From: Sreeraj S Kurup <sreekuttan2156239@gmail.com>
To: "Ryder Lee" <ryder.lee@mediatek.com>,
"Lorenzo Pieralisi" <lpieralisi@kernel.org>,
"Krzysztof Wilczyński" <kwilczynski@kernel.org>,
"Manivannan Sadhasivam" <mani@kernel.org>,
"Rob Herring" <robh@kernel.org>,
"Bjorn Helgaas" <bhelgaas@google.com>,
"Matthias Brugger" <matthias.bgg@gmail.com>,
"AngeloGioacchino Del Regno"
<angelogioacchino.delregno@collabora.com>
Cc: linux-pci@vger.kernel.org, linux-mediatek@lists.infradead.org,
linux-kernel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org,
Sreeraj S Kurup <sreekuttan2156239@gmail.com>
Subject: [PATCH v2] PCI: mediatek: Fix integer truncation in fls() and clamp size
Date: Wed, 30 Sep 2026 10:54:35 +0000 [thread overview]
Message-ID: <20260930105435.3660-1-sreekuttan2156239@gmail.com> (raw)
resource_size() returns a resource_size_t, which is 64-bit on 64-bit
architectures or 32-bit systems with LPAE/PAE enabled. Passing this
directly to fls(), which accepts an unsigned int, implicitly
truncates the upper 32 bits.
Furthermore, AHB2PCIE_SIZE() uses a 5-bit mask GENMASK(4, 0). If a
resource size of 4 GiB or larger is passed, fls64() returns 33 or
greater, which overflows the 5-bit mask and wraps around (e.g. 33 & 31
= 1).
Fix this by using fls64() for 64-bit resource sizes and clamping the
result to a maximum of 31 to fit the 5-bit register field.
Signed-off-by: Sreeraj S Kurup <sreekuttan2156239@gmail.com>
---
drivers/pci/controller/pcie-mediatek.c | 19 +++++++++++++++++--
1 file changed, 17 insertions(+), 2 deletions(-)
diff --git a/drivers/pci/controller/pcie-mediatek.c b/drivers/pci/controller/pcie-mediatek.c
index a60d1ae076f8..9576fe532b92 100644
--- a/drivers/pci/controller/pcie-mediatek.c
+++ b/drivers/pci/controller/pcie-mediatek.c
@@ -8,6 +8,7 @@
*/
#include <linux/bitfield.h>
+#include <linux/bitops.h>
#include <linux/clk.h>
#include <linux/delay.h>
#include <linux/errno.h>
@@ -686,6 +687,8 @@ static int mtk_pcie_startup_port_v2(struct mtk_pcie_port *port)
const struct mtk_pcie_soc *soc = port->pcie->soc;
u32 val;
int err;
+ resource_size_t size;
+ int size_order;
entry = resource_list_first_type(&host->windows, IORESOURCE_MEM);
if (entry)
@@ -753,8 +756,13 @@ static int mtk_pcie_startup_port_v2(struct mtk_pcie_port *port)
mtk_pcie_enable_msi(port);
/* Set AHB to PCIe translation windows */
+ size = resource_size(mem);
+ size_order = fls64(size);
+ if (size_order > 31)
+ size_order = 31;
+
val = lower_32_bits(mem->start) |
- AHB2PCIE_SIZE(fls(resource_size(mem)));
+ AHB2PCIE_SIZE(size_order);
writel(val, port->base + PCIE_AHB_TRANS_BASE0_L);
val = upper_32_bits(mem->start);
@@ -775,6 +783,8 @@ static int mtk_pcie_startup_port_en7528(struct mtk_pcie_port *port)
struct resource_entry *entry;
u32 val, link_mask;
int err;
+ resource_size_t size;
+ int size_order;
entry = resource_list_first_type(&host->windows, IORESOURCE_MEM);
if (entry)
@@ -829,8 +839,13 @@ static int mtk_pcie_startup_port_en7528(struct mtk_pcie_port *port)
mtk_pcie_enable_msi(port);
/* Set AHB to PCIe translation windows */
+ size = resource_size(mem);
+ size_order = fls64(size);
+ if (size_order > 31)
+ size_order = 31;
+
val = lower_32_bits(mem->start) |
- AHB2PCIE_SIZE(fls(resource_size(mem)));
+ AHB2PCIE_SIZE(size_order);
writel(val, port->base + PCIE_AHB_TRANS_BASE0_L);
val = upper_32_bits(mem->start);
--
2.55.0
next reply other threads:[~2026-09-30 10:55 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 10:54 Sreeraj S Kurup [this message]
2026-09-30 11:04 ` [PATCH v2] PCI: mediatek: Fix integer truncation in fls() and clamp size sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930105435.3660-1-sreekuttan2156239@gmail.com \
--to=sreekuttan2156239@gmail.com \
--cc=angelogioacchino.delregno@collabora.com \
--cc=bhelgaas@google.com \
--cc=kwilczynski@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mediatek@lists.infradead.org \
--cc=linux-pci@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=mani@kernel.org \
--cc=matthias.bgg@gmail.com \
--cc=robh@kernel.org \
--cc=ryder.lee@mediatek.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox