From: sashiko-bot@kernel.org
To: "Srirangan Madhavan" <smadhavan@nvidia.com>
Cc: linux-pci@vger.kernel.org, linux-cxl@vger.kernel.org
Subject: Re: [PATCH v11 10/12] PCI/CXL: Expose CXL Reset as a PCI reset method
Date: Wed, 02 Sep 2026 07:51:59 +0000 [thread overview]
Message-ID: <20260902075159.8DCB51F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260902072804.665639-11-smadhavan@nvidia.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Bypass of hardware-enforced CXL decoder lock via reset
--
commit ac98b5cb3878ca89e0ba4a99f7bf56eb9d00c253
Author: Srirangan Madhavan <smadhavan@nvidia.com>
PCI/CXL: Expose CXL Reset as a PCI reset method
Add the CXL Reset helper to the PCI reset-method table so userspace can
select it through the existing reset_method ABI.
Advertise the method for Type 2 CXL devices that report CXL Reset
support in the CXL Device DVSEC and pass the function-scope check. Reset
execution requires cached HDM decoder state for the target so affected
ranges can be validated and HDM programming can be restored. If that
state is unavailable at reset time, return -ENOTTY so PCI can try the
next reset method.
> diff --git a/drivers/pci/pci.c b/drivers/pci/pci.c
> index b2879a6be5f80..157f06c576e93 100644
> --- a/drivers/pci/pci.c
> +++ b/drivers/pci/pci.c
[ ... ]
> @@ -5145,6 +5146,7 @@ const struct pci_reset_fn_method pci_reset_fn_methods[] = {
> { },
> { pci_dev_specific_reset, .name = "device_specific" },
> { pci_dev_acpi_reset, .name = "acpi" },
> + { cxl_reset_function, .name = "cxl_reset" },
[Severity: High]
Does exposing this reset method allow bypassing the hardware-enforced CXL
decoder lock?
When a privileged user triggers a PCI reset on the CXL device via sysfs, the
hardware reset clears the decoder lock bit.
During recovery, the lock bit is explicitly stripped from the saved state
before restoration:
drivers/cxl/core/resource.c:cxl_restore_hdm_decoder_state() {
...
ctrl &= ~(CXL_HDM_DECODER0_CTRL_COMMIT |
CXL_HDM_DECODER0_CTRL_COMMITTED |
CXL_HDM_DECODER0_CTRL_COMMIT_ERROR |
CXL_HDM_DECODER0_CTRL_LOCK);
...
}
Then in setup_hw_decoder(), which is called by cxl_commit_start(), the
decoder is committed but fails to check settings->flags & CXL_DECODER_F_LOCK
to re-apply the lock. The modified control register is written to hardware,
leaving it permanently unlocked:
drivers/cxl/core/resource.c:setup_hw_decoder() {
...
writel(ctrl, hdm + CXL_HDM_DECODER0_CTRL_OFFSET(id));
...
}
Since firmware/BIOS sets the CXL decoder lock bit to prevent system memory
map modifications, does exposing this reset method expose the system to
malicious reprogramming of CXL decoders by bypassing the hardware lock?
> { pcie_reset_flr, .name = "flr" },
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260902072804.665639-1-smadhavan@nvidia.com?part=10
next prev parent reply other threads:[~2026-09-02 7:51 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 7:27 [PATCH v11 00/12] PCI/CXL: Add CXL reset support for Type 2 devices Srirangan Madhavan
2026-09-02 7:27 ` [PATCH v11 01/12] cxl: Move HDM decoder programming helpers Srirangan Madhavan
2026-09-02 8:00 ` sashiko-bot
2026-09-02 7:27 ` [PATCH v11 02/12] cxl: Make HDM commit helpers available to reset code Srirangan Madhavan
2026-09-02 7:37 ` sashiko-bot
2026-09-02 7:27 ` [PATCH v11 03/12] cxl: Share HDM decoder decode logic Srirangan Madhavan
2026-09-02 7:39 ` sashiko-bot
2026-09-02 7:27 ` [PATCH v11 04/12] cxl: Cache decoder settings on PCI devices Srirangan Madhavan
2026-09-02 7:40 ` sashiko-bot
2026-09-02 7:27 ` [PATCH v11 05/12] cxl: Cache endpoint decoder settings during PCI enumeration Srirangan Madhavan
2026-09-02 7:41 ` sashiko-bot
2026-09-02 14:03 ` Li Ming
2026-09-02 7:27 ` [PATCH v11 06/12] cxl: Add CXL Device Reset helper Srirangan Madhavan
2026-09-02 7:35 ` sashiko-bot
2026-09-02 7:27 ` [PATCH v11 07/12] cxl: Validate HDM ranges before CXL reset Srirangan Madhavan
2026-09-02 7:42 ` sashiko-bot
2026-09-04 9:19 ` Richard Cheng
2026-09-02 7:28 ` [PATCH v11 08/12] PCI/CXL: Reject CXL Reset on multifunction devices Srirangan Madhavan
2026-09-02 7:39 ` sashiko-bot
2026-09-04 9:26 ` Richard Cheng
2026-09-02 7:28 ` [PATCH v11 09/12] cxl: Restore CXL HDM state after PCI reset Srirangan Madhavan
2026-09-02 7:45 ` sashiko-bot
2026-09-04 9:23 ` Richard Cheng
2026-09-02 7:28 ` [PATCH v11 10/12] PCI/CXL: Expose CXL Reset as a PCI reset method Srirangan Madhavan
2026-09-02 7:51 ` sashiko-bot [this message]
2026-09-02 7:28 ` [PATCH v11 11/12] Documentation/ABI: Document CXL Reset " Srirangan Madhavan
2026-09-02 7:40 ` sashiko-bot
2026-09-02 7:28 ` [PATCH v11 12/12] PCI/CXL: Restore HDM state after CXL bus reset Srirangan Madhavan
2026-09-02 7:54 ` sashiko-bot
2026-09-04 9:15 ` [PATCH v11 00/12] PCI/CXL: Add CXL reset support for Type 2 devices Richard Cheng
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902075159.8DCB51F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-cxl@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=smadhavan@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox