From: sashiko-bot@kernel.org
To: "Davidlohr Bueso" <dave@stgolabs.net>
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH v9 09/10] cxl/test: Add mock BI topology support
Date: Wed, 23 Sep 2026 01:11:29 +0000 [thread overview]
Message-ID: <20260923011129.BF5F31F000FF@smtp.kernel.org> (raw)
In-Reply-To: <113381dfa31a452a5522ed84b14a3b77b6e027f3.1790103847.git.dave@stgolabs.net>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] cxl/test: Use-After-Free in mock_cxl_setup_hdm() on unbind/rebind
--
commit 943579b999ae7670b28d433527c8563008ab779f
Author: Davidlohr Bueso <dave@stgolabs.net>
cxl/test: Add mock BI topology support
Extend the mock topology with a Back-Invalidate path
covering both the type3 memdevs and the type2 accelerator.
[ ... ]
Reviewed-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Davidlohr Bueso <dave@stgolabs.net>
> diff --git a/tools/testing/cxl/test/cxl.c b/tools/testing/cxl/test/cxl.c
> index 62bd92b3be45f..cddea44e780aa 100644
> --- a/tools/testing/cxl/test/cxl.c
> +++ b/tools/testing/cxl/test/cxl.c
[ ... ]
> @@ -736,10 +767,65 @@ static struct cxl_hdm *mock_cxl_setup_hdm(struct cxl_port *port,
> cxlhdm->port = port;
> cxlhdm->interleave_mask = ~0U;
> cxlhdm->iw_cap_mask = ~0UL;
> +
> + /*
> + * A page of plain memory stands in for the HDM decoder register
> + * block: cxled_committed_bi() reads the per-decoder BI bit from
> + * it, which mock_decoder_commit()/reset() maintain below. All
> + * other consumers of these registers are bypassed by the mocked
> + * decoder setup and commit paths.
> + */
> + cxlhdm->regs.hdm_decoder =
> + (void __iomem *)devm_get_free_pages(dev,
> + GFP_KERNEL | __GFP_ZERO, 0);
> + if (!cxlhdm->regs.hdm_decoder)
> + return ERR_PTR(-ENOMEM);
> +
> + /* likewise for the endpoint's BI Decoder block, BI Enable set */
> + if (is_cxl_endpoint(port) && !port->regs.bi_decoder) {
> + void __iomem *bi = (void __iomem *)
> + devm_get_free_pages(dev, GFP_KERNEL | __GFP_ZERO, 0);
> +
> + if (!bi)
> + return ERR_PTR(-ENOMEM);
> + writel(CXL_BI_DECODER_CTRL_BI_ENABLE,
> + bi + CXL_BI_DECODER_CTRL_OFFSET);
> + port->regs.bi_decoder = bi;
> + }
[Severity: Medium]
Could this lead to a use-after-free during a driver unbind/rebind cycle?
In mock_cxl_setup_hdm(), devm_get_free_pages() is used to allocate memory
for port->regs.bi_decoder. During a cxl_test unbind, devres will free this
memory, but the pointer remains set in the long-lived struct cxl_port.
On a subsequent rebind, the condition !port->regs.bi_decoder will evaluate to
false, skipping the allocation of new memory. This leaves a dangling pointer
that could be dereferenced later by cxl_bi_decoder_enabled().
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1790103847.git.dave@stgolabs.net?part=9
next prev parent reply other threads:[~2026-09-23 1:11 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 23:38 [PATCH v9 0/10] cxl: Support Back-Invalidate Davidlohr Bueso
2026-09-22 23:38 ` [PATCH v9 01/10] cxl: Add BI register probing and port initialization Davidlohr Bueso
2026-09-29 4:06 ` Richard Cheng
2026-09-22 23:38 ` [PATCH v9 02/10] cxl/pci: Add BI topology enable/disable Davidlohr Bueso
2026-09-23 1:12 ` sashiko-bot
2026-09-23 17:00 ` Davidlohr Bueso
2026-09-23 5:41 ` Li Ming
2026-09-25 23:32 ` Jonathan Cameron
2026-09-29 8:52 ` Richard Cheng
2026-09-30 23:01 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 03/10] cxl/hdm: Add BI coherency support for endpoint decoders Davidlohr Bueso
2026-09-23 6:06 ` Li Ming
2026-09-30 23:11 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 04/10] cxl: Add HDM-DB region creation Davidlohr Bueso
2026-10-01 3:28 ` Alison Schofield
2026-10-01 8:57 ` Davidlohr Bueso
2026-09-22 23:38 ` [PATCH v9 05/10] cxl/hdm: Rename decoder coherency flags Davidlohr Bueso
2026-09-24 0:49 ` Li Ming
2026-09-22 23:38 ` [PATCH v9 06/10] cxl/region: Log the coherency model at region creation Davidlohr Bueso
2026-09-24 0:49 ` Li Ming
2026-09-30 23:10 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 07/10] cxl/pci: Split BI capability probe from setup Davidlohr Bueso
2026-09-24 0:49 ` Li Ming
2026-09-30 23:09 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 08/10] cxl: Allow auto-committed BI hdm decoders Davidlohr Bueso
2026-10-01 3:49 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 09/10] cxl/test: Add mock BI topology support Davidlohr Bueso
2026-09-23 1:11 ` sashiko-bot [this message]
2026-09-23 20:57 ` Davidlohr Bueso
2026-09-23 0:43 ` [PATCH v9 10/10] cxl/doc: Update maturity map with BI support Davidlohr Bueso
2026-09-24 0:50 ` Li Ming
2026-09-30 23:08 ` Alison Schofield
2026-09-30 16:47 ` [PATCH v9 0/10] cxl: Support Back-Invalidate Alison Schofield
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923011129.BF5F31F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dave@stgolabs.net \
--cc=linux-cxl@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox