From: Frank Li <Frank.li@nxp.com>
To: Koichiro Den <den@valinux.co.jp>
Cc: ntb@lists.linux.dev, linux-pci@vger.kernel.org,
dmaengine@vger.kernel.org, linux-kernel@vger.kernel.org,
mani@kernel.org, kwilczynski@kernel.org, kishon@kernel.org,
bhelgaas@google.com, corbet@lwn.net, vkoul@kernel.org,
jdmason@kudzu.us, dave.jiang@intel.com, allenbh@gmail.com,
Basavaraj.Natikar@amd.com, Shyam-sundar.S-k@amd.com,
kurt.schwemmer@microsemi.com, logang@deltatee.com,
jingoohan1@gmail.com, lpieralisi@kernel.org, robh@kernel.org,
jbrunet@baylibre.com, fancer.lancer@gmail.com, arnd@arndb.de,
pstanner@redhat.com, elfring@users.sourceforge.net
Subject: Re: [RFC PATCH 01/25] PCI: endpoint: pci-epf-vntb: Use array_index_nospec() on mws_size[] access
Date: Thu, 23 Oct 2025 20:06:40 -0400 [thread overview]
Message-ID: <aPrDEE80hSLbL57a@lizhi-Precision-Tower-5810> (raw)
In-Reply-To: <20251023071916.901355-2-den@valinux.co.jp>
On Thu, Oct 23, 2025 at 04:18:52PM +0900, Koichiro Den wrote:
> Follow common kernel idioms for indices derived from configfs attributes
> and suppress Smatch warnings:
>
> epf_ntb_mw1_show() warn: potential spectre issue 'ntb->mws_size' [r]
> epf_ntb_mw1_store() warn: potential spectre issue 'ntb->mws_size' [w]
>
> No functional changes.
>
> Signed-off-by: Koichiro Den <den@valinux.co.jp>
> ---
> drivers/pci/endpoint/functions/pci-epf-vntb.c | 23 +++++++++++--------
> 1 file changed, 14 insertions(+), 9 deletions(-)
>
> diff --git a/drivers/pci/endpoint/functions/pci-epf-vntb.c b/drivers/pci/endpoint/functions/pci-epf-vntb.c
> index 83e9ab10f9c4..55307cd613c9 100644
> --- a/drivers/pci/endpoint/functions/pci-epf-vntb.c
> +++ b/drivers/pci/endpoint/functions/pci-epf-vntb.c
> @@ -876,17 +876,19 @@ static ssize_t epf_ntb_##_name##_show(struct config_item *item, \
> struct config_group *group = to_config_group(item); \
> struct epf_ntb *ntb = to_epf_ntb(group); \
> struct device *dev = &ntb->epf->dev; \
> - int win_no; \
> + int win_no, idx; \
> \
> if (sscanf(#_name, "mw%d", &win_no) != 1) \
> return -EINVAL; \
> \
> - if (win_no <= 0 || win_no > ntb->num_mws) { \
> - dev_err(dev, "Invalid num_nws: %d value\n", ntb->num_mws); \
> + idx = win_no - 1; \
> + if (idx < 0 || idx >= ntb->num_mws) { \
> + dev_err(dev, "MW%d out of range (num_mws=%d)\n", \
> + win_no, ntb->num_mws); \
> return -EINVAL; \
> } \
> - \
> - return sprintf(page, "%lld\n", ntb->mws_size[win_no - 1]); \
> + idx = array_index_nospec(idx, ntb->num_mws); \
> + return sprintf(page, "%lld\n", ntb->mws_size[idx]); \
keep original check if (win_no <= 0 || win_no > ntb->num_mws)
just
idx = array_index_nospec(win_no - 1, ntb->num_mws);
return sprintf(page, "%lld\n", ntb->mws_size[idx]);
It should be more simple.
Frank
> }
>
> #define EPF_NTB_MW_W(_name) \
> @@ -896,7 +898,7 @@ static ssize_t epf_ntb_##_name##_store(struct config_item *item, \
> struct config_group *group = to_config_group(item); \
> struct epf_ntb *ntb = to_epf_ntb(group); \
> struct device *dev = &ntb->epf->dev; \
> - int win_no; \
> + int win_no, idx; \
> u64 val; \
> int ret; \
> \
> @@ -907,12 +909,15 @@ static ssize_t epf_ntb_##_name##_store(struct config_item *item, \
> if (sscanf(#_name, "mw%d", &win_no) != 1) \
> return -EINVAL; \
> \
> - if (win_no <= 0 || win_no > ntb->num_mws) { \
> - dev_err(dev, "Invalid num_nws: %d value\n", ntb->num_mws); \
> + idx = win_no - 1; \
> + if (idx < 0 || idx >= ntb->num_mws) { \
> + dev_err(dev, "MW%d out of range (num_mws=%d)\n", \
> + win_no, ntb->num_mws); \
> return -EINVAL; \
> } \
> \
> - ntb->mws_size[win_no - 1] = val; \
> + idx = array_index_nospec(idx, ntb->num_mws); \
> + ntb->mws_size[idx] = val; \
> \
> return len; \
> }
> --
> 2.48.1
>
next prev parent reply other threads:[~2025-10-24 0:06 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-10-23 7:18 [RFC PATCH 00/25] NTB/PCI: Add DW eDMA intr fallback and BAR MW offsets Koichiro Den
2025-10-23 7:18 ` [RFC PATCH 01/25] PCI: endpoint: pci-epf-vntb: Use array_index_nospec() on mws_size[] access Koichiro Den
2025-10-24 0:06 ` Frank Li [this message]
2025-10-24 16:24 ` Koichiro Den
2025-10-24 18:40 ` Frank Li
2025-10-23 7:18 ` [RFC PATCH 02/25] PCI: endpoint: pci-epf-vntb: Add mwN_offset configfs attributes Koichiro Den
2025-10-23 7:18 ` [RFC PATCH 03/25] NTB: epf: Handle mwN_offset for inbound MW regions Koichiro Den
2025-10-23 7:18 ` [RFC PATCH 04/25] PCI: endpoint: Add inbound mapping ops to EPC core Koichiro Den
2025-10-23 7:18 ` [RFC PATCH 05/25] PCI: dwc: ep: Implement EPC inbound mapping support Koichiro Den
2025-10-23 7:18 ` [RFC PATCH 06/25] PCI: endpoint: pci-epf-vntb: Use pci_epc_map_inbound() for MW mapping Koichiro Den
2025-10-23 7:18 ` [RFC PATCH 07/25] NTB: Add offset parameter to MW translation APIs Koichiro Den
2025-10-23 7:18 ` [RFC PATCH 08/25] PCI: endpoint: pci-epf-vntb: Propagate MW offset from configfs when present Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 09/25] NTB: ntb_transport: Support offsetted partial memory windows Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 10/25] NTB/msi: Support offsetted partial memory window for MSI Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 11/25] NTB/msi: Do not force MW to its maximum possible size Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 12/25] NTB: ntb_transport: Stricter checks for peer-reported interrupt values Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 13/25] NTB/msi: Skip mw_set_trans() if already configured Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 14/25] NTB/msi: Add a inner loop for PCI-MSI cases Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 15/25] dmaengine: dw-edma: Add self-interrupt registration API Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 16/25] dmaengine: dw-edma: Expose self-IRQ register offsets Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 17/25] dmaengine: dw-edma: Add dw_edma_find_by_child() helper Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 18/25] NTB: core: Add .get_pci_epc() to ntb_dev_ops Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 19/25] NTB: epf: vntb: Implement .get_pci_epc() callback Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 20/25] NTB: ntb_transport: Rename use_msi to use_intr (keep alias) Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 21/25] NTB: Introduce generic interrupt backend abstraction and convert MSI Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 22/25] NTB: ntb_transport: Rename MSI symbols to generic interrupt form Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 23/25] NTB: intr_dw_edma: Add DW eDMA emulated interrupt backend Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 24/25] NTB: epf: Add MW2 for interrupt use on Renesas R-Car Koichiro Den
2025-10-23 7:19 ` [RFC PATCH 25/25] Documentation: PCI: endpoint: pci-epf-vntb: Update and add mwN_offset usage Koichiro Den
2025-10-23 7:55 ` [RFC PATCH 00/25] NTB/PCI: Add DW eDMA intr fallback and BAR MW offsets Jerome Brunet
2025-10-24 16:11 ` Koichiro Den
2025-10-24 3:27 ` Frank Li
2025-10-24 16:04 ` Koichiro Den
2025-10-24 16:43 ` Frank Li
2025-10-27 5:29 ` Koichiro Den
2025-10-28 20:50 ` Frank Li
2025-10-29 7:13 ` Koichiro Den
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aPrDEE80hSLbL57a@lizhi-Precision-Tower-5810 \
--to=frank.li@nxp.com \
--cc=Basavaraj.Natikar@amd.com \
--cc=Shyam-sundar.S-k@amd.com \
--cc=allenbh@gmail.com \
--cc=arnd@arndb.de \
--cc=bhelgaas@google.com \
--cc=corbet@lwn.net \
--cc=dave.jiang@intel.com \
--cc=den@valinux.co.jp \
--cc=dmaengine@vger.kernel.org \
--cc=elfring@users.sourceforge.net \
--cc=fancer.lancer@gmail.com \
--cc=jbrunet@baylibre.com \
--cc=jdmason@kudzu.us \
--cc=jingoohan1@gmail.com \
--cc=kishon@kernel.org \
--cc=kurt.schwemmer@microsemi.com \
--cc=kwilczynski@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=logang@deltatee.com \
--cc=lpieralisi@kernel.org \
--cc=mani@kernel.org \
--cc=ntb@lists.linux.dev \
--cc=pstanner@redhat.com \
--cc=robh@kernel.org \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®