From: sashiko-bot@kernel.org
To: "Gaobin Huang" <huanggaobin23@semi.ac.cn>
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH v2] cxl/mbox: bound the Get Supported Logs entry count by the payload
Date: Thu, 17 Sep 2026 10:53:01 +0000 [thread overview]
Message-ID: <20260917105302.165CF1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260917104603.2658529-1-huanggaobin23@semi.ac.cn>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] cxl/mbox: memory leak of gsl buffer on truncated payload error path
--
commit 7ecb0885e04d5e150bd0769634b9a3391c017244
Author: Gaobin Huang <huanggaobin23@semi.ac.cn>
cxl/mbox: bound the Get Supported Logs entry count by the payload
This commit adds bounds checking for the number of entries in the Get
Supported Logs response against the actual payload size. It prevents
out-of-bounds reads during device probe by ensuring the device doesn't
report more entries than it actually returns.
> diff --git a/drivers/cxl/core/mbox.c b/drivers/cxl/core/mbox.c
> --- a/drivers/cxl/core/mbox.c
> +++ b/drivers/cxl/core/mbox.c
[ ... ]
> @@ -849,18 +851,47 @@ int cxl_enumerate_cmds(struct cxl_memdev_state *mds)
> struct cxl_mbox_get_supported_logs *gsl;
> struct device *dev = mds->cxlds.dev;
> struct cxl_mem_command *cmd;
> + size_t gsl_len, gsl_hdr_size, max_entries;
> int i, rc;
>
> - gsl = cxl_get_gsl(mds);
> + gsl = cxl_get_gsl(mds, &gsl_len);
> if (IS_ERR(gsl))
> return PTR_ERR(gsl);
>
> + /*
> + * The device chooses the reported payload length and min_out only
> + * requires the entry count field on its own (2 bytes), so a response
> + * shorter than the header is reachable. There is nothing to enumerate
> + * in that case: fail rather than derive a bound from an underflowed
> + * subtraction.
> + */
> + gsl_hdr_size = struct_offset(gsl, entry);
> + if (gsl_len < gsl_hdr_size) {
> + dev_err(dev,
> + "GSL: response of %zu bytes is too short for the header\n",
> + gsl_len);
> + return -EIO;
[Severity: Medium]
Does this code leak the `gsl` buffer allocated by cxl_get_gsl()?
cxl_get_gsl() dynamically allocates the `gsl` buffer using kvmalloc() and
returns it. By directly returning -EIO when the payload is shorter than the
header, we bypass the `goto out;` block which contains the necessary
kvfree(gsl) call. Since this occurs on a device probe error path, it leaks
the allocated memory.
As an additional observation, leaving `.min_out = 2` in cxl_get_gsl() forces
higher layers to manually re-validate the payload length here. Setting
`.min_out = 8` (or using struct_size()) in cxl_get_gsl() would allow the CXL
mailbox core to handle this validation natively without requiring these
manual checks.
> + }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260917104603.2658529-1-huanggaobin23@semi.ac.cn?part=1
next prev parent reply other threads:[~2026-09-17 10:53 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 10:46 [PATCH v2] cxl/mbox: bound the Get Supported Logs entry count by the payload Gaobin Huang
2026-09-17 10:53 ` sashiko-bot [this message]
2026-09-17 23:41 ` Alison Schofield
2026-09-18 19:32 ` Jonathan Cameron
2026-09-29 6:14 ` 黄高彬
2026-09-21 7:29 ` Richard Cheng
2026-09-29 6:15 ` 黄高彬
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917105302.165CF1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=huanggaobin23@semi.ac.cn \
--cc=linux-cxl@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox