From: sashiko-bot@kernel.org
To: "Dave Jiang" <dave.jiang@intel.com>
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH v3 2/3] cxl/core: Hold the dport host lock across dport lookup and use
Date: Wed, 30 Sep 2026 15:40:58 +0000 [thread overview]
Message-ID: <20260930154059.2F6971F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930152311.4164036-3-dave.jiang@intel.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] cxl: dead output parameter in cxl_pci_find_port() and cxl_mem_find_port()
--
commit 58eb742e11e94e0c9aa8769fb391c94f00a507ed
Author: Dave Jiang <dave.jiang@intel.com>
cxl/core: Hold the dport host lock across dport lookup and use
This commit addresses a use-after-free risk during dport lookup. It introduces
helpers to look up the dport with the host lock held, and updates existing
callers to pass NULL instead of fetching the dport from the port lookup
functions.
> diff --git a/drivers/cxl/cxl.h b/drivers/cxl/cxl.h
> index cab8ce39f4653..f08de094f4125 100644
> --- a/drivers/cxl/cxl.h
> +++ b/drivers/cxl/cxl.h
> @@ -747,6 +759,10 @@ DEFINE_FREE(put_cxl_dax_region, struct cxl_dax_region *, if (!IS_ERR_OR_NULL(_T)
> int devm_cxl_enumerate_ports(struct cxl_memdev *cxlmd);
> void cxl_bus_rescan(void);
> void cxl_bus_drain(void);
> +struct cxl_dport *cxl_pci_find_dport(struct pci_dev *pdev,
> + struct cxl_port *port);
> +struct cxl_dport *cxl_mem_find_dport(struct cxl_memdev *cxlmd,
> + struct cxl_port *port);
> struct cxl_port *cxl_pci_find_port(struct pci_dev *pdev,
> struct cxl_dport **dport);
> struct cxl_port *cxl_mem_find_port(struct cxl_memdev *cxlmd,
[Severity: Low]
Since this patch updates all callers to pass NULL for the dport argument,
the dport parameter is now completely unused in both cxl_pci_find_port()
and cxl_mem_find_port() defined in drivers/cxl/core/port.c.
Should the struct cxl_dport **dport parameter be removed entirely from these
function signatures and internal helpers like find_cxl_port_by_dport() to
avoid leaving dead output parameters?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930152311.4164036-1-dave.jiang@intel.com?part=2
next prev parent reply other threads:[~2026-09-30 15:41 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 15:23 [PATCH v3 0/3] cxl: dport fixes from sashiko reports Dave Jiang
2026-09-30 15:23 ` [PATCH v3 1/3] cxl/port: Clear cached dport pointers when a dport is removed Dave Jiang
2026-09-30 22:56 ` Alison Schofield
2026-09-30 15:23 ` [PATCH v3 2/3] cxl/core: Hold the dport host lock across dport lookup and use Dave Jiang
2026-09-30 15:40 ` sashiko-bot [this message]
2026-09-30 22:59 ` Alison Schofield
2026-10-01 1:47 ` Li Ming
2026-09-30 15:23 ` [PATCH v3 3/3] cxl/port: Attach endpoints to a dport under the lock that pins it Dave Jiang
2026-09-30 23:00 ` Alison Schofield
2026-10-01 1:59 ` Li Ming
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930154059.2F6971F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dave.jiang@intel.com \
--cc=linux-cxl@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).