From: sashiko-bot@kernel.org
To: "Michael J. Ruhl" <michael.j.ruhl@intel.com>
Cc: intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v4 04/18] platform/x86/intel/pmt: Add register access callbacks
Date: Tue, 01 Sep 2026 19:45:12 +0000 [thread overview]
Message-ID: <20260901194512.E53A71F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260901192736.626777-24-michael.j.ruhl@intel.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] In `pmt_crashlog_rc()`, an error from `pmt_crashlog_read_reg()` incorrectly returns `false` (which evaluates to integer `0`) instead of propagating the error code. This tricks callers into assuming the operation succeeded, leading to the use of uninitialized stack variables.
--
commit e8f90b7603dd0762e0fc5325b88546ddb36185c1
Author: Michael J. Ruhl <michael.j.ruhl@intel.com>
platform/x86/intel/pmt: Add register access callbacks
Some HW does not have direct MMIO access to PMT control and data
features. Augment the current callback infrastructure to allow a
registered driver to customize read/write access.
> diff --git a/drivers/platform/x86/intel/pmt/crashlog.c b/drivers/platform/x86/intel/pmt/crashlog.c
> --- a/drivers/platform/x86/intel/pmt/crashlog.c
> +++ b/drivers/platform/x86/intel/pmt/crashlog.c
[ ... ]
> @@ -147,7 +181,13 @@ static int pmt_crashlog_rmw(struct crashlog_entry *crashlog, u32 bit, bool set)
> static int pmt_crashlog_rc(struct crashlog_entry *crashlog, u32 bit, bool *state)
> {
> const struct crashlog_status *status = &crashlog->info->status;
> - u32 reg = readl(crashlog->entry.disc_table + status->offset);
> + struct intel_pmt_entry *entry = &crashlog->entry;
> + u32 reg;
> + int ret;
> +
> + ret = pmt_crashlog_read_reg(entry, ®, status->offset);
> + if (ret)
> + return false;
[Severity: High]
Does returning false here incorrectly mask the error code as success?
The function pmt_crashlog_rc() returns an int. Returning false evaluates to
0, which tricks callers into thinking the register read was successful.
For example, when a sysfs attribute calls clear_show():
drivers/platform/x86/intel/pmt/crashlog.c:clear_show() {
bool cleared;
int ret;
ret = pmt_crashlog_cleared(crashlog, &cleared);
if (ret)
return sysfs_emit(buf, "read error: %d\n", ret);
else
return sysfs_emit(buf, "%d\n", cleared);
}
If pmt_crashlog_read_reg() fails and returns an error code, ret will be 0,
and sysfs_emit() will leak the uninitialized stack variable cleared to
userspace.
A similar issue occurs in trigger_store(), where the code will branch on an
uninitialized disabled variable if the register read fails. Should this
instead propagate the ret value?
>
> *state = !!(reg & bit);
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260901192736.626777-20-michael.j.ruhl@intel.com?part=4
next prev parent reply other threads:[~2026-09-01 19:45 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 19:27 [PATCH v4 00/18] Crescent Island PMT support Michael J. Ruhl
2026-09-01 19:27 ` [PATCH v4 01/18] platform/x86/intel/pmt: complete pcidev to device update Michael J. Ruhl
2026-09-01 19:27 ` [PATCH v4 02/18] platform/x86/intel/pmt: refactor rmw with a return value Michael J. Ruhl
2026-09-02 9:05 ` Ilpo Järvinen
2026-09-02 9:07 ` Ilpo Järvinen
2026-09-01 19:27 ` [PATCH v4 03/18] platform/x86/intel/pmt: refactor rc " Michael J. Ruhl
2026-09-01 19:38 ` sashiko-bot
2026-09-02 9:08 ` Ilpo Järvinen
2026-09-01 19:27 ` [PATCH v4 04/18] platform/x86/intel/pmt: Add register access callbacks Michael J. Ruhl
2026-09-01 19:45 ` sashiko-bot [this message]
2026-09-01 19:27 ` [PATCH v4 05/18] platform/x86/intel/pmt: Add helpers for callback info Michael J. Ruhl
2026-09-01 19:40 ` sashiko-bot
2026-09-02 9:10 ` Ilpo Järvinen
2026-09-01 19:27 ` [PATCH v4 06/18] platform/x86/intel/pmt: Do not remap when using callbacks Michael J. Ruhl
2026-09-01 19:51 ` sashiko-bot
2026-09-02 9:18 ` Ilpo Järvinen
2026-09-01 19:27 ` [PATCH v4 07/18] drm/xe/vsec: Do not register BMG PMT for VF Michael J. Ruhl
2026-09-02 19:06 ` Rodrigo Vivi
2026-09-02 20:47 ` Ruhl, Michael J
2026-09-01 19:27 ` [PATCH v4 08/18] drm/xe/vsec: Correct locking order Michael J. Ruhl
2026-09-02 19:08 ` Rodrigo Vivi
2026-09-02 19:11 ` Matthew Brost
2026-09-01 19:27 ` [PATCH v4 09/18] drm/xe/vsec: Use correct pm state get Michael J. Ruhl
2026-09-02 19:10 ` Rodrigo Vivi
2026-09-01 19:27 ` [PATCH v4 10/18] drm/xe/vsec: Support possible hotplug exit Michael J. Ruhl
2026-09-02 19:15 ` Rodrigo Vivi
2026-09-01 19:27 ` [PATCH v4 11/18] drm/xe/vsec: Support Crescent Island PMT Michael J. Ruhl
2026-09-02 19:16 ` Rodrigo Vivi
2026-09-01 19:27 ` [PATCH v4 12/18] drm/xe/vsec: Refactor BattleMage PMT defines Michael J. Ruhl
2026-09-02 19:18 ` Rodrigo Vivi
2026-09-01 19:27 ` [PATCH v4 13/18] drm/xe/vsec: Crescent Island PMT decode Michael J. Ruhl
2026-09-01 19:27 ` [PATCH v4 14/18] drm/xe/vsec: Crescent Island PMT callbacks Michael J. Ruhl
2026-09-01 19:27 ` [PATCH v4 15/18] drm/xe/vsec: Support late bind fw information Michael J. Ruhl
2026-09-01 20:14 ` sashiko-bot
2026-09-01 19:27 ` [PATCH v4 16/18] drm/xe/vsec: Add PMT GUID internal access Michael J. Ruhl
2026-09-01 20:20 ` sashiko-bot
2026-09-01 19:27 ` [PATCH v4 17/18] drm/xe/vsec: Update PMT " Michael J. Ruhl
2026-09-01 20:21 ` sashiko-bot
2026-09-03 5:50 ` Poosa, Karthik
2026-09-01 19:27 ` [PATCH v4 18/18] drm/xe/vsec: Refactor platform check Michael J. Ruhl
2026-09-03 5:57 ` Poosa, Karthik
2026-09-01 19:34 ` ✗ CI.checkpatch: warning for Crescent Island PMT support (rev6) Patchwork
2026-09-01 19:35 ` ✗ CI.KUnit: failure " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260901194512.E53A71F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=michael.j.ruhl@intel.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.