Re: [PATCH v7 1/2] serial: core: fix baud rate fallback in uart_get_baud_rate()
From: Greg Kroah-Hartman
Date: Thu Oct 01 2026 - 05:44:37 EST
On Wed, Sep 30, 2026 at 12:59:00PM +0000, Hui Peng wrote:
> When uart_get_baud_rate() is called with a baud rate exceeding the port's
> maximum supported speed (port->uartclk / 16), it clips baud to [min,
> max - 1] and encodes it into termios via tty_termios_encode_baud_rate().
>
> However, because the loop bound is for (try = 0; try < 2; try++), the
> loop terminates immediately after try == 1 without re-evaluating
But try == 1 should keep the loop going as it is < 2, right? What am I
missing here? Do I need more coffee?
> baud = tty_termios_baud_rate(termios) for the clipped rate, hitting
> WARN_ON(1) and returning 0, which then triggers a fatal divide-by-zero
> (Oops: divide error) in uart_get_divisor():
>
> WARNING: drivers/tty/serial/serial_core.c:548 at uart_get_baud_rate+0x136/0x260
> [ ... ]
> divide error: 0000 [#1] PREEMPT SMP KASAN
>
> Increase the retry count in uart_get_baud_rate() from 2 to 3 iterations so
> that clipped baud rates are re-evaluated in the third iteration.
What is the magic 2 here, and why turning it into a magic 3 somehow fix
things?
thanks,
greg k-h