Rust for Linux List
 help / color / mirror / Atom feed
* [PATCH v4] rust: pci: reject IRQ vector indices that do not fit in u32
@ 2026-08-31 17:09 Sophon Zhang via B4 Relay
  2026-09-01 10:58 ` Alexandre Courbot
                   ` (2 more replies)
  0 siblings, 3 replies; 15+ messages in thread
From: Sophon Zhang via B4 Relay @ 2026-08-31 17:09 UTC (permalink / raw)
  To: Danilo Krummrich, Bjorn Helgaas, Krzysztof Wilczyński,
	Miguel Ojeda, Boqun Feng, Gary Guo, Björn Roy Baron,
	Benno Lossin, Andreas Hindborg, Alice Ryhl, Trevor Gross,
	Daniel Almeida, Tamir Duberstein, Alexandre Courbot,
	Onur Özkan
  Cc: linux-pci, rust-for-linux, linux-kernel, Sophon Zhang

From: Sophon Zhang <aiqubits@hotmail.com>

IrqVectorRegistration::index() accepts a usize, but pci_irq_vector()
takes an unsigned int. On 64-bit architectures, casting an index larger
than u32::MAX wraps it before the PCI core can validate it. In
particular, u32::MAX + 1 becomes zero and can resolve to the first
allocated vector.

Use a checked conversion and return EINVAL when the index cannot be
represented by the C API.

Fixes: 2fb7755b0a7e ("rust: pci: resolve IRQ in index() and embed IrqRequest in IrqVector")
Signed-off-by: Sophon Zhang <aiqubits@hotmail.com>
---
Prevent 64-bit Rust IRQ vector indices from wrapping when they cross the
PCI C API boundary.
---
Changes in v4:
- Drop the explicit length check in favor of PCI core range validation.
- Use the existing TryFromIntError-to-Error conversion directly.
- Keep commit trailers adjacent and narrow the description to truncation.
- Link to v3: https://patch.msgid.link/20260831-fix-pci-irq-vector-index-truncation-v3-1-a2103084d20e@hotmail.com

Changes in v3:
- Check the index against the allocated vector count before entering the C API.
- Keep the checked usize-to-u32 conversion and document the C-side warning.
- Link to v2: https://patch.msgid.link/20260831-fix-pci-irq-vector-index-truncation-v2-1-4030ea7746a9@hotmail.com

Changes in v2:
- No code changes.
- Link to v1: https://patch.msgid.link/20260831-fix-pci-irq-vector-index-truncation-v1-1-d63217d99b67@hotmail.com

Testing:
- make rustfmtcheck
- Not build- or hardware-tested; bindgen is unavailable in the test environment.
---
 rust/kernel/pci/irq.rs | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/rust/kernel/pci/irq.rs b/rust/kernel/pci/irq.rs
index 6741046ec1c0..22e2cdf82a21 100644
--- a/rust/kernel/pci/irq.rs
+++ b/rust/kernel/pci/irq.rs
@@ -151,8 +151,10 @@ pub fn irq_type(&self) -> IrqType {
     /// [`Self::len()`].
     #[inline]
     pub fn index(&self, index: usize) -> Result<IrqVector<'_>> {
+        let index = u32::try_from(index)?;
+
         // SAFETY: `self.dev.as_raw()` is a valid pointer to a `struct pci_dev`.
-        let irq = unsafe { bindings::pci_irq_vector(self.dev.as_raw(), index as u32) };
+        let irq = unsafe { bindings::pci_irq_vector(self.dev.as_raw(), index) };
         if irq < 0 {
             return Err(Error::from_errno(irq));
         }

---
base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
change-id: 20260831-fix-pci-irq-vector-index-truncation-6752f3751a0d

Best regards,
--  
Sophon Zhang <aiqubits@hotmail.com>



^ permalink raw reply related	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2026-09-01 16:31 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-31 17:09 [PATCH v4] rust: pci: reject IRQ vector indices that do not fit in u32 Sophon Zhang via B4 Relay
2026-09-01 10:58 ` Alexandre Courbot
2026-09-01 11:08   ` Danilo Krummrich
2026-09-01 13:32     ` Alexandre Courbot
2026-09-01 13:36       ` Danilo Krummrich
2026-09-01 13:52         ` Alexandre Courbot
2026-09-01 13:48       ` Gary Guo
2026-09-01 14:08         ` Alexandre Courbot
2026-09-01 15:58           ` 回复: " ai qubits
2026-09-01 11:47   ` ai qubits
2026-09-01 12:06     ` Gary Guo
2026-09-01 12:35       ` 回复: " ai qubits
2026-09-01 12:42   ` Miguel Ojeda
2026-09-01 16:19 ` Gary Guo
2026-09-01 16:31 ` Danilo Krummrich

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox