All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Igor Skalkin" <igor.skalkin@oss.qualcomm.com>
Cc: virtualization@lists.linux.dev,
	"Michael S. Tsirkin" <mst@redhat.com>,
	"Eugenio Perez" <eperezma@redhat.com>
Subject: Re: [PATCH 7/8] virtio-usb: add SuperSpeed device-role support
Date: Thu, 24 Sep 2026 16:35:09 +0000	[thread overview]
Message-ID: <20260924163509.AFF3F1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924160907.145405-8-igor.skalkin@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] usb: payload corruption due to oversized endpoint descriptor mapping
--

commit 3644614322079b958f1f64d6f45046b653de97cb
Author: Igor Skalkin <igor.skalkin@oss.qualcomm.com>

virtio-usb: add SuperSpeed device-role support

This commit updates virtio-usb to dynamically parse the maximum supported 
speed from the host backend's bind event rather than hardcoding it. It also 
configures endpoint packet sizes accordingly and includes the companion 
descriptor alongside the endpoint descriptor for SuperSpeed bring-up.

> diff --git a/drivers/usb/virtio_usb/device.c b/drivers/usb/virtio_usb/device.c
> index 9ee1f050019f1..ee41ea9d164f1 100644
> --- a/drivers/usb/virtio_usb/device.c
> +++ b/drivers/usb/virtio_usb/device.c

[ ... ]

> @@ -461,7 +463,13 @@ static void vep_enable_work(struct work_struct *work)
>  		goto done;
>  	}
>  
> -	sg_init_one(psg_data, desc, sizeof(*desc));
> +	if (virtio_usb_ep_comp_valid(comp))
> +		n_sgs = 2;
> +
> +	sg_init_table(psg_data, n_sgs);
> +	sg_set_buf(&psg_data[0], desc, sizeof(*desc));

[Severity: High]
Does mapping sizeof(*desc) misalign the payload sent to the host backend?

Since sizeof(struct usb_endpoint_descriptor) is 9 bytes (which includes
audio-only fields) and desc->bLength is typically 7, appending the companion
descriptor immediately after this 9-byte chunk might shift it by 2 bytes in
the resulting payload.

When the host backend parses the descriptors sequentially by advancing
bLength bytes, could this cause it to parse misaligned data instead of the
companion descriptor, causing the SuperSpeed endpoint configuration to fail?

> +	if (n_sgs == 2)
> +		sg_set_buf(&psg_data[1], comp, sizeof(*comp));
>  	hdr = virtio_usb_cmd_request(cmd);
>  	hdr->endpoint = cpu_to_le16(endpoint);
>  

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924160907.145405-1-igor.skalkin@oss.qualcomm.com?part=7

  reply	other threads:[~2026-09-24 16:35 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 16:08 [PATCH 0/8] virtio-usb: add dual-role virtio USB driver Igor Skalkin
2026-09-24 16:09 ` [PATCH 1/8] virtio-usb: add protocol header and skeleton dual-role driver Igor Skalkin
2026-09-24 16:23   ` sashiko-bot
2026-09-25  5:14   ` Greg Kroah-Hartman
2026-09-28 14:19     ` Igor Skalkin
2026-09-25  5:21   ` Greg Kroah-Hartman
2026-09-28 14:14     ` Igor Skalkin
2026-09-24 16:09 ` [PATCH 2/8] virtio-usb: add host role (USB Host Controller) support Igor Skalkin
2026-09-24 16:25   ` sashiko-bot
2026-09-25  5:18   ` Greg Kroah-Hartman
2026-09-28 14:01     ` Igor Skalkin
2026-09-24 16:09 ` [PATCH 3/8] virtio-usb: add device role (USB Device " Igor Skalkin
2026-09-24 16:28   ` sashiko-bot
2026-09-24 16:09 ` [PATCH 4/8] virtio-usb: add OTG role query support Igor Skalkin
2026-09-24 16:19   ` sashiko-bot
2026-09-24 16:09 ` [PATCH 5/8] virtio-usb: add USB On-The-Go role-switching support Igor Skalkin
2026-09-24 16:24   ` sashiko-bot
2026-09-24 16:09 ` [PATCH 6/8] virtio-usb: rework endpoint lifecycle to an async split-phase state machine Igor Skalkin
2026-09-24 16:30   ` sashiko-bot
2026-09-24 16:09 ` [PATCH 7/8] virtio-usb: add SuperSpeed device-role support Igor Skalkin
2026-09-24 16:35   ` sashiko-bot [this message]
2026-09-24 16:09 ` [PATCH 8/8] virtio-usb: support a guest UDC name prefix from the bind event Igor Skalkin
2026-09-24 16:35   ` sashiko-bot
2026-09-25  5:17 ` [PATCH 0/8] virtio-usb: add dual-role virtio USB driver Greg Kroah-Hartman
2026-09-28 13:55   ` Igor Skalkin
2026-09-28 14:44     ` Greg Kroah-Hartman
2026-09-28 15:56       ` Igor Skalkin
2026-09-28 16:10         ` Greg Kroah-Hartman
2026-09-29  9:47     ` Michael S. Tsirkin
2026-09-29 16:01       ` Greg Kroah-Hartman
2026-09-29 19:02         ` Vasilii Ianikeev
2026-09-29 19:58         ` Vasilii Ianikeev

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924163509.AFF3F1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=eperezma@redhat.com \
    --cc=igor.skalkin@oss.qualcomm.com \
    --cc=mst@redhat.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=virtualization@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.