* [PATCH] PCI: probe: Fix 64-bit limit truncation in prefetchable window
@ 2026-08-14 16:46 Mohamad Raizudeen
2026-08-14 16:57 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Mohamad Raizudeen @ 2026-08-14 16:46 UTC (permalink / raw)
To: bhelgaas
Cc: skhan, jkoolstra, linux-pci, linux-kernel, gregkh, yinghai,
Mohamad Raizudeen
In pci_read_bridge_mmio_pref(), the code checks if the 64 bit base
address is truncated on 32 bit pci_bus_addr_t. However, it misses this
same check for the limit address.
If firmware sets a window that starts below 4GB but ends above 4GB, the
base check passes. But the 64 bit limit is silently cut down to 32 bits
and wraps around to zero. This makes the base larger than the limit,
causing the kernel to silently disable the memory window instead of
printing an error.
Fix this by checking if the limit was truncated, just like the base.
Also, update the error message to print both the base and limit
addresses to make debugging easier.
Fixes: 7fc986d8a9727 ("PCI: Support 64-bit bridge windows if we have 64-bit dma_addr_t")
Signed-off-by: Mohamad Raizudeen <raizudeen.kerneldev@gmail.com>
---
drivers/pci/probe.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/pci/probe.c b/drivers/pci/probe.c
index dd0abbc63e18..0cf2d1d35146 100644
--- a/drivers/pci/probe.c
+++ b/drivers/pci/probe.c
@@ -479,9 +479,10 @@ static void pci_read_bridge_mmio_pref(struct pci_dev *dev, struct resource *res,
base = (pci_bus_addr_t) base64;
limit = (pci_bus_addr_t) limit64;
- if (base != base64) {
- pci_err(dev, "can't handle bridge window above 4GB (bus address %#010llx)\n",
- (unsigned long long) base64);
+ if (base != base64 || limit != limit64) {
+ pci_err(dev, "can't handle bridge window above 4GB (bus address %#010llx-%#010llx)\n",
+ (unsigned long long) base64,
+ (unsigned long long) limit64);
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] PCI: probe: Fix 64-bit limit truncation in prefetchable window
2026-08-14 16:46 [PATCH] PCI: probe: Fix 64-bit limit truncation in prefetchable window Mohamad Raizudeen
@ 2026-08-14 16:57 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-08-14 16:57 UTC (permalink / raw)
To: Mohamad Raizudeen; +Cc: linux-pci
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] If a 64-bit prefetchable memory window is disabled via its high registers (`mem_base_hi > mem_limit_hi`), the kernel fails to propagate this disabled state and may incorrectly enable the window using only the 32-bit low registers.
--
--- Patch [1]: [PATCH] PCI: probe: Fix 64-bit limit truncation in prefetchable window ---
commit 83ac911fac4a068a7685be844df59a43a0825bcf
Author: Mohamad Raizudeen <raizudeen.kerneldev@gmail.com>
PCI: probe: Fix 64-bit limit truncation in prefetchable window
This commit fixes a missing truncation check for 64-bit limit addresses on
32-bit platforms in pci_read_bridge_mmio_pref(). It ensures the memory
window is properly handled or disabled if the limit exceeds 32 bits, and
updates the error message to include both base and limit.
> diff --git a/drivers/pci/probe.c b/drivers/pci/probe.c
> index dd0abbc63e18d..0cf2d1d351467 100644
> --- a/drivers/pci/probe.c
> +++ b/drivers/pci/probe.c
> @@ -479,9 +479,10 @@ static void pci_read_bridge_mmio_pref(struct pci_dev *dev, struct resource *res,
> base = (pci_bus_addr_t) base64;
> limit = (pci_bus_addr_t) limit64;
>
[Severity: High]
This is a pre-existing issue, but I noticed a potential problem in how
disabled 64-bit windows are handled just above this code.
If a 64-bit prefetchable memory window is disabled by firmware setting the
upper 32-bit registers such that mem_base_hi > mem_limit_hi, the kernel
skips appending the high bits to base64 and limit64:
if (mem_base_hi <= mem_limit_hi) {
base64 |= (u64) mem_base_hi << 32;
limit64 |= (u64) mem_limit_hi << 32;
}
If the lower 16-bit registers happen to evaluate to base <= limit (for
instance, if both base and limit are 0), will the subsequent check at the
end of pci_read_bridge_mmio_pref() incorrectly succeed?
if (base <= limit) {
region.start = base;
region.end = limit + 0xfffff;
pcibios_bus_to_resource(dev->bus, res, ®ion);
Could this cause the kernel to incorrectly enable a 1MB window at address 0
instead of marking the resource as disabled, potentially overlapping with
system RAM?
> - if (base != base64) {
> - pci_err(dev, "can't handle bridge window above 4GB (bus address %#010llx)\n",
> - (unsigned long long) base64);
> + if (base != base64 || limit != limit64) {
> + pci_err(dev, "can't handle bridge window above 4GB (bus address %#010llx-%#010llx)\n",
> + (unsigned long long) base64,
> + (unsigned long long) limit64);
> return;
> }
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260814164652.43501-1-raizudeen.kerneldev@gmail.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-14 16:57 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-14 16:46 [PATCH] PCI: probe: Fix 64-bit limit truncation in prefetchable window Mohamad Raizudeen
2026-08-14 16:57 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox