drivers/rtc/rtc-mpfs.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-)
devm_clk_get(&pdev->dev, "rtcref")'s return value was passed straight
into clk_get_rate() without checking it for an error first, unlike the
"rtc" clock a few lines above which is correctly checked with
IS_ERR(). clk_get_rate() only guards against a NULL clk, not an error
pointer:
if (!clk)
return 0;
...
rate = clk_core_get_rate_recalc(clk->core);
so if devm_clk_get() ever returns an error pointer here (for example
ERR_PTR(-EPROBE_DEFER), which is the normal, expected outcome if the
clkcfg clock-provider this RTC depends on has not registered its
clocks yet by the time this driver probes), clk_get_rate() dereferences
that error pointer instead of returning 0, crashing instead of letting
probe defer.
Capture the clock in the existing 'clk' local and check it with
IS_ERR() before calling clk_get_rate(), matching the handling already
used for the "rtc" clock in this same function.
Signed-off-by: Manush Prajwal <manushprajwal555@gmail.com>
---
drivers/rtc/rtc-mpfs.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/rtc/rtc-mpfs.c b/drivers/rtc/rtc-mpfs.c
index ece6de4a6..60596b0ea 100644
--- a/drivers/rtc/rtc-mpfs.c
+++ b/drivers/rtc/rtc-mpfs.c
@@ -256,8 +256,12 @@ static int mpfs_rtc_probe(struct platform_device *pdev)
return ret;
}
+ clk = devm_clk_get(&pdev->dev, "rtcref");
+ if (IS_ERR(clk))
+ return PTR_ERR(clk);
+
/* prescaler hardware adds 1 to reg value */
- prescaler = clk_get_rate(devm_clk_get(&pdev->dev, "rtcref")) - 1;
+ prescaler = clk_get_rate(clk) - 1;
if (prescaler > MAX_PRESCALER_COUNT) {
dev_dbg(&pdev->dev, "invalid prescaler %lu\n", prescaler);
return -EINVAL;
--
2.46.2.windows.1
On Sun, 06 Sep 2026 16:44:09 +0530, Manush Prajwal wrote:
> devm_clk_get(&pdev->dev, "rtcref")'s return value was passed straight
> into clk_get_rate() without checking it for an error first, unlike the
> "rtc" clock a few lines above which is correctly checked with
> IS_ERR(). clk_get_rate() only guards against a NULL clk, not an error
> pointer:
>
> if (!clk)
> return 0;
> ...
> rate = clk_core_get_rate_recalc(clk->core);
>
> [...]
Applied, thanks!
[1/1] rtc: mpfs: fix unchecked devm_clk_get() error pointer in probe()
https://git.kernel.org/abelloni/c/ac41b05d15db
Best regards,
--
Alexandre Belloni, co-owner and COO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
On Sun, Sep 06, 2026 at 04:44:09PM +0530, Manush Prajwal wrote:
> devm_clk_get(&pdev->dev, "rtcref")'s return value was passed straight
> into clk_get_rate() without checking it for an error first, unlike the
> "rtc" clock a few lines above which is correctly checked with
> IS_ERR(). clk_get_rate() only guards against a NULL clk, not an error
> pointer:
>
> if (!clk)
> return 0;
> ...
> rate = clk_core_get_rate_recalc(clk->core);
>
> so if devm_clk_get() ever returns an error pointer here (for example
> ERR_PTR(-EPROBE_DEFER), which is the normal, expected outcome if the
> clkcfg clock-provider this RTC depends on has not registered its
> clocks yet by the time this driver probes), clk_get_rate() dereferences
> that error pointer instead of returning 0, crashing instead of letting
> probe defer.
>
> Capture the clock in the existing 'clk' local and check it with
> IS_ERR() before calling clk_get_rate(), matching the handling already
> used for the "rtc" clock in this same function.
>
> Signed-off-by: Manush Prajwal <manushprajwal555@gmail.com>
Fixes: 0b31d703598d ("rtc: Add driver for Microchip PolarFire SoC")
CC: stable@vger.kernel.org
Reviewed-by: Conor Dooley <conor.dooley@microchip.com>
> ---
> drivers/rtc/rtc-mpfs.c | 6 +++++-
> 1 file changed, 5 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/rtc/rtc-mpfs.c b/drivers/rtc/rtc-mpfs.c
> index ece6de4a6..60596b0ea 100644
> --- a/drivers/rtc/rtc-mpfs.c
> +++ b/drivers/rtc/rtc-mpfs.c
> @@ -256,8 +256,12 @@ static int mpfs_rtc_probe(struct platform_device *pdev)
> return ret;
> }
>
> + clk = devm_clk_get(&pdev->dev, "rtcref");
> + if (IS_ERR(clk))
> + return PTR_ERR(clk);
> +
> /* prescaler hardware adds 1 to reg value */
> - prescaler = clk_get_rate(devm_clk_get(&pdev->dev, "rtcref")) - 1;
> + prescaler = clk_get_rate(clk) - 1;
> if (prescaler > MAX_PRESCALER_COUNT) {
> dev_dbg(&pdev->dev, "invalid prescaler %lu\n", prescaler);
> return -EINVAL;
> --
> 2.46.2.windows.1
>
>
© 2016 - 2026 Red Hat, Inc.