From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f171.google.com (mail-pl1-f171.google.com [209.85.214.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3593F156C6A for ; Sun, 9 Aug 2026 01:29:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786238941; cv=none; b=Vh1xLa5LGxqfTtVAf4fsfUSZiliqGhJvhRZjsQL28ZEPYL2/n+6oLpP7KmRXuIRJKgdfDcE0Yb0+RCeMRlZo+TMOvSC6s2dEsDrHBFuAmW9uOeQxZAj7jYvMLUbYJ0FktWjo4RKKAM3EFzYJApdc2mkB7c+je+EsB+TK7rfU9Ow= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786238941; c=relaxed/simple; bh=QziYzalYqJqEO9wkxAYZemeJLDTeF0VAxkUjX8sRizk=; h=From:To:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=IYc4Mo9tJ0ccSAzxnmjXg2RipIr/EV2+V0mfbwL04Z1ufYwk0dkLyxDAERBiNSTmk9a6dXidCi0G+ArOk3jZ8o5WBCW3XK07GNqUhfQvvO71gs7EMeGgfYg+J0L4lTpbOBhBC7URtO9xvntgEHfS06bkxWAuSj0iamlm39YkUO8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=DILSTd/E; arc=none smtp.client-ip=209.85.214.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="DILSTd/E" Received: by mail-pl1-f171.google.com with SMTP id d9443c01a7336-2cc73e322dbso7000375ad.1 for ; Sat, 08 Aug 2026 18:29:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786238939; x=1786843739; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=unnrLiRG1r18nJZN1a5a6TML6nSi3RB1Ndbj2CmlTck=; b=DILSTd/ETGLcLoirPRk3i+6pJhuUHj+bqi7sBUM3ZJIiyh3gmx+nHblHDfrlN+7/ks 1zQtr02g1AMRoAiSfka2eRpSstoRY4U0CDFZWJpR7kebkKet01wMOBTCKSPVRVHQ0vw8 aRyuQKFOBm4KHbbB+BbTZPBHd8dQYy99+bNoAXP9aGCHVuEgrZ/4cvpdlHz0ZT8naTQo S43KoYA4+ODyF3Uf2M47Xl/pM/z07uqzrc47zzgOpPrHL+ImbSgWDbR+5kaviCgyZ1va 4Fd7kxGphUg8gz4+enH/hZOJh3sggDhKEe8MazPGoD62YPMpmC6U3PvB8z5kak9rltIQ /YzQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786238939; x=1786843739; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=unnrLiRG1r18nJZN1a5a6TML6nSi3RB1Ndbj2CmlTck=; b=Ijx3q7Fji9mHGdnyUuiqPPAXf3dg7ttHPz3udpGTegEST+mfQEMwg5KzNCGBAkg581 WhDWWmlD5tEocNTE5whwWH6jXcajLXZRbNYJxDh7uzrPBG/NTv5psvsaRcH4X5kCyRdp tQAA1IUtx1IjAm9q0WboR7t8gGc2PbAUsTqpm4c3T7DKrLp5i6U4Gu88U+wCXULVS8QD Jf8UP/JE7UtOXykTznHgkgQSoDmtgA5RzeZGTVMFxjvQFzJee81s2oyw0i0Cu3kJONnZ F9O7/ea0OYOhEdNkplXZEPgzd+1oIJ9ORO/iZzW4a9SgKn3bLPNRm5H9peAw7AKSwOq3 jgvw== X-Forwarded-Encrypted: i=1; AHgh+RrAdkwe8MWOzvz1osUtjU+Q/bjnIqPZGLjf9sGrHkIfaqtlEhym4OsgCdblExafQu78N24eII3b3JvpH+A=@vger.kernel.org X-Gm-Message-State: AOJu0YznXhy72GNW4Jyudhgs2Yhm5LDakGCciSjFbxlenePVUB6Z0rRP RJEOfGqSuwiyxptyfRIS55PI0drPNNGOh/Q18P/vlFWW6IFxkn3EKemk X-Gm-Gg: AR+sD12wr+jW8GTW7IcVIBwhjkneqb9RtPWg6gOl8ElWoK11tavi3ytR3w1CkpSsocf mJjiCrsHxqVa+tCNRjSBKIO+xOtQe5qO3LupvkbwRVsP0LWqINRDzXMhC45uxqU+9Mobqc3x1sA ev4UuhKbCz98QAou27I0shBqHylbj9sAKfmGbgrJ3/LMODwhk4TabmGHZ0CyZZdXKz2ZZnxELjk 0zichJ/yL2lLXFMpLFJSBRFEdq0FT/LDeMGFicwY4SQSQb74ccsK74YyOQen7oOsu6S5dDxUr5d hXJfygI9xV5F0A9LmccqIn61az2RwaBDRDrgc2ol9ml4udRUXaKLJLhaT6QNH5SaGCNSjGRQr1X U+d/zEfsAiVjhrXz/4wO/ieoNGVui8F3APWQaT47ApjTM7dHzacqiB9q9+Jd7fdttBBQ9/VlTy6 iGnhhJqKQGNu3anedruq73PINHwe/ngp2N3IpRWSDy6XB7jePHFuSyOAMR9Cf5 X-Received: by 2002:a17:902:d2c9:b0:2cf:b330:e0e8 with SMTP id d9443c01a7336-2d0ca7599d6mr344811355ad.10.1786238939305; Sat, 08 Aug 2026 18:28:59 -0700 (PDT) Received: from ubuntu.. ([219.241.133.184]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d16c4a35c0sm20768965ad.63.2026.08.08.18.28.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 18:28:58 -0700 (PDT) From: Rihyeon Kim To: syzbot+7134530b25073b4ef373@syzkaller.appspotmail.com, bhelgaas@google.com, linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Subject: Re: [syzbot] [pci?] BUG: unable to handle kernel paging request in pci_resource_io Date: Sun, 9 Aug 2026 10:28:55 +0900 Message-ID: <20260809012855.109608-1-rihyeon8648@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <6a778f12.b50370da.49fe0.002d.GAE@google.com> References: <6a778f12.b50370da.49fe0.002d.GAE@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit On Sat Aug 8, 2026 at 8:18 PM UTC, syzbot wrote: > Unable to handle kernel paging request at virtual address ffffffffc0801001 > FSC = 0x21: alignment fault > pc : logic_outw+0x58/0x124 lib/logic_pio.c:305 > pci_resource_io+0x1f4/0x3dc drivers/pci/pci-sysfs.c:1187 I'm interested in this one and had a look at it today. I can reproduce it here, with the same faulting address and the same ESR 0x96000061 as the report. It seems that pci_resource_io() validates the access width (1, 2 or 4 bytes) and the range against the BAR, but never checks that the port itself is naturally aligned. The port is the BAR start plus the sysfs file offset, so a 2-byte write at an odd offset reaches outw() with an odd port number. arm64 has no separate I/O address space, so outw() becomes the __raw_writew() to PCI_IOBASE + port that the report shows in the pc line. The pte in the report has AttrIndx 4, i.e. MT_DEVICE_nGnRE, so that window is Device memory and the unaligned store faults. The registers in the report seem to agree. x22 and x23 are 0x1001 and 0x101f, which is an offset of 1 into a 32-byte I/O BAR at 0x1000, and x21 is 0xffbfff, i.e. MMIO_UPPER_LIMIT, so logic_outw() took the _outw() branch rather than the indirect PIO one. PCI_IOBASE is 0xffffffffc0800000 there, and adding the 0x1001 port gives the faulting address exactly. The read path goes through the same helper, and an unaligned pread() faults the same way in inw(). If anything it is easier to reach, since pci_read_resource() has no security_locked_down() check. If I'm reading this correctly, rejecting accesses whose port is not naturally aligned for the width should be enough, and it would not affect any aligned access that works today. I will prepare a patch. Thanks, Rihyeon Kim