[PATCH] ata: pata_ep93xx: fix incorrect return value in data_xfer

Rosen Penev posted 1 patch 5 days ago
drivers/ata/pata_ep93xx.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
[PATCH] ata: pata_ep93xx: fix incorrect return value in data_xfer
Posted by Rosen Penev 5 days ago
The while (words--) loop post-decrements words, so it underflows from
0 to UINT_MAX on exit.  The function then returns "words << 1", which
is either 0 (for odd-length transfers after words++) or 0xFFFFFFFE
(for even-length transfers).  Callers like __atapi_pio_bytes() depend
on the correct byte count to manage scatter-gather progress; a wrong
value causes ATAPI PIO transfer errors.

Fix by returning ALIGN(buflen, 2) instead of the corrupted words
counter, matching what ata_sff_data_xfer() effectively returns via
its words counter.

Assisted-by: opencode:big-pickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
 drivers/ata/pata_ep93xx.c | 8 +++-----
 1 file changed, 3 insertions(+), 5 deletions(-)

diff --git a/drivers/ata/pata_ep93xx.c b/drivers/ata/pata_ep93xx.c
index 21d7261f537e..97dda6213878 100644
--- a/drivers/ata/pata_ep93xx.c
+++ b/drivers/ata/pata_ep93xx.c
@@ -502,15 +502,13 @@ static unsigned int ep93xx_pata_data_xfer(struct ata_queued_cmd *qc,
 	if (unlikely(buflen & 0x01)) {
 		buf += buflen - 1;
 
-		if (rw == READ) {
+		if (rw == READ)
 			*buf = ep93xx_pata_read_data(drv_data, IDECTRL_ADDR_DATA);
-		} else {
+		else
 			ep93xx_pata_write_data(drv_data, *buf, IDECTRL_ADDR_DATA);
-		}
-		words++;
 	}
 
-	return words << 1;
+	return ALIGN(buflen, 2);
 }
 
 /* Note: original code is ata_devchk */
-- 
2.55.0
Re: [PATCH] ata: pata_ep93xx: fix incorrect return value in data_xfer
Posted by Damien Le Moal 1 day, 19 hours ago
On 7/20/26 11:09, Rosen Penev wrote:
> The while (words--) loop post-decrements words, so it underflows from
> 0 to UINT_MAX on exit.  The function then returns "words << 1", which
> is either 0 (for odd-length transfers after words++) or 0xFFFFFFFE
> (for even-length transfers).  Callers like __atapi_pio_bytes() depend
> on the correct byte count to manage scatter-gather progress; a wrong
> value causes ATAPI PIO transfer errors.
> 
> Fix by returning ALIGN(buflen, 2) instead of the corrupted words
> counter, matching what ata_sff_data_xfer() effectively returns via
> its words counter.
> 
> Assisted-by: opencode:big-pickle
> Signed-off-by: Rosen Penev <rosenp@gmail.com>

This does not apply cleanly. Please rebase on libata/for-7.3.

-- 
Damien Le Moal
Western Digital Research