From: Dave Jiang <dave.jiang@intel.com>
To: Alison Schofield <alison.schofield@intel.com>,
Davidlohr Bueso <dave@stgolabs.net>,
Jonathan Cameron <jonathan.cameron@huawei.com>,
Vishal Verma <vishal.l.verma@intel.com>,
Ira Weiny <ira.weiny@intel.com>,
Dan Williams <dan.j.williams@intel.com>
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH] cxl/region: Use %pa printk format to emit resource_size_t
Date: Tue, 14 Oct 2025 07:38:07 -0700 [thread overview]
Message-ID: <0a3201ec-3169-4e08-93e0-87a514d46a61@intel.com> (raw)
In-Reply-To: <20251014073106.730952-1-alison.schofield@intel.com>
On 10/14/25 12:31 AM, Alison Schofield wrote:
> KASAN reports a stack-out-of-bounds access in validate_region_offset()
> while running the cxl-poison.sh unit test because the printk format
> specifier, %pr format, is not a match for the resource_size_t type of
> the variables. %pr expects struct resource pointers and attempts to
> dereference the structure fields, reading beyond the bounds of the
> stack variables.
>
> Since these messages emit an 'A exceeds B' type of message, keep
> the resource_size_t's and use the %pa specifier to be architecture
> safe.
>
> BUG: KASAN: stack-out-of-bounds in resource_string.isra.0+0xe9a/0x1690
> [] Read of size 8 at addr ffff88800a7afb40 by task bash/1397
> ...
> [] The buggy address belongs to stack of task bash/1397
> [] and is located at offset 56 in frame:
> [] validate_region_offset+0x0/0x1c0 [cxl_core]
>
> Fixes: c3dd67681c70 ("cxl/region: Add inject and clear poison by region offset")
> Signed-off-by: Alison Schofield <alison.schofield@intel.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>> ---
> drivers/cxl/core/region.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/cxl/core/region.c b/drivers/cxl/core/region.c
> index e14c1d305b22..4e567f7e06bc 100644
> --- a/drivers/cxl/core/region.c
> +++ b/drivers/cxl/core/region.c
> @@ -3666,14 +3666,14 @@ static int validate_region_offset(struct cxl_region *cxlr, u64 offset)
>
> if (offset < p->cache_size) {
> dev_err(&cxlr->dev,
> - "Offset %#llx is within extended linear cache %pr\n",
> + "Offset %#llx is within extended linear cache %pa\n",
> offset, &p->cache_size);
> return -EINVAL;
> }
>
> region_size = resource_size(p->res);
> if (offset >= region_size) {
> - dev_err(&cxlr->dev, "Offset %#llx exceeds region size %pr\n",
> + dev_err(&cxlr->dev, "Offset %#llx exceeds region size %pa\n",
> offset, ®ion_size);
> return -EINVAL;
> }
>
> base-commit: 3a8660878839faadb4f1a6dd72c3179c1df56787
next prev parent reply other threads:[~2025-10-14 14:38 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-10-14 7:31 [PATCH] cxl/region: Use %pa printk format to emit resource_size_t Alison Schofield
2025-10-14 14:38 ` Dave Jiang [this message]
2025-10-14 14:46 ` Dave Jiang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0a3201ec-3169-4e08-93e0-87a514d46a61@intel.com \
--to=dave.jiang@intel.com \
--cc=alison.schofield@intel.com \
--cc=dan.j.williams@intel.com \
--cc=dave@stgolabs.net \
--cc=ira.weiny@intel.com \
--cc=jonathan.cameron@huawei.com \
--cc=linux-cxl@vger.kernel.org \
--cc=vishal.l.verma@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox