From c404d8ddf71bd422dc670a884ecd838b29ce3c3f Mon Sep 17 00:00:00 2001 From: Alexander Winkowski Date: Thu, 14 May 2026 19:56:04 +0000 Subject: [PATCH] disp: msm: Avoid UB in VBIF register shift calculation Left-shifting a 32-bit integer by 32 bits or more results in UB. The common values for vbif_xin_id[] are {10, 11} which means reg_shift becomes 40/44. For IDs >= 8, the shift is meant to be relative to the second 32-bit register, not to the first. Fix this issue by masking the ID so that it will properly describe the intended shift. Change-Id: Icd530a3bb7cfd9d087e2aecc763d24f775e20466 Signed-off-by: Alexander Winkowski --- techpack/display/rotator/sde_rotator_r3.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/techpack/display/rotator/sde_rotator_r3.c b/techpack/display/rotator/sde_rotator_r3.c index b1e2f15a4b84..f36c0ce6ce7c 100644 --- a/techpack/display/rotator/sde_rotator_r3.c +++ b/techpack/display/rotator/sde_rotator_r3.c @@ -1419,14 +1419,14 @@ static void sde_hw_rotator_vbif_rt_setting(void) for (j = 0; j < MAX_XIN; j++) { reg_high = ((mdata->vbif_xin_id[j] & 0x8) >> 3) * 4 + (i * 8); - reg_shift = mdata->vbif_xin_id[j] * 4; + reg_shift = (mdata->vbif_xin_id[j] & 0x7) * 4; reg_val = SDE_VBIF_READ(mdata, MMSS_VBIF_NRT_VBIF_QOS_RP_REMAP_000 + reg_high); reg_val_lvl = SDE_VBIF_READ(mdata, MMSS_VBIF_NRT_VBIF_QOS_LVL_REMAP_000 + reg_high); - mask = 0x7 << (mdata->vbif_xin_id[j] * 4); + mask = 0x7 << reg_shift; vbif_qos = mdata->vbif_nrt_qos[i];