Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] i2c: designware: out-of-bounds MMIO access via debugfs on non-AMD 
models
--

commit 4dc8f1b4bfdf49722d6f1e25100bf25c45d88afb
Author: Aniket Limaye <[email protected]>
Subject: i2c: designware: Support per-variant reg/bit offsets and intr handling

This commit refactors the DesignWare I2C driver to support per-variant
register offsets and interrupt handling. It converts DW_IC_* to a logical enum,
using a regmap to internally translate to physical offsets. It also moves the
interrupt-acknowledgment pattern into a common helper driven by a per-variant
table.

Link: 
https://lore.kernel.org/r/[email protected]/

> diff --git a/drivers/i2c/busses/i2c-designware-common.c 
> b/drivers/i2c/busses/i2c-designware-common.c
> index a1eca6cd4b75e..eeeb1f1892054 100644
> --- a/drivers/i2c/busses/i2c-designware-common.c
> +++ b/drivers/i2c/busses/i2c-designware-common.c
> @@ -72,11 +72,55 @@ static const char *const abort_sources[] = {
[ ... ]
>  static int dw_reg_read(void *context, unsigned int reg, unsigned int *val)
>  {
>       struct dw_i2c_dev *dev = context;
>  
> -     *val = readl(dev->base + reg);
> +     *val = readl(dev->base + dev->regs[reg]);
>  
>       return 0;
>  }
[ ... ]
> @@ -143,11 +189,11 @@ static int i2c_dw_init_regmap(struct dw_i2c_dev *dev)
>       struct regmap_config map_cfg = {
>               .reg_bits = 32,
>               .val_bits = 32,
> -             .reg_stride = 4,
> +             .reg_stride = 1,
>               .disable_locking = true,
>               .reg_read = dw_reg_read,
>               .reg_write = dw_reg_write,
> -             .max_register = DW_IC_COMP_TYPE,
> +             .max_register = DW_IC_REG_MAX - 1,
>       };
>       u32 reg;
>       int ret;
> @@ -163,12 +209,9 @@ static int i2c_dw_init_regmap(struct dw_i2c_dev *dev)
>       if (ret)
>               return ret;
>  
> -     reg = readl(dev->base + DW_IC_COMP_TYPE);
> +     reg = readl(dev->base + dev->regs[DW_IC_COMP_TYPE]);
>       i2c_dw_release_lock(dev);
>  
> -     if ((dev->flags & MODEL_MASK) == MODEL_AMD_NAVI_GPU)
> -             map_cfg.max_register = AMD_UCSI_INTR_REG;
> -

[Severity: High]
By unconditionally setting max_register to DW_IC_REG_MAX - 1, could this expose
the AMD-specific register (AMD_UCSI_INTR_REG, logical ID 40) via the regmap
debugfs interface on all models?

If a privileged user reads the regmap registers file in debugfs on a non-AMD
platform, the iteration would reach logical register 40. This translates to
physical offset 0x474 in dw_i2c_reg_offsets, which dw_reg_read() would attempt
to read via readl(dev->base + dev->regs[reg]).

Could this lead to an out-of-bounds MMIO read and potentially cause a system
crash (such as a bus fault or SError) or hardware hang, since the mapped MMIO
region on standard platforms might not extend to 0x474?

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=2

Reply via email to