Re: [PATCH] iio: common: scmi_sensors: fix truncating 64-bit divisions
From: Andy Shevchenko
Date: Sat Oct 03 2026 - 15:27:33 EST
On Sat, Oct 03, 2026 at 11:25:55AM +0530, Arnav Kapoor wrote:
> do_div() divides a 64-bit dividend by a 32-bit divisor: the divisor is
> stored in a uint32_t on all architectures. The driver passes 64-bit
> divisors to it in several places, so they are silently truncated:
>
> - scmi_iio_set_odr_val() divides by uHz, which exceeds 32 bits for
> sampling frequencies above ~4294 Hz.
> - convert_ns_to_freq() divides by interval_ns, which exceeds 32 bits
> for update intervals of ~4.29 s and above. If its low 32 bits happen
> to be zero, this is a division by zero.
> - scmi_iio_get_odr_val(), scmi_iio_convert_interval_to_ns(),
> scmi_iio_sensor_update_cb() and scmi_iio_get_raw_available() divide
> by int_pow(10, n), which returns u64 and exceeds 32 bits for n >= 10.
> The SCMI exponent fields allow values down to -16.
>
> Truncation results in wrong sampling frequency, timestamp and
> raw_available values being reported to userspace.
>
> Use div64_u64() and div64_u64_rem(), which take a 64-bit divisor.
> Fixes: f774117c96f9 ("iio/scmi: Adding support for IIO SCMI Based Sensors")
> Reported-by: kernel test robot <lkp@xxxxxxxxx>
> Closes: https://lore.kernel.org/oe-kbuild-all/202606040245.XfmRpBhA-lkp@xxxxxxxxx/
> Assisted-by: Claude:claude-opus-5-5 coccinelle
Assisted-by: LLM coccinelle
> Signed-off-by: Arnav Kapoor <kapoorarnav43@xxxxxxxxx>
...
> tstamp_scale = sensor->sensor_info->tstamp_scale + 9;
> if (tstamp_scale < 0) {
> - do_div(time, int_pow(10, abs(tstamp_scale)));
> - time_ns = time;
> + time_ns = div64_u64(time,
> + int_pow(10, abs(tstamp_scale)));
It's fine to have 82 character single line in this case.
> } else {
> time_ns = time * int_pow(10, tstamp_scale);
> }
...
> static void convert_ns_to_freq(u64 interval_ns, u64 *hz, u64 *uhz)
> {
> - u64 rem, freq;
> + u64 rem;
>
> - freq = NSEC_PER_SEC;
Yeah... (see below)
> - rem = do_div(freq, interval_ns);
> - *hz = freq;
> - *uhz = rem * 1000000UL;
> - do_div(*uhz, interval_ns);
> + *hz = div64_u64_rem(NSEC_PER_SEC, interval_ns, &rem);
I would expect to see this be a frequency unit to help with left side of the
equation
*hz = div64_u64_rem(HZ_PER_GHZ, interval_ns, &rem);
> + *uhz = div64_u64(rem * 1000000UL, interval_ns);
And MICROHZ_PER_HZ here respectively.
> }
--
With Best Regards,
Andy Shevchenko