* [PATCH v2] PCI: mediatek: Fix integer truncation in fls() and clamp size
@ 2026-09-30 10:54 Sreeraj S Kurup
0 siblings, 0 replies; only message in thread
From: Sreeraj S Kurup @ 2026-09-30 10:54 UTC (permalink / raw)
To: Ryder Lee, Lorenzo Pieralisi, Krzysztof Wilczyński,
Manivannan Sadhasivam, Rob Herring, Bjorn Helgaas,
Matthias Brugger, AngeloGioacchino Del Regno
Cc: linux-pci, linux-mediatek, linux-kernel, linux-arm-kernel,
Sreeraj S Kurup
resource_size() returns a resource_size_t, which is 64-bit on 64-bit
architectures or 32-bit systems with LPAE/PAE enabled. Passing this
directly to fls(), which accepts an unsigned int, implicitly
truncates the upper 32 bits.
Furthermore, AHB2PCIE_SIZE() uses a 5-bit mask GENMASK(4, 0). If a
resource size of 4 GiB or larger is passed, fls64() returns 33 or
greater, which overflows the 5-bit mask and wraps around (e.g. 33 & 31
= 1).
Fix this by using fls64() for 64-bit resource sizes and clamping the
result to a maximum of 31 to fit the 5-bit register field.
Signed-off-by: Sreeraj S Kurup <sreekuttan2156239@gmail.com>
---
drivers/pci/controller/pcie-mediatek.c | 19 +++++++++++++++++--
1 file changed, 17 insertions(+), 2 deletions(-)
diff --git a/drivers/pci/controller/pcie-mediatek.c b/drivers/pci/controller/pcie-mediatek.c
index a60d1ae076f8..9576fe532b92 100644
--- a/drivers/pci/controller/pcie-mediatek.c
+++ b/drivers/pci/controller/pcie-mediatek.c
@@ -8,6 +8,7 @@
*/
#include <linux/bitfield.h>
+#include <linux/bitops.h>
#include <linux/clk.h>
#include <linux/delay.h>
#include <linux/errno.h>
@@ -686,6 +687,8 @@ static int mtk_pcie_startup_port_v2(struct mtk_pcie_port *port)
const struct mtk_pcie_soc *soc = port->pcie->soc;
u32 val;
int err;
+ resource_size_t size;
+ int size_order;
entry = resource_list_first_type(&host->windows, IORESOURCE_MEM);
if (entry)
@@ -753,8 +756,13 @@ static int mtk_pcie_startup_port_v2(struct mtk_pcie_port *port)
mtk_pcie_enable_msi(port);
/* Set AHB to PCIe translation windows */
+ size = resource_size(mem);
+ size_order = fls64(size);
+ if (size_order > 31)
+ size_order = 31;
+
val = lower_32_bits(mem->start) |
- AHB2PCIE_SIZE(fls(resource_size(mem)));
+ AHB2PCIE_SIZE(size_order);
writel(val, port->base + PCIE_AHB_TRANS_BASE0_L);
val = upper_32_bits(mem->start);
@@ -775,6 +783,8 @@ static int mtk_pcie_startup_port_en7528(struct mtk_pcie_port *port)
struct resource_entry *entry;
u32 val, link_mask;
int err;
+ resource_size_t size;
+ int size_order;
entry = resource_list_first_type(&host->windows, IORESOURCE_MEM);
if (entry)
@@ -829,8 +839,13 @@ static int mtk_pcie_startup_port_en7528(struct mtk_pcie_port *port)
mtk_pcie_enable_msi(port);
/* Set AHB to PCIe translation windows */
+ size = resource_size(mem);
+ size_order = fls64(size);
+ if (size_order > 31)
+ size_order = 31;
+
val = lower_32_bits(mem->start) |
- AHB2PCIE_SIZE(fls(resource_size(mem)));
+ AHB2PCIE_SIZE(size_order);
writel(val, port->base + PCIE_AHB_TRANS_BASE0_L);
val = upper_32_bits(mem->start);
--
2.55.0
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-30 11:03 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 10:54 [PATCH v2] PCI: mediatek: Fix integer truncation in fls() and clamp size Sreeraj S Kurup
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox