[PATCH v2] PCI/TPH: fold reserved completer encoding in get_rp_completer_type()
From: Zhiping Zhang
Date: Wed Jul 15 2026 - 16:24:36 EST
get_rp_completer_type() returns the Root Port's "TPH Completer
Supported" field (bits 13:12 of Device Capabilities 2) verbatim. The
0b10 encoding is reserved, but pcie_enable_tph() feeds the raw value
into the requester type:
pdev->tph_req_type = min(pdev->tph_req_type, rp_req_type);
and later writes tph_req_type to the TPH Requester Enable field, which
only defines 0b00 (disable), 0b01 (TPH only) and 0b11 (extended TPH).
If a Root Port ever presents the reserved 0b10, that value could be
written back to hardware, risking undefined behavior.
Fold the reserved encoding into "not supported" so only the three
defined values can propagate.
Fixes: f69767a1ada3 ("PCI: Add TLP Processing Hints (TPH) support")
Signed-off-by: Zhiping Zhang <zhipingz@xxxxxxxx>
---
drivers/pci/tph.c | 18 +++++++++++++++++-
1 file changed, 17 insertions(+), 1 deletion(-)
diff --git a/drivers/pci/tph.c b/drivers/pci/tph.c
index 655ffd60e62f..ebe1aa5ba5eb 100644
--- a/drivers/pci/tph.c
+++ b/drivers/pci/tph.c
@@ -196,6 +196,21 @@ u16 pcie_tph_get_st_table_size(struct pci_dev *pdev)
}
EXPORT_SYMBOL(pcie_tph_get_st_table_size);
+/*
+ * Fold the reserved 0b10 "TPH Completer Supported" encoding into
+ * "not supported" so only the three defined values propagate.
+ */
+static u8 tph_completer_type_fold(u8 comp)
+{
+ switch (comp) {
+ case PCI_EXP_DEVCAP2_TPH_COMP_TPH_ONLY:
+ case PCI_EXP_DEVCAP2_TPH_COMP_EXT_TPH:
+ return comp;
+ default:
+ return PCI_EXP_DEVCAP2_TPH_COMP_NONE;
+ }
+}
+
/* Return device's Root Port completer capability */
static u8 get_rp_completer_type(struct pci_dev *pdev)
{
@@ -211,7 +226,8 @@ static u8 get_rp_completer_type(struct pci_dev *pdev)
if (ret)
return 0;
- return FIELD_GET(PCI_EXP_DEVCAP2_TPH_COMP_MASK, reg);
+ return tph_completer_type_fold(FIELD_GET(PCI_EXP_DEVCAP2_TPH_COMP_MASK,
+ reg));
}
/* Write tag to ST table - Return 0 if OK, otherwise -errno */
--
2.53.0-Meta