From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from ale.deltatee.com (ale.deltatee.com [204.191.154.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6E367429CE8; Tue, 14 Jul 2026 21:44:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=204.191.154.188 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784065460; cv=none; b=U+0oOI65nENucIMe6GmRbMFLJzNo7lap1JsfTdmJDqDj75JXsztZoDFaDRrPtbxdNbqSkcyu5iYAWrJorpolDOK8v145oIKANwydms1XymHF483FS8rexZz7WLhmvSkq9n+gdpX25uCalYUDLpUXdlBGuY+6ZcsuIqruVANTKXU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784065460; c=relaxed/simple; bh=5MMvUzfPFSHRFS9iGY5trpg9sc8q7isOO7HuCXazzbc=; h=Message-ID:Date:MIME-Version:To:Cc:References:From:In-Reply-To: Content-Type:Subject; b=UFrA3TSJKrJJmieZ/+Wopf6bbOYBZzgv2JLGjp6kyCSXS3MPDV5o6YPIEW4CBGjAnUwWsu2ZkjvYGvzOHvaQT0+MyKt8PIhJf88HFf43HI2s67BPMGWk4S/vEBdd7fB7RAjhUU2SH/gxtWecF3gmssWCyj8Z5RwRDn2x9pwN5j8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com; spf=pass smtp.mailfrom=deltatee.com; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b=ZNnkTYRG; arc=none smtp.client-ip=204.191.154.188 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=deltatee.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=deltatee.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=deltatee.com header.i=@deltatee.com header.b="ZNnkTYRG" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=deltatee.com; s=20200525; h=Subject:In-Reply-To:From:References:Cc:To: MIME-Version:Date:Message-ID:content-disposition; bh=JvSBZj1Vq5wUOwV0VVic1jYGrF9K1DEaesscS8WrHOs=; b=ZNnkTYRGed9/i/sXg025bNJf+s MV0+tcfokYyDYVzmOXwycEU0UtZ4gBngjEe/EBqL8KLTgzl5F+ib1Ghnz8X0WlIw+IsQ4/frU8PrR GGeHgurLuKrAHiiUiboU/efnTJZwa8CmLybiwXadtLYsmWJrVSf/rVkehF1PlEpcNL4F/ALatT+YH uZ2tmuByOwLbXl0TSwpjeK5W8clTf497Qzps3MGBG6dv5gPaaUKTS9yIpjfTevSNzdgcEOXT7v9Eq G4IuOTB5Qdhecgzj5k7aH3cc3b6jBWU/gqxiLZ4Bf/JsZOkkFW/nP9Z3RTdFylf6c/31oRCFg+gfT YH4agZrQ==; Received: from guinness.priv.deltatee.com ([172.16.1.162]) by ale.deltatee.com with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1wjkvK-00000006fJT-0mvL; Tue, 14 Jul 2026 15:44:18 -0600 Message-ID: Date: Tue, 14 Jul 2026 15:44:18 -0600 Precedence: bulk X-Mailing-List: dmaengine@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird To: sashiko-reviews@lists.linux.dev Cc: linux-pci@vger.kernel.org, Frank.Li@kernel.org, dmaengine@vger.kernel.org, vkoul@kernel.org References: <20260714212010.230606-1-logang@deltatee.com> <20260714212010.230606-4-logang@deltatee.com> <20260714213824.A2F201F000E9@smtp.kernel.org> Content-Language: en-CA From: Logan Gunthorpe In-Reply-To: <20260714213824.A2F201F000E9@smtp.kernel.org> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-SA-Exim-Connect-IP: 172.16.1.162 X-SA-Exim-Rcpt-To: sashiko-reviews@lists.linux.dev, linux-pci@vger.kernel.org, Frank.Li@kernel.org, dmaengine@vger.kernel.org, vkoul@kernel.org X-SA-Exim-Mail-From: logang@deltatee.com X-Spam-Level: Subject: Re: [PATCH v1 3/3] PCI: Add PCI1008 to switchtec NTB DMA alias quirk X-SA-Exim-Version: 4.2.1 (built Sun, 23 Feb 2025 07:57:16 +0000) X-SA-Exim-Scanned: Yes (on ale.deltatee.com) On 2026-07-14 15:38, sashiko-bot@kernel.org wrote: > [Severity: High] > This isn't a bug introduced by this patch, but while looking at the function > triggered by this quirk (quirk_switchtec_ntb_dma_alias()), I noticed an > incorrect pointer arithmetic issue. > > In drivers/pci/quirks.c:quirk_switchtec_ntb_dma_alias(): > > partition_map = ioread32(&mmio_ntb->ep_map); > partition_map |= ((u64) ioread32(&mmio_ntb->ep_map + 4)) << 32; > > Since mmio_ntb->ep_map is a u64, does the + 4 advance the pointer by 32 > bytes (4 * sizeof(u64)) instead of the intended 4 bytes? > > Looking at struct ntb_info_regs, this would read from offset 36 > (target_part_low) instead of the upper 32 bits of ep_map at offset 8. This > populates the upper 32 bits of partition_map with unintended data, causing > the device initialization loop to process invalid partition IDs, which > could potentially access out-of-bounds MMIO registers or create incorrect > DMA aliases. > > Could this read be corrected to avoid scaling by the type size? > As noted by the Sashiko bot, this issue is unrelated to this series. But I'll dig into it and try to remember if that was intended or a mistake and send a patch if needed. In the mean time, this shouldn't gate this series. Logan