From: Niklas Schnelle <schnelle@linux.ibm.com>
To: Gerd Bayer <gbayer@linux.ibm.com>, sashiko-reviews@lists.linux.dev
Cc: Alexander Gordeev <agordeev@linux.ibm.com>,
Heiko Carstens <hca@linux.ibm.com>,
Christian Borntraeger <borntraeger@linux.ibm.com>,
linux-s390@vger.kernel.org, Vasily Gorbik <gor@linux.ibm.com>
Subject: Re: [PATCH 3/3] s390/pci: Add function handle to RPCIT insn trace
Date: Wed, 07 Oct 2026 16:38:09 +0200 [thread overview]
Message-ID: <ef1ad0489e7606cffb8a1b7cdc13321a73c03453.camel@linux.ibm.com> (raw)
In-Reply-To: <d46130a7fa9b84dce30c8cf372be469cb615c7f7.camel@linux.ibm.com>
On Wed, 2026-10-07 at 15:12 +0200, Gerd Bayer wrote:
> On Wed, 2026-10-07 at 11:17 +0000, sashiko-bot@kernel.org wrote:
> > Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> > - [Medium] s390/pci: info leak of uninitialized struct padding in zpci_err_insn_rpcit
> > --
> >
> > commit 9deafec98847a2a1de20826fbaa6431e1e3c973f
> > Author: Gerd Bayer <gbayer@linux.ibm.com>
> >
> > s390/pci: Add function handle to RPCIT insn trace
> >
> > In certain debug situations it would be helpful, if the insn trace for a
> > failing RPCIT would reveal the PCI function on which this was attempted.
> >
> > Introduce a variant of zpci_err_insn_req() called zpci_err_insn_rpcit()
> > that accepts an IO virtual address and a range parameter together with
> > the req conveying the function handle. Switch zpci_refresh_trans() to
> > use that new error trace.
> >
> > > diff --git a/arch/s390/pci/pci_insn.c b/arch/s390/pci/pci_insn.c
> > > index 053afb3e7a990..ae9ed4aa2ec9c 100644
> > > --- a/arch/s390/pci/pci_insn.c
> > > +++ b/arch/s390/pci/pci_insn.c
--- snip ---
> >
> > [Severity: Medium]
> > Does this code leak uninitialized stack memory to the s390dbf debug trace
> > buffer?
> >
> > According to the C standard, unnamed bit-fields do not participate in
> > designated initialization. The struct zpci_err_insn_data starts with:
> >
> > struct zpci_err_insn_data {
> > u8 insn;
> > u8 cc;
> > u8 status;
> > u8: 8;
> > u32: 32;
> > ...
> >
> > Because the unnamed bit-fields are skipped by the designated initializer here,
> > up to 5 bytes of uninitialized kernel stack memory are left in the padding
> > of "data".
> >
> > Since sizeof(data) (which is 32 bytes) is then passed to zpci_err_hex_level(),
> > could these indeterminate stack bytes be copied into the trace buffer on every
> > invocation of zpci_err_insn_rpcit()?
>
> This is basically the same concern as with patch 1/3 - I'll replace the
> unnamed bit-fields with dummy members of appropriate size in a v2.
Same as for the other patch this sounds good to me and the rest of the
change looks good too. Having the function handle could come in handy.
Thanks,
Niklas
prev parent reply other threads:[~2026-10-07 14:39 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 11:07 [PATCH 0/3] s390/pci: Updates to PCI insn tracing Gerd Bayer
2026-10-07 11:07 ` [PATCH 1/3] s390/pci: Adjust alignment in insn trace Gerd Bayer
2026-10-07 11:14 ` sashiko-bot
2026-10-07 13:10 ` Gerd Bayer
2026-10-07 14:36 ` Niklas Schnelle
2026-10-07 11:07 ` [PATCH 2/3] s390/pci: Use 32-bit fh outside of inline asm Gerd Bayer
2026-10-07 11:19 ` sashiko-bot
2026-10-07 14:46 ` Gerd Bayer
2026-10-07 16:21 ` Matthew Rosato
2026-10-08 8:50 ` Gerd Bayer
2026-10-08 9:28 ` Niklas Schnelle
2026-10-07 11:07 ` [PATCH 3/3] s390/pci: Add function handle to RPCIT insn trace Gerd Bayer
2026-10-07 11:17 ` sashiko-bot
2026-10-07 13:12 ` Gerd Bayer
2026-10-07 14:38 ` Niklas Schnelle [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ef1ad0489e7606cffb8a1b7cdc13321a73c03453.camel@linux.ibm.com \
--to=schnelle@linux.ibm.com \
--cc=agordeev@linux.ibm.com \
--cc=borntraeger@linux.ibm.com \
--cc=gbayer@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox