All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Michael J. Ruhl" <michael.j.ruhl@intel.com>
Cc: intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v5 01/18] platform/x86/intel/pmt: complete pcidev to device update
Date: Thu, 03 Sep 2026 20:27:42 +0000	[thread overview]
Message-ID: <20260903202742.8A7691F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903201002.1064889-21-michael.j.ruhl@intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Type confusion in `pmt_copy_region` when casting an ACPI device to `struct pci_dev`.
--

commit db191f282e57b915c53aca0bc92d3bca969e1af4
Author: Michael J. Ruhl <michael.j.ruhl@intel.com>

platform/x86/intel/pmt: complete pcidev to device update

The update that moved struct pci_dev usage to struct device is
incomplete. Only telemetry endpoints are covered. This patch changes
the struct intel_pmt_entry pci_dev member to device, and updates
callback usage to use the intel_pmt_entry rather than the telemetry
endpoint.

> diff --git a/drivers/platform/x86/intel/pmt/class.h b/drivers/platform/x86/intel/pmt/class.h
> index a0ece4fc3837d..258cb460e61c2 100644
> --- a/drivers/platform/x86/intel/pmt/class.h
> +++ b/drivers/platform/x86/intel/pmt/class.h
[ ... ]
> @@ -42,7 +41,7 @@ struct intel_pmt_header {
>  
>  struct intel_pmt_entry {
>  	struct telem_endpoint	*ep;

[Severity: High]
This is a pre-existing issue, but does this lead to type confusion in
pmt_copy_region() when an ACPI device has registered telemetry?

In drivers/platform/x86/intel/pmt/telemetry.c:pmt_copy_region(), there is an
unconditional cast of this device (accessed via entry->ep->dev) to a PCI
device:

	struct pci_dev *pdev = to_pci_dev(entry->ep->dev);
	struct oobmsm_plat_info *plat_info;

	plat_info = intel_vsec_get_mapping(pdev);

If the generic struct device is actually an ACPI device (as during runtime
hardware enumeration of ACPI devices that expose PMT telemetry), can
intel_vsec_get_mapping() calling pci_match_id() end up dereferencing
PCI-specific fields (like vendor and device ID) at invalid memory offsets
and cause an out-of-bounds memory read?

This issue appears to have been introduced in commit 353042d54d82 and does
not appear to be resolved by this patch.

> -	struct pci_dev		*pcidev;
> +	struct device		*dev;
>  	struct intel_pmt_header	header;
>  	u32			disc_header[PMT_DISC_DWORDS];
>  	struct bin_attribute	pmt_bin_attr;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903201002.1064889-20-michael.j.ruhl@intel.com?part=1

  reply	other threads:[~2026-09-03 20:27 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03 20:10 [PATCH v5 00/18] Crescent Island PMT support Michael J. Ruhl
2026-09-03 20:10 ` [PATCH v5 01/18] platform/x86/intel/pmt: complete pcidev to device update Michael J. Ruhl
2026-09-03 20:27   ` sashiko-bot [this message]
2026-09-03 20:10 ` [PATCH v5 02/18] platform/x86/intel/pmt: refactor rmw with a return value Michael J. Ruhl
2026-09-03 20:10 ` [PATCH v5 03/18] platform/x86/intel/pmt: refactor rc " Michael J. Ruhl
2026-09-03 20:19   ` sashiko-bot
2026-09-03 20:33     ` Ruhl, Michael J
2026-09-03 20:10 ` [PATCH v5 04/18] platform/x86/intel/pmt: Add register access callbacks Michael J. Ruhl
2026-09-03 20:10 ` [PATCH v5 05/18] platform/x86/intel/pmt: Do not remap when using callbacks Michael J. Ruhl
2026-09-03 20:24   ` sashiko-bot
2026-09-03 20:54     ` Ruhl, Michael J
2026-09-03 20:10 ` [PATCH v5 06/18] drm/xe/vsec: Do not register BMG PMT for VF Michael J. Ruhl
2026-09-03 20:33   ` sashiko-bot
2026-09-03 20:10 ` [PATCH v5 07/18] drm/xe/vsec: Correct locking order Michael J. Ruhl
2026-09-03 20:10 ` [PATCH v5 08/18] drm/xe/vsec: Use correct pm state get Michael J. Ruhl
2026-09-03 20:26   ` sashiko-bot
2026-09-03 20:55     ` Ruhl, Michael J
2026-09-03 20:10 ` [PATCH v5 09/18] drm/xe/vsec: Add DOC text for VSEC Michael J. Ruhl
2026-09-03 20:17   ` sashiko-bot
2026-09-03 20:34     ` Ruhl, Michael J
2026-09-03 20:10 ` [PATCH v5 10/18] drm/xe/vsec: Support possible hotplug exit Michael J. Ruhl
2026-09-03 20:10 ` [PATCH v5 11/18] drm/xe/vsec: Support Crescent Island PMT Michael J. Ruhl
2026-09-03 20:10 ` [PATCH v5 12/18] drm/xe/vsec: Refactor BattleMage PMT defines Michael J. Ruhl
2026-09-03 20:10 ` [PATCH v5 13/18] drm/xe/vsec: Crescent Island PMT decode Michael J. Ruhl
2026-09-03 20:10 ` [PATCH v5 14/18] drm/xe/vsec: Crescent Island PMT callbacks Michael J. Ruhl
2026-09-03 20:26   ` sashiko-bot
2026-09-03 20:10 ` [PATCH v5 15/18] drm/xe/vsec: Support late bind fw information Michael J. Ruhl
2026-09-03 20:28   ` sashiko-bot
2026-09-03 20:57     ` Ruhl, Michael J
2026-09-03 20:10 ` [PATCH v5 16/18] drm/xe/vsec: Add PMT GUID internal access Michael J. Ruhl
2026-09-04 15:14   ` Poosa, Karthik
2026-09-04 16:00     ` Ruhl, Michael J
2026-09-03 20:10 ` [PATCH v5 17/18] drm/xe/vsec: Update PMT " Michael J. Ruhl
2026-09-03 20:10 ` [PATCH v5 18/18] drm/xe/vsec: Refactor platform check Michael J. Ruhl
2026-09-03 20:17 ` ✗ CI.checkpatch: warning for Crescent Island PMT support (rev7) Patchwork
2026-09-03 20:18 ` ✗ CI.KUnit: failure " Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903202742.8A7691F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=michael.j.ruhl@intel.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.