From nobody Fri Oct 2 07:46:57 2026 Received: from mail-pl1-f169.google.com (mail-pl1-f169.google.com [209.85.214.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BC34D3F9264 for ; Tue, 4 Aug 2026 02:25:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785810316; cv=none; b=qtV/tirPa1yBfyXY/fenoxrG9HMV2Vgz40dUXrtXKTPHvKehKV3S6eWa1LpQ8ZIgnuRm3x2Ip7oVuLYUL6ANjfkirabmcgHh2D8D0C4cM/HLzkZl1awhFT6HHF3CcppMtKjMYHDL/tYhi4csv/2jDcEUIEHoMu29/ycV43jxX40= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785810316; c=relaxed/simple; bh=0ajQB+hPab2vIWSNK6YjKmU3k2ZE+ruh1odyGqqOzg8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=fUnO8pKcYsSOzzkIwCFhdvR02pGepG72yq1XHUslfw0MB4ocElHxJhLF3cSorPX3rBoaEyQWwdsEvzrFLsKqZKkNcrgWyJLDCBEuo7fcg25drVPPyVC9LFUz18faflVkCoHRrCBYEd55qlm/MLVH/Dfm9bMmUxqPWj/dkPpGMzU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=OVV4PXhL; arc=none smtp.client-ip=209.85.214.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OVV4PXhL" Received: by mail-pl1-f169.google.com with SMTP id d9443c01a7336-2cf27856f9cso40617195ad.2 for ; Mon, 03 Aug 2026 19:25:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785810310; x=1786415110; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=1OaiGLLoxTsUad13rL5qrpAU9a1lh1UZkttvZnhnlXg=; b=OVV4PXhLzZLP8OQoWeJOJafRZj1Q1/uqjr+H4cemRtroqQK1zzAhvSPJEgaMAm/Hn5 e9pJzZdVt9YDYQojIAtzvRwQEotV0xX2lPqOFdknjKuJHsYgOL+Qtpo3tlSx2i2MGqTM hzqp/H8Qaw7iPkEnL9+3OdU5CwOstGRRcE+HAESnBFoJOzH5yArhIFA6XkAnoQSAVu94 Mgv3sWDXCCVoXSoS935qKLyiCdINFAev03baH6hPwdPoMj0n9UmtCoCLfLalyqgJORkD WBpNFsXwS+xhupjFnO1GU826p2lWhZn+bUskAm3vzyAry3zcE6qupz0+07iAqmNdKLX6 D3mA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785810310; x=1786415110; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1OaiGLLoxTsUad13rL5qrpAU9a1lh1UZkttvZnhnlXg=; b=RjJoyzSdodbbAJ1A5oGcAtmJIGUotgMpO++tPiOIsw12cSUuG7qiBt9GUEe0ygEgYk C0Qc0YmqgMxq+BKp4AoME43ycdR9lc4sGpb/tB3kY/2qXv8QZsw1y9yxu5U1uUsbvg+V Hj3WE+msq4pddyv0Vr2IASWrUzGwvpA0CKkVSassCgfUDHNimja93F6QwKaYdRz+meK8 1isL0xTendlF89sJHO92SAlyaA8HhUwUQn+1W/avW+qXRjb+qFCEuCZNSkOneo8hAVcf qiiRKbCfG3fHtvyrnc9jfZkD6/Sq8cVb56AtsYp5/EIK6pSTvY5ij0y5FCTs+riMrutZ 0eBQ== X-Forwarded-Encrypted: i=1; AHgh+Rob7rKhtm65gXsV2VHjvR/hbF6QWuFqq4FoHuVZCMjoavxvYlGVg8gwyrLwaxK/xzFbRrnrKLAER2BZYR0=@vger.kernel.org X-Gm-Message-State: AOJu0Yyz0GLGq1pLenjofM1Nv97Bsn2qWQuAb3L0LsHMUqbuX8SfXhFR bCjgFhvqsG7dT5Su4fD/mT/L3HSDMdS3BOPfh6pKhROg3z3Nv745tJN/ X-Gm-Gg: AR+sD11AbdS+L1lDP7x7umGzHNUtHOvM8bCmze8Cz07L/7SZzKINTyNIypBQ3BR+wJi B955iBTyXJNNryj1rOTBnR3fIetmb5TO+SZ2RaRo4mUPvHW3ls+gWZPFUUb7gRtyBuvl42YE3ZZ Y5N6V08DY9FMpnuB5xyfQ+HGCg+w4m1Tm0zKq40wgHBOwdfd2oRpfRpv2nNJBX2jBAlbamMP0O/ KUa2vap4kkli5i3plny4Jsu0AUEUhVOrg6Y5+0tZlHSGw0F0vJ8ABcGeH80YoGXh3D+Rjp05CvP tXzRq8rJ4+uJbhPPCfxqlxtVdpNxFxfFuzOZidRnIaPVobFAnWvTOW5kEwY42HHnON+b5Pr9n7Z Vk/uggwn5bi0coswyt/fMbp7hkaCp1zXHop9rx16+ySr2EhpmiC+tk7PJ8AyoNKuxJJ3bp+D1fA ZYiUTVB+fxOCqPc+1UewhI1U4Z5DjGUKSVtUaRTB7BUjY4d/BBaSZ85chDgXh+HBfwl504E3FU X-Received: by 2002:a17:902:ea05:b0:2c9:d55d:2d3 with SMTP id d9443c01a7336-2d052244e67mr121387165ad.15.1785810309827; Mon, 03 Aug 2026 19:25:09 -0700 (PDT) Received: from osman.mioffice.cn ([43.224.245.178]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d04b1216bdsm45230825ad.69.2026.08.03.19.25.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 19:25:08 -0700 (PDT) From: Zhan Xusheng X-Google-Original-From: Zhan Xusheng To: Ulf Hansson Cc: Jisheng Zhang , Kishon Vijay Abraham I , Sekhar Nori , Ravikumar Kattekola , Pedro Demarchi Gomes , linux-mmc@vger.kernel.org, linux-omap@vger.kernel.org, linux-kernel@vger.kernel.org, Zhan Xusheng , stable@vger.kernel.org Subject: [PATCH] mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit Date: Tue, 4 Aug 2026 10:25:00 +0800 Message-ID: <20260804022500.3768116-1-zhanxusheng@xiaomi.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" omap_hsmmc_prepare_data() converts the command busy timeout to nanoseconds with: timeout =3D req->cmd->busy_timeout * NSEC_PER_MSEC; busy_timeout is an unsigned int (milliseconds) and timeout is a u64, but NSEC_PER_MSEC is 1000000L. On 32-bit builds the multiplication is performed in 32-bit arithmetic and wraps for busy_timeout values above ~4294 ms, before the result is assigned to the u64. The driver does not set mmc->max_busy_timeout, so the core does not cap the busy timeout, and commands such as erase or SANITIZE (MMC_SANITIZE_TIMEOUT_= MS is 240000 ms) can pass a busy_timeout far larger than 4294 ms. The wrapped, much smaller ns value is then programmed via set_data_timeout(), so the data timeout is set too short and the operation can time out prematurely. Cast busy_timeout to u64 before the multiplication so the conversion is done in 64-bit arithmetic. Fixes: 8cc9a3e73de1 ("mmc: host: omap_hsmmc: use generic_cmd6_time to progr= am timeout value for CMD6") Cc: stable@vger.kernel.org Signed-off-by: Zhan Xusheng --- drivers/mmc/host/omap_hsmmc.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/mmc/host/omap_hsmmc.c b/drivers/mmc/host/omap_hsmmc.c index 58c881f2725b..3356ac5a1fa0 100644 --- a/drivers/mmc/host/omap_hsmmc.c +++ b/drivers/mmc/host/omap_hsmmc.c @@ -1357,7 +1357,7 @@ omap_hsmmc_prepare_data(struct omap_hsmmc_host *host,= struct mmc_request *req) if (req->data =3D=3D NULL) { OMAP_HSMMC_WRITE(host->base, BLK, 0); if (req->cmd->flags & MMC_RSP_BUSY) { - timeout =3D req->cmd->busy_timeout * NSEC_PER_MSEC; + timeout =3D (u64)req->cmd->busy_timeout * NSEC_PER_MSEC; =20 /* * Set an arbitrary 100ms data timeout for commands with --=20 2.43.0