[PATCH] iio: humidity: am2315: fix negative temperature decoding

From: Vidhu Sarwal

Date: Mon Sep 28 2026 - 10:30:52 EST


The AM2315/AM2320 report temperature as a sign-magnitude value,
with bit 15 as the sign and bits 14-0 as the magnitude.
am2315_read_data() stores the raw value directly in an s16, causing
negative temperatures to be interpreted as two's complement. Both the
read_raw and the triggered buffer paths are affected.

Decode the sign bit before storing the temperature value. Positive
readings are unaffected.

Fixes: 366a3270c1c5 ("iio: humidity: Add support for AM2315")
Signed-off-by: Vidhu Sarwal <vidhu.linux@xxxxxxxxx>
---
Other implementations [1] [2] for the same sensor have hit this bug when the
sensor was placed in a freezer, although neither is kernel code.
[1] https://github.com/adafruit/Adafruit_CircuitPython_AM2320/issues/1
[2] https://github.com/letscontrolit/ESPEasy/issues/307

drivers/iio/humidity/am2315.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/drivers/iio/humidity/am2315.c b/drivers/iio/humidity/am2315.c
index f29baa251f9f..31c4f52a0108 100644
--- a/drivers/iio/humidity/am2315.c
+++ b/drivers/iio/humidity/am2315.c
@@ -113,6 +113,7 @@ static int am2315_read_data(struct am2315_data *data,
*/
u8 rx_buf[8];
u16 crc;
+ u16 temp_raw;

/* First wake up the device. */
am2315_ping(data->client);
@@ -144,8 +145,15 @@ static int am2315_read_data(struct am2315_data *data,

sensor_data->hum_data = (rx_buf[AM2315_HUM_OFFSET] << 8) |
rx_buf[AM2315_HUM_OFFSET + 1];
- sensor_data->temp_data = (rx_buf[AM2315_TEMP_OFFSET] << 8) |
- rx_buf[AM2315_TEMP_OFFSET + 1];
+
+ /*
+ * Temperature is sign-magnitude, not two's complement:
+ * bit 15 is the sign, bits 14-0 are the magnitude (x0.1 degC).
+ */
+ temp_raw = (rx_buf[AM2315_TEMP_OFFSET] << 8) |
+ rx_buf[AM2315_TEMP_OFFSET + 1];
+ sensor_data->temp_data = (temp_raw & 0x8000) ?
+ -(temp_raw & 0x7fff) : temp_raw;

return ret;

--
2.53.0