]> git.ipfire.org Git - thirdparty/u-boot.git/commitdiff
mmc: rpmb: fix tautological condition in RPMB_REQ_READ_DATA validation
authorPeng Fan <peng.fan@nxp.com>
Mon, 13 Jul 2026 13:32:53 +0000 (21:32 +0800)
committerPeng Fan <peng.fan@nxp.com>
Wed, 29 Jul 2026 03:15:55 +0000 (11:15 +0800)
In rpmb_route_frames(), the RPMB_REQ_READ_DATA case checks
"req_cnt != 1 || !req_cnt" which is tautological -- !req_cnt (req_cnt
== 0) is always a subset of req_cnt != 1. The second operand is dead
code.

Based on the pattern of all other cases in the switch (RPMB_REQ_KEY,
RPMB_REQ_WRITE_DATA, RPMB_REQ_WCOUNTER) which validate rsp_cnt, this
was meant to be "req_cnt != 1 || !rsp_cnt". Without this fix, a caller
could pass rsp_cnt=0 for a read request without validation.

Signed-off-by: Peng Fan <peng.fan@nxp.com>
drivers/mmc/rpmb.c

index 8bfdffd56f58575703a4a8ff25e803389f55afe2..26d2262ef45fb0ad83194faa266537812cc1432c 100644 (file)
@@ -452,7 +452,7 @@ static int rpmb_route_frames(struct mmc *mmc, struct s_rpmb *req,
                return rpmb_route_read_req(mmc, req, req_cnt, rsp, rsp_cnt);
 
        case RPMB_REQ_READ_DATA:
-               if (req_cnt != 1 || !req_cnt)
+               if (req_cnt != 1 || !rsp_cnt)
                        return -EINVAL;
                return rpmb_route_read_req(mmc, req, req_cnt, rsp, rsp_cnt);