From: sashiko-bot@kernel.org
To: "Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH 2/5] PCI: Fix nesting windows with remainder at the left edge
Date: Wed, 23 Sep 2026 13:32:01 +0000 [thread overview]
Message-ID: <20260923133202.07DF61F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923131757.7792-3-ilpo.jarvinen@linux.intel.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] pci: __pci_assign_resource assigns address bound min to alignment
- [High] pci: pci_resreq_check incorrectly shifts normal BARs out of alignment
--
commit 5024064a0f2ceedd425ef93754ec9f56cae0112c
Author: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
PCI: Fix nesting windows with remainder at the left edge
This commit attempts to fix a bridge window assignment failure in nested
topologies where the non-aligning remainder sits at the left edge. It
introduces pci_resreq_check() to wrap pcibios_align_resource() and recalculate
the start address if there are constraints, bypassing standard alignment checks.
Fixes: 9036bd0efcb6 ("PCI: Align head space better")
> diff --git a/drivers/pci/setup-res.c b/drivers/pci/setup-res.c
> index 376f09630a4ab..eacce9e2486bf 100644
> --- a/drivers/pci/setup-res.c
> +++ b/drivers/pci/setup-res.c
[ ... ]
> @@ -311,15 +326,54 @@ resource_size_t __weak pcibios_align_resource(void *data,
> return pci_align_resource(dev, res, empty_res, size, align);
> }
>
> +struct pci_resreq_data {
> + struct pci_dev *dev;
> + resource_size_t real_align;
> +};
> +
> +static resource_size_t pci_resreq_check(void *data,
> + const struct resource *res,
> + const struct resource *empty_res,
> + resource_size_t size,
> + resource_size_t min_align)
> +{
> + struct pci_resreq_data *rr = data;
> + resource_size_t align = rr->real_align;
> + resource_size_t remainder, start;
> + struct resource tmp = *res;
> +
> + if (res->flags & IORESOURCE_MEM && !IS_ALIGNED(res->start, align)) {
> + resource_set_range(&tmp, ALIGN(res->start, align), size);
> + if (!__resource_contains_unbound(empty_res, &tmp)) {
> + remainder = pci_resreq_remainder(size, align);
> + resource_set_range(&tmp, tmp.start - remainder, size);
[Severity: High]
Does this subtraction incorrectly shift normal device BARs out of alignment?
When a user overrides alignment via the pci=resource_alignment= parameter,
the requested alignment can be much larger than the size, resulting in a
non-zero remainder. For normal device BARs, subtracting this remainder shifts
the start address out of the requested alignment boundaries.
Could this silent violation of user alignment requests break use cases like
VFIO pass-through that rely on IOMMU page alignment to isolate device memory?
> + if (!__resource_contains_unbound(empty_res, &tmp))
> + return tmp.start; /* caller skips range */
> + }
> + }
> +
> + start = pcibios_align_resource(rr->dev, &tmp, empty_res, size, align);
> + WARN_ON_ONCE(!IS_ALIGNED(start, min_align));
> +
> + return start;
> +}
> +
> static int __pci_assign_resource(struct pci_bus *bus, struct pci_dev *dev,
> int resno, resource_size_t size, resource_size_t align)
> {
> + struct pci_resreq_data rr = { .dev = dev, .real_align = align };
> struct resource *res = pci_resource_n(dev, resno);
> resource_size_t min;
> int ret;
>
> min = (res->flags & IORESOURCE_IO) ? PCIBIOS_MIN_IO : PCIBIOS_MIN_MEM;
>
> + if ((res->flags & IORESOURCE_MEM) && pci_resreq_remainder(size, align)) {
> + align = min;
> + if (pci_resource_is_bridge_win(resno))
> + align = pci_min_window_alignment(bus, res->flags);
> + }
[Severity: High]
Can this logic unintentionally catch normal device BARs with overridden
alignments and cause resource allocation to fail?
If pci=resource_alignment= is used, pci_resreq_remainder() evaluates to
non-zero for a normal device BAR. This block is then entered and align is
overwritten with min (which is PCIBIOS_MIN_MEM).
On architectures where PCIBIOS_MIN_MEM is 0 (like ARM64), this destroys the
original alignment constraint and assigns an alignment of 0. Passing a 0
alignment to allocate_resource() causes ALIGN(x, 0) to evaluate to 0, which
can trigger a catastrophic allocation failure.
Should this condition specifically check if the resource is a bridge window
before proceeding?
> +
> /*
> * First, try exact prefetching match. Even if a 64-bit
> * prefetchable bridge window is below 4GB, we can't put a 32-bit
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260923131757.7792-1-ilpo.jarvinen@linux.intel.com?part=2
next prev parent reply other threads:[~2026-09-23 13:32 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20260923131757.7792-1-ilpo.jarvinen@linux.intel.com>
2026-09-23 13:17 ` [PATCH 2/5] PCI: Fix nesting windows with remainder at the left edge Ilpo Järvinen
2026-09-23 13:32 ` sashiko-bot [this message]
2026-09-23 13:17 ` [PATCH 3/5] PCI: Place resources to either edge of the window Ilpo Järvinen
2026-09-23 13:28 ` sashiko-bot
2026-09-24 11:03 ` Ilpo Järvinen
2026-09-23 13:17 ` [PATCH 4/5] PCI: Fix composite resource sizing Ilpo Järvinen
2026-09-23 13:31 ` sashiko-bot
2026-09-23 13:39 ` Ilpo Järvinen
2026-09-23 13:17 ` [PATCH 5/5] PCI/quirks: Avoid certain BAR 0 address with igb Ilpo Järvinen
2026-09-23 13:29 ` sashiko-bot
2026-09-24 20:20 ` Bjorn Helgaas
2026-09-28 12:20 ` Ilpo Järvinen
2026-09-28 13:19 ` David Laight
2026-09-28 14:30 ` Ilpo Järvinen
2026-09-28 18:56 ` David Laight
2026-09-26 2:00 ` [PATCH 0/5] PCI: Resource placement algorithm fixes Nikolas Joshua Britton
2026-09-28 12:34 ` Ilpo Järvinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923133202.07DF61F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=ilpo.jarvinen@linux.intel.com \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox