Re: [PATCH v11 15/31] cxl/mem: Drop misaligned DCD extent groups

Anisa Su <[email protected]> Wed, 29 Jul 2026 00:59:28 -0700
Newsgroups dev.linux.lists.nvdimm,dev.linux.lists.sashiko-reviews,org.kernel.vger.linux-cxl
Message-ID <[email protected]>
On Thu, Jun 25, 2026 at 06:19:44PM +0000, [email protected] wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Medium] Un-ratelimited `dev_warn` on invalid CXL device input can lead to log flooding and Denial of Service.
I don't think that's very likely but fixed to prevent future complaints -__-

Including 2 other places in Patch 17 and 19 for consistency:

Patch 17:
        - mbox.c: cxl_check_group_seq() shared_extn_seq-density and
          cxl_check_group_partition() partition-span warnings.
Patch 19:
        - mbox.c: cross-More "tag already committed" warning.

> --
> 
> commit 2eb192d0644cd71e7046e47b82d5b1422081590e
> Author: Ira Weiny <[email protected]>
> 
> cxl/mem: Drop misaligned DCD extent groups
> 
> This commit adds an alignment check to cxl_add_pending() to ensure that
> extents in a tag group are aligned to the dax region's mapping granularity.
> Misaligned extents now cause the entire group to be dropped.
> 
> > diff --git a/drivers/cxl/core/mbox.c b/drivers/cxl/core/mbox.c
> > index 08f51b8807c06..14ba263044f08 100644
> > --- a/drivers/cxl/core/mbox.c
> > +++ b/drivers/cxl/core/mbox.c
> 
> [ ... ]
> 
> > @@ -1395,11 +1410,38 @@ static int cxl_realize_group(struct cxl_memdev_state *mds, const uuid_t *tag,
> >  	return group_cnt;
> >  }
> >  
> > +/*
> > + * Validate a tag @group before realizing it.  Returns 0 if the group may be
> > + * added, or a negative errno if it must be dropped.  Further gates layer in
> > + * here in later commits.
> > + */
> > +static int cxl_validate_group(struct cxl_memdev_state *mds, const uuid_t *tag,
> > +			      struct list_head *group)
> > +{
> > +	struct device *dev = mds->cxlds.dev;
> > +	struct cxl_extent_list_node *pos;
> > +
> > +	/* Alignment gate — drop the group if any member fails */
> > +	list_for_each_entry(pos, group, list) {
> > +		if (!cxl_extent_dcd_aligned(pos->extent)) {
> > +			dev_warn(dev,
> > +				 "Tag %pUb: dropping group, extent DPA:%#llx LEN:%#llx not %#llx-aligned\n",
> > +				 tag,
> > +				 le64_to_cpu(pos->extent->start_dpa),
> > +				 le64_to_cpu(pos->extent->length),
> > +				 (u64)PMD_SIZE);
> 
> [Severity: Medium]
> Could this un-ratelimited dev_warn() lead to log flooding?
> 
> If a malfunctioning or compromised CXL device rapidly sends DCD_ADD_CAPACITY
> events with misaligned extents, it appears this could spam the kernel log
> and cause high CPU overhead.
> 
> Should this use dev_warn_ratelimited() instead, since it is driven by
> untrusted device input?
> 
> > +			return -EINVAL;
> > +		}
> > +	}
> > +
> > +	return 0;
> > +}
> 
> -- 
> Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=15