From: sashiko-bot@kernel.org
To: "Francesco Valla" <francesco@valla.it>
Cc: devicetree@vger.kernel.org, "Eugenio Perez" <eperezma@redhat.com>,
Frank.Li@kernel.org, robh@kernel.org, conor+dt@kernel.org,
imx@lists.linux.dev, "Michael S. Tsirkin" <mst@redhat.com>,
virtualization@lists.linux.dev
Subject: Re: [PATCH RFC 04/12] dma-coherent: add base and size APIs
Date: Wed, 16 Sep 2026 21:55:55 +0000 [thread overview]
Message-ID: <20260916215555.F03051F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260916-remoteproc_virtio_map-v1-4-dac8c5eb4aa9@valla.it>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] dma: integer overflow in dma_dev_coherent_size()
--
commit c7a3821680bbb5546ff7e7a9e6fe376429788c67
Author: Francesco Valla <francesco@valla.it>
dma-coherent: add base and size APIs
This commit adds two new APIs, dma_dev_coherent_size() and
dma_dev_coherent_base(), to retrieve the size and base address of the
coherent memory pool associated with a device.
> diff --git a/kernel/dma/coherent.c b/kernel/dma/coherent.c
> index 45bbae947f4be..f4aa5813604b8 100644
> --- a/kernel/dma/coherent.c
> +++ b/kernel/dma/coherent.c
[ ... ]
> @@ -277,6 +277,40 @@ int dma_mmap_from_dev_coherent(struct device *dev, struct vm_area_struct *vma,
[ ... ]
> +size_t dma_dev_coherent_size(struct device *dev)
> +{
> + struct dma_coherent_mem *mem = dev_get_coherent_memory(dev);
> +
> + if (!mem)
> + return 0;
> +
> + return (mem->size << PAGE_SHIFT);
[Severity: High]
Could this left shift overflow for large coherent pools?
If the pool size is 2GB or larger, mem->size (which is an int representing
the number of pages) will be >= 524288. Shifting a signed 32-bit integer by
PAGE_SHIFT overflows in this case, and the result incorrectly sign-extends
when implicitly cast to size_t.
This might cause the function to return an astronomically large size_t value
instead of the actual pool size, which could lead to out-of-bounds accesses
or allocation failures in callers trusting the returned size.
Would casting mem->size to size_t before the shift prevent this?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916-remoteproc_virtio_map-v1-0-dac8c5eb4aa9@valla.it?part=4
next prev parent reply other threads:[~2026-09-16 21:55 UTC|newest]
Thread overview: 58+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 21:10 [PATCH RFC 00/12] remoteproc: add support for any virtio device Francesco Valla
2026-09-16 21:10 ` [PATCH RFC 01/12] remoteproc: virtio: cleanup rproc_add_virtio_dev error path Francesco Valla
2026-09-16 21:56 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 02/12] remoteproc: virtio: replace commas with semicolons Francesco Valla
2026-09-16 21:58 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 03/12] remoteproc: virtio: support dynamic number of vrings Francesco Valla
2026-09-16 22:00 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 04/12] dma-coherent: add base and size APIs Francesco Valla
2026-09-16 21:55 ` sashiko-bot [this message]
2026-09-16 21:10 ` [PATCH RFC 05/12] remoteproc: always report VIRTIO_F_VERSION_1 feature Francesco Valla
2026-09-16 22:00 ` sashiko-bot
2026-09-21 15:47 ` Mathieu Poirier
2026-09-22 6:32 ` Francesco Valla
2026-09-22 15:10 ` Mathieu Poirier
2026-09-16 21:10 ` [PATCH RFC 06/12] remoteproc: virtio: add bounce buffering for data buffers Francesco Valla
2026-09-16 22:03 ` sashiko-bot
2026-09-22 15:58 ` Mathieu Poirier
2026-09-22 19:39 ` Francesco Valla
2026-09-23 14:44 ` Mathieu Poirier
2026-09-23 16:05 ` Francesco Valla
2026-09-25 15:07 ` Mathieu Poirier
2026-09-25 16:48 ` Robin Murphy
2026-09-25 19:05 ` Francesco Valla
2026-09-27 22:12 ` Francesco Valla
2026-09-25 17:03 ` Robin Murphy
2026-09-16 21:10 ` [PATCH RFC 07/12] dt-bindings: spi: add bindings for spi-virtio Francesco Valla
2026-09-16 21:52 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 08/12] dt-bindings: remoteproc: add remoteproc-virtio Francesco Valla
2026-09-16 21:56 ` sashiko-bot
2026-09-22 15:40 ` Mathieu Poirier
2026-09-22 19:44 ` Francesco Valla
2026-09-23 14:56 ` Mathieu Poirier
2026-10-06 18:39 ` Rob Herring
2026-10-07 0:51 ` Mathieu Poirier
2026-10-07 13:42 ` Rob Herring
2026-10-07 16:34 ` Francesco Valla
2026-09-16 21:10 ` [PATCH RFC 09/12] remoteproc: search for a fwnode during vdev registration Francesco Valla
2026-09-16 21:58 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 10/12] remoteproc: imx_rproc: always use non-blocking mailboxes Francesco Valla
2026-09-16 22:05 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 11/12] dt-bindings: remoteproc: imx-rproc: support virtio Francesco Valla
2026-09-16 22:04 ` sashiko-bot
2026-09-16 21:10 ` [PATCH RFC 12/12] PoC: arm64: dts: imx93-11x11-frdm: add multiple vdevs Francesco Valla
2026-09-16 22:07 ` sashiko-bot
2026-09-22 15:43 ` Mathieu Poirier
2026-09-22 20:19 ` Francesco Valla
2026-09-23 15:48 ` Mathieu Poirier
2026-09-23 18:42 ` Francesco Valla
2026-09-24 15:49 ` Mathieu Poirier
2026-09-25 19:13 ` Francesco Valla
2026-09-25 8:39 ` Alexander Stein
2026-09-25 19:26 ` Francesco Valla
2026-09-18 16:53 ` [PATCH RFC 00/12] remoteproc: add support for any virtio device Mathieu Poirier
2026-09-19 7:33 ` Francesco Valla
2026-09-21 3:31 ` Mathieu Poirier
2026-09-22 6:28 ` Francesco Valla
2026-09-22 13:53 ` Mathieu Poirier
2026-09-23 15:13 ` Robin Murphy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916215555.F03051F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=eperezma@redhat.com \
--cc=francesco@valla.it \
--cc=imx@lists.linux.dev \
--cc=mst@redhat.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=virtualization@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox