From: sashiko-bot@kernel.org
To: "Adrian Hunter" <adrian.hunter@intel.com>
Cc: "Alexandre Belloni" <alexandre.belloni@bootlin.com>,
linux-i3c@lists.infradead.org, Frank.Li@kernel.org
Subject: Re: [PATCH V2 05/17] i3c: master: Remove stale GETSTATUS length check
Date: Thu, 17 Sep 2026 19:26:29 +0000 [thread overview]
Message-ID: <20260917192630.41F6F1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260917191356.133242-6-adrian.hunter@intel.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] i3c: GETSTATUS silent success on 0-byte read with amd-i3c-master
--
commit f719c6d08e31060f2440ad1b34f948657af68459
Author: Adrian Hunter <adrian.hunter@intel.com>
i3c: master: Remove stale GETSTATUS length check
This commit removes an explicit length check in i3c_master_getstatus_locked(),
relying instead on the generic CCC response length validation.
> diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c
> index 425b98e6efaaa..c50887b0b37d0 100644
> --- a/drivers/i3c/master.c
> +++ b/drivers/i3c/master.c
> @@ -1777,11 +1777,6 @@ static int i3c_master_getstatus_locked(struct i3c_master_controller *master,
> if (ret)
> goto out;
>
> - if (dest.payload.len != sizeof(*getstatus)) {
> - ret = -EIO;
> - goto out;
> - }
> -
> if (status)
> *status = be16_to_cpu(getstatus->status);
[Severity: Medium]
Does removing this explicit length check introduce a silent failure on systems
using the amd-i3c-master controller?
When an I3C device terminates a GETSTATUS read with 0 bytes on the
amd-i3c-master controller, the driver incorrectly mutates payload.len to 0
instead of setting actual_len.
The generic validation in i3c_ccc_validate_payload_len() explicitly skips
validation if !p->len, incorrectly returning success. Before this patch, the
explicit length check here safely caught the driver's mutated 0-length and
correctly returned -EIO.
Without this check, the function silently succeeds and reads the zeroed
getstatus->status structure. Can this lead to incorrect behavior on these
systems?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260917191356.133242-1-adrian.hunter@intel.com?part=5
--
linux-i3c mailing list
linux-i3c@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-i3c
next prev parent reply other threads:[~2026-09-17 19:26 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 19:13 [PATCH V2 00/17] i3c: Fixes, cleanups and HDR-DDR support Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 01/17] i3c: master: Fix out-of-bounds read in DMA bounce buffer setup Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 02/17] i3c: mipi-i3c-hci: Bounce short reads irrespective of the IOMMU Adrian Hunter
2026-09-17 21:21 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 03/17] i3c: mipi-i3c-hci-pci: Set drvdata before creating LTR sysfs attribute Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 04/17] i3c: master: Match ACPI targets to the correct bus controller instance Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 05/17] i3c: master: Remove stale GETSTATUS length check Adrian Hunter
2026-09-17 19:26 ` sashiko-bot [this message]
2026-09-20 13:10 ` Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 06/17] i3c: mipi-i3c-hci: Restore controller state if i3c_hci_enable_ibi() returns an error Adrian Hunter
2026-09-17 21:23 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 07/17] i3c: mipi-i3c-hci: Send DISEC before disabling IBIs in hardware Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 08/17] i3c: mipi-i3c-hci: Fix runtime PM violation in i3c_hci_free_ibi() Adrian Hunter
2026-09-17 21:32 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 09/17] i3c: mipi-i3c-hci: Process multiple IBIs per interrupt Adrian Hunter
2026-09-17 21:37 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 10/17] i3c: mipi-i3c-hci: Move DMA suspend/resume callbacks Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 11/17] i3c: mipi-i3c-hci: Stop rings gracefully when suspending Adrian Hunter
2026-09-17 21:40 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 12/17] i3c: mipi-i3c-hci: Correct RESP_DATA_LENGTH to bits 15:0 Adrian Hunter
2026-09-17 21:42 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 13/17] i3c: mipi-i3c-hci: Remove invalid transfer size limit Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 14/17] i3c: mipi-i3c-hci: Remove invalid HDR-BT and Fm/Fm+ definitions Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 15/17] i3c: mipi-i3c-hci: Support configurable device NACK retries Adrian Hunter
2026-09-18 13:44 ` Frank Li
2026-09-17 19:13 ` [PATCH V2 16/17] i3c: Restrict HDR modes to those supported by the bus and target Adrian Hunter
2026-09-17 19:13 ` [PATCH V2 17/17] i3c: mipi-i3c-hci: Add HDR-DDR support Adrian Hunter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917192630.41F6F1F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=adrian.hunter@intel.com \
--cc=alexandre.belloni@bootlin.com \
--cc=linux-i3c@lists.infradead.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox