From: sashiko-bot@kernel.org
To: "Daniel Zahka" <daniel.zahka@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH net-next 2/8] eth: mpnic: add register init for the device
Date: Thu, 24 Sep 2026 01:44:34 +0000 [thread overview]
Message-ID: <20260924014434.9A2781F00898@smtp.kernel.org> (raw)
In-Reply-To: <20260922-linux-mpnic-v1-2-236844f53072@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] pci: missing pci_resource_len() check in mpnic_probe() allows OOB MMIO access
--
commit 647e9ec73143ec855da6fd69e03902213d836df8
Author: Mohsin Bashir <mohsin.bashr@gmail.com>
eth: mpnic: add register init for the device
This commit adds one-time register initialization for the mpnic device during
the probe process. It covers static configurations and pulses for zeroizing
on-chip SRAMs.
> diff --git a/drivers/net/ethernet/meta/mpnic/mpnic_init.c b/drivers/net/ethernet/meta/mpnic/mpnic_init.c
> new file mode 100644
> index 0000000000000..f8ebb19766731
> --- /dev/null
> +++ b/drivers/net/ethernet/meta/mpnic/mpnic_init.c
[ ... ]
> +static void mpnic_ro_init(struct mpnic_dev *mpd)
> +{
> + u64 attr = mpd->relaxed_ord ? MPNIC_OB_ATTR_RO : 0;
> +
> + mpnic_wr64(mpd, MPNIC_OB_ATTR_TDE_H, attr);
> + mpnic_wr64(mpd, MPNIC_OB_ATTR_TDE_P, attr);
> + mpnic_wr64(mpd, MPNIC_OB_ATTR_TDF, attr);
> + mpnic_wr64(mpd, MPNIC_OB_ATTR_RBP_HPQ, attr);
> + mpnic_wr64(mpd, MPNIC_OB_ATTR_RBP_PPQ, attr);
> + mpnic_wr64(mpd, MPNIC_OB_ATTR_RDE_H, attr);
> + mpnic_wr64(mpd, MPNIC_OB_ATTR_RDE_P, attr);
[Severity: High]
Can this write out of bounds of the mapped MMIO region if the PCI BAR is
unexpectedly small?
This function accesses MPNIC_OB_ATTR_RDE_P, which is at offset 0x2680068.
This requires the mapped region to be at least ~40MB.
Earlier in the initialization path, mpnic_probe() maps the PCI BAR via
pcim_iomap_region() without verifying if pci_resource_len() covers these
expected MMIO registers.
If a malicious or spoofed PCI device (e.g., connected via Thunderbolt)
advertises an artificially small BAR, the driver will map this short length
but unconditionally write to offsets far beyond the mapped boundary here.
This could cause an immediate page fault and system crash upon device
connection.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922-linux-mpnic-v1-0-236844f53072@gmail.com?part=2
next prev parent reply other threads:[~2026-09-24 1:44 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 1:43 [PATCH net-next 0/8] eth: mpnic: initial support for Meta Platforms NIC Daniel Zahka
2026-09-23 1:43 ` [PATCH net-next 1/8] eth: mpnic: add scaffolding " Daniel Zahka
2026-09-24 1:44 ` sashiko-bot
2026-09-23 1:43 ` [PATCH net-next 2/8] eth: mpnic: add register init for the device Daniel Zahka
2026-09-24 1:44 ` sashiko-bot [this message]
2026-09-24 2:05 ` netdev-bot+sashiko
2026-09-24 16:16 ` Daniel Zahka
2026-09-24 16:22 ` Jakub Kicinski
2026-09-23 1:43 ` [PATCH net-next 3/8] eth: mpnic: allocate MSI-X vectors Daniel Zahka
2026-09-23 1:43 ` [PATCH net-next 4/8] eth: mpnic: implement Tx queue allocation and cleanup Daniel Zahka
2026-09-24 1:44 ` sashiko-bot
2026-09-24 2:05 ` netdev-bot+sashiko
2026-09-24 16:39 ` Daniel Zahka
2026-09-23 1:43 ` [PATCH net-next 5/8] eth: mpnic: start and stop the Tx HW queues Daniel Zahka
2026-09-24 1:44 ` sashiko-bot
2026-09-24 2:05 ` netdev-bot+sashiko
2026-09-24 17:49 ` Daniel Zahka
2026-09-23 1:43 ` [PATCH net-next 6/8] eth: mpnic: add a netdevice and basic Tx handling Daniel Zahka
2026-09-24 1:44 ` sashiko-bot
2026-09-24 2:05 ` netdev-bot+sashiko
2026-09-24 18:08 ` Daniel Zahka
2026-09-23 1:43 ` [PATCH net-next 7/8] eth: mpnic: implement Rx queue allocation and cleanup Daniel Zahka
2026-09-24 2:05 ` netdev-bot+sashiko
2026-09-24 18:23 ` Daniel Zahka
2026-09-23 1:43 ` [PATCH net-next 8/8] eth: mpnic: add basic Rx handling Daniel Zahka
2026-09-24 1:44 ` sashiko-bot
2026-09-24 2:05 ` netdev-bot+sashiko
2026-09-24 18:38 ` Daniel Zahka
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924014434.9A2781F00898@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel.zahka@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox