[PATCH] mtd: spi-nor: reduce stack usage in spi_nor_parse_sfdp()

Michael Walle mwalle at kernel.org
Mon Sep 21 02:24:33 PDT 2026


On Mon Sep 21, 2026 at 10:59 AM CEST, David Laight wrote:
> On Mon, 21 Sep 2026 09:55:37 +0200
> "Michael Walle" <mwalle at kernel.org> wrote:
>
>> Hi Arnd,
>> 
>> On Tue Sep 15, 2026 at 9:40 PM CEST, Arnd Bergmann wrote:
>> > From: Arnd Bergmann <arnd at arndb.de>
>> >
>> > Two large spi_nor_flash_parameter structures on a function stack
>> > is really too much, and this can exceed an otherwise reasonable
>> > frame limit:
>> >
>> > drivers/mtd/spi-nor/sfdp.c: In function 'spi_nor_parse_sfdp':
>> > drivers/mtd/spi-nor/sfdp.c:1717:1: error: the frame size of 1600 bytes is larger than 1536 bytes [-Werror=frame-larger-than=]
>> >
>> > Change one of them to a dynamic allocation to make this more reasonable.  
>> 
>> Thanks for taking care of that. Will you respin the patch with what
>> David suggested?
>
> This compiles...
> David
>
> diff --git a/drivers/mtd/spi-nor/sfdp.c b/drivers/mtd/spi-nor/sfdp.c
> index 641f17ad51a0..cec699b52f27 100644
> --- a/drivers/mtd/spi-nor/sfdp.c
> +++ b/drivers/mtd/spi-nor/sfdp.c
> @@ -1519,9 +1519,9 @@ int spi_nor_check_sfdp_signature(struct spi_nor *nor)
>   */
>  int spi_nor_parse_sfdp(struct spi_nor *nor)
>  {
> +       struct spi_nor_flash_parameter sv_params __free(kfree) = kmalloc_objs(*sv_params, 2);

What does sv_ stands for?

>         const struct sfdp_parameter_header *param_header, *bfpt_header;
>         struct sfdp_parameter_header *param_headers = NULL;
> -       struct spi_nor_flash_parameter params, params2;
>         struct sfdp_header header;
>         struct device *dev = nor->dev;
>         struct sfdp *sfdp;
> @@ -1533,7 +1533,9 @@ int spi_nor_parse_sfdp(struct spi_nor *nor)
>          * Get a backup of all the parameter to roll back to in case of an
>          * error.
>          */
> -       memcpy(&params, nor->params, sizeof(params));
> +       if (!sv_params)
> +               return -ENOMEM
> +       sv_params[0] = nor->params;
>
>         /* Get the SFDP header. */
>         err = spi_nor_read_sfdp_dma_unsafe(nor, 0, sizeof(header), &header);
> @@ -1653,7 +1655,7 @@ int spi_nor_parse_sfdp(struct spi_nor *nor)
>
>         /* Parse optional parameter tables. */
>         for (i = 0; i < header.nph; i++) {
> -               memcpy(&params2, nor->params, sizeof(params2));
> +               sv_params[1] nor->params;

sv_params[1] = nor->params;

-michael

>                 param_header = &param_headers[i];
>
>                 switch (SFDP_PARAM_HEADER_ID(param_header)) {
> @@ -1691,7 +1693,7 @@ int spi_nor_parse_sfdp(struct spi_nor *nor)
>                          * spi_nor_flash_parameter data.
>                          */
>                         err = 0;
> -                       memcpy(nor->params, &params2, sizeof(*nor->params));
> +                       nor->params = sv_params[1];
>                 }
>         }
>
> @@ -1712,7 +1714,7 @@ int spi_nor_parse_sfdp(struct spi_nor *nor)
>  free_param_headers:
>         kfree(param_headers);
>         if (err)
> -               memcpy(nor->params, &params, sizeof(*nor->params));
> +               nor->params = sv_params[0];
>
>         return err;
>  }
> --
>
>> 
>> -michael
>> 
>> > Fixes: d20029474a76 ("mtd: spi-nor: push the rollback mechanism into the sfdp module")
>> > Signed-off-by: Arnd Bergmann <arnd at arndb.de>
>> > ---
>> >  drivers/mtd/spi-nor/sfdp.c | 10 +++++++---
>> >  1 file changed, 7 insertions(+), 3 deletions(-)  

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 297 bytes
Desc: not available
URL: <http://lists.infradead.org/pipermail/linux-mtd/attachments/20260921/dda30f4e/attachment.sig>


More information about the linux-mtd mailing list