[PATCH v14 3/4] clk: scmi: reject SSC configuration out of the OEM field range

From: Dario Binacchi

Date: Fri Sep 04 2026 - 06:43:42 EST


The i.MX SCMI OEM extension stores the spread in an 8-bit field, in
tenths of a percent, and the modulation frequency in a 16-bit field.

FIELD_PREP() silently truncates values that do not fit in the target
field. Moreover, the conversion from permyriad to tenths of a percent
turns values below 10 permyriad into zero, which is then passed to the
firmware as no spread at all.

Reject these cases with a warning instead of silently programming a
configuration different from the requested one.

A request with no spread method disables SSC, so send a zeroed
configuration to the firmware in that case, without checking the
spread and the modulation frequency, which are meaningless then.

Signed-off-by: Dario Binacchi <dario.binacchi@xxxxxxxxxxxxxxxxxxxx>

---

Changes in v14:
- Send a zeroed configuration when no spread method is requested,
instead of rejecting it, so that SSC can still be disabled.

Changes in v13:
- New patch

drivers/clk/clk-scmi-oem.c | 25 ++++++++++++++++++++++---
1 file changed, 22 insertions(+), 3 deletions(-)

diff --git a/drivers/clk/clk-scmi-oem.c b/drivers/clk/clk-scmi-oem.c
index c1ebbdc6bbc5..29acd2923fd6 100644
--- a/drivers/clk/clk-scmi-oem.c
+++ b/drivers/clk/clk-scmi-oem.c
@@ -35,19 +35,38 @@ scmi_clk_imx_set_spread_spectrum(struct clk_hw *hw,
const struct clk_spread_spectrum *ss_conf)
{
struct scmi_clk *clk = to_scmi_clk(hw);
+ u32 spread_pm = ss_conf->spread_bp / 10;
int ret;
u32 val;

+ if (ss_conf->method == CLK_SPREAD_NO) {
+ val = 0;
+ goto oem_set;
+ }
+
/*
* extConfigValue[7:0] - spread percentage in tenths of a percent
* extConfigValue[23:8] - Modulation Frequency
* extConfigValue[24] - Enable/Disable
* extConfigValue[31:25] - Reserved
*/
- val = FIELD_PREP(SCMI_CLOCK_IMX_SS_PERCENTAGE_MASK, ss_conf->spread_bp / 10);
+ if (!spread_pm || spread_pm > FIELD_MAX(SCMI_CLOCK_IMX_SS_PERCENTAGE_MASK)) {
+ dev_warn(clk->dev, "%s: spread (%u permyriad) out of range\n",
+ clk_hw_get_name(hw), ss_conf->spread_bp);
+ return -EINVAL;
+ }
+
+ if (ss_conf->modfreq_hz > FIELD_MAX(SCMI_CLOCK_IMX_SS_MOD_FREQ_MASK)) {
+ dev_warn(clk->dev, "%s: modulation frequency (%u Hz) out of range\n",
+ clk_hw_get_name(hw), ss_conf->modfreq_hz);
+ return -EINVAL;
+ }
+
+ val = FIELD_PREP(SCMI_CLOCK_IMX_SS_PERCENTAGE_MASK, spread_pm);
val |= FIELD_PREP(SCMI_CLOCK_IMX_SS_MOD_FREQ_MASK, ss_conf->modfreq_hz);
- if (ss_conf->method != CLK_SPREAD_NO)
- val |= SCMI_CLOCK_IMX_SS_ENABLE_MASK;
+ val |= SCMI_CLOCK_IMX_SS_ENABLE_MASK;
+
+oem_set:
ret = scmi_proto_clk_ops->config_oem_set(clk->ph, clk->id,
SCMI_CLOCK_CFG_IMX_SSC,
val, false);
--
2.43.0