From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 85ECF283CA7 for ; Fri, 22 Aug 2025 17:29:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1755883798; cv=none; b=dP02jWyZLxG5DnBQeDg/Pvb7j6bKfr2dvZCkO4n9ZM8cBUBDOIUygk8Yi9HQn21/XJi/ytDlZaRKwnUWUbkW8jjW6l82l0Fbp5KzVXWfT4O+o9Kx+g+rdARih2HUsNgCJCuC9IJwx8rlfb9eNZMsL58WGNscQ5YxgWo86rr+iOE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1755883798; c=relaxed/simple; bh=AI1cf5eTmGR/Ybrbyzy9D+0+r7njHp3NyWxb/hlWodo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=vFiBiJQsZyMYRDWLTvvZH6ll6PdmZ92HLXTYNPNEzbgfeD/8BwB148oZuYQ/t8D2PxcaRzbCv8WQWNLUwhkMozGzBZeURJjplxCvDhux5IbiFfNLkwgnQXvcSngGDIpRqTmyAZKp6VZO2IP9Q9nT0ZUvYKInDZb0lfR1oFSafG0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Jvlt208H; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Jvlt208H" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7C585C4CEED; Fri, 22 Aug 2025 17:29:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1755883798; bh=AI1cf5eTmGR/Ybrbyzy9D+0+r7njHp3NyWxb/hlWodo=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=Jvlt208H/p5BTzCvz4JoU+o050W00vVepY8QOLJ8TJmoIK28B5sC4CMDWLyqEd66/ JRNSjM3hiEcdIluzeWTB9/aWzFN+Q2UtbnXWCSXEV8zJh8otNVPyv+RnSumGq348K0 PeeDS/4yQuyNfrq/wcIkw8Pj1DREMiFNxEMH7lcB/Na7m2+hS7NZhmUFBb1s/QYbTZ qHSnMdIo6hbRkfN/EUrHO2XGn55R4d0x9kiYHS6+donuJo5cyPZ70rVLOxd1FTpACZ XTaz0jp6awBMvofpk0LeWF9VTLdjgGZDxzuuXEUJ6wGXL9TozzFvc8r7mplU2MsB6i w0qFgNDsXOhYg== From: Sasha Levin To: stable@vger.kernel.org Cc: =?UTF-8?q?Andr=C3=A9=20Draszik?= , Bart Van Assche , Peter Griffin , "Martin K. Petersen" , Sasha Levin Subject: [PATCH 5.15.y] scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE Date: Fri, 22 Aug 2025 13:29:55 -0400 Message-ID: <20250822172955.1334600-1-sashal@kernel.org> X-Mailer: git-send-email 2.50.1 In-Reply-To: <2025082137-liver-glimpse-25bf@gregkh> References: <2025082137-liver-glimpse-25bf@gregkh> Precedence: bulk X-Mailing-List: stable@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit From: André Draszik [ Upstream commit 01aad16c2257ab8ff33b152b972c9f2e1af47912 ] On Google gs101, the number of UTP transfer request slots (nutrs) is 32, and in this case the driver ends up programming the UTRL_NEXUS_TYPE incorrectly as 0. This is because the left hand side of the shift is 1, which is of type int, i.e. 31 bits wide. Shifting by more than that width results in undefined behaviour. Fix this by switching to the BIT() macro, which applies correct type casting as required. This ensures the correct value is written to UTRL_NEXUS_TYPE (0xffffffff on gs101), and it also fixes a UBSAN shift warning: UBSAN: shift-out-of-bounds in drivers/ufs/host/ufs-exynos.c:1113:21 shift exponent 32 is too large for 32-bit type 'int' For consistency, apply the same change to the nutmrs / UTMRL_NEXUS_TYPE write. Fixes: 55f4b1f73631 ("scsi: ufs: ufs-exynos: Add UFS host support for Exynos SoCs") Cc: stable@vger.kernel.org Signed-off-by: André Draszik Link: https://lore.kernel.org/r/20250707-ufs-exynos-shift-v1-1-1418e161ae40@linaro.org Reviewed-by: Bart Van Assche Reviewed-by: Peter Griffin Signed-off-by: Martin K. Petersen [ Adjusted path from drivers/ufs/host to drivers/scsi/ufs ] Signed-off-by: Sasha Levin --- drivers/scsi/ufs/ufs-exynos.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/scsi/ufs/ufs-exynos.c b/drivers/scsi/ufs/ufs-exynos.c index 8d4c695cd8d1..9a10d262bac7 100644 --- a/drivers/scsi/ufs/ufs-exynos.c +++ b/drivers/scsi/ufs/ufs-exynos.c @@ -837,8 +837,8 @@ static int exynos_ufs_post_link(struct ufs_hba *hba) hci_writel(ufs, 0xa, HCI_DATA_REORDER); hci_writel(ufs, PRDT_SET_SIZE(12), HCI_TXPRDT_ENTRY_SIZE); hci_writel(ufs, PRDT_SET_SIZE(12), HCI_RXPRDT_ENTRY_SIZE); - hci_writel(ufs, (1 << hba->nutrs) - 1, HCI_UTRL_NEXUS_TYPE); - hci_writel(ufs, (1 << hba->nutmrs) - 1, HCI_UTMRL_NEXUS_TYPE); + hci_writel(ufs, BIT(hba->nutrs) - 1, HCI_UTRL_NEXUS_TYPE); + hci_writel(ufs, BIT(hba->nutmrs) - 1, HCI_UTMRL_NEXUS_TYPE); hci_writel(ufs, 0xf, HCI_AXIDMA_RWDATA_BURST_LEN); if (ufs->opts & EXYNOS_UFS_OPT_SKIP_CONNECTION_ESTAB) -- 2.50.1