All of lore.kernel.org
 help / color / mirror / Atom feed
From: Guixin Liu <kanie@linux.alibaba.com>
To: sashiko-reviews@lists.linux.dev
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH v2] cxl/hdm: Fix out of bounds read of the decoder target list
Date: Wed, 12 Aug 2026 15:51:33 +0800	[thread overview]
Message-ID: <6be8a860-a56f-4776-9017-d976571fbee7@linux.alibaba.com> (raw)
In-Reply-To: <20260812062605.610B61F000E9@smtp.kernel.org>



在 2026/8/12 14:26, sashiko-bot@kernel.org 写道:
> Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
>
> Pre-existing issues:
> - [High] Endianness bug when decoding the HDM decoder Target List registers on big-endian architectures.
> - [High] Permanent port state corruption on decoder initialization failure due to un-reverted `port->commit_end`.
> --
>
> --- Patch [1]: [PATCH v2] cxl/hdm: Fix out of bounds read of the decoder target list ---
> commit c692efbe782398330e6841bfdd1146cdee44ef3b
> Author: Guixin Liu <kanie@linux.alibaba.com>
> Subject: cxl/hdm: Fix out of bounds read of the decoder target list
>
> This commit fixes an out-of-bounds read in the HDM decoder initialization. It
> adds a check to ensure the interleave ways do not exceed the size of the
> target list array when programming the target map.
>
> Link: https://lore.kernel.org/linux-cxl/20260811113608.2815625-1-kanie@linux.alibaba.com/
>
>> diff --git a/drivers/cxl/core/hdm.c b/drivers/cxl/core/hdm.c
>> index 0c80b76a5f9b4..9d49b48a4456e 100644
>> --- a/drivers/cxl/core/hdm.c
>> +++ b/drivers/cxl/core/hdm.c
>> @@ -1084,6 +1084,18 @@ static int init_hdm_decoder(struct cxl_port *port, struct cxl_decoder *cxld,
>>   		cxld->interleave_ways, cxld->interleave_granularity);
>>   
>>   	if (!cxled) {
>> +		/*
>> +		 * The Target List register only holds
>> +		 * ARRAY_SIZE(target_list.target_id) entries, so a switch
>> +		 * decoder cannot interleave across more ports than that.
>> +		 */
>> +		if (cxld->interleave_ways > ARRAY_SIZE(target_list.target_id)) {
>> +			dev_warn(&port->dev,
>> +				 "decoder%d.%d: Interleave ways: %d exceeds target list size\n",
>> +				 port->id, cxld->id, cxld->interleave_ways);
>> +			return -ENXIO;
> [Severity: High]
> This is a pre-existing issue, but does returning here leave port->commit_end
> permanently advanced?
>
> Earlier in init_hdm_decoder(), port->commit_end is updated:
>
> 	if (committed) {
> 		...
> 		port->commit_end = cxld->id;
> 	}
>
> If we fail here and return -ENXIO, port->commit_end is not rolled back.  If
> initialization is retried, cxl_num_decoders_committed() will return an
> inflated count, which could cause the out of order commit check to fail.
> Could this permanently prevent the port from initializing?
Yes, this is another bug, I will send another patch to fix this.
>> +		}
>> +
>>   		lo = readl(hdm + CXL_HDM_DECODER0_TL_LOW(which));
>>   		hi = readl(hdm + CXL_HDM_DECODER0_TL_HIGH(which));
>>   		target_list.value = (hi << 32) + lo;
> [Severity: High]
> This is a pre-existing issue, but does this code read the target IDs
> incorrectly on big-endian architectures?
>
> target_list.value is populated as a native 64-bit integer.  The subsequent loop
> reads it byte-by-byte via the target_id union:
>
> 		for (i = 0; i < cxld->interleave_ways; i++)
> 			cxld->target_map[i] = target_list.target_id[i];
>
> On big-endian hardware, accessing the native 64-bit integer byte-by-byte will
> read the most significant bytes first, which could scramble the port target
> routing.
There is no CXL big-endian architecture platform, should not change this 
currently. Best Regards, Guixin Liu


  reply	other threads:[~2026-08-12  7:51 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-12  6:10 [PATCH v2] cxl/hdm: Fix out of bounds read of the decoder target list Guixin Liu
2026-08-12  6:26 ` sashiko-bot
2026-08-12  7:51   ` Guixin Liu [this message]
2026-08-12 11:31 ` Li Ming

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6be8a860-a56f-4776-9017-d976571fbee7@linux.alibaba.com \
    --to=kanie@linux.alibaba.com \
    --cc=linux-cxl@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.