From: "Bowman, Terry" <terry.bowman@amd.com>
To: sashiko-reviews@lists.linux.dev
Cc: linux-pci@vger.kernel.org, linux-cxl@vger.kernel.org
Subject: Re: [PATCH v19 01/14] cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
Date: Tue, 4 Aug 2026 11:20:18 -0500 [thread overview]
Message-ID: <1ca568f6-b9f5-45f6-a362-5ba0be8272f9@amd.com> (raw)
In-Reply-To: <20260803224230.85CD81F000E9@smtp.kernel.org>
On 8/3/2026 5:42 PM, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
>
> Pre-existing issues:
> - [High] cxl_dport_map_rch_aer() requests an MMIO region using the software-only size of struct aer_capability_regs, over-reserving memory beyond the physical capability.
> --
>
> --- Patch [1]: [PATCH v19 01/14] cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read ---
> commit b208d5e7d4a18c48dd06f33bc3c5667e9a2c13dd
> Author: Terry Bowman <terry.bowman@amd.com>
>
> cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
>
> cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from
> the RCRB MMIO block using a readl() loop bounded by sizeof(struct
> aer_capability_regs). This struct is a software layout and its embedded
> struct pcie_tlp_log is larger than the on-wire AER capability. As a
> result the loop reads past the mapped AER register block.
>
>> diff --git a/drivers/cxl/core/ras_rch.c b/drivers/cxl/core/ras_rch.c
>> index 0a8b3b9b63884..8a3965edaa12c 100644
>> --- a/drivers/cxl/core/ras_rch.c
>> +++ b/drivers/cxl/core/ras_rch.c
>> @@ -58,13 +58,28 @@ void cxl_disable_rch_root_ints(struct cxl_dport *dport)
>> static bool cxl_rch_get_aer_info(void __iomem *aer_base,
>> struct aer_capability_regs *aer_regs)
>> {
>> - int read_cnt = sizeof(struct aer_capability_regs) / sizeof(u32);
>> + /*
>> + * Bound the copy to the physically-defined AER registers (header
>> + * through the 16-byte Header Log). struct aer_capability_regs is a
>> + * software layout whose embedded struct pcie_tlp_log is larger than
>> + * the on-wire AER capability; copying sizeof(*aer_regs) would
>> + * over-read the RCRB-mapped MMIO block.
>> + */
>> + int read_cnt = (PCI_ERR_HEADER_LOG + 16) / sizeof(u32);
>
> [Severity: High]
> This is a pre-existing issue, but since you are fixing the oversized read
> here, should we also fix the initial mapping size in cxl_dport_map_rch_aer()?
>
> In drivers/cxl/core/ras_rch.c:cxl_dport_map_rch_aer():
>
> dport->regs.dport_aer =
> devm_cxl_iomap_block(host, aer_phys,
> sizeof(struct aer_capability_regs));
>
> This uses the same oversized software struct size to request the MMIO region.
>
> If another CXL Extended Capability is densely packed immediately following the
> AER block, won't any subsequent driver attempting to map it (e.g.,
> cxl_dport_map_rcd_linkcap()) fail with a -EBUSY conflict and break device
> initialization?
>
I will be adding a patch fix to v20 for the existing cxl_dport_map_rch_aer()
issue reported by sashiko.
- Terry
next prev parent reply other threads:[~2026-08-04 16:20 UTC|newest]
Thread overview: 46+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-03 22:17 [PATCH v19 00/14] Enable CXL PCIe Port Protocol Error handling and logging Terry Bowman
2026-08-03 22:17 ` [PATCH v19 01/14] cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read Terry Bowman
2026-08-03 22:42 ` sashiko-bot
2026-08-04 16:20 ` Bowman, Terry [this message]
2026-08-04 2:10 ` Alison Schofield
2026-08-03 22:17 ` [PATCH v19 02/14] cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register Terry Bowman
2026-08-03 22:35 ` sashiko-bot
2026-08-04 2:11 ` Alison Schofield
2026-08-03 22:17 ` [PATCH v19 03/14] acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks Terry Bowman
2026-08-03 22:39 ` sashiko-bot
2026-08-05 18:41 ` Luck, Tony
2026-08-03 22:18 ` [PATCH v19 04/14] cxl: Tighten CPER kfifo registration API and symbol visibility Terry Bowman
2026-08-03 22:30 ` sashiko-bot
2026-08-04 2:13 ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 05/14] cxl: Rename find_cxl_port() to find_cxl_port_by_dport() Terry Bowman
2026-08-03 22:29 ` sashiko-bot
2026-08-04 2:14 ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 06/14] PCI/AER: Introduce AER-CXL protocol error kfifo Terry Bowman
2026-08-03 22:28 ` sashiko-bot
2026-08-04 8:15 ` Richard Cheng
2026-08-04 14:10 ` Bowman, Terry
2026-08-03 22:18 ` [PATCH v19 07/14] PCI: Establish common CXL Port protocol error flow Terry Bowman
2026-08-03 22:56 ` sashiko-bot
2026-08-03 22:18 ` [PATCH v19 08/14] cxl/ras: Handle RCH correctable and uncorrectable errors in one pass Terry Bowman
2026-08-03 22:29 ` sashiko-bot
2026-08-04 2:16 ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 09/14] cxl/pci: Thread port and dport through RAS handling helpers Terry Bowman
2026-08-03 22:33 ` sashiko-bot
2026-08-04 2:16 ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 10/14] cxl: Update CXL Endpoint AER handler Terry Bowman
2026-08-03 22:40 ` sashiko-bot
2026-08-04 2:17 ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 11/14] PCI: Cache PCI DSN into pci_dev->dsn during probe Terry Bowman
2026-08-03 22:29 ` sashiko-bot
2026-08-04 2:26 ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 12/14] cxl: Add port and dport identifiers to CXL AER trace events Terry Bowman
2026-08-03 22:42 ` sashiko-bot
2026-08-04 2:27 ` Alison Schofield
2026-08-04 7:56 ` Richard Cheng
2026-08-04 13:46 ` Bowman, Terry
2026-08-03 22:18 ` [PATCH v19 13/14] PCI/CXL: Mask/Unmask CXL protocol errors Terry Bowman
2026-08-03 22:55 ` sashiko-bot
2026-08-04 2:29 ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 14/14] Documentation: cxl: Document CXL protocol error handling Terry Bowman
2026-08-03 22:31 ` sashiko-bot
2026-08-04 2:30 ` Alison Schofield
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1ca568f6-b9f5-45f6-a362-5ba0be8272f9@amd.com \
--to=terry.bowman@amd.com \
--cc=linux-cxl@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox