Linux PCI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jose Ignacio Tornos Martinez" <jtornosm@redhat.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v14 1/2] PCI: Add device-specific reset for Qualcomm SDX62/SDX65 modems
Date: Thu, 17 Sep 2026 07:35:28 +0000	[thread overview]
Message-ID: <20260917073528.A47E61F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260917071651.14174-2-jtornosm@redhat.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] pci: reset_qualcomm_modem re-enables memory decoding with zeroed BARs
--

commit 697e75cacc91e92df3d44b2fa95b07329f110e59
Author: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>

PCI: Add device-specific reset for Qualcomm SDX62/SDX65 modems

Qualcomm SDX62/SDX65 5G modems lack working reset methods for VFIO
passthrough. This commit adds a device-specific reset method for them using
MHI SoC reset via BAR0. The reset method writes to a hardware reset
register and waits for completion.

> diff --git a/drivers/pci/quirks.c b/drivers/pci/quirks.c
> index de9bbccda21fd..e72af7d2c7755 100644
> --- a/drivers/pci/quirks.c
> +++ b/drivers/pci/quirks.c

[ ... ]

> +static int reset_qualcomm_modem(struct pci_dev *pdev, bool probe)
> +{
> +	void __iomem *bar;
> +	u16 cmd;
> +
> +	if (probe)
> +		return 0;
> +
> +	if (pdev->current_state != PCI_D0)
> +		return -EINVAL;
> +
> +	pci_read_config_word(pdev, PCI_COMMAND, &cmd);
> +	pci_write_config_word(pdev, PCI_COMMAND, cmd | PCI_COMMAND_MEMORY);
> +
> +	bar = pci_iomap(pdev, 0, 0);
> +	if (!bar) {
> +		pci_write_config_word(pdev, PCI_COMMAND, cmd);
> +		return -ENODEV;
> +	}
> +
> +	iowrite32(MHI_SOC_RESET_REQ, bar + MHI_SOC_RESET_REQ_OFFSET);
> +	ioread32(bar + MHI_SOC_RESET_REQ_OFFSET);
> +
> +	/* Be sure device reset has been executed */
> +	msleep(2000);
> +
> +	pci_iounmap(pdev, bar);
> +	pci_write_config_word(pdev, PCI_COMMAND, cmd);

[Severity: High]
Does this unsafely enable memory decoding on a hardware-reset device with
zeroed BARs?

If the caller did not explicitly clear PCI_COMMAND_MEMORY before the reset,
cmd will have PCI_COMMAND_MEMORY set.

The hardware reset zeroes the device's PCI configuration space, including all
BARs. Restoring cmd with PCI_COMMAND_MEMORY set will immediately enable memory
decoding while the BARs are still 0, potentially causing severe PCIe bus
conflicts, IOMMU faults, or kernel panics since the device will intercept
memory accesses to physical address 0.

Should we clear PCI_COMMAND_MEMORY before returning (e.g.,
cmd & ~PCI_COMMAND_MEMORY), relying on the caller's subsequent
pci_restore_state() to safely reprogram the BARs before memory decoding is
formally re-enabled?

> +
> +	return 0;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260917071651.14174-1-jtornosm@redhat.com?part=1

  reply	other threads:[~2026-09-17  7:35 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17  7:16 [PATCH v14 0/2] PCI: Add device-specific reset for Qualcomm devices Jose Ignacio Tornos Martinez
2026-09-17  7:16 ` [PATCH v14 1/2] PCI: Add device-specific reset for Qualcomm SDX62/SDX65 modems Jose Ignacio Tornos Martinez
2026-09-17  7:35   ` sashiko-bot [this message]
2026-09-17 12:45     ` Jose Ignacio Tornos Martinez
2026-09-17  7:16 ` [PATCH v14 2/2] PCI: Add device-specific reset for Qualcomm WCN6855/WCN7850 WLAN Jose Ignacio Tornos Martinez
2026-09-17  7:26   ` sashiko-bot
2026-10-02 21:40 ` [PATCH v14 0/2] PCI: Add device-specific reset for Qualcomm devices Bjorn Helgaas
2026-10-02 23:09   ` Alex Williamson
2026-10-02 23:47     ` Bjorn Helgaas
2026-10-05 10:48       ` Jose Ignacio Tornos Martinez

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917073528.A47E61F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=jtornosm@redhat.com \
    --cc=linux-pci@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox