From: sashiko-bot@kernel.org
To: "Sasha Levin" <sashal@kernel.org>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH AUTOSEL 6.18-5.10] PCI/sysfs: Use kstrtobool() to parse the ROM attribute input
Date: Mon, 31 Aug 2026 17:00:13 +0000 [thread overview]
Message-ID: <20260831170014.28DB51F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831133314.4125787-534-sashal@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Unlocked read-modify-write of the `rom_attr_enabled` bitfield in `struct pci_dev` exposes a data race.
--
commit ede1ff2652bff89ab4ad252e8e7e79bb533b4702
Author: Krzysztof Wilczyński <kwilczynski@kernel.org>
PCI/sysfs: Use kstrtobool() to parse the ROM attribute input
This patch modifies pci_write_rom() to parse sysfs input using kstrtobool().
It ensures that the ROM attribute is properly disabled even when a trailing
newline is missing from the input, and it rejects invalid inputs with -EINVAL.
Link: https://patch.msgid.link/20260612182448.552406-1-kwilczynski@kernel.org
> diff --git a/drivers/pci/pci-sysfs.c b/drivers/pci/pci-sysfs.c
> --- a/drivers/pci/pci-sysfs.c
> +++ b/drivers/pci/pci-sysfs.c
> @@ -1336,18 +1336,19 @@ void __weak pci_remove_resource_files(struct pci_dev *dev) { return; }
[ ... ]
> static ssize_t pci_write_rom(struct file *filp, struct kobject *kobj,
> const struct bin_attribute *bin_attr, char *buf,
> loff_t off, size_t count)
> {
> struct pci_dev *pdev = to_pci_dev(kobj_to_dev(kobj));
> + bool enable;
>
> - if ((off == 0) && (*buf == '0') && (count == 2))
> - pdev->rom_attr_enabled = 0;
> - else
> - pdev->rom_attr_enabled = 1;
> + if (kstrtobool(buf, &enable))
> + return -EINVAL;
> +
> + pdev->rom_attr_enabled = enable;
[Severity: High]
This is a pre-existing issue, but does this unlocked assignment expose a
data race?
In include/linux/pci.h, rom_attr_enabled is declared as a bitfield:
struct pci_dev {
...
unsigned int rom_attr_enabled:1;
...
};
This bitfield shares a 32-bit machine word with other dynamically updated
fields like is_probed and irq_managed.
Since C bitfield assignments compile to non-atomic read-modify-write
operations on the underlying machine word, could a concurrent write to the
rom sysfs attribute race with updates to these other bitfields?
If a privileged user writes to the rom sysfs attribute concurrently with the
device being probed (where is_probed is toggled) or its IRQs being
configured, could this silently corrupt the word and result in deadlocks in
VF probing or IRQ resource leaks?
>
> return count;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260831133314.4125787-534-sashal@kernel.org?part=1
next prev parent reply other threads:[~2026-08-31 17:00 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20260831133314.4125787-1-sashal@kernel.org>
2026-08-31 13:20 ` [PATCH AUTOSEL 6.18-6.12] PCI: plda: Protect root bus removal with rescan lock Sasha Levin
2026-08-31 13:43 ` sashiko-bot
2026-08-31 13:20 ` [PATCH AUTOSEL 6.18-6.12] PCI: Avoid FLR for MediaTek MT7925 WiFi Sasha Levin
2026-08-31 13:45 ` sashiko-bot
2026-08-31 13:21 ` [PATCH AUTOSEL 6.18-5.10] PCI: altera: Protect root bus removal with rescan lock Sasha Levin
2026-08-31 14:05 ` sashiko-bot
2026-08-31 13:21 ` [PATCH AUTOSEL 6.18-6.1] PCI: intel-gw: Enable clock before PHY init Sasha Levin
2026-08-31 14:12 ` sashiko-bot
2026-08-31 13:22 ` [PATCH AUTOSEL 6.18-6.1] PCI/proc: Fix race between pci_proc_init() and pci_bus_add_device() Sasha Levin
2026-08-31 14:27 ` sashiko-bot
2026-08-31 13:22 ` [PATCH AUTOSEL 6.18-5.10] PCI: rockchip: Protect root bus removal with rescan lock Sasha Levin
2026-08-31 14:30 ` sashiko-bot
2026-08-31 13:23 ` [PATCH AUTOSEL 6.18-5.10] PCI: Avoid SBR for Qualcomm WCN6855/WCN7850 WiFi, SDX62/SDX65 modems Sasha Levin
2026-08-31 14:50 ` sashiko-bot
2026-08-31 13:24 ` [PATCH AUTOSEL 6.18] misc: pci_endpoint_test: Validate BAR index in doorbell test Sasha Levin
2026-08-31 15:07 ` sashiko-bot
2026-08-31 13:25 ` [PATCH AUTOSEL 6.18-6.1] PCI: Wait for device readiness after D3hot -> D0uninitialized transition Sasha Levin
2026-08-31 15:30 ` sashiko-bot
2026-08-31 13:26 ` [PATCH AUTOSEL 6.18-6.1] PCI: switchtec: Add Gen6 Device IDs Sasha Levin
2026-08-31 15:43 ` sashiko-bot
2026-08-31 13:26 ` [PATCH AUTOSEL 6.18-5.10] PCI: mediatek: Protect root bus removal with rescan lock Sasha Levin
2026-08-31 15:44 ` sashiko-bot
2026-08-31 13:27 ` [PATCH AUTOSEL 6.18] PCI: cadence: " Sasha Levin
2026-08-31 16:15 ` sashiko-bot
2026-08-31 13:28 ` [PATCH AUTOSEL 6.18-5.15] ACPI: PCI: Clear _DEP dependencies after PCI root bridge attach Sasha Levin
2026-08-31 16:33 ` sashiko-bot
2026-08-31 13:28 ` [PATCH AUTOSEL 6.18-6.12] PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store() Sasha Levin
2026-08-31 13:29 ` [PATCH AUTOSEL 6.18-5.10] PCI/sysfs: Use kstrtobool() to parse the ROM attribute input Sasha Levin
2026-08-31 17:00 ` sashiko-bot [this message]
2026-08-31 13:29 ` [PATCH AUTOSEL 6.18] PCI: dwc: Protect root bus removal with rescan lock Sasha Levin
2026-08-31 17:09 ` sashiko-bot
2026-08-31 13:31 ` [PATCH AUTOSEL 6.18-5.10] PCI: Stop setting cached power state to 'unknown' on unbind Sasha Levin
2026-08-31 17:28 ` sashiko-bot
2026-08-31 13:31 ` [PATCH AUTOSEL 6.18-5.10] PCI: iproc: Protect root bus removal with rescan lock Sasha Levin
2026-08-31 17:43 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831170014.28DB51F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=sashal@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox