[PATCH v2 0/5] firmware/clk: arm_scpi hardening (leak, OPP bounds, cpufreq)

From: Xixin Liu

Date: Mon Jul 27 2026 - 23:12:26 EST


Hi Sudeep,

Thanks for reviewing v1.

This v2 hardens the OF SCPI firmware and clock paths against a few
real defects found while reviewing linux-next:

1) device_node leak in scpi_dev_domain_id() after
of_parse_phandle_with_args()
2) DVFS OPP count from SCP trusted beyond MAX_DVFS_OPPS (OOB read /
bad OPP table size)
3) DVFS index used as clock rate without an upper bound check
4) scpi-cpufreq registered once only, and cleared on register failure
so remove() does not unregister an ERR_PTR
5) use PLATFORM_DEVID_NONE instead of bare -1 for the scpi-cpufreq
platform device id (readability; Fixes the original registration)

Changes since v1:
- 2/5: add Fixes: 8cb7cf56c9fe ("firmware: add support for ARM System
Control and Power Interface(SCPI) protocol")
- 3/5: add Fixes: cd52c2a4b5c4 ("clk: add support for clocks provided by
SCP(System Control Processor)")
- 4/5: correct commit message (scpi_clocks_probe; multi-DVFS child
overwrites the first good cpufreq_dev with ERR_PTR(-EEXIST)) and
add Fixes: 9490f01e2471 / 67bcc2c5f1da
All per maintainer feedback; code unchanged.
- add 5/5: clk: scpi: use PLATFORM_DEVID_NONE for scpi-cpufreq
(readability; Fixes: 9490f01e2471)
- Rebased onto linux-next next-20260727 (0d33d21e47d9); 2/5 context
updated for kmalloc_obj() (logic unchanged).

Please review.

Thanks,
Xixin Liu

---

Xixin Liu (5):
firmware: arm_scpi: fix device_node leak in scpi_dev_domain_id
firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
clk: scpi: register scpi-cpufreq once and clear on failure
clk: scpi: use PLATFORM_DEVID_NONE for scpi-cpufreq

drivers/clk/clk-scpi.c | 10 ++++++++--
drivers/firmware/arm_scpi.c | 9 ++++++---
2 files changed, 13 insertions(+), 6 deletions(-)

--
2.53.0