Skip to content

[virtio] Fix MSI-X caps control register offset in legacy fallback mode - #1857

Open
dfaggioli wants to merge 1 commit into
ipxe:masterfrom
dfaggioli:msix-fix
Open

dfaggioli wants to merge 1 commit into
ipxe:masterfrom
dfaggioli:msix-fix

Conversation

@dfaggioli

Copy link
Copy Markdown

In fallback mode when checking if MSI-X is enabled to calculate the device-specific region offset, the code accesses the base of the MSI-X capability structure instead of the Message Control register and, if the Next Pointer value exceeds 0x80, the subsequent check of PCI_MSIX_CTRL_ENABLE mask incorrectly evaluates to true.

This false positive forces an erroneous 24-byte base offset, shifting subsequent configuration reads by 4 bytes. This manifests as a mangled MAC address during device probe (e.g. reading 34:56:01:00:ff:ff).

Fix the read offset to target the Message Control register.

Reported-by: Kent Konishi konishi.kento@fujitsu.com
References: https://bugzilla.suse.com/show_bug.cgi?id=1271200

In fallback mode when checking if MSI-X is enabled to calculate the
device-specific region offset, the code accesses the base of the MSI-X
capability structure instead of the Message Control register and, if
the Next Pointer value exceeds 0x80, the subsequent check of
PCI_MSIX_CTRL_ENABLE mask incorrectly evaluates to true.

This false positive forces an erroneous 24-byte base offset, shifting
subsequent configuration reads by 4 bytes. This manifests as a mangled
MAC address during device probe (e.g. reading 34:56:01:00:ff:ff).

Fix the read offset to target the Message Control register.

Reported-by: Kent Konishi <konishi.kento@fujitsu.com>
References: https://bugzilla.suse.com/show_bug.cgi?id=1271200
Signed-off-by: Dario Faggioli <dfaggioli@suse.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant