From nobody Tue Jul 28 13:52:19 2026 Received: from mail-ed1-f53.google.com (mail-ed1-f53.google.com [209.85.208.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C765940926D for ; Wed, 8 Jul 2026 15:48:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783525737; cv=none; b=gIHMTKsCxAraWyNbmY4i6MbIPN8YThqyihsUz3Gf73YazdRrXHlGxOUSqXPGsf5o9Ny9olsPBBDd0gzrBVAjhd15gmBJHxQoR3O9n4BXOhiWJQYxn6xnjQ12/J0f662dvHMQnDq8Ttrz2B3AD3MWcuq5TMv1YPRQYTxz5paLoPA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783525737; c=relaxed/simple; bh=uvwChTlpVZgmp2VBtDJWKXkefk6EFCfg7e+Nt53HS8k=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CNYk1ID+ezR3gJf0jmF2Nv6dOzH5PBz6JomqT5Tvdv19mqvroa03c8Ex6KSEouolPOdWGB7nxOwP/U8MVTFhG4n2bVptPradw5b9KznWMSWZMtUze6JKlO43MXryAWnoNBxZ2BX6g3qxsCtbG+SmJ66x4K9Jd/xRyWoWeVQqCGg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=E/Kn2k8f; arc=none smtp.client-ip=209.85.208.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="E/Kn2k8f" Received: by mail-ed1-f53.google.com with SMTP id 4fb4d7f45d1cf-697de23bd7dso1157173a12.1 for ; Wed, 08 Jul 2026 08:48:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783525734; x=1784130534; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6TK4yrvOlGIeZ2P4todUYjrSWgXjYBLmh88a3Xdkwsc=; b=E/Kn2k8f7nJYKh3/4L/vTyyG9rbzu3yIF9IERPxBJBJJmBV4s2UzkJBkFItFEpC86A MiQiG20W5DGYz1cvvUEXAxr2pr+dFaC7AloXplIRSkzfOGasLR9ZSZlwkafFlV4PUBW3 XPpkhVAKXyUSZuJmiLVffL7puXgrd8ewvEsMyti6LC1YfhOQFO4fcOSUGn+w4Ma05nlF zg+RG1j9uHiTvSrXVfD6aSGXEQ6jQXUmPLuAcZe9r3iJCAnnEHCzRoThWn92B86/3VrT kuEiW0Gn1GEXZT0nGHEDMMbZgNPI/AkS1E4y0fY7x63MEgFhbvC416MKqFz0gf9Ulqa1 HciQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783525734; x=1784130534; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=6TK4yrvOlGIeZ2P4todUYjrSWgXjYBLmh88a3Xdkwsc=; b=JP6AUwMH6R1ihiLfQzOucCC3G6dtnpMUL0xepsG2hqpQ8o5JLNOaSQldyfqzGeJWIG OkH0btx+Uel9z+/uFC3PNg9QoIvZ6xsEUL+tkpB4MMx9w/ERN7j8MACxANMS1c+2Ukwu PWL9fFULI1JbYISM2P/oMjUdcAUmpBY1yierCG+ZbfAQC9ORJRpFktdE7UvlqPfRnMuN EpgTri4gDWx1mw7ZRGxHJkKJEoVMFwM6aLDueZOPv+Po5yoty4XfNXpOGqPEu/9o5iDy 5WLD/sv3xwINwv7hWxHAKfx8B/+iIO/qnNcQUfkOhnaSr2DQUHUCEvQZ6gM8EaSHVAnK BQ4A== X-Forwarded-Encrypted: i=1; AHgh+RqBtqI8RZrA5o9YPiN9naKAwm5kbM4lLeLGHgtHPHFfvymlabBKBx0mLl6sxLxZzmEDaVjn5uRYbzjbaKA=@vger.kernel.org X-Gm-Message-State: AOJu0YxBs7TCRGrnJlDfzTbpT3XdVj17Ha7es4MaZwUG8W69GUf19F0u tOuDLxElDLJLt50WKZfgfhhpzSuiTpUs6LE1SY0QrVBfxNTYmNia9esc X-Gm-Gg: AfdE7ckhwEVqK7yjNeYh7Dp3j2cr0hIhdtDKUWdLXm5KkbvL68MTXsbhS5dnmg7RlMY JuHJvDbWO0RCnja11xOhvQHVRg81pPNRn+BLDASQvUPWvaFbXzLdP53Sr2ZyjA+cXpBxqFLXBVT SYln1RNNBEGIJq513AYt0AyPRYLmG4+PrMpgTuD87l/LoTDpwspwwylKXCdniyMU5teTiDwEtT/ Zv5ZbkVSb+IXHXIT8S1//YUbB3mG/LiStWAOrE2OVknOREVjFpI/M6ErySj2x49Xk6uBXA8gBct wtVapo20UYJntvDAmxiGMZ5DflbZX2sH5dWUVX7wvGMykI/tD7aFqXsmecfYHDtBwaUr5SOqRwx +A6MnkOrknCinwnMaoAn86UJM9uYMwfcoWsoF+mePRyQ6SEJiuK81RrG+P0tO+SNGGJYyKWOga0 3kE+/f8zahwSxtAJ5ALvA6oQVW2g3mH/YPGhl/eAyxZub5FFlq19XvEdVxizQC/z8= X-Received: by 2002:a05:6402:e85:b0:687:7fa4:faa0 with SMTP id 4fb4d7f45d1cf-69ab449f3bdmr1242683a12.23.1783525733893; Wed, 08 Jul 2026 08:48:53 -0700 (PDT) Received: from node ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69ac41d7ceesm945125a12.23.2026.07.08.08.48.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 Jul 2026 08:48:53 -0700 (PDT) From: Muhammad Bilal To: hansg@kernel.org, ilpo.jarvinen@linux.intel.com, jorge.lopez2@hp.com, linux@weissschuh.net, platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org Cc: stable@vger.kernel.org, Mario Limonciello , Armin Wolf , Muhammad Bilal Subject: [PATCH v4 1/4] platform/x86: hp-bioscfg: pass validated element count to package parsers Date: Wed, 8 Jul 2026 20:48:42 +0500 Message-ID: <20260708154846.12356-2-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260708154846.12356-1-meatuni001@gmail.com> References: <20260708154846.12356-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The per-type package parsers are handed the wrong element count. hp_init_bios_package_attribute() validates obj->package.count and then calls one of the five hp_populate_*_package_data() wrappers (string, integer, enumeration, ordered list, password). Each wrapper forwards a count to its hp_populate_*_elements_from_package() parser, but instead of forwarding the validated obj->package.count it derives the count from elements[0]. elements[0] is the NAME field and is always an ACPI_TYPE_STRING, so reading ->package.count from it in fact reads ->string.length through the union acpi_object. The parsers thus bound themselves against the length of the name string rather than against the real number of elements in the package. This is safe today because hp_init_bios_package_attribute() refuses any package that has fewer than the type's element count, so a parser only ever runs on a full package and never reads past it regardless of the bogus bound. An upcoming change relaxes that check to accept shorter packages. Once a parser can receive fewer elements than its per-type count, a bound taken from the name length no longer reflects the array size, and the "elem < count" loop conditions and "elem + n >=3D count" sub-loop guards read past the end of elements[] - an out-of-bounds heap read. Forward the validated obj->package.count to every *_package_data() wrapper so the parsers bound themselves against the real package size. This does not change behaviour for the packages that enumerate correctly today and is a prerequisite for accepting shorter packages safely. Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 5 +++++ drivers/platform/x86/hp/hp-bioscfg/bioscfg.h | 5 +++++ drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c | 3 ++- drivers/platform/x86/hp/hp-bioscfg/int-attributes.c | 3 ++- drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c | 5 +++-- drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 5 +++-- drivers/platform/x86/hp/hp-bioscfg/string-attributes.c | 3 ++- 7 files changed, 22 insertions(+), 7 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.c index 27fd6cd215290..768330d291da8 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c @@ -731,26 +731,31 @@ static int hp_init_bios_package_attribute(enum hp_wmi= _data_type attr_type, switch (attr_type) { case HPWMI_STRING_TYPE: ret =3D hp_populate_string_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; case HPWMI_INTEGER_TYPE: ret =3D hp_populate_integer_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; case HPWMI_ENUMERATION_TYPE: ret =3D hp_populate_enumeration_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; case HPWMI_ORDERED_LIST_TYPE: ret =3D hp_populate_ordered_list_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; case HPWMI_PASSWORD_TYPE: ret =3D hp_populate_password_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.h index f1eec0e4ba075..416d7e7aaaae3 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h @@ -401,6 +401,7 @@ int hp_populate_string_buffer_data(u8 *buffer_ptr, u32 = *buffer_size, int hp_alloc_string_data(void); void hp_exit_string_attributes(void); int hp_populate_string_package_data(union acpi_object *str_obj, + int str_obj_count, int instance_id, struct kobject *attr_name_kobj); =20 @@ -411,6 +412,7 @@ int hp_populate_integer_buffer_data(u8 *buffer_ptr, u32= *buffer_size, int hp_alloc_integer_data(void); void hp_exit_integer_attributes(void); int hp_populate_integer_package_data(union acpi_object *integer_obj, + int integer_obj_count, int instance_id, struct kobject *attr_name_kobj); =20 @@ -421,6 +423,7 @@ int hp_populate_enumeration_buffer_data(u8 *buffer_ptr,= u32 *buffer_size, int hp_alloc_enumeration_data(void); void hp_exit_enumeration_attributes(void); int hp_populate_enumeration_package_data(union acpi_object *enum_obj, + int enum_obj_count, int instance_id, struct kobject *attr_name_kobj); =20 @@ -432,6 +435,7 @@ int hp_populate_ordered_list_buffer_data(u8 *buffer_ptr, int hp_alloc_ordered_list_data(void); void hp_exit_ordered_list_attributes(void); int hp_populate_ordered_list_package_data(union acpi_object *order_obj, + int order_obj_count, int instance_id, struct kobject *attr_name_kobj); =20 @@ -440,6 +444,7 @@ int hp_populate_password_buffer_data(u8 *buffer_ptr, u3= 2 *buffer_size, int instance_id, struct kobject *attr_name_kobj); int hp_populate_password_package_data(union acpi_object *password_obj, + int password_obj_count, int instance_id, struct kobject *attr_name_kobj); int hp_alloc_password_data(void); diff --git a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c b/drivers= /platform/x86/hp/hp-bioscfg/enum-attributes.c index af4d1920d4880..3aa2c440e0528 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c @@ -304,6 +304,7 @@ static int hp_populate_enumeration_elements_from_packag= e(union acpi_object *enum * @attr_name_kobj: The parent kernel object */ int hp_populate_enumeration_package_data(union acpi_object *enum_obj, + int enum_obj_count, int instance_id, struct kobject *attr_name_kobj) { @@ -312,7 +313,7 @@ int hp_populate_enumeration_package_data(union acpi_obj= ect *enum_obj, enum_data->attr_name_kobj =3D attr_name_kobj; =20 hp_populate_enumeration_elements_from_package(enum_obj, - enum_obj->package.count, + enum_obj_count, instance_id); hp_update_attribute_permissions(enum_data->common.is_readonly, &enumeration_current_val); diff --git a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c b/drivers/= platform/x86/hp/hp-bioscfg/int-attributes.c index d96e160953e39..107e4cf1efb8a 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c @@ -279,6 +279,7 @@ static int hp_populate_integer_elements_from_package(un= ion acpi_object *integer_ * @attr_name_kobj: The parent kernel object */ int hp_populate_integer_package_data(union acpi_object *integer_obj, + int integer_obj_count, int instance_id, struct kobject *attr_name_kobj) { @@ -286,7 +287,7 @@ int hp_populate_integer_package_data(union acpi_object = *integer_obj, =20 integer_data->attr_name_kobj =3D attr_name_kobj; hp_populate_integer_elements_from_package(integer_obj, - integer_obj->package.count, + integer_obj_count, instance_id); hp_update_attribute_permissions(integer_data->common.is_readonly, &integer_current_val); diff --git a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c b/d= rivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c index f09489a085c86..83ddf99f93954 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c @@ -301,7 +301,8 @@ static int hp_populate_ordered_list_elements_from_packa= ge(union acpi_object *ord * @instance_id: The instance to enumerate * @attr_name_kobj: The parent kernel object */ -int hp_populate_ordered_list_package_data(union acpi_object *order_obj, in= t instance_id, +int hp_populate_ordered_list_package_data(union acpi_object *order_obj, in= t order_obj_count, + int instance_id, struct kobject *attr_name_kobj) { struct ordered_list_data *ordered_list_data =3D &bioscfg_drv.ordered_list= _data[instance_id]; @@ -309,7 +310,7 @@ int hp_populate_ordered_list_package_data(union acpi_ob= ject *order_obj, int inst ordered_list_data->attr_name_kobj =3D attr_name_kobj; =20 hp_populate_ordered_list_elements_from_package(order_obj, - order_obj->package.count, + order_obj_count, instance_id); hp_update_attribute_permissions(ordered_list_data->common.is_readonly, &ordered_list_current_val); diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index 4d79eb8056a5d..89316d90454d2 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -388,7 +388,8 @@ static int hp_populate_password_elements_from_package(u= nion acpi_object *passwor * @instance_id: The instance to enumerate * @attr_name_kobj: The parent kernel object */ -int hp_populate_password_package_data(union acpi_object *password_obj, int= instance_id, +int hp_populate_password_package_data(union acpi_object *password_obj, int= password_obj_count, + int instance_id, struct kobject *attr_name_kobj) { struct password_data *password_data =3D &bioscfg_drv.password_data[instan= ce_id]; @@ -396,7 +397,7 @@ int hp_populate_password_package_data(union acpi_object= *password_obj, int insta password_data->attr_name_kobj =3D attr_name_kobj; =20 hp_populate_password_elements_from_package(password_obj, - password_obj->package.count, + password_obj_count, instance_id); =20 hp_friendly_user_name_update(password_data->common.path, diff --git a/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c b/drive= rs/platform/x86/hp/hp-bioscfg/string-attributes.c index fe5a9a3a4ef17..da5e81f1d188f 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c @@ -267,6 +267,7 @@ static int hp_populate_string_elements_from_package(uni= on acpi_object *string_ob * @attr_name_kobj: The parent kernel object */ int hp_populate_string_package_data(union acpi_object *string_obj, + int string_obj_count, int instance_id, struct kobject *attr_name_kobj) { @@ -275,7 +276,7 @@ int hp_populate_string_package_data(union acpi_object *= string_obj, string_data->attr_name_kobj =3D attr_name_kobj; =20 hp_populate_string_elements_from_package(string_obj, - string_obj->package.count, + string_obj_count, instance_id); =20 hp_update_attribute_permissions(string_data->common.is_readonly, --=20 2.55.0 From nobody Tue Jul 28 13:52:19 2026 Received: from mail-ed1-f53.google.com (mail-ed1-f53.google.com [209.85.208.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4B0AB409285 for ; Wed, 8 Jul 2026 15:48:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783525739; cv=none; b=QNdZBF1E/ri7dmO6x5hKyD7M+EQZK/ks5m8wEWbzWz8eZYQiNErc1qInsik0jtPxXfuC8wXK/PWbpTzaPo4dsMrf8GnB+OEiei5M0jZOtwfmsoG5vO/Fh8gfxJZ6mIEHgPWB/scVPOyxuXggbSudv199wGjBne+mviAkt+UmDXg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783525739; c=relaxed/simple; bh=ULNMmbxVh4tHyr9ahlwXKgzZ7AKozKUrjhwvPkGtpoM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GQU7n7TIG824RtIbqijrmwSXaUNWyYduJataP7NLzCovIr+J3L549HZ1gzPkJ9nvfiOcP1d5TnCpHN/AIJMfNxmWMLHn1S5EctIFvZMNp10JvJdqdEAfHhkyJdOePTji8d5D7mtR8Dkx1UDFuHu1MYEfmw0U/KrtzbwAvT8xHeo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=TWmalRrI; arc=none smtp.client-ip=209.85.208.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="TWmalRrI" Received: by mail-ed1-f53.google.com with SMTP id 4fb4d7f45d1cf-6989c0ec3c5so1546122a12.2 for ; Wed, 08 Jul 2026 08:48:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783525737; x=1784130537; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=B/fgggRHrJbJt1RDIuoWb+BH35AXwLqWARanhG2X30s=; b=TWmalRrIelf9bZmAGpz6gJ4mDr+L5xgwUiANUR23iZuApfN/lk+PoP7KE46LFz2lnN WdXOQ2cnLCZTKF73YdFIDsWc9WfM01ZuJhwCXSxHfHSrzEDXIYWNx56FZ0B2C32tdZTB XIfeWFD61bYfWGUjgjWiWy/qrK7s4K7Bu8kKWs7aB4gEVLJWueVzuZwYb8US0mFkvktA PszCloy1oo0NE6mXOxuKqHyPF7vZ8dcWX8oeduPByQHwUE0GFnjSSLp24RJIPfYRA7Gb eKjJ8f3eR0moxykh1L1tFW/8ttMJXkphfpkiHPnygC/lTPgDHqXSDUtrz0VcYLed+gnA vBoA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783525737; x=1784130537; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=B/fgggRHrJbJt1RDIuoWb+BH35AXwLqWARanhG2X30s=; b=Q7lSAYkTqoOBe4VXVOLqdvavCYieAxsVC/2kpAUctXYhU5ehY7pTEK9LykHIDXdJbc BlBziH18Xh4SAdvJWb8TUmUx0drAzeZyIag6xfiKiIW3Mgwn0IXGAgk1KN+6Wunw9QJo u3TDuAqdmkPkYiAeQc26bTZBdmxhM3a74iiMHDek2Hrkd59irq7SNybBymYDhBPcOYge Fk1Bl0qWvNYrZ14Or61bFDB9rm16+s/OATj3q8W5ZYWQgu54w/L/aOEsqsgkTC9oixOt 7P6/8fftQvZNo2ZbmUs2hxgCnOPCQlmCWfKT1Tzn5wx8Te3UxqJdO/PDgsGUUV5FE7qE 1xJg== X-Forwarded-Encrypted: i=1; AHgh+Rq1c6wIFMXejvOZ+pJqxVZRhTzNWCQcHM6Gcfl4wA9Mkk7qoJ4XHcqs+aQfQXaZIdMmqfvUgTilVey/8RU=@vger.kernel.org X-Gm-Message-State: AOJu0YwHhGo3Lw05Y5nL5egTcKUvzjUChD9Y2oErTev6PeFQByY1reXd vRNIss2AJiVekCcPAB24zYj7BFw3BCh/ZL/4L8mqKwhsMrxHGKHA/Neg X-Gm-Gg: AfdE7ck3I+31X8EEKx6SeOUCYaVRuvZHp64YACZWobbMJnsxHRDy2PObpDu3LqY2Sek Iwrr+6sluQWR+GfRDHmMeroMqNT7q+aNhhECMAQ8jlKOKuwCT9QJJlI4h9CPvQV8DvdZqjneHrA VjevMSYeoMP5P+k3EAzC8KWo3pivi4Xndw1TnGSWE7IJAxzVhcbFNH9kXjU5oKdBr99pFfZSYOA qKQFFAW9A4RLi6zVvFXxDh6ySHDqE8c4f4FJzC7ikYg+oA1wCPl4wyZ8d1FtixZpepwdgaHiuIo RmqcZCCgV4ZiglpgHNF/1KzyBFWPWvqss2QY3u5M7d8olyK6S3Mx1MLEdGjqFeKztIhK7SXrjQw bX+Qnub3t+F1KgiF70cw09uxeSHnH7b4wKjxFMcddDhIvGonS17AgPblyP6Xzzosr3JRNtS9FON AeqKnVUHsHahNc535Lk1n6a8OtD1pg5RDuE/ShHn4BGa5SnAeMBztqgbShYFgvht7U6xKXhC6gM w== X-Received: by 2002:a05:6402:e85:b0:69a:a4bb:bfcf with SMTP id 4fb4d7f45d1cf-69ab4471007mr1196178a12.14.1783525736512; Wed, 08 Jul 2026 08:48:56 -0700 (PDT) Received: from node ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69ac41d7ceesm945125a12.23.2026.07.08.08.48.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 Jul 2026 08:48:56 -0700 (PDT) From: Muhammad Bilal To: hansg@kernel.org, ilpo.jarvinen@linux.intel.com, jorge.lopez2@hp.com, linux@weissschuh.net, platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org Cc: stable@vger.kernel.org, Mario Limonciello , Armin Wolf , Muhammad Bilal Subject: [PATCH v4 2/4] platform/x86: hp-bioscfg: bound ordered-list parsing by the package count Date: Wed, 8 Jul 2026 20:48:43 +0500 Message-ID: <20260708154846.12356-3-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260708154846.12356-1-meatuni001@gmail.com> References: <20260708154846.12356-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_populate_ordered_list_elements_from_package() differs from the other per-type parsers: its main loop is bounded only by the fixed per-type count and never checks elem against the number of elements actually present in the package, for (elem =3D 1, eloc =3D 1; eloc < ORD_ELEM_CNT; elem++, eloc++) whereas the string, integer, enumeration and password parsers bound their main loop with "elem < count" as well. This is safe today because hp_init_bios_package_attribute() rejects any package with fewer than ORD_ELEM_CNT elements before the parser runs. An upcoming change, however, relaxes that check to accept shorter packages. Bound the loop by the validated element count as well, so it stops at whichever comes first, the per-type count or the real package size, for (elem =3D 1, eloc =3D 1; eloc < ORD_ELEM_CNT && elem < order_obj_coun= t; elem++, eloc++) order_obj_count is the validated element count, now correctly forwarded from the caller. No functional change for packages that enumerate correctly today. Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c b/d= rivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c index 83ddf99f93954..a50d074125268 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c @@ -145,7 +145,7 @@ static int hp_populate_ordered_list_elements_from_packa= ge(union acpi_object *ord if (!order_obj) return -EINVAL; =20 - for (elem =3D 1, eloc =3D 1; eloc < ORD_ELEM_CNT; elem++, eloc++) { + for (elem =3D 1, eloc =3D 1; eloc < ORD_ELEM_CNT && elem < order_obj_coun= t; elem++, eloc++) { =20 switch (order_obj[elem].type) { case ACPI_TYPE_STRING: --=20 2.55.0 From nobody Tue Jul 28 13:52:19 2026 Received: from mail-ed1-f47.google.com (mail-ed1-f47.google.com [209.85.208.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EDC8840929C for ; Wed, 8 Jul 2026 15:49:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783525742; cv=none; b=nLVsvkHZt1EdYxFbwg/3191rt2sA+Vk2HzUEvTbfxiTDwibB80fMCDs6dCTptdcKw8CKDmWjSowCv3FOG+i3ES7DK4GtJuHZytguJUgcHYvLXZM8On2kwCFaE1wGvOtCfQg1n9B3yoWZqyfTO70AdFlfId7/KrJRIDYa4LPExkQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783525742; c=relaxed/simple; bh=4NG8zneOYe7p0UrTp9P9R7HnMyKE7GyM9DN8ppk6JVo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=oo5vurQpR9V7Mq6vkQ7tk7x1AWw4n0WICoIv+5eWj2nEh7hQUJ0gWvuW4xqCBScTiqNwq6ZqfMiXDLdUJ/i5TyGrkrHB56ctSFSCv5xS99FMuk2SzBgtDw7w/KQl64XDgih48brLIEpljTuT7hvteXrXypcwVeDdS204U5vP8Xs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=RHnPqqJZ; arc=none smtp.client-ip=209.85.208.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="RHnPqqJZ" Received: by mail-ed1-f47.google.com with SMTP id 4fb4d7f45d1cf-68bd9fce347so1657539a12.2 for ; Wed, 08 Jul 2026 08:49:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783525739; x=1784130539; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UMhE6Jch/T1UvoknEZxvYaZzdpc2xBp5cw8Z7tMZGzI=; b=RHnPqqJZoenkw9rgfcxvey6riVEQ0Mw/Fe3+usArOtXO8EQotDJIZRr+uVAaOkYRhl wJFIqs6f+HphBy7JzeLwgv7l0f/VoG+R0h+w/o4gV970HENwUlEj2YA9d8klESOuNoCC JN5oc6NTu2dFkagMtChC+jiEqkhdfbxWTCYNeWFJ5CdQ3vUWoZ1H3iRz32bSngEbTuNH eh7NqLUBIvljkS8M6z5m8LLkhsfECkxz4yoT/1qnOO+gPKmdqMIYXOh8vwwof/8GwmhT hk3aW/PtrDGmn1YeCeLAQs1dUZgdcy5qhyF8h/1tCCR48c7gNSr7JyABXIpFuwfr7HyX oYcQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783525739; x=1784130539; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=UMhE6Jch/T1UvoknEZxvYaZzdpc2xBp5cw8Z7tMZGzI=; b=gRp29w9D3NYRcE635i5bohAscABqijuBgYTD3xA8ulULrf630fHVGkDVawxFyEDV/b 2R4I2WONeeeoDjVZYwfWilsoA5/zkBrNql1JJA0P7dxfddlCCSH5/af0jQ92xc614QQ0 oU6H1L7IiFZ0yrRm43lcnnit+dAL/0t+AlN8IpHzgBAIPi/bjfoI+7cdtaTT3+X+FOvc lT2BFTNksffNzne9gTlAMRTC4+2Yfge2ZPRpDQfBUECtHiVpXHe7RevaWqAytr3P5PO3 UhGADWLbfTjToz8CBTmu/K5vUaA3hAtwJdQ90HBvdWKtVlIHYUBJBm20KuatzdaPERLk 5nAg== X-Forwarded-Encrypted: i=1; AHgh+RqI9ta0nhBcz/MDxMV8QrzyTp0oWZCLJNL2XGmMlaN1D5MgIGYVZdySqM3XrcL0D5LuYQpSJ1Y+plzjZkY=@vger.kernel.org X-Gm-Message-State: AOJu0YwArCDHNacG6x0V+nLy7zbNsd7GB4mU2TXLdK+sBqoMZyNbE3GY zp/p7zD2tIJak0ww9uNOarbzAT/AVvVHZTFRDhP/l8zbcVNxksGfJr2i X-Gm-Gg: AfdE7ckPgVPFt/gSPak1xJOpgsILiGMCCoRUQnqDVEImjWzZopBNh+Cm99N7MZN8lGY 2cttRay2bChd3jBhHqns9RL2z5OIQGr49BdeEoH1VvDo/IWD0nLXL7RHmU8DHftdqTl1wiS64fV dB75e+jo/7/4Qz/3OxYV/mm3cJcpwn3+M5wLNE2931CY+VTQeC6QYXtrD+YXkWmkr1IBnIDlD80 gyLN5B+6KhFBy+3mlwJ9UMv3/fcYGClbvbQOSaFTVMXB/t9Arl/IJAZANWrjMh9ynQUeCfd5WyO kA5TZnVANZlNrO+Z7QND36wwcZSP+7jwR4YpEiqsoJp66reymLKzDTXqkfw4aY+Z5lsitUIn48X fuyHOGvSHPgQHBxHAWT1A7IPVElHd9ZepwnpVvqREjYBNRHRxbTPEikGjfnCJ9H/V5JW59/yCVU bxYyQtdGtnuyMpXiq/pWPQfvw2UpGXmAY2VWrC/8EtjA2m149irbPqv1XDz616HkdyFdzHlQtAt A== X-Received: by 2002:a05:6402:449b:b0:698:c11b:b180 with SMTP id 4fb4d7f45d1cf-69ab44534bamr1247834a12.3.1783525739146; Wed, 08 Jul 2026 08:48:59 -0700 (PDT) Received: from node ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69ac41d7ceesm945125a12.23.2026.07.08.08.48.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 Jul 2026 08:48:58 -0700 (PDT) From: Muhammad Bilal To: hansg@kernel.org, ilpo.jarvinen@linux.intel.com, jorge.lopez2@hp.com, linux@weissschuh.net, platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org Cc: stable@vger.kernel.org, Mario Limonciello , Armin Wolf , Muhammad Bilal Subject: [PATCH v4 3/4] platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS Date: Wed, 8 Jul 2026 20:48:44 +0500 Message-ID: <20260708154846.12356-4-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260708154846.12356-1-meatuni001@gmail.com> References: <20260708154846.12356-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_init_bios_package_attribute() hard-fails when a WMI ACPI package contains fewer elements than the type-specific expected count (e.g. 11 elements instead of 13 for INTEGER or ENUMERATION attributes). This causes the entire hp_bioscfg driver to skip attribute enumeration on older HP hardware whose BIOS returns shortened packages when optional fields like prerequisites or possible values are absent. Observed on HP EliteBook 840 G2 (BIOS M71 Ver. 01.31): hp_bioscfg: ACPI-package does not have enough elements: 11 < 13 The element layout has two tiers: - Elements 0-9 (SECURITY_LEVEL+1 =3D 10): common to all attribute types - Elements 10-N: type-specific (bounds, values, encodings, ...) The per-type populate functions (hp_populate_*_elements_from_package) already handle sparse packages correctly via their own elem < count loop guards and inner-loop bounds checks. The only unsafe case is when we lack even the common elements needed to register the attribute. Fix by introducing COMMON_ELEM_CNT to mark the hard minimum (10), and splitting the check into two tiers: - Fewer than COMMON_ELEM_CNT elements: hard fail, can't proceed. - Fewer than expected type-specific elements: warn, but let the populate function parse what is available. Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 11 ++++++++--- drivers/platform/x86/hp/hp-bioscfg/bioscfg.h | 3 +++ 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.c index 768330d291da8..78019644ec358 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c @@ -661,12 +661,17 @@ static int hp_init_bios_package_attribute(enum hp_wmi= _data_type attr_type, int ret =3D 0; =20 /* Take action appropriate to each ACPI TYPE */ - if (obj->package.count < min_elements) { - pr_err("ACPI-package does not have enough elements: %d < %d\n", - obj->package.count, min_elements); + if (obj->package.count < COMMON_ELEM_CNT) { + pr_err("ACPI-package is missing common elements: %d < %d\n", + obj->package.count, COMMON_ELEM_CNT); goto pack_attr_exit; } =20 + if (obj->package.count < min_elements) { + pr_warn("ACPI-package has fewer elements than expected: %d < %d, parsing= available elements\n", + obj->package.count, min_elements); + } + elements =3D obj->package.elements; =20 /* sanity checking */ diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.h index 416d7e7aaaae3..ac57d6eab4c35 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h @@ -279,6 +279,9 @@ enum hp_wmi_data_elements { PSWD_ENCODINGS =3D 13, PSWD_IS_SET =3D 14, PSWD_ELEM_CNT =3D 15, + + /* Minimum elements shared by all attribute types (NAME..SECURITY_LEVEL) = */ + COMMON_ELEM_CNT =3D SECURITY_LEVEL + 1, }; =20 #define GET_INSTANCE_ID(type) \ --=20 2.55.0 From nobody Tue Jul 28 13:52:19 2026 Received: from mail-ej1-f54.google.com (mail-ej1-f54.google.com [209.85.218.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DC72E41CB44 for ; Wed, 8 Jul 2026 15:49:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.54 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783525745; cv=none; b=WARg+2PtYQiqSUvsli59ZEX68sudRYu0xQhUCUQIU1g0LlnltS1kzofyyy7O1KHCCIQ9qrPedrZ+oc1pgGMTnnKmAya8mr/14yDSUl3wGYriQaFgCLU0lJYlA3E3naDRY4J3cWp67H1DcUEaX4J1jWARpfMbLSghiJjjqA4a4+A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783525745; c=relaxed/simple; bh=+fb2hm/AV+gpBOcwwKZ0VASVGKm3XP6ZLpjp9sYFqfw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=L1xrvqdk1g2KMKasvZNbKNTcsxPgbIm7OnWygjp+WVY3nQQt3fxZQc0x3xNvtodMxhj3bHCUrVVT+c2w2YfWvtgQHv6s49eh4uwj+t9u0NWRIGSSUjxvKoEHHuF331+eWFnXpweMYkebKr+erqBCgdSZ8g+KuNus1OFpfBArV5c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=tCVFg0vE; arc=none smtp.client-ip=209.85.218.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="tCVFg0vE" Received: by mail-ej1-f54.google.com with SMTP id a640c23a62f3a-c15c7c07a57so138189866b.1 for ; Wed, 08 Jul 2026 08:49:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783525742; x=1784130542; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aWjcO3quzBLPCQpyEkYQryJlDPpxypgV7KUttYaLljc=; b=tCVFg0vE8SjqeX73phKxLJdwORjAjBov0SFnBJxL5VAlKDnjn+qfjAmxSwpBUBTEtS xZ9vySE7EDsJzTcWUoU5gZnLxmLg0lj/ss3zj9JaI5lAV7nhV1dRIEbHwRTqQz6xn3TY bItr2zHbVWrrvJ4s4YUumBY2XYQsx4f+HREw316kAL/uVAZbdRqiIgAjHaJEAieu6mZg HQA6Nt7oM6GKeaJI+g+iNw5WDoln3643MTkQ/N9qs5GzSaz6wuUine6180jR4Zh4n1r3 35gkjlaiRCRuYjq21IIsstw0RLZsAdX6IcZu9dA+oabNn8jyNnefHmzbwLvjtJMtl26K J+ig== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783525742; x=1784130542; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aWjcO3quzBLPCQpyEkYQryJlDPpxypgV7KUttYaLljc=; b=OqrTpk3Eq/1DH+8E/l7ISaLlpcPzI3XJ/sQ5gndHyx4HLhyjrDM+I2KhQPMZcdV55u Dz69UvYDXW3tsWX14OVd0wGnQcwXeP6STVID9F1FYFU5I45RlF1qt8iiGG6GhwJa0YV7 I7U3buDITx/ukcKsC8E6fMxkCFB/vTh/Ik1uAh97WAzpwZOcYkkk5rTmywnQILgQwRgm lTZ5xelXfaDB3EyPg39+Hhi4dQYj8rmAUQfuBHEkSQifdpXPW6xS6LzuZd77CoXCnLQ9 eA5lNQUcGEa8iSknHspbInx4iVSRp2oyMKscVr19OD5BZNwF0GtN9OwQ6i7Vj6ZiDK0l Joyw== X-Forwarded-Encrypted: i=1; AHgh+Rq3ex6DuRxv5wlzhz618kb9HWUqShrwXpyirdajs9UDu9wEiSWiQhm9QwpLHLLD8Am3rhUC7H28bXyyRgM=@vger.kernel.org X-Gm-Message-State: AOJu0YxUeJaOFB8PENy2nl3Dj0udQMjhkY+LbhMiY1LzRt+2FIOURtqH h0fW4bLZ7UkuzsGd/WG0ZVc0Qf2AOClimQ3Qm3qU84b4Q9yQM4AEm7f/ X-Gm-Gg: AfdE7ck9c4fQQsJkvNBT51ys1dCPg0FU6RM+7FV7YWn8Jow+RKElIJ7Y0Kgkivnrq/q 419b36Ef/MNI3R2LbHMB6gVIRr6nSki6YtQlPXZK4+2Y6zJxwMHgGNjb3wpf0UxDD24G0OIox/H LZolNIuK9O4eK9Xrq1qnsVb+ZeXKaNa9uRW6KfhkXFVRBhNalTvgmIIiIyCf1QxqGLdQNH4F25K wyBSHMwYbxtGGscx8blGHmNdYS8uRu81Vbc/A3gMTnc6NnbNBDrH76f2R7tSGYQlHvlZh8bOHcY d5QXnVVTqcD7YwZJEJ6lSuDFfWIfLyE/XPEEsDYecr7GhUEsDoql1p+jevXY3dcXklZMW8d8fhI gju+p4KnKPuVxIRXTZtBGImA9paH6/vq9w2qbsBhZKyWCOf1vr+bLEb4Dp8cjdFgboCKKfVCrE+ V74NzcA77l6PjWiY11mO59UDd+NhTI/IEJSNp7P4H4//4WeuM/VNIzghZ+DpM/6Yc= X-Received: by 2002:a17:906:6a0f:b0:bec:fa92:d36c with SMTP id a640c23a62f3a-c15ce1884e6mr147647666b.38.1783525742031; Wed, 08 Jul 2026 08:49:02 -0700 (PDT) Received: from node ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69ac41d7ceesm945125a12.23.2026.07.08.08.48.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 Jul 2026 08:49:01 -0700 (PDT) From: Muhammad Bilal To: hansg@kernel.org, ilpo.jarvinen@linux.intel.com, jorge.lopez2@hp.com, linux@weissschuh.net, platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org Cc: stable@vger.kernel.org, Mario Limonciello , Armin Wolf , Muhammad Bilal Subject: [PATCH v4 4/4] platform/x86: hp-bioscfg: warn on element type mismatch instead of failing Date: Wed, 8 Jul 2026 20:48:45 +0500 Message-ID: <20260708154846.12356-5-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260708154846.12356-1-meatuni001@gmail.com> References: <20260708154846.12356-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_populate_enumeration_elements_from_package() returns -EIO and aborts enumeration of the entire attribute when any single element has an unexpected ACPI type. This is observed on HP EliteBook 840 G2 when the BIOS returns malformed ACPI data following a failed WMI query: ACPI BIOS Error (bug): AE_AML_BUFFER_LIMIT, Index (0x000000032) is beyond end of object (length 0x32) ACPI Error: Aborting method \_SB.WMID.WQBE due to previous error Error expected type 2 for elem 13, but got type 1 instead hp_bioscfg: Returned error 0x3, "Invalid command value/Feature not supported" Aborting immediately discards the attribute entirely. Warn about the unexpected element type, free the temporary string, skip the offending element, and continue parsing the remaining package instead of failing the whole attribute. Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c b/drivers= /platform/x86/hp/hp-bioscfg/enum-attributes.c index 3aa2c440e0528..b834303e5bc79 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c @@ -163,10 +163,11 @@ static int hp_populate_enumeration_elements_from_pack= age(union acpi_object *enum =20 /* Check that both expected and read object type match */ if (expected_enum_types[eloc] !=3D enum_obj[elem].type) { - pr_err("Error expected type %d for elem %d, but got type %d instead\n", - expected_enum_types[eloc], elem, enum_obj[elem].type); + pr_warn("Unexpected element type at elem %d: expected %d, got %d, skipp= ing\n", + elem, expected_enum_types[eloc], enum_obj[elem].type); kfree(str_value); - return -EIO; + str_value =3D NULL; + continue; } =20 /* Assign appropriate element value to corresponding field */ --=20 2.55.0