drivers/ata/pata_ep93xx.c | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-)
The while (words--) loop post-decrements words, so it underflows from
0 to UINT_MAX on exit. The function then returns "words << 1", which
is either 0 (for odd-length transfers after words++) or 0xFFFFFFFE
(for even-length transfers). Callers like __atapi_pio_bytes() depend
on the correct byte count to manage scatter-gather progress; a wrong
value causes ATAPI PIO transfer errors.
Fix by returning ALIGN(buflen, 2) instead of the corrupted words
counter, matching what ata_sff_data_xfer() effectively returns via
its words counter.
Assisted-by: opencode:big-pickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
drivers/ata/pata_ep93xx.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/ata/pata_ep93xx.c b/drivers/ata/pata_ep93xx.c
index 21d7261f537e..97dda6213878 100644
--- a/drivers/ata/pata_ep93xx.c
+++ b/drivers/ata/pata_ep93xx.c
@@ -502,15 +502,13 @@ static unsigned int ep93xx_pata_data_xfer(struct ata_queued_cmd *qc,
if (unlikely(buflen & 0x01)) {
buf += buflen - 1;
- if (rw == READ) {
+ if (rw == READ)
*buf = ep93xx_pata_read_data(drv_data, IDECTRL_ADDR_DATA);
- } else {
+ else
ep93xx_pata_write_data(drv_data, *buf, IDECTRL_ADDR_DATA);
- }
- words++;
}
- return words << 1;
+ return ALIGN(buflen, 2);
}
/* Note: original code is ata_devchk */
--
2.55.0
On 7/20/26 11:09, Rosen Penev wrote: > The while (words--) loop post-decrements words, so it underflows from > 0 to UINT_MAX on exit. The function then returns "words << 1", which > is either 0 (for odd-length transfers after words++) or 0xFFFFFFFE > (for even-length transfers). Callers like __atapi_pio_bytes() depend > on the correct byte count to manage scatter-gather progress; a wrong > value causes ATAPI PIO transfer errors. > > Fix by returning ALIGN(buflen, 2) instead of the corrupted words > counter, matching what ata_sff_data_xfer() effectively returns via > its words counter. > > Assisted-by: opencode:big-pickle > Signed-off-by: Rosen Penev <rosenp@gmail.com> This does not apply cleanly. Please rebase on libata/for-7.3. -- Damien Le Moal Western Digital Research
© 2016 - 2026 Red Hat, Inc.