From nobody Sat Sep 26 20:51:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=baidu.com ARC-Seal: i=1; a=rsa-sha256; t=1789713394; cv=none; d=zohomail.com; s=zohoarc; b=L4dss/hwaSpQgRBQio3S8ihstYCuuPtWVb38W/oz02k2s4RZvwqfoV9WB+YXEhI8JXkK4avxKhFq2UFBxetwqcwi4RQWotQOYDVzzp/VKMdacoa++VlvPBbS/nbCSbqh31EXoddQdOkxueXqLQrlgi0KHDR4Yn7tb+K1Ld2gOY4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789713394; h=Content-Type:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=d5FC4Yg0oTjZ0sBoNRxonYn9axtEGnVf6xF5hHBqw/I=; b=hRRnsIwPw8x8mGoa3EDEuqhaJOH3h2a7N1LDK0gE+bCFMXOdo0nIunRmjCZcSIcQ9zEiAcWBkqZCH2vSPNBASMoTPLVnjAWiIHiWPI0L0ae9jPKoNPwhZ3oNrVjsfMSlEMWZycEFz7myN4wbfUxRS0v39Cfx2PpaI5/giFXIRRo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789713390571638.2903559081886; Thu, 17 Sep 2026 23:36:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7SCn-0003Sl-2i; Fri, 18 Sep 2026 02:36:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7SCN-0003Rf-Pe for qemu-devel@nongnu.org; Fri, 18 Sep 2026 02:35:52 -0400 Received: from mx15.baidu.com ([111.202.115.100] helo=outbound.baidu.com) by eggs.gnu.org with smtp (Exim 4.90_1) (envelope-from ) id 1x7SCG-0000gE-Q1 for qemu-devel@nongnu.org; Fri, 18 Sep 2026 02:35:51 -0400 X-MD-Sfrom: lirongqing@baidu.com X-MD-SrcIP: 172.31.50.47 From: lirongqing To: "Michael S . Tsirkin" , CC: Li RongQing Subject: [PATCH v2] pcie_sriov: fix wrong write width and off-by-one in pf_reset Date: Fri, 18 Sep 2026 14:35:26 +0800 Message-ID: <20260918063526.2191-1-lirongqing@baidu.com> X-Mailer: git-send-email 2.17.1 MIME-Version: 1.0 X-Originating-IP: [10.127.73.8] X-ClientProxiedBy: bjkjy-exc9.internal.baidu.com (172.31.50.19) To bjkjy-exc3.internal.baidu.com (172.31.50.47) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=baidu.com; s=selector1; t=1789713335; bh=d5FC4Yg0oTjZ0sBoNRxonYn9axtEGnVf6xF5hHBqw/I=; h=From:To:CC:Subject:Date:Message-ID:Content-Type; b=Cvx4KaDkyBI7PYRsvF2KjZjR7ltnpUNFE9WBtSWH4A/y4+ls9Id3SC+wmugVoGeUU 4SCArp2hjKBQoxI+IRwBn+yOCUCduU969lnWRRug7UH/J9ouhU4gv3/LOynuEavJA+ AWadc9LHluQXua3+KwM41AOZsxnJcS6ndwUfC8ZgM+sPS5hRKyOzPTMbY2NHXfliGI a3lYv6ACHbVCWGpH5eVGl4Tpl2kTZyJDeIP2EZGHF6Lc4nJ5DRh27TNqn7faY2tSGm tLEY1TwmSrNVv+0Nff9175wzAg+9EGcwNYKgiEH5Vq/1P0JDOkqDZ12hO+tsc3mlRo k2dgrWI2VUt+Q== Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=111.202.115.100; envelope-from=prvs=md1715FC36BB=lirongqing@baidu.com; helo=outbound.baidu.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @baidu.com) X-ZM-MESSAGEID: 1789713398462158500 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Li RongQing pcie_sriov_pf_reset() restores the VF BAR type registers using pci_set_quad() with a 4-byte stride. Since each VF BAR register is 4 bytes wide, the 8-byte write also covers the following BAR register. Although subsequent iterations overwrite most of the unintended writes, the access is incorrect and the final iteration can write beyond the VF BAR registers. SR-IOV defines six VF BAR registers and does not provide a VF ROM BAR. However, several SR-IOV code paths use PCI_NUM_REGIONS, which includes the ROM slot and therefore has a value of seven. In particular, the final iteration in pcie_sriov_pf_reset() currently writes a quadword at the offset of the seventh region. This starts at the byte immediately following the six VF BAR registers and can overwrite subsequent fields in the SR-IOV capability. Use pci_set_long() to match the 4-byte VF BAR register width, and use PCI_SRIOV_NUM_BARS when iterating over SR-IOV VF BARs. This also makes the BAR count consistent with the assertion in pcie_sriov_pf_init_vf_bar(). Fixes: 19e55471d4e8a4 ("pcie_sriov: Allow user to create SR-IOV device") Fixes: c8bc4db403e176 ("pcie_sriov: Reset SR-IOV extended capability") Signed-off-by: Li RongQing --- Diff with v1: fix the Fixes tag, it should be 19e55471d4e8a4 hw/pci/pcie_sriov.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/hw/pci/pcie_sriov.c b/hw/pci/pcie_sriov.c index c41ac95..6122a26 100644 --- a/hw/pci/pcie_sriov.c +++ b/hw/pci/pcie_sriov.c @@ -229,7 +229,7 @@ void pcie_sriov_pf_init_vf_bar(PCIDevice *dev, int regi= on_num, =20 assert(sriov_cap > 0); assert(region_num >=3D 0); - assert(region_num < PCI_NUM_REGIONS); + assert(region_num < PCI_SRIOV_NUM_BARS); assert(region_num !=3D PCI_ROM_SLOT); =20 wmask =3D ~(size - 1); @@ -308,7 +308,7 @@ int16_t pcie_sriov_pf_init_from_user_created_vfs(PCIDev= ice *dev, return -1; } =20 - for (size_t j =3D 0; j < PCI_NUM_REGIONS; j++) { + for (size_t j =3D 0; j < PCI_SRIOV_NUM_BARS; j++) { if (vfs[i]->io_regions[j].size !=3D vfs[0]->io_regions[j].size= || vfs[i]->io_regions[j].type !=3D vfs[0]->io_regions[j].type= ) { error_setg(errp, "inconsistent SR-IOV BARs"); @@ -344,7 +344,7 @@ int16_t pcie_sriov_pf_init_from_user_created_vfs(PCIDev= ice *dev, dev->exp.sriov_pf.vf =3D vfs; dev->exp.sriov_pf.vf_user_created =3D true; =20 - for (i =3D 0; i < PCI_NUM_REGIONS; i++) { + for (i =3D 0; i < PCI_SRIOV_NUM_BARS; i++) { PCIIORegion *region =3D &vfs[0]->io_regions[i]; =20 if (region->size) { @@ -463,8 +463,8 @@ void pcie_sriov_pf_reset(PCIDevice *dev) */ pci_set_word(dev->config + sriov_cap + PCI_SRIOV_SYS_PGSIZE, 0x1); =20 - for (uint16_t i =3D 0; i < PCI_NUM_REGIONS; i++) { - pci_set_quad(dev->config + sriov_cap + PCI_SRIOV_BAR + i * 4, + for (uint16_t i =3D 0; i < PCI_SRIOV_NUM_BARS; i++) { + pci_set_long(dev->config + sriov_cap + PCI_SRIOV_BAR + i * 4, dev->exp.sriov_pf.vf_bar_type[i]); } } --=20 2.9.4