Re: [PATCH] cxl/mbox: Break poison list loop on an empty payload
Dave Jiang <[email protected]>
| Newsgroups | org.kernel.vger.linux-cxl |
|---|---|
| Message-ID | <[email protected]> |
On 7/9/26 8:57 AM, Dave Jiang wrote: > A device that returns count == 0 with CXL_POISON_FLAG_MORE set on every > iteration never advances nr_records, so the max_errors guard never > trips and the do/while loops forever while holding poison.mutex. That > hangs the sysfs-triggered scan thread and blocks all subsequent poison > operations on the device. The existing "Protect against an uncleared > _FLAG_MORE" guard was intended to bound a misbehaving device but does > not cover the count == 0 case. > > Stop the loop on an empty payload so a malfunctioning or malicious > device cannot wedge the poison scan. > > Link: https://sashiko.dev/#/patchset/[email protected]?part=3 > Fixes: ed83f7ca398b ("cxl/mbox: Add GET_POISON_LIST mailbox command") > Assisted-by: Claude:claude-opus-4-8 > Signed-off-by: Dave Jiang <[email protected]> Applied to cxl/next 8b301c4afbce > --- > drivers/cxl/core/mbox.c | 5 +++++ > 1 file changed, 5 insertions(+) > > diff --git a/drivers/cxl/core/mbox.c b/drivers/cxl/core/mbox.c > index 7c6c5b7450a5..c09fae2cae9f 100644 > --- a/drivers/cxl/core/mbox.c > +++ b/drivers/cxl/core/mbox.c > @@ -1455,6 +1455,11 @@ int cxl_mem_get_poison(struct cxl_memdev *cxlmd, u64 offset, u64 len, > if (rc) > break; > > + if (!le16_to_cpu(po->count)) { > + dev_dbg(&cxlmd->dev, "Poison empty payload!\n"); > + break; > + } > + > for (int i = 0; i < le16_to_cpu(po->count); i++) > trace_cxl_poison(cxlmd, cxlr, &po->record[i], > po->flags, po->overflow_ts, > > base-commit: 8cdeaa50eae8dad34885515f62559ee83e7e8dda