From: sashiko-bot@kernel.org
To: "Francesco Valla" <francesco@valla.it>
Cc: devicetree@vger.kernel.org, "Eugenio Perez" <eperezma@redhat.com>,
Frank.Li@kernel.org, robh@kernel.org, conor+dt@kernel.org,
imx@lists.linux.dev, "Michael S. Tsirkin" <mst@redhat.com>,
virtualization@lists.linux.dev
Subject: Re: [PATCH RFC 04/12] dma-coherent: add base and size APIs
Date: Wed, 16 Sep 2026 21:55:55 +0000 [thread overview]
Message-ID: <20260916215555.F03051F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260916-remoteproc_virtio_map-v1-4-dac8c5eb4aa9@valla.it>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] dma: integer overflow in dma_dev_coherent_size()
--
commit c7a3821680bbb5546ff7e7a9e6fe376429788c67
Author: Francesco Valla <francesco@valla.it>
dma-coherent: add base and size APIs
This commit adds two new APIs, dma_dev_coherent_size() and
dma_dev_coherent_base(), to retrieve the size and base address of the
coherent memory pool associated with a device.
> diff --git a/kernel/dma/coherent.c b/kernel/dma/coherent.c
> index 45bbae947f4be..f4aa5813604b8 100644
> --- a/kernel/dma/coherent.c
> +++ b/kernel/dma/coherent.c
[ ... ]
> @@ -277,6 +277,40 @@ int dma_mmap_from_dev_coherent(struct device *dev, struct vm_area_struct *vma,
[ ... ]
> +size_t dma_dev_coherent_size(struct device *dev)
> +{
> + struct dma_coherent_mem *mem = dev_get_coherent_memory(dev);
> +
> + if (!mem)
> + return 0;
> +
> + return (mem->size << PAGE_SHIFT);
[Severity: High]
Could this left shift overflow for large coherent pools?
If the pool size is 2GB or larger, mem->size (which is an int representing
the number of pages) will be >= 524288. Shifting a signed 32-bit integer by
PAGE_SHIFT overflows in this case, and the result incorrectly sign-extends
when implicitly cast to size_t.
This might cause the function to return an astronomically large size_t value
instead of the actual pool size, which could lead to out-of-bounds accesses
or allocation failures in callers trusting the returned size.
Would casting mem->size to size_t before the shift prevent this?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916-remoteproc_virtio_map-v1-0-dac8c5eb4aa9@valla.it?part=4
next prev parent reply other threads:[~2026-09-16 21:55 UTC|newest]
Thread overview: 59+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 21:10 [PATCH RFC 00/12] remoteproc: add support for any virtio device Francesco Valla
2026-09-16 21:10 ` [PATCH RFC 01/12] remoteproc: virtio: cleanup rproc_add_virtio_dev error path Francesco Valla
2026-09-16 21:56 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 02/12] remoteproc: virtio: replace commas with semicolons Francesco Valla
2026-09-16 21:58 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 03/12] remoteproc: virtio: support dynamic number of vrings Francesco Valla
2026-09-16 22:00 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 04/12] dma-coherent: add base and size APIs Francesco Valla
2026-09-16 21:55 ` sashiko-bot [this message]
2026-09-16 21:10 ` [PATCH RFC 05/12] remoteproc: always report VIRTIO_F_VERSION_1 feature Francesco Valla
2026-09-16 22:00 ` sashiko-bot
2026-09-21 15:47 ` Mathieu Poirier
2026-09-22 6:32 ` Francesco Valla
2026-09-22 15:10 ` Mathieu Poirier
2026-09-16 21:10 ` [PATCH RFC 06/12] remoteproc: virtio: add bounce buffering for data buffers Francesco Valla
2026-09-16 22:03 ` sashiko-bot
2026-09-22 15:58 ` Mathieu Poirier
2026-09-22 19:39 ` Francesco Valla
2026-09-23 14:44 ` Mathieu Poirier
2026-09-23 16:05 ` Francesco Valla
2026-09-25 15:07 ` Mathieu Poirier
2026-09-25 16:48 ` Robin Murphy
2026-09-25 19:05 ` Francesco Valla
2026-09-27 22:12 ` Francesco Valla
2026-09-25 17:03 ` Robin Murphy
2026-09-16 21:10 ` [PATCH RFC 07/12] dt-bindings: spi: add bindings for spi-virtio Francesco Valla
2026-09-16 21:52 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 08/12] dt-bindings: remoteproc: add remoteproc-virtio Francesco Valla
2026-09-16 21:56 ` sashiko-bot
2026-09-22 15:40 ` Mathieu Poirier
2026-09-22 19:44 ` Francesco Valla
2026-09-23 14:56 ` Mathieu Poirier
2026-10-06 18:39 ` Rob Herring
2026-10-07 0:51 ` Mathieu Poirier
2026-10-07 13:42 ` Rob Herring
2026-10-07 16:34 ` Francesco Valla
2026-09-16 21:10 ` [PATCH RFC 09/12] remoteproc: search for a fwnode during vdev registration Francesco Valla
2026-09-16 21:58 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 10/12] remoteproc: imx_rproc: always use non-blocking mailboxes Francesco Valla
2026-09-16 22:05 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 11/12] dt-bindings: remoteproc: imx-rproc: support virtio Francesco Valla
2026-09-16 22:04 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 12/12] PoC: arm64: dts: imx93-11x11-frdm: add multiple vdevs Francesco Valla
2026-09-16 22:07 ` sashiko-bot
2026-09-22 15:43 ` Mathieu Poirier
2026-09-22 20:19 ` Francesco Valla
2026-09-23 15:48 ` Mathieu Poirier
2026-09-23 18:42 ` Francesco Valla
2026-09-24 15:49 ` Mathieu Poirier
2026-09-25 19:13 ` Francesco Valla
2026-10-09 4:27 ` Peng Fan
2026-09-25 8:39 ` Alexander Stein
2026-09-25 19:26 ` Francesco Valla
2026-09-18 16:53 ` [PATCH RFC 00/12] remoteproc: add support for any virtio device Mathieu Poirier
2026-09-19 7:33 ` Francesco Valla
2026-09-21 3:31 ` Mathieu Poirier
2026-09-22 6:28 ` Francesco Valla
2026-09-22 13:53 ` Mathieu Poirier
2026-09-23 15:13 ` Robin Murphy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916215555.F03051F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=eperezma@redhat.com \
--cc=francesco@valla.it \
--cc=imx@lists.linux.dev \
--cc=mst@redhat.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=virtualization@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.