summaryrefslogtreecommitdiff
path: root/rust
diff options
context:
space:
mode:
authorSophon Zhang <aiqubits@hotmail.com>2026-09-01 01:09:53 +0800
committerDanilo Krummrich <dakr@kernel.org>2026-09-01 18:21:01 +0200
commit8d7b3e41ffecc69388a566ecc52093d292074c2a (patch)
treeb225e141b05ce3d19707846de92d8e0da7229397 /rust
parent7b15d6cf25e6c2aea77129179b75c191b20d79a9 (diff)
downloadlinux-8d7b3e41ffecc69388a566ecc52093d292074c2a.tar.gz
linux-8d7b3e41ffecc69388a566ecc52093d292074c2a.zip
rust: pci: reject IRQ vector indices that do not fit in u32
IrqVectorRegistration::index() accepts a usize, but pci_irq_vector() takes an unsigned int. On 64-bit architectures, casting an index larger than u32::MAX wraps it before the PCI core can validate it. In particular, u32::MAX + 1 becomes zero and can resolve to the first allocated vector. Use a checked conversion and return EINVAL when the index cannot be represented by the C API. Fixes: 2fb7755b0a7e ("rust: pci: resolve IRQ in index() and embed IrqRequest in IrqVector") Signed-off-by: Sophon Zhang <aiqubits@hotmail.com> Reviewed-by: Gary Guo <gary@garyguo.net> Reviewed-by: Alexandre Courbot <acourbot@nvidia.com> Link: https://patch.msgid.link/20260901-fix-pci-irq-vector-index-truncation-v4-1-f94aa6932fd9@hotmail.com Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Diffstat (limited to 'rust')
-rw-r--r--rust/kernel/pci/irq.rs4
1 files changed, 3 insertions, 1 deletions
diff --git a/rust/kernel/pci/irq.rs b/rust/kernel/pci/irq.rs
index 6741046ec1c0..22e2cdf82a21 100644
--- a/rust/kernel/pci/irq.rs
+++ b/rust/kernel/pci/irq.rs
@@ -151,8 +151,10 @@ impl<'a> IrqVectorRegistration<'a> {
/// [`Self::len()`].
#[inline]
pub fn index(&self, index: usize) -> Result<IrqVector<'_>> {
+ let index = u32::try_from(index)?;
+
// SAFETY: `self.dev.as_raw()` is a valid pointer to a `struct pci_dev`.
- let irq = unsafe { bindings::pci_irq_vector(self.dev.as_raw(), index as u32) };
+ let irq = unsafe { bindings::pci_irq_vector(self.dev.as_raw(), index) };
if irq < 0 {
return Err(Error::from_errno(irq));
}