From: sashiko-bot@kernel.org
To: "Daniel Zahka" <daniel.zahka@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH net-next v2 1/8] eth: mpnic: add scaffolding for Meta Platforms NIC
Date: Sat, 26 Sep 2026 00:36:02 +0000 [thread overview]
Message-ID: <20260926003602.848A31F00898@smtp.kernel.org> (raw)
In-Reply-To: <20260924-linux-mpnic-v2-1-4badc9b58b9e@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] eth: mpnic: missing PCI BAR0 length validation leads to out-of-bounds MMIO access
--
commit 716880959e1661559f15c4ddde5849a4394122ac
Author: Daniel Zahka <daniel.zahka@gmail.com>
eth: mpnic: add scaffolding for Meta Platforms NIC
This commit introduces a bare PCI driver for the Meta Platforms Network
Interface Controller (MPNIC). It maps BAR0 and provides basic 64-bit MMIO
accessors with a fallback check to detect removed devices.
> diff --git a/drivers/net/ethernet/meta/mpnic/mpnic.h b/drivers/net/ethernet/meta/mpnic/mpnic.h
> new file mode 100644
> index 0000000000000..6b8bee93033ab
> --- /dev/null
> +++ b/drivers/net/ethernet/meta/mpnic/mpnic.h
[ ... ]
> +static inline void mpnic_wr64(struct mpnic_dev *mpd, u32 reg, u64 val)
> +{
> + u32 __iomem *csr = READ_ONCE(mpd->uc_addr0);
> +
> + if (csr)
> + writeq(val, csr + reg);
[Severity: High]
Does this blind pointer arithmetic risk out-of-bounds MMIO writes?
The generic accessor lacks bounds checking on reg, which could result in
writing past the end of the mapped BAR.
[ ... ]
> diff --git a/drivers/net/ethernet/meta/mpnic/mpnic_pci.c b/drivers/net/ethernet/meta/mpnic/mpnic_pci.c
> new file mode 100644
> index 0000000000000..96393e7812418
> --- /dev/null
> +++ b/drivers/net/ethernet/meta/mpnic/mpnic_pci.c
[ ... ]
> +u64 mpnic_rd64(struct mpnic_dev *mpd, u32 reg)
> +{
> + u32 __iomem *csr = READ_ONCE(mpd->uc_addr0);
> + u64 value;
> +
> + if (!csr)
> + return ~0ULL;
> +
> + value = readq(csr + reg);
> +
> + /* If any bits are 0 value should be valid */
> + if (~value)
> + return value;
> +
> + /* All ones can be a valid value, so confirm against a register
> + * which never reads that way on a live device.
> + */
> + if (reg != MPNIC_BDQ_SPARE && ~readq(csr + MPNIC_BDQ_SPARE))
[Severity: High]
Can this fallback check cause a kernel panic if a malicious or spoofed PCIe
device advertises a small BAR0?
This unconditionally reads from MPNIC_BDQ_SPARE (index 0x42013e, byte
offset 0x10804F8). If the mapped BAR is smaller than ~17.3MB, reading from
this hardcoded offset will crash the kernel.
> + return value;
> +
> + mpnic_mmio_err(mpd, reg);
> +
> + return ~0ULL;
> +}
[ ... ]
> +static int mpnic_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
> +{
[ ... ]
> + mpd = mpnic_alloc(pdev);
> + if (!mpd)
> + return -ENOMEM;
> +
> + uc_addr0 = pcim_iomap_region(pdev, 0, MPNIC_DRV_NAME);
[Severity: High]
Should we verify the device-provided BAR length before mapping it here?
BAR0 is mapped without checking if pci_resource_len(pdev, 0) is large
enough to encompass the driver's register layout. An attacker plugging in
untrusted hardware could advertise a small BAR0 (e.g., 4KB) and return
all-ones to an initial read. This would force the driver to read from
csr + MPNIC_BDQ_SPARE and crash the system.
> + if (IS_ERR(uc_addr0)) {
> + err = PTR_ERR(uc_addr0);
> + dev_err(&pdev->dev, "Mapping the register file failed: %d\n",
> + err);
> + goto err_free_mpd;
> + }
> + mpd->uc_addr0 = uc_addr0;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924-linux-mpnic-v2-0-4badc9b58b9e@gmail.com?part=1
next prev parent reply other threads:[~2026-09-26 0:36 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 0:35 [PATCH net-next v2 0/8] eth: mpnic: initial support for Meta Platforms NIC Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 1/8] eth: mpnic: add scaffolding " Daniel Zahka
2026-09-26 0:36 ` sashiko-bot [this message]
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 12:13 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 2/8] eth: mpnic: add register init for the device Daniel Zahka
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 12:14 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 3/8] eth: mpnic: allocate MSI-X vectors Daniel Zahka
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 16:01 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 4/8] eth: mpnic: implement Tx queue allocation and cleanup Daniel Zahka
2026-09-26 0:36 ` sashiko-bot
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 14:46 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 5/8] eth: mpnic: start and stop the Tx HW queues Daniel Zahka
2026-09-26 0:36 ` sashiko-bot
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 15:00 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 6/8] eth: mpnic: add a netdevice and basic Tx handling Daniel Zahka
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 15:10 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 7/8] eth: mpnic: implement Rx queue allocation and cleanup Daniel Zahka
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 15:11 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 8/8] eth: mpnic: add basic Rx handling Daniel Zahka
2026-09-26 0:36 ` sashiko-bot
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 15:17 ` Daniel Zahka
2026-09-29 2:03 ` Jakub Kicinski
2026-09-28 18:16 ` [PATCH net-next v2 0/8] eth: mpnic: initial support for Meta Platforms NIC Daniel Zahka
2026-09-29 8:50 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926003602.848A31F00898@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel.zahka@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.