From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from zg8tmtyylji0my4xnjqumte4.icoremail.net (zg8tmtyylji0my4xnjqumte4.icoremail.net [162.243.164.118]) by smtp.subspace.kernel.org (Postfix) with ESMTP id EBEE447207D for ; Wed, 23 Sep 2026 08:28:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=162.243.164.118 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790152111; cv=none; b=dDcKgXYaGe6GI7YdYxUAmgZBsN9XNpreiWPs76/Xgjp+JilbKTmtPCI6DvihzH+5xtfB8hgBV4ZykQ4h0i+87O48OmkMGdqva+DTGq8SRfcg4LPQnV7v2NCuBSa3BajBwqAR02+aLhBI/Sh2t7tY+jqJ/73YGd84srfKwPp6Vv8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790152111; c=relaxed/simple; bh=ZmcWXyE8OSGuPHUEtqU5eUiWHkkA6mdXQ9j6oCOCq/o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=pT4d5+8E94waFoTofUrHf2MIKmysGBORVhcLkTVclva5ezV1fJRsSKcWujf1nO1vorgAM6nUvWY7fCDcqhdi9wVC4IsyIDE+2wtc71QxIRvr+6WIJNB9jEailzd50UwpENGuSGU+QmsEJB8K4FPfgDwBt+1ty5b0zDyf3vd+58Q= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=phytium.com.cn; spf=pass smtp.mailfrom=phytium.com.cn; arc=none smtp.client-ip=162.243.164.118 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=phytium.com.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=phytium.com.cn Received: from prodtpl.icoremail.net (unknown [10.12.1.20]) by hzbj-icmmx-7 (Coremail) with UTF8SMTP id AQAAfwCHjcGpjbNqKovbAA--.31110S2; Wed, 23 Sep 2026 16:28:25 +0800 (CST) Received: from WIN-B62RPRBL2BM.localdomain (unknown [218.76.62.144]) by mail (Coremail) with SMTP id AQAAf8DwSnOijbNq5NjbAA--.47885S3; Wed, 23 Sep 2026 16:28:18 +0800 (CST) From: Zhu Ling To: maz@kernel.org, tglx@kernel.org Cc: radu@rendec.net, zenghui.yu@linux.dev, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Zhu Ling Subject: [PATCH v3] irqchip/gic: Fix UBSAN shift-out-of-bounds in GIC helpers Date: Wed, 23 Sep 2026 16:28:04 +0800 Message-ID: <20260923082804.13197-1-zhuling2709@phytium.com.cn> X-Mailer: git-send-email 2.43.0 In-Reply-To: <6b668efe-ef7a-474a-957c-893755ebba46@linux.dev> References: <6b668efe-ef7a-474a-957c-893755ebba46@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-CM-TRANSID:AQAAf8DwSnOijbNq5NjbAA--.47885S3 X-CM-SenderInfo: x2kxzxlqjsliuz6sx5pwlxzhxfrphubq/1tbiAQAHAWqy10oDhAAAsF Authentication-Results: hzbj-icmmx-7; spf=neutral smtp.mail=zhuling270 9@phytium.com.cn; X-Coremail-Antispam: 1Uk129KBjvJXoWxXrWxKw45Gr1kXrW8uFW5GFg_yoW5tryxpF W5J34Iyr4Iy3WjgF4DCF1DZry5t3ZakrZFkrWxJasxZry5Gas5Aayavr9aq3WqqrZrCa45 Cw4aqF1Uu3WUAFDanT9S1TB71UUUUUJqnTZGkaVYY2UrUUUUj1kv1TuYvTs0mT0YCTnIWj DUYxn0WfASr-VFAU7a7-sFnT9fnUUIcSsGvfJ3UbIYCTnIWIevJa73UjIFyTuYvj4RJUUU UUUUU When running with UBSAN enabled, enabling a GPIO controller that uses a GIC interrupt as its parent triggers several shift-out-of-bounds warnings: shift-out-of-bounds in drivers/irqchip/irq-gic-common.c:50:21 left shift of 2 by 30 places cannot be represented in type 'int' Similar reports are emitted from gic_poke_irq() and gic_peek_irq() in drivers/irqchip/irq-gic-v3.c. The corresponding GICv2 helpers use the same signed-shift pattern. These masks are generated by shifting signed integer constants, which invokes undefined behavior when bit 31 is selected. Use BIT() to generate the masks with an unsigned type and make their intent explicit. Signed-off-by: Zhu Ling --- Changes in v3: - Fix the same issue in the GICv2 gic_poke_irq() and gic_peek_irq() helpers, as pointed out by Zenghui. Changes in v2: - Use BIT() instead of explicit unsigned shifts, as suggested by Marc. - Drop the redundant introductory text from the email. - Update the author email address. Link: https://lore.kernel.org/r/2fJDwUUYdEf2_eaRa041L9xkT8RkSWFeo7euOnqMbbPhUatLlEaAvGfB6sOspDmXaxO87Eh7bQLV9UolyjbMtZBT1wB2UGypjPOo0Z-RC0Q=@proton.me --- drivers/irqchip/irq-gic-common.c | 2 +- drivers/irqchip/irq-gic-v3.c | 4 ++-- drivers/irqchip/irq-gic.c | 4 ++-- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/drivers/irqchip/irq-gic-common.c b/drivers/irqchip/irq-gic-common.c index c776f9142610..8bd1eaa54295 100644 --- a/drivers/irqchip/irq-gic-common.c +++ b/drivers/irqchip/irq-gic-common.c @@ -48,7 +48,7 @@ void gic_enable_quirks(u32 iidr, const struct gic_quirk *quirks, int gic_configure_irq(unsigned int irq, unsigned int type, void __iomem *base) { - u32 confmask = 0x2 << ((irq % 16) * 2); + u32 confmask = BIT(((irq % 16) * 2) + 1); u32 confoff = (irq / 16) * 4; u32 val, oldval; int ret = 0; diff --git a/drivers/irqchip/irq-gic-v3.c b/drivers/irqchip/irq-gic-v3.c index 6e1fa5b247fc..15110d47ddb0 100644 --- a/drivers/irqchip/irq-gic-v3.c +++ b/drivers/irqchip/irq-gic-v3.c @@ -457,7 +457,7 @@ static int gic_peek_irq(struct irq_data *d, u32 offset) u32 index, mask; offset = convert_offset_index(d, offset, &index); - mask = 1 << (index % 32); + mask = BIT(index % 32); if (gic_irq_in_rdist(d)) base = gic_data_rdist_sgi_base(); @@ -473,7 +473,7 @@ static void gic_poke_irq(struct irq_data *d, u32 offset) u32 index, mask; offset = convert_offset_index(d, offset, &index); - mask = 1 << (index % 32); + mask = BIT(index % 32); if (gic_irq_in_rdist(d)) base = gic_data_rdist_sgi_base(); diff --git a/drivers/irqchip/irq-gic.c b/drivers/irqchip/irq-gic.c index f6bc29f515fb..fb7a55f5b394 100644 --- a/drivers/irqchip/irq-gic.c +++ b/drivers/irqchip/irq-gic.c @@ -178,14 +178,14 @@ static inline bool cascading_gic_irq(struct irq_data *d) */ static void gic_poke_irq(struct irq_data *d, u32 offset) { - u32 mask = 1 << (irqd_to_hwirq(d) % 32); + u32 mask = BIT(irqd_to_hwirq(d) % 32); writel_relaxed(mask, gic_dist_base(d) + offset + (irqd_to_hwirq(d) / 32) * 4); } static int gic_peek_irq(struct irq_data *d, u32 offset) { - u32 mask = 1 << (irqd_to_hwirq(d) % 32); + u32 mask = BIT(irqd_to_hwirq(d) % 32); return !!(readl_relaxed(gic_dist_base(d) + offset + (irqd_to_hwirq(d) / 32) * 4) & mask); } -- 2.43.0