From: "Gary Guo" <gary@garyguo.net>
To: aiqubits@hotmail.com, "Danilo Krummrich" <dakr@kernel.org>,
"Bjorn Helgaas" <bhelgaas@google.com>,
"Krzysztof Wilczyński" <kwilczynski@kernel.org>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Boqun Feng" <boqun@kernel.org>, "Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Andreas Hindborg" <a.hindborg@kernel.org>,
"Alice Ryhl" <aliceryhl@google.com>,
"Trevor Gross" <tmgross@umich.edu>,
"Daniel Almeida" <daniel.almeida@collabora.com>,
"Tamir Duberstein" <tamird@kernel.org>,
"Alexandre Courbot" <acourbot@nvidia.com>,
"Onur Özkan" <work@onurozkan.dev>
Cc: <linux-pci@vger.kernel.org>, <rust-for-linux@vger.kernel.org>,
<linux-kernel@vger.kernel.org>
Subject: Re: [PATCH v3] rust: pci: reject out-of-bounds IRQ vector indices
Date: Mon, 31 Aug 2026 13:45:34 +0100 [thread overview]
Message-ID: <DL350X20BPP5.2Y218YDKZP8CL@garyguo.net> (raw)
In-Reply-To: <20260831-fix-pci-irq-vector-index-truncation-v3-1-a2103084d20e@hotmail.com>
On Mon Aug 31, 2026 at 8:17 AM BST, Sophon Z via B4 Relay wrote:
> From: Sophon Z <aiqubits@hotmail.com>
>
> IrqVectorRegistration::index() accepts a usize and documents that
> out-of-bounds indices return EINVAL, while pci_irq_vector() takes an
> unsigned int.
>
> Casting an index larger than u32::MAX wraps it before the PCI core can
> validate it. In particular, u32::MAX + 1 becomes zero and can resolve to
> the first allocated vector. Values that fit in u32 but exceed
> MSI_MAX_INDEX can also reach msi_domain_get_virq() and trigger
> WARN_ON_ONCE.
>
> Check the index against the registration length before entering the C
> API, and keep the usize-to-u32 conversion checked so the ABI boundary
> does not rely on an unchecked cast.
>
> Fixes: 2fb7755b0a7e ("rust: pci: resolve IRQ in index() and embed IrqRequest in IrqVector")
>
> Signed-off-by: Sophon Z <aiqubits@hotmail.com>
> ---
> Changes in v3:
> - Check the index against the allocated vector count before entering the C API.
> - Keep the checked usize-to-u32 conversion and document the C-side warning.
> - Link to v2: https://patch.msgid.link/20260831-fix-pci-irq-vector-index-truncation-v2-1-4030ea7746a9@hotmail.com
>
> Changes in v2:
> - No code changes.
> - Link to v1: https://patch.msgid.link/20260831-fix-pci-irq-vector-index-truncation-v1-1-d63217d99b67@hotmail.com
> ---
> rust/kernel/pci/irq.rs | 8 +++++++-
> 1 file changed, 7 insertions(+), 1 deletion(-)
>
> diff --git a/rust/kernel/pci/irq.rs b/rust/kernel/pci/irq.rs
> index 6741046ec1c0..dfab323f26f7 100644
> --- a/rust/kernel/pci/irq.rs
> +++ b/rust/kernel/pci/irq.rs
> @@ -151,8 +151,14 @@ pub fn irq_type(&self) -> IrqType {
> /// [`Self::len()`].
> #[inline]
> pub fn index(&self, index: usize) -> Result<IrqVector<'_>> {
> + if index >= self.len.get() {
> + return Err(EINVAL);
> + }
> +
> + let index = u32::try_from(index).map_err(|_| EINVAL)?;
Just having this line should be fine, no need for the length check above.
Alternatively, just have the check above, and do the cast, while documenting
that `len` fits u32 as invariant (which is always true given the length is
handed out by PCI core.
Best,
Gary
> +
> // SAFETY: `self.dev.as_raw()` is a valid pointer to a `struct pci_dev`.
> - let irq = unsafe { bindings::pci_irq_vector(self.dev.as_raw(), index as u32) };
> + let irq = unsafe { bindings::pci_irq_vector(self.dev.as_raw(), index) };
> if irq < 0 {
> return Err(Error::from_errno(irq));
> }
>
> ---
> base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
> change-id: 20260831-fix-pci-irq-vector-index-truncation-6752f3751a0d
>
> Best regards,
> --
> Sophon Z <aiqubits@hotmail.com>
prev parent reply other threads:[~2026-08-31 12:45 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 7:17 [PATCH v3] rust: pci: reject out-of-bounds IRQ vector indices Sophon Z via B4 Relay
2026-08-31 7:17 ` Sophon Z
2026-08-31 7:25 ` sashiko-bot
2026-08-31 9:50 ` Miguel Ojeda
[not found] ` <SN7PR07MB9708E606E5C607ABE28C1F44CFA92@SN7PR07MB9708.namprd07.prod.outlook.com>
2026-09-01 9:47 ` 回复: " ai qubits
2026-08-31 12:45 ` Gary Guo [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DL350X20BPP5.2Y218YDKZP8CL@garyguo.net \
--to=gary@garyguo.net \
--cc=a.hindborg@kernel.org \
--cc=acourbot@nvidia.com \
--cc=aiqubits@hotmail.com \
--cc=aliceryhl@google.com \
--cc=bhelgaas@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun@kernel.org \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=kwilczynski@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=tamird@kernel.org \
--cc=tmgross@umich.edu \
--cc=work@onurozkan.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.