Linux-i3c Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Adrian Hunter" <adrian.hunter@intel.com>
Cc: "Alexandre Belloni" <alexandre.belloni@bootlin.com>,
	linux-i3c@lists.infradead.org, Frank.Li@kernel.org
Subject: Re: [PATCH V2 05/17] i3c: master: Remove stale GETSTATUS length check
Date: Thu, 17 Sep 2026 19:26:29 +0000	[thread overview]
Message-ID: <20260917192630.41F6F1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260917191356.133242-6-adrian.hunter@intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] i3c: GETSTATUS silent success on 0-byte read with amd-i3c-master
--

commit f719c6d08e31060f2440ad1b34f948657af68459
Author: Adrian Hunter <adrian.hunter@intel.com>

    i3c: master: Remove stale GETSTATUS length check

This commit removes an explicit length check in i3c_master_getstatus_locked(),
relying instead on the generic CCC response length validation.

> diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c
> index 425b98e6efaaa..c50887b0b37d0 100644
> --- a/drivers/i3c/master.c
> +++ b/drivers/i3c/master.c
> @@ -1777,11 +1777,6 @@ static int i3c_master_getstatus_locked(struct i3c_master_controller *master,
>  	if (ret)
>  		goto out;
>  
> -	if (dest.payload.len != sizeof(*getstatus)) {
> -		ret = -EIO;
> -		goto out;
> -	}
> -
>  	if (status)
>  		*status = be16_to_cpu(getstatus->status);

[Severity: Medium]
Does removing this explicit length check introduce a silent failure on systems
using the amd-i3c-master controller?

When an I3C device terminates a GETSTATUS read with 0 bytes on the
amd-i3c-master controller, the driver incorrectly mutates payload.len to 0
instead of setting actual_len.

The generic validation in i3c_ccc_validate_payload_len() explicitly skips
validation if !p->len, incorrectly returning success. Before this patch, the
explicit length check here safely caught the driver's mutated 0-length and
correctly returned -EIO.

Without this check, the function silently succeeds and reads the zeroed
getstatus->status structure. Can this lead to incorrect behavior on these
systems?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260917191356.133242-1-adrian.hunter@intel.com?part=5

-- 
linux-i3c mailing list
linux-i3c@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-i3c

  reply	other threads:[~2026-09-17 19:26 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 19:13 [PATCH V2 00/17] i3c: Fixes, cleanups and HDR-DDR support Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 01/17] i3c: master: Fix out-of-bounds read in DMA bounce buffer setup Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 02/17] i3c: mipi-i3c-hci: Bounce short reads irrespective of the IOMMU Adrian Hunter
2026-09-17 21:21   ` Frank Li
2026-09-17 19:13 ` [PATCH V2 03/17] i3c: mipi-i3c-hci-pci: Set drvdata before creating LTR sysfs attribute Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 04/17] i3c: master: Match ACPI targets to the correct bus controller instance Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 05/17] i3c: master: Remove stale GETSTATUS length check Adrian Hunter
2026-09-17 19:26   ` sashiko-bot [this message]
2026-09-20 13:10     ` Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 06/17] i3c: mipi-i3c-hci: Restore controller state if i3c_hci_enable_ibi() returns an error Adrian Hunter
2026-09-17 21:23   ` Frank Li
2026-09-17 19:13 ` [PATCH V2 07/17] i3c: mipi-i3c-hci: Send DISEC before disabling IBIs in hardware Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 08/17] i3c: mipi-i3c-hci: Fix runtime PM violation in i3c_hci_free_ibi() Adrian Hunter
2026-09-17 21:32   ` Frank Li
2026-09-17 19:13 ` [PATCH V2 09/17] i3c: mipi-i3c-hci: Process multiple IBIs per interrupt Adrian Hunter
2026-09-17 21:37   ` Frank Li
2026-09-17 19:13 ` [PATCH V2 10/17] i3c: mipi-i3c-hci: Move DMA suspend/resume callbacks Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 11/17] i3c: mipi-i3c-hci: Stop rings gracefully when suspending Adrian Hunter
2026-09-17 21:40   ` Frank Li
2026-09-17 19:13 ` [PATCH V2 12/17] i3c: mipi-i3c-hci: Correct RESP_DATA_LENGTH to bits 15:0 Adrian Hunter
2026-09-17 21:42   ` Frank Li
2026-09-17 19:13 ` [PATCH V2 13/17] i3c: mipi-i3c-hci: Remove invalid transfer size limit Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 14/17] i3c: mipi-i3c-hci: Remove invalid HDR-BT and Fm/Fm+ definitions Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 15/17] i3c: mipi-i3c-hci: Support configurable device NACK retries Adrian Hunter
2026-09-18 13:44   ` Frank Li
2026-09-17 19:13 ` [PATCH V2 16/17] i3c: Restrict HDR modes to those supported by the bus and target Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 17/17] i3c: mipi-i3c-hci: Add HDR-DDR support Adrian Hunter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917192630.41F6F1F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=adrian.hunter@intel.com \
    --cc=alexandre.belloni@bootlin.com \
    --cc=linux-i3c@lists.infradead.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox