@samitouri / QOSamiQemu / commits / 56bd07a859

hw/i3c/dw-i3c: Fix uninitialized data use in short transfer

Coverity reports that dw_i3c_short_transfer() may pass an uninitialized buffer to dw_i3c_send(). The immediate cause is the use of `data[len] += arg.byte0`, which reads from an uninitialized element of the buffer. Replace this with a simple assignment. Additionally, avoid calling dw_i3c_send() when the constructed payload length is zero. In that case the transfer has no data phase, so the controller can transition to the idle state directly. This resolves the Coverity UNINIT warning and clarifies the handling of zero-length short transfers. Resolves: Coverity CID 1645555 Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com> Reviewed-by: Nabih Estefan <nabihestefan@google.com> Reviewed-by: Cédric Le Goater <clg@redhat.com> Message-ID: <20260311021319.1053774-1-jamin_lin@aspeedtech.com> Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>

Jamin Lin committed Mar 11, 2026 at 02:13 UTC 56bd07a8594795d40e781124512cd4e72ba2fbee
1 file changed +10 -4
hw/i3c/dw-i3c.c
+10 -4
@@ -1213,7 +1213,7 @@ static void dw_i3c_short_transfer(DWI3C *s, DWI3CTransferCmd cmd,
1213 * ignored.
1214 */
1215 if (cmd.dbp) {
1216 - data[len] += arg.byte0;
1216 + data[len] = arg.byte0;
1217 len++;
1218 }
1219 }
@@ -1228,10 +1228,16 @@ static void dw_i3c_short_transfer(DWI3C *s, DWI3CTransferCmd cmd,
1228 len++;
1229 }
1230
1231 - if (dw_i3c_send(s, data, len, &bytes_sent, is_i2c)) {
1232 - err = DW_I3C_RESP_QUEUE_ERR_I2C_NACK;
1231 + if (len > 0) {
1232 + if (dw_i3c_send(s, data, len, &bytes_sent, is_i2c)) {
1233 + err = DW_I3C_RESP_QUEUE_ERR_I2C_NACK;
1234 + } else {
1235 + /* Only go to an idle state on a successful transfer. */
1236 + ARRAY_FIELD_DP32(s->regs, PRESENT_STATE, CM_TFR_ST_STATUS,
1237 + DW_I3C_TRANSFER_STATE_IDLE);
1238 + }
1239 } else {
1234 - /* Only go to an idle state on a successful transfer. */
1240 + /* No payload bytes for this short transfer. */
1241 ARRAY_FIELD_DP32(s->regs, PRESENT_STATE, CM_TFR_ST_STATUS,
1242 DW_I3C_TRANSFER_STATE_IDLE);
1243 }