieR3NZz YjDwsY0Qfp9xjbTxhOQku3wSrS+tbqRnZFXq232oUwLdwljwAZ/BqzxAD0CuSBShhXqh 0yR+scm5vmqL1kUHPiRJn10mDdMYLUKE7m99xdeJduzU1O5eBjT1lwMB3T8yzVlKiCNw 6Hoyp2X6lJf2Cl1gDiL3lj9WTs2PISJ3uWSwWzHT3jfqncXpqN5z++gUPFgB2x3GAYqZ xQ9KV5C2lgVWuRuGXFFFRAsvVYkgE0nWiOVMs6s8ZTueawJENxjHzEQX635trELv/Ee2 thcA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786428137; x=1787032937; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=NhlS5DCvXMRcCc3UaPNyrbXwvBz9PYUN+5lwYOhBUzE=; b=P6kdthP3VVyi7bkL1rZgVz8/V8wbv3a1sad/0xP+NxpSWYuq0byUNmS6SYBPgR28JG /VwSGKL2J4nRrAqDUbTMwvnnjUti9gSKeRZLlbHZJLFlgzgzcVBFvQiYYrUZFTTxH+CT 20fD9CUS9GEaYgUQQRm552S7t74yV5fyC4H7CqUhENU6xTR3W/DQTNOiRnUYJAgkWtxa bpsohaCMd+SWb2/CKZE/YvU43oRlG6/upXCloEp+J20Hww6ihZYeui8TKGcQFuXnDmq3 MJmFewm7HrJ9mdNvXcsWlpi8CEDdPVVe9XSBFiC9qck2s4S1MXDMHpYP3kQHq1o8agL3 moGA== X-Forwarded-Encrypted: i=1; AHgh+Rpo9yvE1ddUyfwQILz3PCaQTK4+lRAGKk4ph6xKmc1CNk0NBSZ21g5WGjF5XWTwQO5tQglscKMflj46t54=@vger.kernel.org X-Gm-Message-State: AOJu0YyDA3peFiuLf1dFWxArzgEpIYEnQg5j4x1gmogtVRpIcE/nkWaa yccufvsYCvKh8SeTVlCC8as3GN0b3NW8oA+ly3VM+5Jgbk7LsOe5uEda X-Gm-Gg: AR+sD10mllhEQAUSa0xI9lZX/3i9JfQUcLe7WB9kFw+zrn5QcK8rA/+GwHzucKitTku GMqFBeKZYwtuv0d8wyQ6ahObCs8cDDpDhFHRhqPcPUfmKc4plXvnF1TxyPDAleeqaS8OcZXUZh/ ump/0ZhX0xXX9roZLECUsmiQ5c1r5IYDorUPG0kXmE7UJRZimnFC5r6JFeDGSiYCMGeEh3j1RX8 6qhM8v9TSK2IbE3J97o1Jc0+CvMpOFZZfyO7M+RmJztUXuU5BesREXTGtlVoZXPRKB19YVptdsb Q4Yk3HoVh++x8qpxI/1JtgdciG2c0DCGiPWfu+cCx8cVtqEa6p4Esf+/zrGh6krtj/HsrN/Nn1M wmJErhjpkLoCh0Fz+rVzUEbeyazwwbkXSr1pelcsNnGT1FvkWIXULz4KK4YTpRCEQV5H8V9YVdD 4ALZSqe+h1fKvJ2JueilyR66zOHT5hEpKTEsFm3HiMEtYmtlYXk38g+u1Pr2VOxSdb8Nk41UATb FJ+fgWdL5tdWxIXrC82DtN60GaFEeJB6tNop5G0KOuU7ClEn9aPDsfxbkrZd4dmBOYkIdilDjox Iv9TCXmgyc6E8b+i+nbaPOVyQd8F3mPwMcOcunQhc6aQxxEw/Ak+j52eFkelflTyGaFJDA9ZMpA JACCX29cxi47SdmURTBw7jDUD2rw= X-Received: by 2002:a05:6820:198f:b0:6aa:d792:e078 with SMTP id 006d021491bc7-6b0a31e2b23mr332881eaf.27.1786428137224; Mon, 10 Aug 2026 23:02:17 -0700 (PDT) Received: from [127.0.1.1] (184-96-154-59.hlrn.qwest.net. [184.96.154.59]) by smtp.gmail.com with ESMTPSA id 006d021491bc7-6b09fa1ef9esm676004eaf.0.2026.08.10.23.02.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 23:02:13 -0700 (PDT) From: James Hilliard Date: Tue, 11 Aug 2026 00:02:01 -0600 Subject: [PATCH 3/3] mtd: rawnand: sunxi: use a stack buffer for BBM randomization Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-sunxi-nand-protected-oob-fixes-v1-3-412e50444673@gmail.com> References: <20260811-sunxi-nand-protected-oob-fixes-v1-0-412e50444673@gmail.com> In-Reply-To: <20260811-sunxi-nand-protected-oob-fixes-v1-0-412e50444673@gmail.com> To: Miquel Raynal , Richard Weinberger , Vignesh Raghavendra , Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Richard Genoud Cc: linux-mtd@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, James Hilliard X-Mailer: b4 0.15.2 Variable protected user-data lengths replaced the original four-byte stack buffer with a heap allocation before compensating the bad block marker. The allocation is unchecked, and a zero length returns ZERO_SIZE_PTR which sunxi_nfc_randomize_bbm() dereferences. The controller supports at most 32 protected user-data bytes per ECC step, so use a zero-initialized buffer of that bounded size. This removes the allocation failure path and keeps zero-sized invalid layouts from dereferencing ZERO_SIZE_PTR. Fixes: 54dcd6aa69db ("mtd: rawnand: sunxi: introduce maximize variable user= data length") Signed-off-by: James Hilliard --- drivers/mtd/nand/raw/sunxi_nand.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/drivers/mtd/nand/raw/sunxi_nand.c b/drivers/mtd/nand/raw/sunxi= _nand.c index 01a0d0fa7b62..83666dd6cb2a 100644 --- a/drivers/mtd/nand/raw/sunxi_nand.c +++ b/drivers/mtd/nand/raw/sunxi_nand.c @@ -222,6 +222,7 @@ * USER_DATA_LEN registers. */ #define USER_DATA_SZ 4 +#define SUNXI_NFC_MAX_USER_DATA_SZ 32 =20 /** * struct sunxi_nand_chip_sel - stores information related to NAND Chip Se= lect @@ -1003,11 +1004,10 @@ static void sunxi_nfc_hw_ecc_set_prot_oob_bytes(str= uct nand_chip *nand, struct sunxi_nfc *nfc =3D to_sunxi_nfc(nand->controller); struct sunxi_nand_chip *sunxi_nand =3D to_sunxi_nand(nand); unsigned int user_data_sz =3D sunxi_nfc_user_data_sz(sunxi_nand, step); - u8 *user_data =3D NULL; + u8 user_data[SUNXI_NFC_MAX_USER_DATA_SZ] =3D {}; =20 /* Randomize the Bad Block Marker. */ if (bbm && (nand->options & NAND_NEED_SCRAMBLING)) { - user_data =3D kmalloc(user_data_sz, GFP_KERNEL); memcpy(user_data, oob, user_data_sz); sunxi_nfc_randomize_bbm(nand, page, user_data); oob =3D user_data; @@ -1040,7 +1040,6 @@ static void sunxi_nfc_hw_ecc_set_prot_oob_bytes(struc= t nand_chip *nand, } } =20 - kfree(user_data); } =20 static void sunxi_nfc_hw_ecc_update_stats(struct nand_chip *nand, --=20 2.53.0