All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v2 2/7] PCI/parisc: Clean up resource debug print & use dynamic debug
Date: Fri, 02 Oct 2026 11:43:47 +0000	[thread overview]
Message-ID: <20261002114348.39A801F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261002113319.6652-3-ilpo.jarvinen@linux.intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] pci: uninitialized stack pointer dereference in pcibios_align_resource() via %pR
--

commit e687046bde97f65f6b278cb7b13dd117863bc565
Author: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>

PCI/parisc: Clean up resource debug print & use dynamic debug

This commit cleans up the ad-hoc RES_DBG() macro in the parisc PCI code
by replacing it with the standard pci_dbg() macro. It also updates the
format string to use %pR for printing resources, which matches the typical
format used by the PCI core.

> diff --git a/arch/parisc/kernel/pci.c b/arch/parisc/kernel/pci.c
> index b8007c7400d47..518f532ccddc5 100644
> --- a/arch/parisc/kernel/pci.c
> +++ b/arch/parisc/kernel/pci.c

[ ... ]

> @@ -204,10 +196,9 @@ resource_size_t pcibios_align_resource(void *data, const struct resource *res,
>  	struct pci_dev *dev = data;
>  	resource_size_t align, start = res->start;
>  
> -	DBG_RES("pcibios_align_resource(%s, (%p) [%lx,%lx]/%x, 0x%lx, 0x%lx)\n",
> -		pci_name(((struct pci_dev *) data)),
> -		res->parent, res->start, res->end,
> -		(int) res->flags, size, alignment);
> +	pci_dbg(dev, "%pR: pcibios_align_resource(%lx, 0x%llx, 0x%llx), parent %pR\n",
> +		res, res->flags, (unsigned long long)size,
> +		(unsigned long long)alignment, res->parent);

[Severity: High]
Could this format string introduce a regression by causing a kernel oops due
to an uninitialized pointer dereference?

The %pR format specifier causes the printk implementation to dereference the
resource pointer to read its boundaries and flags. However,
pcibios_align_resource() is used as an alignf callback for resource
allocation, and it can be called with a partially uninitialized stack
variable from __find_resource_space():

kernel/resource.c:__find_resource_space() {
	...
	struct resource avail;
	...
	avail.start = ALIGN(full_avail.start, constraint->align);
	avail.end = full_avail.end;
	avail.flags = new->flags;
	if (avail.start >= full_avail.start) {
		alloc.flags = avail.flags;
		if (alignf) {
			alloc.start = alignf(constraint->alignf_data,
					     &avail, &full_avail,
					     size, constraint->align);
	...
}

In this path, the avail.parent field is left uninitialized. When %pR attempts
to dereference res->parent, it will be reading stack garbage. The previous
DBG_RES() implementation used %p, which safely printed the pointer address
without dereferencing it.

Would it be safer to revert to %p for the parent pointer or ensure the
struct is fully initialized?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002113319.6652-1-ilpo.jarvinen@linux.intel.com?part=2

  reply	other threads:[~2026-10-02 11:43 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 11:33 [PATCH v2 0/7] PCI: Resource placement algorithm fixes Ilpo Järvinen
2026-10-02 11:33 ` [PATCH v2 1/7] resource: Mark free space assigned Ilpo Järvinen
2026-10-02 11:43   ` sashiko-bot
2026-10-02 11:33 ` [PATCH v2 2/7] PCI/parisc: Clean up resource debug print & use dynamic debug Ilpo Järvinen
2026-10-02 11:43   ` sashiko-bot [this message]
2026-10-02 11:33 ` [PATCH v2 3/7] PCI: Honor alignment overrides Ilpo Järvinen
2026-10-02 11:46   ` Jani Nikula
2026-10-02 11:49   ` sashiko-bot
2026-10-02 11:33 ` [PATCH v2 4/7] PCI: Fix nesting windows with remainder at the left edge Ilpo Järvinen
2026-10-02 11:42   ` sashiko-bot
2026-10-02 11:33 ` [PATCH v2 5/7] PCI: Place resources to either edge of the window Ilpo Järvinen
2026-10-02 11:46   ` sashiko-bot
2026-10-02 11:33 ` [PATCH v2 6/7] PCI: Fix composite resource sizing Ilpo Järvinen
2026-10-02 11:51   ` sashiko-bot
2026-10-02 11:33 ` [PATCH v2 7/7] PCI/quirks: Avoid certain address on Genoa systems Ilpo Järvinen
2026-10-02 11:48   ` sashiko-bot
2026-10-02 13:47     ` Ilpo Järvinen
2026-10-02 13:12   ` Mario Limonciello
2026-10-04 15:44   ` Borislav Petkov
2026-10-09 12:01     ` Ilpo Järvinen
2026-10-05 18:47   ` Bjorn Helgaas
2026-10-06 12:02     ` Ilpo Järvinen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002114348.39A801F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=ilpo.jarvinen@linux.intel.com \
    --cc=linux-pci@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.