From: sashiko-bot@kernel.org
To: "Guixin Liu" <kanie@linux.alibaba.com>
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH v2] cxl/hdm: Fix out of bounds read of the decoder target list
Date: Wed, 12 Aug 2026 06:26:04 +0000 [thread overview]
Message-ID: <20260812062605.610B61F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260812061017.56916-1-kanie@linux.alibaba.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] Endianness bug when decoding the HDM decoder Target List registers on big-endian architectures.
- [High] Permanent port state corruption on decoder initialization failure due to un-reverted `port->commit_end`.
--
--- Patch [1]: [PATCH v2] cxl/hdm: Fix out of bounds read of the decoder target list ---
commit c692efbe782398330e6841bfdd1146cdee44ef3b
Author: Guixin Liu <kanie@linux.alibaba.com>
Subject: cxl/hdm: Fix out of bounds read of the decoder target list
This commit fixes an out-of-bounds read in the HDM decoder initialization. It
adds a check to ensure the interleave ways do not exceed the size of the
target list array when programming the target map.
Link: https://lore.kernel.org/linux-cxl/20260811113608.2815625-1-kanie@linux.alibaba.com/
> diff --git a/drivers/cxl/core/hdm.c b/drivers/cxl/core/hdm.c
> index 0c80b76a5f9b4..9d49b48a4456e 100644
> --- a/drivers/cxl/core/hdm.c
> +++ b/drivers/cxl/core/hdm.c
> @@ -1084,6 +1084,18 @@ static int init_hdm_decoder(struct cxl_port *port, struct cxl_decoder *cxld,
> cxld->interleave_ways, cxld->interleave_granularity);
>
> if (!cxled) {
> + /*
> + * The Target List register only holds
> + * ARRAY_SIZE(target_list.target_id) entries, so a switch
> + * decoder cannot interleave across more ports than that.
> + */
> + if (cxld->interleave_ways > ARRAY_SIZE(target_list.target_id)) {
> + dev_warn(&port->dev,
> + "decoder%d.%d: Interleave ways: %d exceeds target list size\n",
> + port->id, cxld->id, cxld->interleave_ways);
> + return -ENXIO;
[Severity: High]
This is a pre-existing issue, but does returning here leave port->commit_end
permanently advanced?
Earlier in init_hdm_decoder(), port->commit_end is updated:
if (committed) {
...
port->commit_end = cxld->id;
}
If we fail here and return -ENXIO, port->commit_end is not rolled back. If
initialization is retried, cxl_num_decoders_committed() will return an
inflated count, which could cause the out of order commit check to fail.
Could this permanently prevent the port from initializing?
> + }
> +
> lo = readl(hdm + CXL_HDM_DECODER0_TL_LOW(which));
> hi = readl(hdm + CXL_HDM_DECODER0_TL_HIGH(which));
> target_list.value = (hi << 32) + lo;
[Severity: High]
This is a pre-existing issue, but does this code read the target IDs
incorrectly on big-endian architectures?
target_list.value is populated as a native 64-bit integer. The subsequent loop
reads it byte-by-byte via the target_id union:
for (i = 0; i < cxld->interleave_ways; i++)
cxld->target_map[i] = target_list.target_id[i];
On big-endian hardware, accessing the native 64-bit integer byte-by-byte will
read the most significant bytes first, which could scramble the port target
routing.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260812061017.56916-1-kanie@linux.alibaba.com?part=1
next prev parent reply other threads:[~2026-08-12 6:26 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-12 6:10 [PATCH v2] cxl/hdm: Fix out of bounds read of the decoder target list Guixin Liu
2026-08-12 6:26 ` sashiko-bot [this message]
2026-08-12 7:51 ` Guixin Liu
2026-08-12 11:31 ` Li Ming
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260812062605.610B61F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kanie@linux.alibaba.com \
--cc=linux-cxl@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.