]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
thunderbolt: Fix bandwidth group reservation indexing
authorXu Rao <raoxu@uniontech.com>
Wed, 24 Jun 2026 06:27:03 +0000 (14:27 +0800)
committerMika Westerberg <mika.westerberg@linux.intel.com>
Mon, 27 Jul 2026 09:58:54 +0000 (11:58 +0200)
Valid bandwidth group IDs range from 1 through MAX_GROUPS, while Group
ID 0 is reserved. tb_consumed_dp_bandwidth() uses the Group ID directly
to index its local group_reserved[] array.

The array currently has MAX_GROUPS entries, so its valid indices are 0
through MAX_GROUPS - 1. Group ID MAX_GROUPS therefore accesses one
element past the end, and the final group's reserved bandwidth is not
included when the array is summed.

Give group_reserved[] MAX_GROUPS + 1 entries so direct Group ID
indexing covers the reserved ID 0 and valid IDs 1 through MAX_GROUPS.

Fixes: 52a4490e89d7 ("thunderbolt: Reserve released DisplayPort bandwidth for a group for 10 seconds")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
drivers/thunderbolt/tb.c

index 76323255439a88ffecf78e59e467f8e1de124e3e..f43f2d952372c6180f51d4d216b56936bcbaa9ee 100644 (file)
@@ -609,7 +609,7 @@ static int tb_consumed_dp_bandwidth(struct tb *tb,
                                    int *consumed_up,
                                    int *consumed_down)
 {
-       int group_reserved[MAX_GROUPS] = {};
+       int group_reserved[MAX_GROUPS + 1] = {};
        struct tb_cm *tcm = tb_priv(tb);
        struct tb_tunnel *tunnel;
        bool downstream;