[PATCH] platform: generic/andes: fix 32-bit shift overflow in decode_pmaaddrx()

Benoît Monin benoit.monin at bootlin.com
Fri Jul 31 01:47:27 PDT 2026


On Wednesday, 29 July 2026 at 11:23:17 CEST, Randolph wrote:
> decode_pmaaddrx() reconstructs the NAPOT region start and size from a
> pmaaddr CSR value using "1 << (k + 3)" and "1 << k". The integer
> literal 1 has type int, so these shifts are performed in 32-bit
> precision. Shifting a 32-bit value by 32 or more bits is undefined
> behavior, and on RV64 the compiler emits sllw, which truncates the
> shift amount modulo 32.
> 
> As a result, any PMA region with size >= 4 GiB (k >= 29) is decoded
> incorrectly. For example, on the Andes QiLai SoC the PCIe region
> 0x1000000000 - 0x17ffffffff (pmaaddr = 0x4ffffffff, k = 32) is decoded
> as an 8-byte region at 0x13fffffffc.
> 
> This is not merely cosmetic: decode_pmaaddrx() is used by
> has_pma_region_overlap() and andes_sbi_free_pma(), so overlap checks
> are performed against bogus ranges and freeing such an entry by its
> physical address always fails.
> 
> Promote the shifts to unsigned long so they are performed in the
> native register width.
> 
Works fine on Metanoia MT2824 SoC.

Tested-by: Benoît Monin <benoit.monin at bootlin.com>

Best regards,
-- 
Benoît






More information about the opensbi mailing list