From nobody Thu Sep 24 20:24:21 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1788447954; cv=none; d=zohomail.com; s=zohoarc; b=e+khA4sFmj2XgfsPjSOukkWyyLSQYVQVNq4clyDDtjKk2KggXC0dSOVG6voZ44iqIQ7za2OweN5HQCHl3v680e+QNCYVekPagIQKLE2EFVYGjhPNq9uzkTzJGT7NDqiSe6RYpahGVcP44RrTBjTDPxV3yCOVZSTuA+lEKIbjf/g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788447954; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mANjaLxbTBRxPJI3nJCkis86IS9gaBZ1y1v/6VoNZTY=; b=O0j+/op7PPeAGJYadzrV1gx5BRFCTBiMZpnpcIAyb9f0hAIYL0ngqxL/UdP1q8VN/iNOID38IF/9dorLWTgL+EgdQzKxzYr7W0g4xdcl+aWZg3owGZt61ldpeWz8aDVIIZ7XIKalc04PGGsMIv6Atrbsz9BOKFxcHi6bshe2N0Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1788447954544755.2386706001989; Thu, 3 Sep 2026 08:05:54 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1407442.1640533 (Exim 4.92) (envelope-from ) id 1x290O-0007ic-L1; Thu, 03 Sep 2026 15:05:32 +0000 Received: by outflank-mailman (output) from mailman id 1407442.1640533; Thu, 03 Sep 2026 15:05:32 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x290O-0007iV-IT; Thu, 03 Sep 2026 15:05:32 +0000 Received: by outflank-mailman (input) for mailman id 1407442; Thu, 03 Sep 2026 15:05:31 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) id 1x290N-0007iH-SO for xen-devel@lists.xenproject.org; Thu, 03 Sep 2026 15:05:31 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x290M-00FSzv-NS for xen-devel@lists.xenproject.org; Thu, 03 Sep 2026 17:05:30 +0200 Received: from [10.42.69.8] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a998cb6-e002-0a2a0a5209dd-0a2a4508b616-12 for ; Thu, 03 Sep 2026 17:05:30 +0200 Received: from [209.85.128.52] (helo=mail-wm1-f52.google.com) by tlsNG-c1860d.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a998cba-f659-0a2a45080019-d1558034d047-3 for ; Thu, 03 Sep 2026 17:05:30 +0200 Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49b392ccaacso37083575e9.2 for ; Thu, 03 Sep 2026 08:05:30 -0700 (PDT) Received: from fedora (user-109-243-144-234.play-internet.pl. [109.243.144.234]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cee5f912esm78154695e9.4.2026.09.03.08.05.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2026 08:05:28 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=20251104 header.d=gmail.com header.i="@gmail.com" header.h="Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject:Cc:To:From" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788447930; x=1789052730; darn=lists.xenproject.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=mANjaLxbTBRxPJI3nJCkis86IS9gaBZ1y1v/6VoNZTY=; b=rOoQbHR2ao60KApSDeajnTLQ2ijCf6xgKLNMANbLZh5T2Zghc4Xi7StPbe3qdLkLVI GbPxh07BRcW86MccPAWD3ravBcAPMjLBvGtkQJmzGioQGyGtPycah4xlKJMEnFlvswSu X1M7A+g2dC1NCpIEL0UNTqSpqD2ZnVDuweREKwrU2tElBqSTNXlsE2D9y+MtSZ8ZImFv llt0B1N980fnrJ1x+uRgB7Ct5iAc9Nrsgv4r0HFhjaJUhWTuFQwW/05DIQYfx0TRERw3 ilQE5FWqV0kJxU78chbado5qpkOP6TOdFkDKis1EfOtftGtewicWkeY7OmGa6IV/EddJ nwPw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788447930; x=1789052730; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=mANjaLxbTBRxPJI3nJCkis86IS9gaBZ1y1v/6VoNZTY=; b=muL6pCuXJ5UVJD21D6CQ1K74NuC5GmD6+KyN5AWjhULLmpy4X4mqjjp2xdefEEI0Mo +3jePCvM1R/jAL+/NTaosoE0hCZy+lycJY2Y3zLRVv4HW2vC9/8PMPMcRHdPssPLJcav B8+WBUz1Fq6YwfMNQkYcYmnWxTDlMjH50sR/QEgjj2AOB/QumTb2lmKILJB1ZkdY9C33 Jf1+dK9TKHoDUWNe13Yv/KqaNzNyQxeEMIV47qKj3bzgA0yqnKTWUmWvC65Y/HzcYJ17 pwpyMmhFCS+cijWP/6unTI/virSyqMXwkduyByIV6SUSCcaNNt1HJ68Ex/Z0VPX+GHg4 PbLw== X-Gm-Message-State: AFuF++mNYeWw+/+O1vuI2gZEcFKlk3U+CKQ7+C4Oj1jhLgv8KqWmBrFX 8NC97isk2K0/HfMoL/7Ty3y1XZWGWe1rG73UW5ZPiHM7Gsrti01yFv+Zpg/lcQ== X-Gm-Gg: AYBFou2bKotfyXskP/Od2ANIy8S7U0mUSRxX/jOTsosrCu7dk21Dd62KYZpOg7U0GIa JGkdNazAKCJRJYZeiD1f440eQ8y6PpePKstO3YKyzarFZLktDVx/mBvErkA4BlJgBu/m+zADMYq Vm1FK0goYjH+P3a1i7o5c/stJzvLEZM1EHes0V9qSPntWJpvz9CZuQntWkf4cfuslDNOINBa1B9 pkl9vybkojjanM8tQf4oCn0tobW9OJbbDf+wIZJrhxX/1N3gmMywsl1iTKbJi2y4q37cexpGlIx 0eCwgc0kg0KWD6lEmIyQrzwJuJ7g4BTUOOOzUktslO8cGoEXmg0vNczW15aZchhxkgZw6mQTwxF v5UZvwtkO7i8lwqqIqJN8193HbMT6t0eCBwVmIj6IiXSDQcgXCsZOTKwg7LDO+cHKU/62pCRXQ8 Ru19g1tS+MG4b+UvZ9rXuucAtfnVSY4Tbqc7+D8rzGpmZ4Abzkfqp0B61nCT4xLYxy120ziwpg6 yrZmIeNM1JPedDsJdVxtas31fUNAguyJ9oFJ7jTALw= X-Received: by 2002:a05:600c:1da1:b0:499:9eb8:a1d7 with SMTP id 5b1f17b1804b1-49ce5842935mr283797955e9.9.1788447929879; Thu, 03 Sep 2026 08:05:29 -0700 (PDT) From: Oleksii Kurochko To: xen-devel@lists.xenproject.org Cc: Romain Caritey , Baptiste Le Duc , Zheng Zhang , Oleksii Kurochko , Alistair Francis , Connor Davis , Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini Subject: [PATCH v3] xen/riscv: fix out-of-range indexing of the IMSIC per-CPU MSI array Date: Thu, 3 Sep 2026 17:05:21 +0200 Message-ID: <20260903150521.29804-1-oleksii.kurochko@gmail.com> X-Mailer: git-send-email 2.55.0 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-c1860d/1788447930-D614687B-F128AF34/10/73395122804 X-purgate-type: spam X-purgate-size: 2865 X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1788447956568158500 Content-Type: text/plain; charset="utf-8" imsic_init() indexes msi[] by the Xen CPU id hartid_to_cpuid() returns, but that array is allocated with one entry per parent IRQ of the IMSIC node, and the only range check compares the index against num_possible_cpus(). Neither matches the array, and the check comes after the first access: - hartid_to_cpuid() returns NR_CPUS when the hart isn't one Xen brought up, and msi[NR_CPUS].base_addr is read before that is noticed; - an IMSIC node listing fewer parents than Xen has CPUs makes every index past nr_parent_irqs go past the end of the allocation, which the num_possible_cpus() check lets through. Size the array by nr_cpu_ids, which is what it is indexed by, and move the range check ahead of the first msi[] access. Fixes: c9bd8b322ecb ("xen/riscv: imsic_init() implementation") Signed-off-by: Oleksii Kurochko Reviewed-by: Jan Beulich --- Changes in v3: - Drop local variable nr_msis and use nr_cpu_ids explicitly. --- Changes in v2: - Use nr_cpu_ids instead of num_possible_cpus() to not be dependent on if cpu_possible_map is sparsed or not. --- --- xen/arch/riscv/imsic.c | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/xen/arch/riscv/imsic.c b/xen/arch/riscv/imsic.c index f7b70a8da09e..8da72c007225 100644 --- a/xen/arch/riscv/imsic.c +++ b/xen/arch/riscv/imsic.c @@ -346,7 +346,7 @@ int __init imsic_init(const struct dt_device_node *node) goto imsic_init_err; } =20 - msi =3D xvzalloc_array(struct imsic_msi, nr_parent_irqs); + msi =3D xvzalloc_array(struct imsic_msi, nr_cpu_ids); if ( !msi ) { rc =3D -ENOMEM; @@ -405,7 +405,18 @@ int __init imsic_init(const struct dt_device_node *nod= e) continue; } =20 + /* + * hartid_to_cpuid() returns NR_CPUS for a hart Xen doesn't know, = so + * the range has to be checked before msi[] is indexed at all. + */ cpu =3D hartid_to_cpuid(hartid); + if ( cpu >=3D nr_cpu_ids ) + { + printk(XENLOG_WARNING + "%s: unsupported hart ID=3D%#lx for parent irq%u\n", + node->name, hartid, i); + continue; + } =20 /* * If .base_addr is not 0, it indicates that the CPU has already b= een @@ -421,13 +432,6 @@ int __init imsic_init(const struct dt_device_node *nod= e) continue; } =20 - if ( cpu >=3D num_possible_cpus() ) - { - printk(XENLOG_WARNING "%s: unsupported hart ID=3D%#lx for pare= nt irq%u\n", - node->name, hartid, i); - continue; - } - /* Find MMIO location of MSI page */ reloff =3D i * IMSIC_HART_SIZE(imsic_cfg.guest_index_bits); for ( index =3D 0; index < nr_mmios; index++ ) --=20 2.55.0