Re: [PATCH] PCI: rcar-host: Validate IO/MEM resource count in DT ranges property

From: Bjorn Helgaas

Date: Mon Oct 05 2026 - 19:38:18 EST


On Sat, Oct 03, 2026 at 09:35:59AM +0200, Marek Vasut wrote:
> The R-Car Gen3 PCIEC controller supports up to 4 memory area mappings.
> Count the IO and MEM ranges described in DT 'ranges' property of the
> controller DT node, and in case there are more than 4, refuse to probe
> the controller driver, because such DT does not describe valid hardware
> configuration. Do the IO and MEM counting early to avoid controller
> configuration rollback in case of failure.
>
> Fixes: 5d2917d469fa ("PCI: rcar: Convert to DT resource parsing API")
> Signed-off-by: Marek Vasut <marek.vasut+renesas@xxxxxxxxxxx>
> ---
> Cc: "Krzysztof Wilczyński" <kwilczynski@xxxxxxxxxx>
> Cc: Bjorn Helgaas <bhelgaas@xxxxxxxxxx>
> Cc: Geert Uytterhoeven <geert+renesas@xxxxxxxxx>
> Cc: Lad Prabhakar <prabhakar.mahadev-lad.rj@xxxxxxxxxxxxxx>
> Cc: Lorenzo Pieralisi <lpieralisi@xxxxxxxxxx>
> Cc: Magnus Damm <magnus.damm@xxxxxxxxx>
> Cc: Manivannan Sadhasivam <mani@xxxxxxxxxx>
> Cc: Rob Herring <robh@xxxxxxxxxx>
> Cc: Yoshihiro Shimoda <yoshihiro.shimoda.uh@xxxxxxxxxxx>
> Cc: linux-kernel@xxxxxxxxxxxxxxx
> Cc: linux-pci@xxxxxxxxxxxxxxx
> Cc: linux-renesas-soc@xxxxxxxxxxxxxxx
> ---
> drivers/pci/controller/pcie-rcar-host.c | 31 +++++++++++++++++++++++++
> 1 file changed, 31 insertions(+)
>
> diff --git a/drivers/pci/controller/pcie-rcar-host.c b/drivers/pci/controller/pcie-rcar-host.c
> index cd9171eebc289..4bcc8c3051ac4 100644
> --- a/drivers/pci/controller/pcie-rcar-host.c
> +++ b/drivers/pci/controller/pcie-rcar-host.c
> @@ -341,6 +341,32 @@ static void rcar_pcie_force_speedup(struct rcar_pcie *pcie)
> (macsr & LINK_SPEED) == LINK_SPEED_5_0GTS ? "5" : "2.5");
> }
>
> +static int rcar_pcie_validate_resource_count(struct rcar_pcie_host *host)
> +{
> + struct pci_host_bridge *bridge = pci_host_bridge_from_priv(host);
> + struct rcar_pcie *pcie = &host->pcie;
> + struct resource_entry *win;
> + int i = 0;
> +
> + resource_list_for_each_entry(win, &bridge->windows) {
> + struct resource *res = win->res;
> + unsigned long type = resource_type(res);
> +
> + if (!res->flags)
> + continue;
> +
> + if (type == IORESOURCE_IO || type == IORESOURCE_MEM)
> + i++;
> +
> + if (i > RCAR_PCI_MAX_RESOURCES)
> + return dev_err_probe(pcie->dev, -ENOSPC,
> + "Too many IO/MEM entries in DT 'ranges' property, limit is %d\n",
> + RCAR_PCI_MAX_RESOURCES);
> + }
> +
> + return 0;
> +}
> +
> static void rcar_pcie_hw_enable(struct rcar_pcie_host *host)
> {
> struct rcar_pcie *pcie = &host->pcie;
> @@ -947,6 +973,11 @@ static int rcar_pcie_probe(struct platform_device *pdev)
> host = pci_host_bridge_priv(bridge);
> pcie = &host->pcie;
> pcie->dev = dev;
> +
> + err = rcar_pcie_validate_resource_count(host);
> + if (err)
> + return err;

I guess you did this here to avoid rolling back controller config, but
the code would be a lot more readable if it checked the index at the
point where it might exceed the array bound, e.g., (I think) in
rcar_pcie_set_outbound().

This is for an invalid DT, which is unlikely. What if
rcar_pcie_set_outbound() just printed a warning and ignored any excess
windows?

> platform_set_drvdata(pdev, host);
>
> for (i = 0; i < ARRAY_SIZE(rcar_pcie_supplies); i++) {
> --
> 2.53.0
>