[Bug 298344] bhyve: passthru_cfgwrite_default() forwards PCIR_STATUS with swapped width/data

From: <bugzilla-noreply_at_freebsd.org>
Date: Wed, 09 Sep 2026 10:30:42 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298344

            Bug ID: 298344
           Summary: bhyve: passthru_cfgwrite_default() forwards
                    PCIR_STATUS with swapped width/data
           Product: Base System
           Version: CURRENT
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: bhyve
          Assignee: virtualization@FreeBSD.org
          Reporter: paolo.invernizzi@gmail.com

In usr.sbin/bhyve/pci_passthru.c, passthru_cfgwrite_default() handles a 4-byte
guest write to PCIR_COMMAND by forwarding the upper half to the physical status
register:

    passthru_write_config(&sc->psc_sel, PCIR_STATUS, val >> 16, 2);

passthru_write_config() takes (sel, reg, width, data), so this writes data 2
with width val >> 16. The intended call is:

    passthru_write_config(&sc->psc_sel, PCIR_STATUS, 2, val >> 16);

Present on main (line 1545 at 0ffad4ce5655) and releng/15.1 (line 1187). Found
while working on PR 290920; no observed behavioural impact, the RW1C status
bits of the physical device are simply never cleared by the guest.

-- 
You are receiving this mail because:
You are the assignee for the bug.