From: sashiko-bot@kernel.org
To: "Zhi Wang" <zhiw@nvidia.com>
Cc: linux-pci@vger.kernel.org, ojeda@kernel.org, gary@garyguo.net
Subject: Re: [PATCH v2 8/8] samples: rust: add Rust SR-IOV VF driver sample
Date: Thu, 24 Sep 2026 19:22:33 +0000 [thread overview]
Message-ID: <20260924192234.383371F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924190556.1620886-9-zhiw@nvidia.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] pci: resource leak of PCI enable count and bus-master state
--
commit e1308014aae1a5196bca00ac49a31f8c5fc01f1e
Author: Peter Colberg <pcolberg@redhat.com>
samples: rust: add Rust SR-IOV VF driver sample
Add a new SR-IOV driver sample that demonstrates how to enable and disable
the Single Root I/O Virtualization capability for a PCI device. The sample
implements the PF and VF as ordinary PCI drivers.
Link: https://www.qemu.org/docs/master/system/devices/igb.html
> diff --git a/samples/rust/rust_driver_sriov.rs b/samples/rust/rust_driver_sriov.rs
> new file mode 100644
> index 0000000000000..c5fcf4a0c62e9
> --- /dev/null
> +++ b/samples/rust/rust_driver_sriov.rs
[ ... ]
> +#[vtable]
> +impl pci::Driver for SamplePfDriver {
[ ... ]
> + fn probe<'bound>(
> + pdev: &'bound pci::Device<Core<'_>>,
> + _info: Option<&'bound Self::IdInfo>,
> + ) -> impl PinInit<Self::Data<'bound>, Error> + 'bound {
> + pin_init::pin_init_scope(move || {
> + dev_info!(
> + pdev,
> + "Probe Rust SR-IOV PF sample (PCI ID: {}, 0x{:x}).\n",
> + pdev.vendor_id(),
> + pdev.device_id()
> + );
> +
> + pdev.enable_device_mem()?;
> + pdev.set_master();
> +
> + Ok(try_pin_init!(PfDriverData {
[Severity: Medium]
If the allocation for PfDriverData or VfRegistration::new() fails within the
try_pin_init! macro, the PF probe returns an error. Does this leave the PCI
device enabled and bus-mastering active?
The Rust PCI API pdev.enable_device_mem() binds directly to
pci_enable_device_mem(), which increments the device's enable_cnt without
using devres management, so this might leak the enable_cnt on the error path.
> + // SAFETY:
> + // - probe has exclusive access to this PF before SR-IOV is enabled;
[ ... ]
> +#[vtable]
> +impl pci::Driver for SampleVfDriver {
[ ... ]
> + fn probe<'bound>(
> + pdev: &'bound pci::Device<Core<'_>>,
> + _info: Option<&'bound Self::IdInfo>,
> + ) -> impl PinInit<Self::Data<'bound>, Error> + 'bound {
> + pin_init::pin_init_scope(move || {
> + dev_info!(
[ ... ]
> + let pdev_bound: &'bound pci::Device<Bound> = pdev;
> + let pf_api = pdev_bound.vf_registration_data::<PfApiForLt>()?;
> +
> + pdev.enable_device_mem()?;
> + pdev.set_master();
> +
> + let request = pf_api.submit(pdev)?;
[Severity: Medium]
Similarly here in SampleVfDriver::probe, if pf_api.submit(pdev) fails, the VF
probe exits via the ? operator without undoing the manual enable_device_mem()
and set_master() calls. Can this permanently leak the enable_cnt and prevent
proper PCI resource management and power state transitions?
> + dev_info!(pdev, "Submitted request {} through PF data.\n", request);
> +
> + Ok(try_pin_init!(VfDriverData { pdev: pdev.into() }))
> + })
> + }
> +}
> +
> +#[pinned_drop]
> +impl PinnedDrop for PfDriverData<'_> {
> + fn drop(self: Pin<&mut Self>) {
> + dev_info!(self.pdev, "Remove Rust SR-IOV PF sample.\n");
> + }
> +}
[Severity: Medium]
During normal driver removal, the drop logic for PfDriverData (and
VfDriverData below) fails to disable the PCI device or clear the bus master
flag. Does this mean the enable_cnt is leaked even on the successful
teardown path?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924190556.1620886-1-zhiw@nvidia.com?part=8
prev parent reply other threads:[~2026-09-24 19:22 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 19:05 [PATCH v2 0/8] Add Rust PCI SR-IOV support Zhi Wang
2026-09-24 19:05 ` [PATCH v2 1/8] rust: pci: add {enable,disable}_sriov(), to control SR-IOV capability Zhi Wang
2026-09-24 19:20 ` sashiko-bot
2026-09-25 20:43 ` Peter Colberg
2026-09-28 19:32 ` Zhi Wang
2026-09-27 16:37 ` Danilo Krummrich
2026-09-28 19:45 ` Zhi Wang
2026-09-24 19:05 ` [PATCH v2 2/8] rust: pci: add vtable attribute to pci::Driver trait Zhi Wang
2026-09-24 19:13 ` sashiko-bot
2026-09-24 19:05 ` [PATCH v2 3/8] rust: pci: add is_virtfn(), to check for VFs Zhi Wang
2026-09-24 19:14 ` sashiko-bot
2026-09-24 19:05 ` [PATCH v2 4/8] rust: pci: add is_physfn(), to check for PFs Zhi Wang
2026-09-24 19:12 ` sashiko-bot
2026-09-24 19:05 ` [PATCH v2 5/8] rust: pci: add num_vf(), to return number of VFs Zhi Wang
2026-09-24 19:13 ` sashiko-bot
2026-09-24 19:05 ` [PATCH v2 6/8] rust: pci: add bus callback sriov_configure(), to control SR-IOV from sysfs Zhi Wang
2026-09-24 19:19 ` sashiko-bot
2026-09-24 19:05 ` [PATCH v2 7/8] rust: pci: add typed SR-IOV PF registration data Zhi Wang
2026-09-24 19:27 ` sashiko-bot
2026-09-28 20:08 ` Danilo Krummrich
2026-09-29 7:27 ` Zhi Wang
2026-09-29 8:35 ` Danilo Krummrich
2026-09-24 19:05 ` [PATCH v2 8/8] samples: rust: add Rust SR-IOV VF driver sample Zhi Wang
2026-09-24 19:22 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924192234.383371F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=gary@garyguo.net \
--cc=linux-pci@vger.kernel.org \
--cc=ojeda@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=zhiw@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox