mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Frank Li <Frank.li@nxp.com>
To: Koichiro Den <den@valinux.co.jp>
Cc: ntb@lists.linux.dev, linux-pci@vger.kernel.org,
	dmaengine@vger.kernel.org, linux-kernel@vger.kernel.org,
	mani@kernel.org, kwilczynski@kernel.org, kishon@kernel.org,
	bhelgaas@google.com, corbet@lwn.net, vkoul@kernel.org,
	jdmason@kudzu.us, dave.jiang@intel.com, allenbh@gmail.com,
	Basavaraj.Natikar@amd.com, Shyam-sundar.S-k@amd.com,
	kurt.schwemmer@microsemi.com, logang@deltatee.com,
	jingoohan1@gmail.com, lpieralisi@kernel.org, robh@kernel.org,
	jbrunet@baylibre.com, fancer.lancer@gmail.com, arnd@arndb.de,
	pstanner@redhat.com, elfring@users.sourceforge.net
Subject: Re: [RFC PATCH 01/25] PCI: endpoint: pci-epf-vntb: Use array_index_nospec() on mws_size[] access
Date: Thu, 23 Oct 2025 20:06:40 -0400	[thread overview]
Message-ID: <aPrDEE80hSLbL57a@lizhi-Precision-Tower-5810> (raw)
In-Reply-To: <20251023071916.901355-2-den@valinux.co.jp>

On Thu, Oct 23, 2025 at 04:18:52PM +0900, Koichiro Den wrote:
> Follow common kernel idioms for indices derived from configfs attributes
> and suppress Smatch warnings:
>
>   epf_ntb_mw1_show() warn: potential spectre issue 'ntb->mws_size' [r]
>   epf_ntb_mw1_store() warn: potential spectre issue 'ntb->mws_size' [w]
>
> No functional changes.
>
> Signed-off-by: Koichiro Den <den@valinux.co.jp>
> ---
>  drivers/pci/endpoint/functions/pci-epf-vntb.c | 23 +++++++++++--------
>  1 file changed, 14 insertions(+), 9 deletions(-)
>
> diff --git a/drivers/pci/endpoint/functions/pci-epf-vntb.c b/drivers/pci/endpoint/functions/pci-epf-vntb.c
> index 83e9ab10f9c4..55307cd613c9 100644
> --- a/drivers/pci/endpoint/functions/pci-epf-vntb.c
> +++ b/drivers/pci/endpoint/functions/pci-epf-vntb.c
> @@ -876,17 +876,19 @@ static ssize_t epf_ntb_##_name##_show(struct config_item *item,		\
>  	struct config_group *group = to_config_group(item);		\
>  	struct epf_ntb *ntb = to_epf_ntb(group);			\
>  	struct device *dev = &ntb->epf->dev;				\
> -	int win_no;							\
> +	int win_no, idx;						\
>  									\
>  	if (sscanf(#_name, "mw%d", &win_no) != 1)			\
>  		return -EINVAL;						\
>  									\
> -	if (win_no <= 0 || win_no > ntb->num_mws) {			\
> -		dev_err(dev, "Invalid num_nws: %d value\n", ntb->num_mws); \
> +	idx = win_no - 1;						\
> +	if (idx < 0 || idx >= ntb->num_mws) {				\
> +		dev_err(dev, "MW%d out of range (num_mws=%d)\n",	\
> +			win_no, ntb->num_mws);				\
>  		return -EINVAL;						\
>  	}								\
> -									\
> -	return sprintf(page, "%lld\n", ntb->mws_size[win_no - 1]);	\
> +	idx = array_index_nospec(idx, ntb->num_mws);			\
> +	return sprintf(page, "%lld\n", ntb->mws_size[idx]);		\

keep original check if (win_no <= 0 || win_no > ntb->num_mws)

just
	idx = array_index_nospec(win_no - 1, ntb->num_mws);
	return sprintf(page, "%lld\n", ntb->mws_size[idx]);

It should be more simple.

Frank
>  }
>
>  #define EPF_NTB_MW_W(_name)						\
> @@ -896,7 +898,7 @@ static ssize_t epf_ntb_##_name##_store(struct config_item *item,	\
>  	struct config_group *group = to_config_group(item);		\
>  	struct epf_ntb *ntb = to_epf_ntb(group);			\
>  	struct device *dev = &ntb->epf->dev;				\
> -	int win_no;							\
> +	int win_no, idx;						\
>  	u64 val;							\
>  	int ret;							\
>  									\
> @@ -907,12 +909,15 @@ static ssize_t epf_ntb_##_name##_store(struct config_item *item,	\
>  	if (sscanf(#_name, "mw%d", &win_no) != 1)			\
>  		return -EINVAL;						\
>  									\
> -	if (win_no <= 0 || win_no > ntb->num_mws) {			\
> -		dev_err(dev, "Invalid num_nws: %d value\n", ntb->num_mws); \
> +	idx = win_no - 1;						\
> +	if (idx < 0 || idx >= ntb->num_mws) {				\
> +		dev_err(dev, "MW%d out of range (num_mws=%d)\n",	\
> +			win_no, ntb->num_mws);				\
>  		return -EINVAL;						\
>  	}								\
>  									\
> -	ntb->mws_size[win_no - 1] = val;				\
> +	idx = array_index_nospec(idx, ntb->num_mws);			\
> +	ntb->mws_size[idx] = val;					\
>  									\
>  	return len;							\
>  }
> --
> 2.48.1
>

  reply	other threads:[~2025-10-24  0:06 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-10-23  7:18 [RFC PATCH 00/25] NTB/PCI: Add DW eDMA intr fallback and BAR MW offsets Koichiro Den
2025-10-23  7:18 ` [RFC PATCH 01/25] PCI: endpoint: pci-epf-vntb: Use array_index_nospec() on mws_size[] access Koichiro Den
2025-10-24  0:06   ` Frank Li [this message]
2025-10-24 16:24     ` Koichiro Den
2025-10-24 18:40       ` Frank Li
2025-10-23  7:18 ` [RFC PATCH 02/25] PCI: endpoint: pci-epf-vntb: Add mwN_offset configfs attributes Koichiro Den
2025-10-23  7:18 ` [RFC PATCH 03/25] NTB: epf: Handle mwN_offset for inbound MW regions Koichiro Den
2025-10-23  7:18 ` [RFC PATCH 04/25] PCI: endpoint: Add inbound mapping ops to EPC core Koichiro Den
2025-10-23  7:18 ` [RFC PATCH 05/25] PCI: dwc: ep: Implement EPC inbound mapping support Koichiro Den
2025-10-23  7:18 ` [RFC PATCH 06/25] PCI: endpoint: pci-epf-vntb: Use pci_epc_map_inbound() for MW mapping Koichiro Den
2025-10-23  7:18 ` [RFC PATCH 07/25] NTB: Add offset parameter to MW translation APIs Koichiro Den
2025-10-23  7:18 ` [RFC PATCH 08/25] PCI: endpoint: pci-epf-vntb: Propagate MW offset from configfs when present Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 09/25] NTB: ntb_transport: Support offsetted partial memory windows Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 10/25] NTB/msi: Support offsetted partial memory window for MSI Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 11/25] NTB/msi: Do not force MW to its maximum possible size Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 12/25] NTB: ntb_transport: Stricter checks for peer-reported interrupt values Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 13/25] NTB/msi: Skip mw_set_trans() if already configured Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 14/25] NTB/msi: Add a inner loop for PCI-MSI cases Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 15/25] dmaengine: dw-edma: Add self-interrupt registration API Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 16/25] dmaengine: dw-edma: Expose self-IRQ register offsets Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 17/25] dmaengine: dw-edma: Add dw_edma_find_by_child() helper Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 18/25] NTB: core: Add .get_pci_epc() to ntb_dev_ops Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 19/25] NTB: epf: vntb: Implement .get_pci_epc() callback Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 20/25] NTB: ntb_transport: Rename use_msi to use_intr (keep alias) Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 21/25] NTB: Introduce generic interrupt backend abstraction and convert MSI Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 22/25] NTB: ntb_transport: Rename MSI symbols to generic interrupt form Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 23/25] NTB: intr_dw_edma: Add DW eDMA emulated interrupt backend Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 24/25] NTB: epf: Add MW2 for interrupt use on Renesas R-Car Koichiro Den
2025-10-23  7:19 ` [RFC PATCH 25/25] Documentation: PCI: endpoint: pci-epf-vntb: Update and add mwN_offset usage Koichiro Den
2025-10-23  7:55 ` [RFC PATCH 00/25] NTB/PCI: Add DW eDMA intr fallback and BAR MW offsets Jerome Brunet
2025-10-24 16:11   ` Koichiro Den
2025-10-24  3:27 ` Frank Li
2025-10-24 16:04   ` Koichiro Den
2025-10-24 16:43     ` Frank Li
2025-10-27  5:29       ` Koichiro Den
2025-10-28 20:50         ` Frank Li
2025-10-29  7:13           ` Koichiro Den

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aPrDEE80hSLbL57a@lizhi-Precision-Tower-5810 \
    --to=frank.li@nxp.com \
    --cc=Basavaraj.Natikar@amd.com \
    --cc=Shyam-sundar.S-k@amd.com \
    --cc=allenbh@gmail.com \
    --cc=arnd@arndb.de \
    --cc=bhelgaas@google.com \
    --cc=corbet@lwn.net \
    --cc=dave.jiang@intel.com \
    --cc=den@valinux.co.jp \
    --cc=dmaengine@vger.kernel.org \
    --cc=elfring@users.sourceforge.net \
    --cc=fancer.lancer@gmail.com \
    --cc=jbrunet@baylibre.com \
    --cc=jdmason@kudzu.us \
    --cc=jingoohan1@gmail.com \
    --cc=kishon@kernel.org \
    --cc=kurt.schwemmer@microsemi.com \
    --cc=kwilczynski@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=logang@deltatee.com \
    --cc=lpieralisi@kernel.org \
    --cc=mani@kernel.org \
    --cc=ntb@lists.linux.dev \
    --cc=pstanner@redhat.com \
    --cc=robh@kernel.org \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®