From: sashiko-bot@kernel.org
To: "Ziming Du" <duziming2@huawei.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v2 6/6] PCI: Align proc_bus_pci_read() with pci_read_config()
Date: Thu, 30 Jul 2026 03:14:00 +0000 [thread overview]
Message-ID: <20260730031400.8B0461F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260730032438.1643450-7-duziming2@huawei.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Unaligned pointer dereference via `__put_user` cast.
--
--- Patch [6]: [PATCH v2 6/6] PCI: Align proc_bus_pci_read() with pci_read_config() ---
commit 214117562117fd4692f3111d71550ff1bd6ab306
Author: Ziming Du <duziming2@huawei.com>
PCI: Align proc_bus_pci_read() with pci_read_config()
This commit aligns the implementation of proc_bus_pci_read() with
pci_read_config() to improve consistency. It renames variables and updates
the transfer loop conditions without intending functional changes.
> diff --git a/drivers/pci/proc.c b/drivers/pci/proc.c
> index 71d1f34e13a7d..13ac92da4624b 100644
> --- a/drivers/pci/proc.c
> +++ b/drivers/pci/proc.c
[ ... ]
> @@ -46,66 +47,65 @@ static ssize_t proc_bus_pci_read(struct file *file, char __user *buf,
[ ... ]
> - while (cnt >= 4) {
> + while (count > 3) {
> unsigned int val;
> - pci_user_read_config_dword(dev, pos, &val);
> + pci_user_read_config_dword(dev, off, &val);
> __put_user(cpu_to_le32(val), (__le32 __user *) buf);
[Severity: High]
This is a pre-existing issue, but could this cast and dereference trigger
an alignment exception on strict-alignment architectures?
If a normal user opens a PCI config file and calls read() with an aligned
file offset but an unaligned buffer address, the read chunks are aligned
based on the file offset, bypassing the earlier byte and word branches.
The execution would then reach this 32-bit __put_user cast with the
unaligned user buffer.
On architectures that do not emulate unaligned kernel-mode accesses like
older ARM or SPARC, this might result in a local denial of service via a
kernel oops or panic.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260730032438.1643450-1-duziming2@huawei.com?part=6
prev parent reply other threads:[~2026-07-30 3:14 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-30 3:24 [PATCH v2 0/6] PCI: Fix procfs PCI config access issues Ziming Du
2026-07-30 3:24 ` [PATCH v2 1/6] PCI: Prevent overflow in proc_bus_pci_{read,write}() Ziming Du
2026-07-30 3:16 ` sashiko-bot
2026-07-30 3:24 ` [PATCH v2 2/6] PCI/proc: Serialize config inode size updates Ziming Du
2026-07-30 3:13 ` sashiko-bot
2026-07-30 3:24 ` [PATCH v2 3/6] PCI/proc: Warn on writes to driver-exclusive config regions Ziming Du
2026-07-30 3:17 ` sashiko-bot
2026-07-30 3:24 ` [PATCH v2 4/6] PCI/sysfs: Avoid runtime PM at config-space EOF Ziming Du
2026-07-30 3:09 ` sashiko-bot
2026-07-30 3:24 ` [PATCH v2 5/6] PCI: Align proc_bus_pci_write() with pci_write_config() Ziming Du
2026-07-30 3:16 ` sashiko-bot
2026-07-30 3:24 ` [PATCH v2 6/6] PCI: Align proc_bus_pci_read() with pci_read_config() Ziming Du
2026-07-30 3:14 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260730031400.8B0461F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=duziming2@huawei.com \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox