From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8F0B351599C; Thu, 17 Sep 2026 16:56:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789664173; cv=none; b=NgSwNVlKysORMjIdmbDAgqWSYny+NjkTjFqtMI0RvPF0hTILxVpFktlhoMTXWmVo01JrPuBcfTbAZZrpyuN1F8wq+PiqtV++QZX2Gk4EsWJEkMPrr0I4qu118gNYrOLQeycFhk2Lv0tBsSQQRfGxTirhN4O0S3a2bYHJOuHNR/4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789664173; c=relaxed/simple; bh=xJDYCCDcQGWlYrxUbiJd6mtj5EbtmFxDZppLw0OyEbQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=q0iuAt0VbJYEXpJ+4EGjyadpS9v6/J+0POGPAwqbyuxEpWEJ+uuQMsWZEtskKMzq1/zM2ej70SasQLBH/hgbTS3zw2d4xN5MZFWDI33sCCAft45Wl1OO63wXVaBN7pEUHFNbEE8DWdNjpOSW6AD8gD1kizqy0ktW6JdWFsh+Y4s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=qsjFJXhC; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="qsjFJXhC" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CBC251F00893; Thu, 17 Sep 2026 16:56:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789664172; bh=ophrHIKNz+3jdny8HGl8WLNoAgjx5I5B2lgASn5XrRM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qsjFJXhCFO7cw5BpraQiWx02ZmAOGr1laHegLYNhuXmUCeNq0YtL5YkM9SdRaDABo XEDzOn8e3Xk0BJL1rw78F6+2Y6IbkFaMa9aQ1E3vsA+5EGmKqmuxMWpEcbPybyPMAQ EIcfc4GGrP+bdi4jRwfk2QQ6IP5pwNbpzRNqsIkQ= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, liyouhong , Damien Le Moal , Niklas Cassel , Sasha Levin Subject: [PATCH 6.18 0282/1250] ata: ahci: fail probe if BAR too small for claimed ports Date: Thu, 17 Sep 2026 16:01:17 +0100 Message-ID: <20260917151559.779531515@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151551.901433442@linuxfoundation.org> References: <20260917151551.901433442@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: liyouhong [ Upstream commit c4086c6e1af757e1ff26fa2d2926b3ec0195de79 ] When an AHCI controller is disabled in BIOS, its HOST_CAP register may contain a bogus value, e.g. 0xFFFFFFFF. Since CAP.NP (Number of Ports) is a zeroes based 5-bit register field, a value of 0x1f means 32 ports. If CAP.NP claims more ports than can physically fit within the mapped BAR region, accessing port registers beyond the BAR boundary causes a kernel panic. Add validation in ahci_init_one() to check that the BAR size is sufficient for the number of ports claimed in CAP.NP. The check calculates the required MMIO size as: required_size = 0x100 (global registers) + max_ports * 0x80 If required_size exceeds the actual BAR size, the probe fails with -ENODEV, preventing the panic and providing a clear error message. Reported-by: liyouhong Closes: https://lore.kernel.org/all/20260422080322.1006592-1-dayou5941@163.com/ Suggested-by: Damien Le Moal Suggested-by: Niklas Cassel Reviewed-by: Damien Le Moal Signed-off-by: liyouhong [cassel: commit log] Signed-off-by: Niklas Cassel Signed-off-by: Sasha Levin --- drivers/ata/ahci.c | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/drivers/ata/ahci.c b/drivers/ata/ahci.c index 64fc27c044858..d287c84ce80e0 100644 --- a/drivers/ata/ahci.c +++ b/drivers/ata/ahci.c @@ -1933,6 +1933,24 @@ static ssize_t remapped_nvme_show(struct device *dev, static DEVICE_ATTR_RO(remapped_nvme); +static int ahci_validate_bar_size(struct pci_dev *pdev, int bar, + struct ahci_host_priv *hpriv) +{ + u32 cap = readl(hpriv->mmio + HOST_CAP); + unsigned int max_ports = ahci_nr_ports(cap); + u32 last_port_end = 0x100 + (max_ports * 0x80); + resource_size_t bar_size = pci_resource_len(pdev, bar); + + if (last_port_end > bar_size) { + dev_warn(&pdev->dev, + "BAR%d too small for %u ports (last port ends at %#x, BAR %pa)\n", + bar, max_ports, last_port_end, &bar_size); + return -ENODEV; + } + + return 0; +} + static int ahci_init_one(struct pci_dev *pdev, const struct pci_device_id *ent) { unsigned int board_id = ent->driver_data; @@ -2037,6 +2055,10 @@ static int ahci_init_one(struct pci_dev *pdev, const struct pci_device_id *ent) if (!hpriv->mmio) return -ENOMEM; + rc = ahci_validate_bar_size(pdev, ahci_pci_bar, hpriv); + if (rc) + return rc; + /* detect remapped nvme devices */ ahci_remap_check(pdev, ahci_pci_bar, hpriv); -- 2.53.0