From: sashiko-bot@kernel.org
To: "Sophon Zhang" <aiqubits@hotmail.com>
Cc: linux-pci@vger.kernel.org, ojeda@kernel.org
Subject: Re: [PATCH v4] rust: pci: reject IRQ vector indices that do not fit in u32
Date: Mon, 31 Aug 2026 19:46:17 +0000 [thread overview]
Message-ID: <20260831194618.63E6A1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260901-fix-pci-irq-vector-index-truncation-v4-1-f94aa6932fd9@hotmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing bounds check in `IrqVectorRegistration::index()` leads to kernel warning/panic via C API.
--
commit 97b70137801249b8b3a7409015c5b394925bf777
Author: Sophon Zhang <aiqubits@hotmail.com>
rust: pci: reject IRQ vector indices that do not fit in u32
This commit attempts to prevent 64-bit Rust IRQ vector indices from wrapping
when passed to the C API by introducing a checked cast to u32. It relies on
the PCI core to validate the range of the index rather than doing a bounds
check in Rust.
> diff --git a/rust/kernel/pci/irq.rs b/rust/kernel/pci/irq.rs
> --- a/rust/kernel/pci/irq.rs
> +++ b/rust/kernel/pci/irq.rs
> @@ -151,8 +151,10 @@ pub fn irq_type(&self) -> IrqType {
> /// [Self::len()].
> #[inline]
> pub fn index(&self, index: usize) -> Result<IrqVector<'_>> {
> + let index = u32::try_from(index)?;
> +
> // SAFETY: self.dev.as_raw() is a valid pointer to a struct pci_dev.
> - let irq = unsafe { bindings::pci_irq_vector(self.dev.as_raw(), index as u32) };
> + let irq = unsafe { bindings::pci_irq_vector(self.dev.as_raw(), index) };
[Severity: High]
This is a pre-existing issue, but does relying on the C API for bounds
checking violate Rust safety guarantees by triggering a kernel warning or
panic?
If a driver calls this safe Rust function with an out-of-bounds index that
still fits in a u32 (for example, 65536), it will pass the u32 conversion
and be handed directly to bindings::pci_irq_vector().
If MSI is enabled, this eventually calls msi_domain_get_virq() in
kernel/irq/msi.c, which executes:
if (WARN_ON_ONCE(index > MSI_MAX_INDEX || domid >= MSI_MAX_DEVICE_IRQDOMAINS))
return 0;
Because MSI_MAX_INDEX is 65535, an index of 65536 will trigger the
WARN_ON_ONCE, which can crash the kernel if panic_on_warn is set.
Furthermore, if the kernel is built without CONFIG_PCI_MSI, the fallback
inline pci_irq_vector() in include/linux/pci.h will trigger a similar
warning for any index > 0:
if (WARN_ON_ONCE(nr > 0))
return -EINVAL;
Since IrqVectorRegistration::index() is exposed as a safe Rust API, could an
explicit check against self.len() be added here to avoid relying on C-side
WARN_ON_ONCE checks for validation?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260901-fix-pci-irq-vector-index-truncation-v4-1-f94aa6932fd9@hotmail.com?part=1
next prev parent reply other threads:[~2026-08-31 19:46 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 17:09 [PATCH v4] rust: pci: reject IRQ vector indices that do not fit in u32 Sophon Zhang via B4 Relay
2026-08-31 17:09 ` Sophon Zhang
2026-08-31 19:46 ` sashiko-bot [this message]
[not found] ` <SN7PR07MB9708A97EA2A41E601D4E9C9ACFA82@SN7PR07MB9708.namprd07.prod.outlook.com>
2026-09-01 9:37 ` 回复: " ai qubits
2026-09-01 10:58 ` Alexandre Courbot
2026-09-01 11:08 ` Danilo Krummrich
2026-09-01 13:32 ` Alexandre Courbot
2026-09-01 13:36 ` Danilo Krummrich
2026-09-01 13:52 ` Alexandre Courbot
2026-09-01 13:48 ` Gary Guo
2026-09-01 14:08 ` Alexandre Courbot
2026-09-01 15:58 ` 回复: " ai qubits
2026-09-01 11:47 ` ai qubits
2026-09-01 12:06 ` Gary Guo
2026-09-01 12:35 ` 回复: " ai qubits
2026-09-01 12:42 ` Miguel Ojeda
2026-09-01 16:19 ` Gary Guo
2026-09-01 16:31 ` Danilo Krummrich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831194618.63E6A1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=aiqubits@hotmail.com \
--cc=linux-pci@vger.kernel.org \
--cc=ojeda@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.