From: sashiko-bot@kernel.org
To: "Jose Ignacio Tornos Martinez" <jtornosm@redhat.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v15 2/2] PCI: Add device-specific reset for Qualcomm WCN6855/WCN7850 WLAN
Date: Mon, 05 Oct 2026 11:05:24 +0000 [thread overview]
Message-ID: <20261005110524.81DFC1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261005105436.83962-3-jtornosm@redhat.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] pci: out-of-bounds MMIO read in reset_qualcomm_wlan due to unverified BAR length
--
commit 0bf7ebc364dec72a7a29e6f1e5602ff74fc3a191
Author: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
PCI: Add device-specific reset for Qualcomm WCN6855/WCN7850 WLAN
Qualcomm WCN6855 and WCN7850 WLAN devices lack working reset methods for
VFIO passthrough scenarios. This commit adds a device-specific reset method
using BAR-space hardware reset registers that exist in these devices.
> diff --git a/drivers/pci/quirks.c b/drivers/pci/quirks.c
> index e72af7d2c7755..e800dd517614e 100644
> --- a/drivers/pci/quirks.c
> +++ b/drivers/pci/quirks.c
[ ... ]
> +static int reset_qualcomm_wlan(struct pci_dev *pdev, bool probe)
> +{
> + void __iomem *bar;
> + u32 val;
> + u16 cmd;
> + int ret;
[ ... ]
> + bar = pci_iomap(pdev, 0, 0);
> + if (!bar) {
> + pci_write_config_word(pdev, PCI_COMMAND, cmd);
> + return -ENODEV;
> + }
> +
> + val = ioread32(bar + QUALCOMM_WLAN_PCIE_SOC_GLOBAL_RESET);
[Severity: Medium]
Could this lead to an out-of-bounds MMIO read if the device's BAR 0 is
shorter than 0x300C?
The code unconditionally accesses offset 0x3008
(QUALCOMM_WLAN_PCIE_SOC_GLOBAL_RESET) here without verifying if the mapped
memory region is large enough. If an untrusted hardware actor or a spoofed
device exposes a smaller BAR 0 (e.g., 4KB), this access could exceed the
mapped memory boundary and cause a kernel panic due to a page fault.
Would it be safer to verify that pci_resource_len(pdev, 0) is at least
large enough to contain this offset before mapping and reading it?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261005105436.83962-1-jtornosm@redhat.com?part=2
next prev parent reply other threads:[~2026-10-05 11:05 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 10:54 [PATCH v15 0/2] PCI: Add device-specific reset for Qualcomm devices Jose Ignacio Tornos Martinez
2026-10-05 10:54 ` [PATCH v15 1/2] PCI: Add device-specific reset for Qualcomm SDX62/SDX65 modems Jose Ignacio Tornos Martinez
2026-10-05 11:07 ` sashiko-bot
2026-10-05 12:00 ` Jose Ignacio Tornos Martinez
2026-10-05 10:54 ` [PATCH v15 2/2] PCI: Add device-specific reset for Qualcomm WCN6855/WCN7850 WLAN Jose Ignacio Tornos Martinez
2026-10-05 11:05 ` sashiko-bot [this message]
2026-10-05 11:59 ` Jose Ignacio Tornos Martinez
2026-10-05 16:41 ` [PATCH v15 0/2] PCI: Add device-specific reset for Qualcomm devices Bjorn Helgaas
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005110524.81DFC1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=jtornosm@redhat.com \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.