From nobody Sun Sep 20 19:53:10 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=arm.com ARC-Seal: i=1; a=rsa-sha256; t=1777441483; cv=none; d=zohomail.com; s=zohoarc; b=S/Zh/iXag63LJiocnUOFiVfzXUzJO/lZwwAP7Dfyb6QKs838qRYqOlBD9Fm4kRs5PfkC/XttpEeq12ErYt5W5a+rQtUGYW7FQRD9RFcXxuUvxt6IQE/z15TFlBetThyDW4LRQ1wxhwx3vfTk5oEyj2Gij0M5wa6YbiU9QVfEU9E= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1777441483; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tYAYoDi5hgAm4tridDmbrWH8iC+cvseYwOBogS+t33M=; b=WHoL+f0JOsKrAZoR+9A/Ak2BWNTVzIpJcRfHrcL61TgndilEkciDCriPFYa1LPlCXRK1WOv/VKV2LrpevrjCgMxmbV/9E77RvjKfaR0X6fr0PKWwNvNVtt/ANWRQclr09Dvv+GEeNqKHwD4hZ8YJBa/qX/mfg61J1SRUHykxNzc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1777441483713735.9638118830663; Tue, 28 Apr 2026 22:44:43 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1296943.1573091 (Exim 4.92) (envelope-from ) id 1wHxiW-00006i-2k; Wed, 29 Apr 2026 05:44:12 +0000 Received: by outflank-mailman (output) from mailman id 1296943.1573091; Wed, 29 Apr 2026 05:44:12 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wHxiV-00006Y-W4; Wed, 29 Apr 2026 05:44:11 +0000 Received: by outflank-mailman (input) for mailman id 1296943; Wed, 29 Apr 2026 05:44:10 +0000 Received: from mx.expurgate.net ([195.190.135.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wHxiU-0008JC-1u for xen-devel@lists.xenproject.org; Wed, 29 Apr 2026 05:44:10 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wHxiT-002HZP-Dd for xen-devel@lists.xenproject.org; Wed, 29 Apr 2026 07:44:09 +0200 Received: from [10.42.69.11] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 69f19aa3-2eae-0a2a0a5409dd-0a2a450b8fc0-16 for ; Wed, 29 Apr 2026 07:44:09 +0200 Received: from [217.140.110.172] (helo=foss.arm.com) by tlsNG-42698a.mxtls.expurgate.net with ESMTP (eXpurgate 4.56.1) (envelope-from ) id 69f19aa8-212f-0a2a450b0019-d98c6eacb3b4-1 for ; Wed, 29 Apr 2026 07:44:09 +0200 Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 8D80032E2; Tue, 28 Apr 2026 22:44:02 -0700 (PDT) Received: from C3HXLD123V.arm.com (unknown [10.57.90.163]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id A3CF93F62B; Tue, 28 Apr 2026 22:44:06 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=foss header.d=arm.com header.i="@arm.com" header.h="From:To:Cc:Subject:Date:In-Reply-To:References" DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1777441448; bh=xwgrVrb7mJ/jIKX+IuIaposJPSmY8HXotyRYbP0OwgU=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=R4gqe1tXR6ZmJbt735SB+/fEeuSChDwFV3wr4m9hqQ7XjqAE34+5l34M9aPpoFGvA 0UIyKw07aTfycMyWLMoS4reXep3eaX9oJ+VWxXhPA2CND7fijyielN8S2Yq+0wRbLQ l3y+wmL1lufVjK4ujVWuFjd6LgsFsWJQpmQ4a3OE= From: Bertrand Marquis To: xen-devel@lists.xenproject.org Cc: Volodymyr Babchuk , Jens Wiklander , Stefano Stabellini , Julien Grall , Michal Orzel Subject: [PATCH v2 3/6] xen/arm: ffa: Tighten notification parameter validation Date: Wed, 29 Apr 2026 07:43:24 +0200 Message-ID: <9ad2fe8d75a13494536787fc6aa98eb6eb3e67c6.1776955622.git.bertrand.marquis@arm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-42698a/1777441449-06772F3B-A0C9D0BA/0/0 X-purgate-type: clean X-purgate-size: 6031 X-ZohoMail-DKIM: pass (identity @arm.com) X-ZM-MESSAGEID: 1777441486340154100 Content-Type: text/plain; charset="utf-8" The notification handlers still validate overlapping subsets of their inputs. BIND, UNBIND, and SET each decode caller and destination IDs locally, GET still accepts a non-zero receiver vCPU ID and reserved flag bits, and SET still accepts non-zero NS-virtual flags. BIND also treats unsupported non-zero flag encodings as a supported-feature failure instead of as malformed input. Add ffa_notif_validate_params() and use it to centralize the common caller/destination and non-zero bitmap checks for BIND, UNBIND, and SET. Also reject malformed GET and SET requests locally before touching cached state or forwarding anything to the SPMC. Keep BIND limited to global notifications and reject unsupported non-zero flag encodings with INVALID_PARAMETERS. - add a shared parameter validator for notification caller/destination checks - wire BIND and UNBIND through the shared helper and reject unsupported bind flag encodings with INVALID_PARAMETERS - reject non-zero receiver vCPU and reserved flag bits in FFA_NOTIFICATION_GET - reject non-zero flags in the NS-virtual FFA_NOTIFICATION_SET path Functional impact: malformed notification requests are rejected consistently earlier in the mediator. Signed-off-by: Bertrand Marquis Reviewed-by: Jens Wiklander --- Changes since v1: - rename helper to ffa_notif_validate_params() - add R-b from Jens --- xen/arch/arm/tee/ffa_notif.c | 61 +++++++++++++++++++++++++++++------- 1 file changed, 50 insertions(+), 11 deletions(-) diff --git a/xen/arch/arm/tee/ffa_notif.c b/xen/arch/arm/tee/ffa_notif.c index a631481e3815..1260f98a77e9 100644 --- a/xen/arch/arm/tee/ffa_notif.c +++ b/xen/arch/arm/tee/ffa_notif.c @@ -44,21 +44,40 @@ static bool inject_notif_pending(struct domain *d) return false; } =20 +static int32_t ffa_notif_validate_params(uint16_t dom_id, uint16_t caller_= id, + uint16_t dest_id, uint32_t bitmap= _lo, + uint32_t bitmap_hi) +{ + if ( caller_id !=3D dom_id || dest_id =3D=3D dom_id || !dest_id ) + return FFA_RET_INVALID_PARAMETERS; + + if ( !bitmap_lo && !bitmap_hi ) + return FFA_RET_INVALID_PARAMETERS; + + return FFA_RET_OK; +} + int32_t ffa_handle_notification_bind(struct cpu_user_regs *regs) { struct domain *d =3D current->domain; + struct ffa_ctx *ctx =3D d->arch.tee; + int32_t ret; uint32_t src_dst =3D get_user_reg(regs, 1); uint32_t flags =3D get_user_reg(regs, 2); uint32_t bitmap_lo =3D get_user_reg(regs, 3); uint32_t bitmap_hi =3D get_user_reg(regs, 4); + uint16_t caller_id =3D src_dst & GENMASK(15, 0); + uint16_t dest_id =3D src_dst >> 16; =20 - if ( (src_dst & GENMASK(15, 0)) !=3D ffa_get_vm_id(d) ) + if ( flags ) /* Only global notifications are supported */ return FFA_RET_INVALID_PARAMETERS; =20 - if ( flags ) /* Only global notifications are supported */ - return FFA_RET_DENIED; + ret =3D ffa_notif_validate_params(ctx->ffa_id, caller_id, dest_id, + bitmap_lo, bitmap_hi); + if ( ret ) + return ret; =20 - if ( FFA_ID_IS_SECURE(src_dst >> 16) && fw_notif_enabled ) + if ( FFA_ID_IS_SECURE(dest_id) && fw_notif_enabled ) return ffa_simple_call(FFA_NOTIFICATION_BIND, src_dst, flags, bitmap_lo, bitmap_hi); =20 @@ -68,16 +87,22 @@ int32_t ffa_handle_notification_bind(struct cpu_user_re= gs *regs) int32_t ffa_handle_notification_unbind(struct cpu_user_regs *regs) { struct domain *d =3D current->domain; + struct ffa_ctx *ctx =3D d->arch.tee; + int32_t ret; uint32_t src_dst =3D get_user_reg(regs, 1); uint32_t bitmap_lo =3D get_user_reg(regs, 3); uint32_t bitmap_hi =3D get_user_reg(regs, 4); + uint16_t caller_id =3D src_dst & GENMASK(15, 0); + uint16_t dest_id =3D src_dst >> 16; =20 - if ( (src_dst & GENMASK(15, 0)) !=3D ffa_get_vm_id(d) ) - return FFA_RET_INVALID_PARAMETERS; + ret =3D ffa_notif_validate_params(ctx->ffa_id, caller_id, dest_id, + bitmap_lo, bitmap_hi); + if ( ret ) + return ret; =20 - if ( FFA_ID_IS_SECURE(src_dst >> 16) && fw_notif_enabled ) - return ffa_simple_call(FFA_NOTIFICATION_UNBIND, src_dst, 0, bitma= p_lo, - bitmap_hi); + if ( FFA_ID_IS_SECURE(dest_id) && fw_notif_enabled ) + return ffa_simple_call(FFA_NOTIFICATION_UNBIND, src_dst, 0, bitmap= _lo, + bitmap_hi); =20 return FFA_RET_NOT_SUPPORTED; } @@ -144,6 +169,12 @@ void ffa_handle_notification_get(struct cpu_user_regs = *regs) return; } =20 + if ( recv >> 16 || (flags & GENMASK(31, 4)) ) + { + ffa_set_regs_error(regs, FFA_RET_INVALID_PARAMETERS); + return; + } + if ( fw_notif_enabled && (flags & ( FFA_NOTIF_FLAG_BITMAP_SP | FFA_NOTIF_FLAG_BITMAP_SPM )) ) { @@ -208,11 +239,19 @@ int32_t ffa_handle_notification_set(struct cpu_user_r= egs *regs) uint32_t flags =3D get_user_reg(regs, 2); uint32_t bitmap_lo =3D get_user_reg(regs, 3); uint32_t bitmap_hi =3D get_user_reg(regs, 4); + uint16_t caller_id =3D src_dst >> 16; + uint16_t dest_id =3D src_dst & GENMASK(15, 0); + int32_t ret; + + ret =3D ffa_notif_validate_params(ffa_get_vm_id(d), caller_id, dest_id, + bitmap_lo, bitmap_hi); + if ( ret ) + return ret; =20 - if ( (src_dst >> 16) !=3D ffa_get_vm_id(d) ) + if ( flags ) return FFA_RET_INVALID_PARAMETERS; =20 - if ( FFA_ID_IS_SECURE(src_dst & GENMASK(15, 0)) && fw_notif_enabled ) + if ( FFA_ID_IS_SECURE(dest_id) && fw_notif_enabled ) return ffa_simple_call(FFA_NOTIFICATION_SET, src_dst, flags, bitma= p_lo, bitmap_hi); =20 --=20 2.53.0