From: Frank Li <Frank.li@nxp.com>
To: Koichiro Den <den@valinux.co.jp>
Cc: dave.jiang@intel.com, ntb@lists.linux.dev,
linux-pci@vger.kernel.org, dmaengine@vger.kernel.org,
linux-renesas-soc@vger.kernel.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org, mani@kernel.org,
kwilczynski@kernel.org, kishon@kernel.org, bhelgaas@google.com,
corbet@lwn.net, geert+renesas@glider.be, magnus.damm@gmail.com,
robh@kernel.org, krzk+dt@kernel.org, conor+dt@kernel.org,
vkoul@kernel.org, joro@8bytes.org, will@kernel.org,
robin.murphy@arm.com, jdmason@kudzu.us, allenbh@gmail.com,
andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com,
kuba@kernel.org, pabeni@redhat.com, Basavaraj.Natikar@amd.com,
Shyam-sundar.S-k@amd.com, kurt.schwemmer@microsemi.com,
logang@deltatee.com, jingoohan1@gmail.com, lpieralisi@kernel.org,
utkarsh02t@gmail.com, jbrunet@baylibre.com, dlemoal@kernel.org,
arnd@arndb.de, elfring@users.sourceforge.net
Subject: Re: [RFC PATCH v3 01/35] PCI: endpoint: pci-epf-vntb: Use array_index_nospec() on mws_size[] access
Date: Thu, 18 Dec 2025 22:08:02 -0500 [thread overview]
Message-ID: <aUTBkr83isZfmE3x@lizhi-Precision-Tower-5810> (raw)
In-Reply-To: <20251217151609.3162665-2-den@valinux.co.jp>
On Thu, Dec 18, 2025 at 12:15:35AM +0900, Koichiro Den wrote:
> Follow common kernel idioms for indices derived from configfs attributes
> and suppress Smatch warnings:
>
> epf_ntb_mw1_show() warn: potential spectre issue 'ntb->mws_size' [r]
> epf_ntb_mw1_store() warn: potential spectre issue 'ntb->mws_size' [w]
>
> Also fix the error message for out-of-range MW indices and %lld format
> for unsigned values.
>
> Signed-off-by: Koichiro Den <den@valinux.co.jp>
> ---
Reviewed-by: Frank Li <Frank.Li@nxp.com>
> Note: I noticed [RFC PATCH v2 01/27] resurrected the Smatch warnings
> https://lore.kernel.org/all/20251129160405.2568284-2-den@valinux.co.jp/
> This RFC v3 version therefore reverts to the RFC v1 style, with one
> additional fix to correct the sprintf format specifier (%lld->%llu).
> ---
> drivers/pci/endpoint/functions/pci-epf-vntb.c | 24 +++++++++++--------
> 1 file changed, 14 insertions(+), 10 deletions(-)
>
> diff --git a/drivers/pci/endpoint/functions/pci-epf-vntb.c b/drivers/pci/endpoint/functions/pci-epf-vntb.c
> index 3ecc5059f92b..56aab5d354d6 100644
> --- a/drivers/pci/endpoint/functions/pci-epf-vntb.c
> +++ b/drivers/pci/endpoint/functions/pci-epf-vntb.c
> @@ -995,17 +995,19 @@ static ssize_t epf_ntb_##_name##_show(struct config_item *item, \
> struct config_group *group = to_config_group(item); \
> struct epf_ntb *ntb = to_epf_ntb(group); \
> struct device *dev = &ntb->epf->dev; \
> - int win_no; \
> + int win_no, idx; \
> \
> if (sscanf(#_name, "mw%d", &win_no) != 1) \
> return -EINVAL; \
> \
> - if (win_no <= 0 || win_no > ntb->num_mws) { \
> - dev_err(dev, "Invalid num_nws: %d value\n", ntb->num_mws); \
> + idx = win_no - 1; \
> + if (idx < 0 || idx >= ntb->num_mws) { \
> + dev_err(dev, "MW%d out of range (num_mws=%d)\n", \
> + win_no, ntb->num_mws); \
> return -EINVAL; \
> } \
> - \
> - return sprintf(page, "%lld\n", ntb->mws_size[win_no - 1]); \
> + idx = array_index_nospec(idx, ntb->num_mws); \
> + return sprintf(page, "%llu\n", ntb->mws_size[idx]); \
> }
>
> #define EPF_NTB_MW_W(_name) \
> @@ -1015,7 +1017,7 @@ static ssize_t epf_ntb_##_name##_store(struct config_item *item, \
> struct config_group *group = to_config_group(item); \
> struct epf_ntb *ntb = to_epf_ntb(group); \
> struct device *dev = &ntb->epf->dev; \
> - int win_no; \
> + int win_no, idx; \
> u64 val; \
> int ret; \
> \
> @@ -1026,12 +1028,14 @@ static ssize_t epf_ntb_##_name##_store(struct config_item *item, \
> if (sscanf(#_name, "mw%d", &win_no) != 1) \
> return -EINVAL; \
> \
> - if (win_no <= 0 || win_no > ntb->num_mws) { \
> - dev_err(dev, "Invalid num_nws: %d value\n", ntb->num_mws); \
> + idx = win_no - 1; \
> + if (idx < 0 || idx >= ntb->num_mws) { \
> + dev_err(dev, "MW%d out of range (num_mws=%d)\n", \
> + win_no, ntb->num_mws); \
> return -EINVAL; \
> } \
> - \
> - ntb->mws_size[win_no - 1] = val; \
> + idx = array_index_nospec(idx, ntb->num_mws); \
> + ntb->mws_size[idx] = val; \
> \
> return len; \
> }
> --
> 2.51.0
>
next prev parent reply other threads:[~2025-12-19 3:08 UTC|newest]
Thread overview: 61+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-12-17 15:15 [RFC PATCH v3 00/35] NTB transport backed by endpoint DW eDMA Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 01/35] PCI: endpoint: pci-epf-vntb: Use array_index_nospec() on mws_size[] access Koichiro Den
2025-12-19 3:08 ` Frank Li [this message]
2025-12-17 15:15 ` [RFC PATCH v3 02/35] NTB: epf: Add mwN_offset support and config region versioning Koichiro Den
2025-12-19 3:19 ` Frank Li
2025-12-19 7:23 ` Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 03/35] PCI: dwc: ep: Support BAR subrange inbound mapping via address match iATU Koichiro Den
2025-12-19 14:19 ` Frank Li
2025-12-20 15:36 ` Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 04/35] NTB: Add offset parameter to MW translation APIs Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 05/35] PCI: endpoint: pci-epf-vntb: Propagate MW offset from configfs when present Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 06/35] NTB: ntb_transport: Support partial memory windows with offsets Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 07/35] PCI: endpoint: pci-epf-vntb: Hint subrange mapping preference to EPC driver Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 08/35] NTB: core: Add .get_private_data() to ntb_dev_ops Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 09/35] NTB: epf: vntb: Implement .get_private_data() callback Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 10/35] dmaengine: dw-edma: Fix MSI data values for multi-vector IMWr interrupts Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 11/35] NTB: ntb_transport: Move TX memory window setup into setup_qp_mw() Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 12/35] NTB: ntb_transport: Dynamically determine qp count Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 13/35] NTB: ntb_transport: Introduce get_dma_dev() helper Koichiro Den
2025-12-19 14:31 ` Frank Li
2025-12-20 15:29 ` Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 14/35] NTB: epf: Reserve a subset of MSI vectors for non-NTB users Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 15/35] NTB: ntb_transport: Move internal types to ntb_transport_internal.h Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 16/35] NTB: ntb_transport: Introduce ntb_transport_backend_ops Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 17/35] dmaengine: dw-edma: Add helper func to retrieve register base and size Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 18/35] dmaengine: dw-edma: Add per-channel interrupt routing mode Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 19/35] dmaengine: dw-edma: Poll completion when local IRQ handling is disabled Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 20/35] dmaengine: dw-edma: Add notify-only channels support Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 21/35] dmaengine: dw-edma: Add a helper to retrieve LL (Linked List) region Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 22/35] dmaengine: dw-edma: Serialize RMW on shared interrupt registers Koichiro Den
2025-12-19 14:39 ` Frank Li
2025-12-20 15:21 ` Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 23/35] NTB: ntb_transport: Split core into ntb_transport_core.c Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 24/35] NTB: ntb_transport: Add additional hooks for DW eDMA backend Koichiro Den
2025-12-17 15:15 ` [RFC PATCH v3 25/35] NTB: hw: Introduce DesignWare eDMA helper Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 26/35] NTB: ntb_transport: Introduce DW eDMA backed transport mode Koichiro Den
2025-12-19 15:00 ` Frank Li
2025-12-20 15:28 ` Koichiro Den
2026-01-06 18:46 ` Dave Jiang
2026-01-07 15:05 ` Koichiro Den
2026-01-06 18:51 ` Dave Jiang
2026-01-07 14:54 ` Koichiro Den
2026-01-07 19:02 ` Dave Jiang
2026-01-08 1:25 ` Koichiro Den
2026-01-08 17:55 ` Dave Jiang
2026-01-10 13:43 ` Koichiro Den
2026-01-12 15:43 ` Dave Jiang
2026-01-13 2:44 ` Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 27/35] NTB: epf: Provide db_vector_count/db_vector_mask callbacks Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 28/35] ntb_netdev: Multi-queue support Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 29/35] NTB: epf: Add per-SoC quirk to cap MRRS for DWC eDMA (128B for R-Car) Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 30/35] iommu: ipmmu-vmsa: Add PCIe ch0 to devices_allowlist Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 31/35] iommu: ipmmu-vmsa: Add support for reserved regions Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 32/35] arm64: dts: renesas: Add Spider RC/EP DTs for NTB with remote DW PCIe eDMA Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 33/35] NTB: epf: Add an additional memory window (MW2) barno mapping on Renesas R-Car Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 34/35] Documentation: PCI: endpoint: pci-epf-vntb: Update and add mwN_offset usage Koichiro Den
2025-12-17 15:16 ` [RFC PATCH v3 35/35] Documentation: driver-api: ntb: Document remote eDMA transport backend Koichiro Den
2026-01-06 21:09 ` Dave Jiang
2026-01-07 15:13 ` Koichiro Den
2025-12-19 15:12 ` [RFC PATCH v3 00/35] NTB transport backed by endpoint DW eDMA Frank Li
2025-12-20 15:44 ` Koichiro Den
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aUTBkr83isZfmE3x@lizhi-Precision-Tower-5810 \
--to=frank.li@nxp.com \
--cc=Basavaraj.Natikar@amd.com \
--cc=Shyam-sundar.S-k@amd.com \
--cc=allenbh@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=arnd@arndb.de \
--cc=bhelgaas@google.com \
--cc=conor+dt@kernel.org \
--cc=corbet@lwn.net \
--cc=dave.jiang@intel.com \
--cc=davem@davemloft.net \
--cc=den@valinux.co.jp \
--cc=dlemoal@kernel.org \
--cc=dmaengine@vger.kernel.org \
--cc=edumazet@google.com \
--cc=elfring@users.sourceforge.net \
--cc=geert+renesas@glider.be \
--cc=jbrunet@baylibre.com \
--cc=jdmason@kudzu.us \
--cc=jingoohan1@gmail.com \
--cc=joro@8bytes.org \
--cc=kishon@kernel.org \
--cc=krzk+dt@kernel.org \
--cc=kuba@kernel.org \
--cc=kurt.schwemmer@microsemi.com \
--cc=kwilczynski@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux-renesas-soc@vger.kernel.org \
--cc=logang@deltatee.com \
--cc=lpieralisi@kernel.org \
--cc=magnus.damm@gmail.com \
--cc=mani@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=ntb@lists.linux.dev \
--cc=pabeni@redhat.com \
--cc=robh@kernel.org \
--cc=robin.murphy@arm.com \
--cc=utkarsh02t@gmail.com \
--cc=vkoul@kernel.org \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox