Linux PCI subsystem development
 help / color / mirror / Atom feed
From: "Bowman, Terry" <terry.bowman@amd.com>
To: sashiko-reviews@lists.linux.dev
Cc: linux-pci@vger.kernel.org, linux-cxl@vger.kernel.org
Subject: Re: [PATCH v19 01/14] cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
Date: Tue, 4 Aug 2026 11:20:18 -0500	[thread overview]
Message-ID: <1ca568f6-b9f5-45f6-a362-5ba0be8272f9@amd.com> (raw)
In-Reply-To: <20260803224230.85CD81F000E9@smtp.kernel.org>

On 8/3/2026 5:42 PM, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> 
> Pre-existing issues:
> - [High] cxl_dport_map_rch_aer() requests an MMIO region using the software-only size of struct aer_capability_regs, over-reserving memory beyond the physical capability.
> --
> 
> --- Patch [1]: [PATCH v19 01/14] cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read ---
> commit b208d5e7d4a18c48dd06f33bc3c5667e9a2c13dd
> Author: Terry Bowman <terry.bowman@amd.com>
> 
> cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
>     
> cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from
> the RCRB MMIO block using a readl() loop bounded by sizeof(struct
> aer_capability_regs). This struct is a software layout and its embedded
> struct pcie_tlp_log is larger than the on-wire AER capability. As a
> result the loop reads past the mapped AER register block.
> 
>> diff --git a/drivers/cxl/core/ras_rch.c b/drivers/cxl/core/ras_rch.c
>> index 0a8b3b9b63884..8a3965edaa12c 100644
>> --- a/drivers/cxl/core/ras_rch.c
>> +++ b/drivers/cxl/core/ras_rch.c
>> @@ -58,13 +58,28 @@ void cxl_disable_rch_root_ints(struct cxl_dport *dport)
>>  static bool cxl_rch_get_aer_info(void __iomem *aer_base,
>>  				 struct aer_capability_regs *aer_regs)
>>  {
>> -	int read_cnt = sizeof(struct aer_capability_regs) / sizeof(u32);
>> +	/*
>> +	 * Bound the copy to the physically-defined AER registers (header
>> +	 * through the 16-byte Header Log). struct aer_capability_regs is a
>> +	 * software layout whose embedded struct pcie_tlp_log is larger than
>> +	 * the on-wire AER capability; copying sizeof(*aer_regs) would
>> +	 * over-read the RCRB-mapped MMIO block.
>> +	 */
>> +	int read_cnt = (PCI_ERR_HEADER_LOG + 16) / sizeof(u32);
> 
> [Severity: High]
> This is a pre-existing issue, but since you are fixing the oversized read
> here, should we also fix the initial mapping size in cxl_dport_map_rch_aer()?
> 
> In drivers/cxl/core/ras_rch.c:cxl_dport_map_rch_aer():
> 
> 	dport->regs.dport_aer =
> 		devm_cxl_iomap_block(host, aer_phys,
> 				     sizeof(struct aer_capability_regs));
> 
> This uses the same oversized software struct size to request the MMIO region.
> 
> If another CXL Extended Capability is densely packed immediately following the
> AER block, won't any subsequent driver attempting to map it (e.g.,
> cxl_dport_map_rcd_linkcap()) fail with a -EBUSY conflict and break device
> initialization?
> 
I will be adding a patch fix to v20 for the existing cxl_dport_map_rch_aer() 
issue reported by sashiko.

- Terry 

  reply	other threads:[~2026-08-04 16:20 UTC|newest]

Thread overview: 46+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-03 22:17 [PATCH v19 00/14] Enable CXL PCIe Port Protocol Error handling and logging Terry Bowman
2026-08-03 22:17 ` [PATCH v19 01/14] cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read Terry Bowman
2026-08-03 22:42   ` sashiko-bot
2026-08-04 16:20     ` Bowman, Terry [this message]
2026-08-04  2:10   ` Alison Schofield
2026-08-03 22:17 ` [PATCH v19 02/14] cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register Terry Bowman
2026-08-03 22:35   ` sashiko-bot
2026-08-04  2:11   ` Alison Schofield
2026-08-03 22:17 ` [PATCH v19 03/14] acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks Terry Bowman
2026-08-03 22:39   ` sashiko-bot
2026-08-05 18:41   ` Luck, Tony
2026-08-03 22:18 ` [PATCH v19 04/14] cxl: Tighten CPER kfifo registration API and symbol visibility Terry Bowman
2026-08-03 22:30   ` sashiko-bot
2026-08-04  2:13   ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 05/14] cxl: Rename find_cxl_port() to find_cxl_port_by_dport() Terry Bowman
2026-08-03 22:29   ` sashiko-bot
2026-08-04  2:14   ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 06/14] PCI/AER: Introduce AER-CXL protocol error kfifo Terry Bowman
2026-08-03 22:28   ` sashiko-bot
2026-08-04  8:15   ` Richard Cheng
2026-08-04 14:10     ` Bowman, Terry
2026-08-03 22:18 ` [PATCH v19 07/14] PCI: Establish common CXL Port protocol error flow Terry Bowman
2026-08-03 22:56   ` sashiko-bot
2026-08-03 22:18 ` [PATCH v19 08/14] cxl/ras: Handle RCH correctable and uncorrectable errors in one pass Terry Bowman
2026-08-03 22:29   ` sashiko-bot
2026-08-04  2:16   ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 09/14] cxl/pci: Thread port and dport through RAS handling helpers Terry Bowman
2026-08-03 22:33   ` sashiko-bot
2026-08-04  2:16   ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 10/14] cxl: Update CXL Endpoint AER handler Terry Bowman
2026-08-03 22:40   ` sashiko-bot
2026-08-04  2:17   ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 11/14] PCI: Cache PCI DSN into pci_dev->dsn during probe Terry Bowman
2026-08-03 22:29   ` sashiko-bot
2026-08-04  2:26   ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 12/14] cxl: Add port and dport identifiers to CXL AER trace events Terry Bowman
2026-08-03 22:42   ` sashiko-bot
2026-08-04  2:27   ` Alison Schofield
2026-08-04  7:56   ` Richard Cheng
2026-08-04 13:46     ` Bowman, Terry
2026-08-03 22:18 ` [PATCH v19 13/14] PCI/CXL: Mask/Unmask CXL protocol errors Terry Bowman
2026-08-03 22:55   ` sashiko-bot
2026-08-04  2:29   ` Alison Schofield
2026-08-03 22:18 ` [PATCH v19 14/14] Documentation: cxl: Document CXL protocol error handling Terry Bowman
2026-08-03 22:31   ` sashiko-bot
2026-08-04  2:30   ` Alison Schofield

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1ca568f6-b9f5-45f6-a362-5ba0be8272f9@amd.com \
    --to=terry.bowman@amd.com \
    --cc=linux-cxl@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox