[Bug 298344] bhyve: passthru_cfgwrite_default() forwards PCIR_STATUS with swapped width/data
Date: Wed, 09 Sep 2026 10:30:42 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298344
Bug ID: 298344
Summary: bhyve: passthru_cfgwrite_default() forwards
PCIR_STATUS with swapped width/data
Product: Base System
Version: CURRENT
Hardware: Any
OS: Any
Status: New
Severity: Affects Only Me
Priority: ---
Component: bhyve
Assignee: virtualization@FreeBSD.org
Reporter: paolo.invernizzi@gmail.com
In usr.sbin/bhyve/pci_passthru.c, passthru_cfgwrite_default() handles a 4-byte
guest write to PCIR_COMMAND by forwarding the upper half to the physical status
register:
passthru_write_config(&sc->psc_sel, PCIR_STATUS, val >> 16, 2);
passthru_write_config() takes (sel, reg, width, data), so this writes data 2
with width val >> 16. The intended call is:
passthru_write_config(&sc->psc_sel, PCIR_STATUS, 2, val >> 16);
Present on main (line 1545 at 0ffad4ce5655) and releng/15.1 (line 1187). Found
while working on PR 290920; no observed behavioural impact, the RW1C status
bits of the physical device are simply never cleared by the guest.
--
You are receiving this mail because:
You are the assignee for the bug.