[PATCH v2 1/2] iio: adc: ti-ads112c14: fix negative settlingtime check
From: David Lechner (TI)
Date: Fri Oct 09 2026 - 18:27:45 EST
Fix checking for negative values when writing the settlingtime
attribute. MICRO is an unsigned long, so on 32-bit architectures,
integer * MICRO is evaluated as a 32-bit unsigned value. A negative
integer part is then zero-extended to a positive s64 and passes the
< 0 check. Large positive values can also wrap around.
Reject negative input before doing the multiplication and do the
multiplication as 64-bit.
Fixes: 839cbb1e2331 ("iio: adc: ti-ads112c14: add settlingtime attribute")
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Closes: https://sashiko.dev/#/message/20260910-iio-adc-ti-ads112c14-filter-support-v3-9-e5a9b27ddb1a%40baylibre.com
Signed-off-by: David Lechner (TI) <dlechner@xxxxxxxxxxxx>
---
drivers/iio/adc/ti-ads112c14.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/iio/adc/ti-ads112c14.c b/drivers/iio/adc/ti-ads112c14.c
index 3c877126b0be..d8fa8d413e87 100644
--- a/drivers/iio/adc/ti-ads112c14.c
+++ b/drivers/iio/adc/ti-ads112c14.c
@@ -653,7 +653,7 @@ static int ads112c14_get_settling_time_us(struct ads112c14_data *data,
static int ads112c14_find_delay_for_settling_time_us(struct ads112c14_data *data,
struct ads112c14_channel_state *channel_state,
- s64 settling_time_us, u8 *delay)
+ u64 settling_time_us, u8 *delay)
{
u64 delay_us, delay_tmod_needed;
u32 fixed_latency_us;
@@ -719,7 +719,7 @@ static ssize_t ads112c14_write_settling_time(struct iio_dev *indio_dev,
{
struct ads112c14_data *data = iio_priv(indio_dev);
struct ads112c14_channel_state *channel_state;
- s64 settling_time_us;
+ u64 settling_time_us;
int integer;
int fract;
u8 delay;
@@ -729,10 +729,11 @@ static ssize_t ads112c14_write_settling_time(struct iio_dev *indio_dev,
if (ret)
return ret;
- settling_time_us = integer * MICRO + fract;
- if (settling_time_us < 0)
+ if (integer < 0 || fract < 0)
return -EINVAL;
+ settling_time_us = (u64)integer * MICRO + fract;
+
IIO_DEV_ACQUIRE_DIRECT_MODE(indio_dev, claim);
if (IIO_DEV_ACQUIRE_FAILED(claim))
return -EBUSY;
--
2.53.0