On Wed, 08 Jul 2026 12:06:08 +0800, Wayen Yan wrote:
> The boundary checks in airoha_clk_enable(), airoha_clk_get_rate(), and
> airoha_clk_set_rate() use "id > data->num_clocks" which allows id equal
> to num_clocks to pass. Since data->descs[] has exactly num_clocks entries
> (indices 0 to num_clocks-1), id=num_clocks results in an out-of-bounds
> array access.
>
> This is currently not triggered because the device tree clock IDs are
> within bounds, but the check should be defensive. Fix by changing the
> comparison from ">" to ">=".
>
> [...]
Applied to u-boot/main, thanks!
[1/1] clk: airoha: fix off-by-one in clock ID boundary check
commit: fdfe2ec48d5c1c2ed03073d73edd3fdd3fe1ffa1
--
Tom