From nobody Tue Jul 28 14:36:54 2026 Received: from mail-ed1-f53.google.com (mail-ed1-f53.google.com [209.85.208.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4927639C636 for ; Thu, 9 Jul 2026 16:59:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783616353; cv=none; b=Zuk1JqqMg5iBd0rCiyJcX7g20JXSRWnkfkDFhA7TyY3OrnyI8FSzLOQbZoBzNejkdNO/CEz1KR0Z8pBGyVlDDv0YDL5RW8PEQEF4iCdeAwNSsHQU3rQj2TyNEnFWqhQ7MrFKOe/wVP1HHynTRU2ahUR2F8DuFOH/WkBOMYIXjVI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783616353; c=relaxed/simple; bh=ncnC0cZgOIn9WbDqi4OeJBlvxuN/aT4ju5W4zu4///s=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mt1crDMP2SRBeDksaoYek9KaRMSPW2CJ65eTpLFBKjH1Ug2XFUIlscyYmllYgrR22i7cG+lD6GeLBR1KUx8GK4GfgDnmftGyomplFJPGOoen9vnhxOYDAEQ/IJi2Ctwt9O5ktFUKnJI8ZsMpoWanxrukj+rRN726495Rr5E+i6M= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=AJ2lwe7a; arc=none smtp.client-ip=209.85.208.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="AJ2lwe7a" Received: by mail-ed1-f53.google.com with SMTP id 4fb4d7f45d1cf-69532288224so64104a12.0 for ; Thu, 09 Jul 2026 09:59:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783616350; x=1784221150; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=tqupO2cycfWRYtbmT/oP3+yrh6nW6on2Bsj2SXIaYZc=; b=AJ2lwe7aP6k/57iTdIGtv2IyXtGyrWe5KqLKjRNQY0bf+CGgNDz8IFdpsG1lFR8uZc x7hSvKTJDcdiqjPFI9rCYXkskmqUC+ktPBp5erq8a0zmJTdtvtzOQCnh9p59SsLYvDzu PYDGZB5WX+NR0mpdUfW0d8i0ijMM0tLouuYT3gtoNhqDfOUSvsbfhRzv43RjKta1AaI6 xlpFySCtH/dTwaaVe/r89uvnn8mAZ6D7dI8SKb2U+ybO/hCEDVNeVO/4MpNSnuelYFyN ZTN+qjPRH1Ex7q/R5J2eGUbdVOmkOUu7XneU40yQIzdxdlllXmhlg8qj1+qC1ZmmwGxR f7JQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783616350; x=1784221150; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=tqupO2cycfWRYtbmT/oP3+yrh6nW6on2Bsj2SXIaYZc=; b=NQla/ECEJVEpj86kAwSjcohaxHrvhyIikmD+Aeau5nVJUXpoiZUW63rl8BXR/e7cum ndOIYXnbO9LWXoL/MgmziYqezBshxLQtp9DzjzB4MqqpMidDSgTE/hoeQJlFuDb6rl1V GXXStlNe10ulMY+9/BE4L1TuOvVGcoukplglaa7/QEkKg9d4h20UlL3beZp3GIYLZy02 QPJAE3XdYpmMHHmvUAnzFu3d4VZaqrkCGGdgRYnzWj7jsEGkugy1q1AWCeTNuFMbFj3d 36GAfg5tb5bCTdQrtmTaF4AH0H3OhfVmqUWMTjpTy2V1tQg4nXBAcTvWMUMo+OJxrbkJ LcoQ== X-Forwarded-Encrypted: i=1; AHgh+RplRKeE2T7WE/nJ7ZXevoQ0xWOfEeGkFmnqFsiveISlB2aZUyK5cJeu3oeC5NVQ1sJ3n7Mw8rCfSPf2Gw4=@vger.kernel.org X-Gm-Message-State: AOJu0Yyu+ECTv3dhY/J8fYYVBlvikVn4WmxpQONDPe7HktupphGn4zRD DdV6dU82hvXT/21vlpyztNMqAKBuEJTZ4hY6orlRWYi87XNLD7sXRVuk X-Gm-Gg: AfdE7ckFEOzoMn/Ls3ExzDXBa45FXeG9ix/86BDb+zM7lbilwVl8oFESsAwgkOR8cHY zsIg0YGRRz7cBzNT7rDZU5gFvSojzsKWYNHSCIF8EjnM8tNfayZviaJks9vjqYe1hl5f8HuMAQ9 n0aYicrwENZYVRe1VkyBznUqlfi2JmmP8UHHud3z1G9uSvVRu8fAQ53OnxW1XV/p2BiXVD/zxK/ JGmEuduuafMpgsd/GnRYzW/3K2SolXsyhBnJyh3o4HKG5qeO2OE4yPyAadIOwVldwAxRsY16CSC ZCkrpuG4zbinyyhA7hsnfQ10QFp4iqPlaC4fCRiZXsXrjIh5gDmjJPSjkkQ0NBPrzPQBPDrtA48 w2e21IXafsC/S6/5MR1wYr4+GE5dMDj1dmi5+FctSJmVhR0vW8aCNbYORQm+Qoi7y+QblcYiidM D4zArVvDevEaqPSgbT1nSSrsqlrk4gS+I+A6WHuuSkQU9/KOZUOolbjo9WAU1GJU+RphgLBuy20 w== X-Received: by 2002:a17:907:8a8f:b0:c15:cf51:d827 with SMTP id a640c23a62f3a-c15cf51decdmr382259866b.57.1783616349425; Thu, 09 Jul 2026 09:59:09 -0700 (PDT) Received: from node ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c15c79f2a3fsm329902666b.49.2026.07.09.09.59.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Jul 2026 09:59:08 -0700 (PDT) From: Muhammad Bilal To: Hans de Goede , =?UTF-8?q?Ilpo=20J=C3=A4rvinen?= , Jorge Lopez , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org Cc: stable@vger.kernel.org, Mario Limonciello , Armin Wolf , Muhammad Bilal Subject: [PATCH v5 1/4] platform/x86: hp-bioscfg: pass validated element count to package parsers Date: Thu, 9 Jul 2026 21:58:56 +0500 Message-ID: <20260709165900.30615-2-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260709165900.30615-1-meatuni001@gmail.com> References: <20260709165900.30615-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The per-type package parsers are handed the wrong element count. hp_init_bios_package_attribute() validates obj->package.count and then calls one of the five hp_populate_*_package_data() wrappers (string, integer, enumeration, ordered list, password). Each wrapper forwards a count to its hp_populate_*_elements_from_package() parser, but instead of forwarding the validated obj->package.count it derives the count from elements[0]. elements[0] is the NAME field and is always an ACPI_TYPE_STRING, so reading ->package.count from it in fact reads ->string.length through the union acpi_object. The parsers thus bound themselves against the length of the name string rather than against the real number of elements in the package. This is safe today because hp_init_bios_package_attribute() refuses any package that has fewer than the type's element count, so a parser only ever runs on a full package and never reads past it regardless of the bogus bound. An upcoming change relaxes that check to accept shorter packages. Once a parser can receive fewer elements than its per-type count, a bound taken from the name length no longer reflects the array size, and the "elem < count" loop conditions and "elem + n >=3D count" sub-loop guards read past the end of elements[] - an out-of-bounds heap read. Forward the validated obj->package.count to every *_package_data() wrapper so the parsers bound themselves against the real package size. This does not change behaviour for the packages that enumerate correctly today and is a prerequisite for accepting shorter packages safely. Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 5 +++++ drivers/platform/x86/hp/hp-bioscfg/bioscfg.h | 5 +++++ drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c | 4 +++- drivers/platform/x86/hp/hp-bioscfg/int-attributes.c | 4 +++- drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c | 6 ++++-- drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 6 ++++-- drivers/platform/x86/hp/hp-bioscfg/string-attributes.c | 4 +++- 7 files changed, 27 insertions(+), 7 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.c index 27fd6cd215290..768330d291da8 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c @@ -731,26 +731,31 @@ static int hp_init_bios_package_attribute(enum hp_wmi= _data_type attr_type, switch (attr_type) { case HPWMI_STRING_TYPE: ret =3D hp_populate_string_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; case HPWMI_INTEGER_TYPE: ret =3D hp_populate_integer_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; case HPWMI_ENUMERATION_TYPE: ret =3D hp_populate_enumeration_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; case HPWMI_ORDERED_LIST_TYPE: ret =3D hp_populate_ordered_list_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; case HPWMI_PASSWORD_TYPE: ret =3D hp_populate_password_package_data(elements, + obj->package.count, instance_id, attr_name_kobj); break; diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.h index f1eec0e4ba075..416d7e7aaaae3 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h @@ -401,6 +401,7 @@ int hp_populate_string_buffer_data(u8 *buffer_ptr, u32 = *buffer_size, int hp_alloc_string_data(void); void hp_exit_string_attributes(void); int hp_populate_string_package_data(union acpi_object *str_obj, + int str_obj_count, int instance_id, struct kobject *attr_name_kobj); =20 @@ -411,6 +412,7 @@ int hp_populate_integer_buffer_data(u8 *buffer_ptr, u32= *buffer_size, int hp_alloc_integer_data(void); void hp_exit_integer_attributes(void); int hp_populate_integer_package_data(union acpi_object *integer_obj, + int integer_obj_count, int instance_id, struct kobject *attr_name_kobj); =20 @@ -421,6 +423,7 @@ int hp_populate_enumeration_buffer_data(u8 *buffer_ptr,= u32 *buffer_size, int hp_alloc_enumeration_data(void); void hp_exit_enumeration_attributes(void); int hp_populate_enumeration_package_data(union acpi_object *enum_obj, + int enum_obj_count, int instance_id, struct kobject *attr_name_kobj); =20 @@ -432,6 +435,7 @@ int hp_populate_ordered_list_buffer_data(u8 *buffer_ptr, int hp_alloc_ordered_list_data(void); void hp_exit_ordered_list_attributes(void); int hp_populate_ordered_list_package_data(union acpi_object *order_obj, + int order_obj_count, int instance_id, struct kobject *attr_name_kobj); =20 @@ -440,6 +444,7 @@ int hp_populate_password_buffer_data(u8 *buffer_ptr, u3= 2 *buffer_size, int instance_id, struct kobject *attr_name_kobj); int hp_populate_password_package_data(union acpi_object *password_obj, + int password_obj_count, int instance_id, struct kobject *attr_name_kobj); int hp_alloc_password_data(void); diff --git a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c b/drivers= /platform/x86/hp/hp-bioscfg/enum-attributes.c index af4d1920d4880..de156a9f88a18 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c @@ -300,10 +300,12 @@ static int hp_populate_enumeration_elements_from_pack= age(union acpi_object *enum * Populate all properties of an instance under enumeration attribute * * @enum_obj: ACPI object with enumeration data + * @enum_obj_count: Number of elements in @enum_obj * @instance_id: The instance to enumerate * @attr_name_kobj: The parent kernel object */ int hp_populate_enumeration_package_data(union acpi_object *enum_obj, + int enum_obj_count, int instance_id, struct kobject *attr_name_kobj) { @@ -312,7 +314,7 @@ int hp_populate_enumeration_package_data(union acpi_obj= ect *enum_obj, enum_data->attr_name_kobj =3D attr_name_kobj; =20 hp_populate_enumeration_elements_from_package(enum_obj, - enum_obj->package.count, + enum_obj_count, instance_id); hp_update_attribute_permissions(enum_data->common.is_readonly, &enumeration_current_val); diff --git a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c b/drivers/= platform/x86/hp/hp-bioscfg/int-attributes.c index d96e160953e39..f2fd966c9ca4c 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c @@ -275,10 +275,12 @@ static int hp_populate_integer_elements_from_package(= union acpi_object *integer_ * Populate all properties of an instance under integer attribute * * @integer_obj: ACPI object with integer data + * @integer_obj_count: Number of elements in @integer_obj * @instance_id: The instance to enumerate * @attr_name_kobj: The parent kernel object */ int hp_populate_integer_package_data(union acpi_object *integer_obj, + int integer_obj_count, int instance_id, struct kobject *attr_name_kobj) { @@ -286,7 +288,7 @@ int hp_populate_integer_package_data(union acpi_object = *integer_obj, =20 integer_data->attr_name_kobj =3D attr_name_kobj; hp_populate_integer_elements_from_package(integer_obj, - integer_obj->package.count, + integer_obj_count, instance_id); hp_update_attribute_permissions(integer_data->common.is_readonly, &integer_current_val); diff --git a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c b/d= rivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c index f09489a085c86..cc5bebe73a93b 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c @@ -298,10 +298,12 @@ static int hp_populate_ordered_list_elements_from_pac= kage(union acpi_object *ord * Populate all properties of an instance under ordered_list attribute * * @order_obj: ACPI object with ordered_list data + * @order_obj_count: Number of elements in @order_obj * @instance_id: The instance to enumerate * @attr_name_kobj: The parent kernel object */ -int hp_populate_ordered_list_package_data(union acpi_object *order_obj, in= t instance_id, +int hp_populate_ordered_list_package_data(union acpi_object *order_obj, in= t order_obj_count, + int instance_id, struct kobject *attr_name_kobj) { struct ordered_list_data *ordered_list_data =3D &bioscfg_drv.ordered_list= _data[instance_id]; @@ -309,7 +311,7 @@ int hp_populate_ordered_list_package_data(union acpi_ob= ject *order_obj, int inst ordered_list_data->attr_name_kobj =3D attr_name_kobj; =20 hp_populate_ordered_list_elements_from_package(order_obj, - order_obj->package.count, + order_obj_count, instance_id); hp_update_attribute_permissions(ordered_list_data->common.is_readonly, &ordered_list_current_val); diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index 4d79eb8056a5d..ed5e2080f22bd 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -385,10 +385,12 @@ static int hp_populate_password_elements_from_package= (union acpi_object *passwor * Populate all properties for an instance under password attribute * * @password_obj: ACPI object with password data + * @password_obj_count: Number of elements in @password_obj * @instance_id: The instance to enumerate * @attr_name_kobj: The parent kernel object */ -int hp_populate_password_package_data(union acpi_object *password_obj, int= instance_id, +int hp_populate_password_package_data(union acpi_object *password_obj, int= password_obj_count, + int instance_id, struct kobject *attr_name_kobj) { struct password_data *password_data =3D &bioscfg_drv.password_data[instan= ce_id]; @@ -396,7 +398,7 @@ int hp_populate_password_package_data(union acpi_object= *password_obj, int insta password_data->attr_name_kobj =3D attr_name_kobj; =20 hp_populate_password_elements_from_package(password_obj, - password_obj->package.count, + password_obj_count, instance_id); =20 hp_friendly_user_name_update(password_data->common.path, diff --git a/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c b/drive= rs/platform/x86/hp/hp-bioscfg/string-attributes.c index fe5a9a3a4ef17..f98c32dacbc74 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c @@ -263,10 +263,12 @@ static int hp_populate_string_elements_from_package(u= nion acpi_object *string_ob * Populate all properties of an instance under string attribute * * @string_obj: ACPI object with string data + * @string_obj_count: Number of elements in @string_obj * @instance_id: The instance to enumerate * @attr_name_kobj: The parent kernel object */ int hp_populate_string_package_data(union acpi_object *string_obj, + int string_obj_count, int instance_id, struct kobject *attr_name_kobj) { @@ -275,7 +277,7 @@ int hp_populate_string_package_data(union acpi_object *= string_obj, string_data->attr_name_kobj =3D attr_name_kobj; =20 hp_populate_string_elements_from_package(string_obj, - string_obj->package.count, + string_obj_count, instance_id); =20 hp_update_attribute_permissions(string_data->common.is_readonly, --=20 2.55.0 From nobody Tue Jul 28 14:36:54 2026 Received: from mail-ej1-f43.google.com (mail-ej1-f43.google.com [209.85.218.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 35DC538F255 for ; Thu, 9 Jul 2026 16:59:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783616355; cv=none; b=TCl1ZjQbn/sJ4v0h7A3laDjW0W+3sr+nC9zLmtGw6VZOclLt/mRlabKZz3iobvVtnmxgEj3618GTluw35ujpKR2ukDn/IWH54MldyUD/NPGbL1UQDa+wkuMkpJLECa1YB7rgQyufqwkM4M0yqfT/lP1mobTawK04piyM2JWyM6g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783616355; c=relaxed/simple; bh=uJoYCDCn9PmHieohB5D8uKh80F/3g84Pf60VaEuspDI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lQtvdTXczNxG3Me0bW4mp3gHkJMmrH1JD4OZzYyPex6+NrLo43PkVwJNNkDHmZUsZjklky0hg+TVOzo8VJ/umyH9jNYTPdeOydMxyGrHJQWcZRvroWTcCm8IneDOxXq7mFSk++dZtBXFMTP0OclXUwGNLFjBt1Cw4XuOjD+aQmY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=M1vsZ4o9; arc=none smtp.client-ip=209.85.218.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="M1vsZ4o9" Received: by mail-ej1-f43.google.com with SMTP id a640c23a62f3a-c15d111ca99so11637366b.0 for ; Thu, 09 Jul 2026 09:59:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783616353; x=1784221153; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=BdQgCcOZ8AsbD39pJ/8+6FU/oteVawK7PRRyjumlzGo=; b=M1vsZ4o9xHisNGI4Ucm+gDuW05HosHIl9eHvr5jq5Q6EqyzXN2JI5JaWGbHMRe+f5+ Tl7sdUV38BoFQM5HUZMTDmrGr1XQS7vsvsjqHobfcd9my6nPPYTubHMYmAaM9wmvuB0p dnJTBa+x4gpEszalMZfUs+rWw0m0oIT3iRco3mCvDuKXrU5vWxq36Vb0pjiHFyaR57UJ VSjVcMnRUtwhg5ncAkMp5G2pVzXLJpt4zvMxpo1ZxWsn0UtpLCnmSLvBZOri6AyufO48 9CgnZGGVYbrNDK/8xOFB1+0plJtYo/99khKzBo6JFXVKxeb4+R1+wHabwgjPhdbTAyna xl7Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783616353; x=1784221153; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=BdQgCcOZ8AsbD39pJ/8+6FU/oteVawK7PRRyjumlzGo=; b=TUkYQpxO4s/F/tzaBMfhTknAAWxGLomSO9lFi/nj4WurBxS7g8FFvRG7iOHLyxydou x7lJHfkW93hYHRd3naERMgn777zlPT6IKisxMAmFPU/1UBBUAdZMcP/waeqHdGzf+C35 FK9PuwqanlX14s2fB/wfmkdTZU8cRTOQpnMPs8ttXGK0XbOAQABvlI9mCaoBzdOEZK0i OtAphxKPlnEXs9y0ZrnET96qCqz//tGz0b0nyME1nDXRw81wrfZGaG4e0E+pmbllafyL avT6yHAxeF3hxyiJMakzt3xTQNGqU/RcVSnUFYTtMi1zI6zJNxdOcGaddlglTSTYf9xB V6ow== X-Forwarded-Encrypted: i=1; AHgh+RrnCfzkRHtScL4kzPNNnawhMKjndT6Z1PVOgyMXPvK282Sot2FZtH3AtQH5Pj3/QD4BIGZ7SLAoXo1ciUk=@vger.kernel.org X-Gm-Message-State: AOJu0Yx7IoLBqULcyntKA3lFozAbTtOIwbhL8Ju/Il5m+phBgZ7jS+xI 0cCyZo0eFFJYVw35OctXP5MNJamFkr1jHug2dHSYgtoqDwkUwiqXrW/W X-Gm-Gg: AfdE7cm536+1t47l6a6uvM/NeO2taP11SPf4cQDPTnLmi4sdHMp7e9xUdmiud7uSE8H uvNrh03ISQQLjJJpsrtcnoIZvyjTYyQ4Jojab0sYNUVnum3fq6uooIRmEeb/rSrBMAhyKS8KZWI 7Qa+ls1dtu9WvHspTLsnRWH5d4oFJEs32opjw+ZV/RuFW8KDsj4+RGnJRf/bLwJmIEwm0KIlQVX 89/xH6bRitYgGJUAiQOQEtRUCfpEv0EeJkI4FgRkJZevC1UO7BYYbPVgcA7ciwfew54O6Mrg6MJ 2/Mz0m4lMLfI7olw7qLKMMcTAeBzbOSB+EMUCuozCKxvWcVLbV1rI6pZGQllYrT9paegPJ3Rh9C 8DGFIuNp7JrJXa5eU+yHuIn4rIz4ex2uLvVctTmMFm0l6Fnab8IJ28DpOhiGleBp7ncSjb7LJmL CjN2nBt32utoZJOP8U9bwy5KzAyoGXLulbGrWfUA7T2etUSXlDiGjwD6sc8a9JUdQ= X-Received: by 2002:a17:907:3d12:b0:c12:979c:5a5e with SMTP id a640c23a62f3a-c15cda428admr403802066b.0.1783616352383; Thu, 09 Jul 2026 09:59:12 -0700 (PDT) Received: from node ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c15c79f2a3fsm329902666b.49.2026.07.09.09.59.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Jul 2026 09:59:12 -0700 (PDT) From: Muhammad Bilal To: Hans de Goede , =?UTF-8?q?Ilpo=20J=C3=A4rvinen?= , Jorge Lopez , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org Cc: stable@vger.kernel.org, Mario Limonciello , Armin Wolf , Muhammad Bilal Subject: [PATCH v5 2/4] platform/x86: hp-bioscfg: bound ordered-list parsing by the package count Date: Thu, 9 Jul 2026 21:58:57 +0500 Message-ID: <20260709165900.30615-3-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260709165900.30615-1-meatuni001@gmail.com> References: <20260709165900.30615-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_populate_ordered_list_elements_from_package() differs from the other per-type parsers: its main loop is bounded only by the fixed per-type count and never checks elem against the number of elements actually present in the package, for (elem =3D 1, eloc =3D 1; eloc < ORD_ELEM_CNT; elem++, eloc++) whereas the string, integer, enumeration and password parsers bound their main loop with "elem < count" as well. This is safe today because hp_init_bios_package_attribute() rejects any package with fewer than ORD_ELEM_CNT elements before the parser runs. An upcoming change, however, relaxes that check to accept shorter packages. Bound the loop by the validated element count as well, so it stops at whichever comes first, the per-type count or the real package size, for (elem =3D 1, eloc =3D 1; eloc < ORD_ELEM_CNT && elem < order_obj_coun= t; elem++, eloc++) order_obj_count is the validated element count, now correctly forwarded from the caller. No functional change for packages that enumerate correctly today. Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c b/d= rivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c index cc5bebe73a93b..863e486474ad0 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c @@ -145,7 +145,7 @@ static int hp_populate_ordered_list_elements_from_packa= ge(union acpi_object *ord if (!order_obj) return -EINVAL; =20 - for (elem =3D 1, eloc =3D 1; eloc < ORD_ELEM_CNT; elem++, eloc++) { + for (elem =3D 1, eloc =3D 1; eloc < ORD_ELEM_CNT && elem < order_obj_coun= t; elem++, eloc++) { =20 switch (order_obj[elem].type) { case ACPI_TYPE_STRING: --=20 2.55.0 From nobody Tue Jul 28 14:36:54 2026 Received: from mail-ej1-f51.google.com (mail-ej1-f51.google.com [209.85.218.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3A67B39BFF1 for ; Thu, 9 Jul 2026 16:59:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783616360; cv=none; b=VJjqPTjPWsn+RClWAyWDjDpkPIosVErlIx6fFoEYDYdwtodVofRy9R8RWSOieptFPBCjbO4bzhM+Zb7A0pwgrn5dAvNDzjcmGFGOY/gkat7H/16PWTclb+8b+GdC7AV4P7KGsSPFl+BchIFUKY7+p0AEM4NHITkwzHCNzwb2KGE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783616360; c=relaxed/simple; bh=4NG8zneOYe7p0UrTp9P9R7HnMyKE7GyM9DN8ppk6JVo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Cg6aXoTd9p82F09f0gutwao7wZx2iBAMwaey2LNUjXxWqP42oVHwxXNTn99iZpaXKQD90y+wtyG4WRAiH1RkD88mDCHZSEa6cq2MXyY0SyjJebZ0aCn2mSuXBzRxcIeSxoKeHyWUEhhm5c7WPe8q/jmQuo5Gv5RVmxPI1DJZEq8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=K4XTruzw; arc=none smtp.client-ip=209.85.218.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="K4XTruzw" Received: by mail-ej1-f51.google.com with SMTP id a640c23a62f3a-c15f6d667bcso14259666b.2 for ; Thu, 09 Jul 2026 09:59:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783616356; x=1784221156; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UMhE6Jch/T1UvoknEZxvYaZzdpc2xBp5cw8Z7tMZGzI=; b=K4XTruzwZQfWdS03JP5KLRY868vOFIRyRT44vrIGnh16fCgZl7AllXPBjI2b9noJ+0 0b7ECJqZfcsLfkxit+4qM/SZOw+8l5hyfSxdKkpdt19kFKAZTivNedSaheo0e9sMop+y K+JBgXjH6jVrdA6a9XM7RdA7nwCfyfsoYIgih1CuvtUdWBkrQmWvItW1sOlP2sxzQm+5 0tSYmSlZ7xWsv5fdN5Q8dyrut/ujeH8Pt/q2r8LLWpa4urMLIomyvH4DmCMBfpqm4f9p s7fHnQlNs8FePOdMvwu8imjvsLrtWsJMow+UG/0TqOv0xAgnh3HtidI3sdTCqMRFOTQY tD5A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783616356; x=1784221156; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=UMhE6Jch/T1UvoknEZxvYaZzdpc2xBp5cw8Z7tMZGzI=; b=c/rfWm+EhpP/F5/KYzMTzTPLhgKOm1rKRQI6OfClTBnp5GvgxlcVznzVdkN1KhyRrQ UYHAO3PB0gH3AOj6E7A4+6678+r+O5X+KiJU1kfNRQzuvV70Ms4M8cPo06kC+wBg0cbE 0X2ulGCLlVYSq8FQS2IZ6g+69HTH6r6R0+qMtoTE0ytRNNgDbMfHo4EbCXSJkHMUV+Zn 8DL+KwqW2uiTSTLJXZ/dU2G1bFPEonG/hcrmqEgszFm3DRarbMpX/RD7YOIIp3iKcYQ9 KKfyltGxyOuBBvQHyGNpFhPnoILIuSALyW7Ap2gR+QFlf6HCIzj9vlrRIsYHsaSpG0Xz 4T5Q== X-Forwarded-Encrypted: i=1; AFNElJ/51HNpX3qtKIUwdiepkLiI4aEE4iObwa6JGSTGCdaM+L5Z4LTUQwU55kFAOSVI0anmn1VvRton/11mHCg=@vger.kernel.org X-Gm-Message-State: AOJu0YweT7zWlhpcKY+ZvSnqG3ivsTg/TehU3lspGz+l5oyGsWQSBT+g QA9DgxWR8oFFCMgb5N+LpatfFEOPMWZn2S7soKzcwQpk33XisOwm9tE0 X-Gm-Gg: AfdE7cmtBVNoAMyqxUVITFhqIzImucgp96HypBUQD+usH6OkmvgCSavOZlw9UbaDujb cc6Yl9ObOEEHpzYbRDhiwGWFaB7HVzKsK6Pc/LaZvz57ptpe4Gce8L82ROLPXRJMiMns78eW2VP dJVbFhRW2VBRuSC6jBrVU5G6ME1+Y/xLusGGI9LlTdKHLGIb85Y9z7piSV5NrH1DNgDCD42W/xi 724PHbBzqz7rY9T/LsQNDvpjOiEivzMSdKS6Es6PxbWwWCL1OsqRXur/yFVuRfRJvf0YYL/Fajx y5NZRICwGyK2k1fwmSizehJT1d7ItU+NisybK3obFZj6GtUDPna2rBRim+xw1fPP4pO5vY2nR7H HPD0Xtet3n3serbL0gTH6la4uUFm+2WsI4Z1HAyidbYrTrODI6HT3/VTvUbPUfLKMDME5lD/jBe 0tMYEM82klPUnDkHClHIKT8Yj6M3dZvvrJvYKWWa/fUW/dfffgAwAxwR45POoKbHY= X-Received: by 2002:a17:906:a0c7:b0:c15:b26a:8fd1 with SMTP id a640c23a62f3a-c15ce0e208fmr254039566b.55.1783616355657; Thu, 09 Jul 2026 09:59:15 -0700 (PDT) Received: from node ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c15c79f2a3fsm329902666b.49.2026.07.09.09.59.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Jul 2026 09:59:15 -0700 (PDT) From: Muhammad Bilal To: Hans de Goede , =?UTF-8?q?Ilpo=20J=C3=A4rvinen?= , Jorge Lopez , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org Cc: stable@vger.kernel.org, Mario Limonciello , Armin Wolf , Muhammad Bilal Subject: [PATCH v5 3/4] platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS Date: Thu, 9 Jul 2026 21:58:58 +0500 Message-ID: <20260709165900.30615-4-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260709165900.30615-1-meatuni001@gmail.com> References: <20260709165900.30615-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_init_bios_package_attribute() hard-fails when a WMI ACPI package contains fewer elements than the type-specific expected count (e.g. 11 elements instead of 13 for INTEGER or ENUMERATION attributes). This causes the entire hp_bioscfg driver to skip attribute enumeration on older HP hardware whose BIOS returns shortened packages when optional fields like prerequisites or possible values are absent. Observed on HP EliteBook 840 G2 (BIOS M71 Ver. 01.31): hp_bioscfg: ACPI-package does not have enough elements: 11 < 13 The element layout has two tiers: - Elements 0-9 (SECURITY_LEVEL+1 =3D 10): common to all attribute types - Elements 10-N: type-specific (bounds, values, encodings, ...) The per-type populate functions (hp_populate_*_elements_from_package) already handle sparse packages correctly via their own elem < count loop guards and inner-loop bounds checks. The only unsafe case is when we lack even the common elements needed to register the attribute. Fix by introducing COMMON_ELEM_CNT to mark the hard minimum (10), and splitting the check into two tiers: - Fewer than COMMON_ELEM_CNT elements: hard fail, can't proceed. - Fewer than expected type-specific elements: warn, but let the populate function parse what is available. Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 11 ++++++++--- drivers/platform/x86/hp/hp-bioscfg/bioscfg.h | 3 +++ 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.c index 768330d291da8..78019644ec358 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c @@ -661,12 +661,17 @@ static int hp_init_bios_package_attribute(enum hp_wmi= _data_type attr_type, int ret =3D 0; =20 /* Take action appropriate to each ACPI TYPE */ - if (obj->package.count < min_elements) { - pr_err("ACPI-package does not have enough elements: %d < %d\n", - obj->package.count, min_elements); + if (obj->package.count < COMMON_ELEM_CNT) { + pr_err("ACPI-package is missing common elements: %d < %d\n", + obj->package.count, COMMON_ELEM_CNT); goto pack_attr_exit; } =20 + if (obj->package.count < min_elements) { + pr_warn("ACPI-package has fewer elements than expected: %d < %d, parsing= available elements\n", + obj->package.count, min_elements); + } + elements =3D obj->package.elements; =20 /* sanity checking */ diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.h index 416d7e7aaaae3..ac57d6eab4c35 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h @@ -279,6 +279,9 @@ enum hp_wmi_data_elements { PSWD_ENCODINGS =3D 13, PSWD_IS_SET =3D 14, PSWD_ELEM_CNT =3D 15, + + /* Minimum elements shared by all attribute types (NAME..SECURITY_LEVEL) = */ + COMMON_ELEM_CNT =3D SECURITY_LEVEL + 1, }; =20 #define GET_INSTANCE_ID(type) \ --=20 2.55.0 From nobody Tue Jul 28 14:36:54 2026 Received: from mail-ej1-f45.google.com (mail-ej1-f45.google.com [209.85.218.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7422439B498 for ; Thu, 9 Jul 2026 16:59:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783616361; cv=none; b=p5Cy/QfQ4z6W/IqlfSF+E+sCXd3LBu2b4vDiW8wpeW9zrrm0ftGFIs5zZxCz8w+zlzWGJq5NLZ6n0EZps+LDHpBNaebF0dFY4bXOydzh72P3OjcuVdhgpdugB49dy84xYep+WPfz+ytJXlfQCb3lzZOvM97Ci/vWUE+PFO2bkLo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783616361; c=relaxed/simple; bh=pGq6Ho7akFAbOMMkEMP4bgv7HVaDVNSGjgc1WcBOf1o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=j5P4DiAJODd21Hy5u9ZCsu2VsQgpj0rLBAlTed9KnC1y2FNTIOQuEVe5lK/UpgN49avyayWkYzIlsea/uoTnxdS3v4OOuQZmXAUbbVGpAcZOdGRUCMYlU1BMlSxZC+4blwbLapZlaBUr8lvmkwba1ifAyBeda641Od3PuSHjS+U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Z/VFXBqu; arc=none smtp.client-ip=209.85.218.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Z/VFXBqu" Received: by mail-ej1-f45.google.com with SMTP id a640c23a62f3a-c15ba3a2b4bso13913966b.1 for ; Thu, 09 Jul 2026 09:59:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783616359; x=1784221159; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=FcqmO2qOzufGvSZVtWMC1+200YXwxI3/0WI8kXhX1g4=; b=Z/VFXBquoOVgqI9jKhtNefNpdSQGrQyz2SVHh2E9pdylEA9OJFPOUTsg5e+A4XVOtR IZ7LTVmPXfnEZtGr8DLDEe4vUzntA6YEBN51zW/Y414/MgGltVlutgdJnv3qrhXkLukF JxBcHVLImUikKuQjaNgoOravmmsVoSrLKrW1bsiojCIlfPkvxhtrC65N968vEYjSeLdf fzjsNRJ/J7g7l+8vlEttIO7rN5oQ0FYxp20nzW9QUaZ+nSYu+3qa0of3NA3UTKkN+bu1 Auc3/Ug8il6CEKus06AF3q+ikYa+iSu7bvCihZKs+6aGLPqOKlqt7aJhee4Zi2LtaLbl CBlA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783616359; x=1784221159; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=FcqmO2qOzufGvSZVtWMC1+200YXwxI3/0WI8kXhX1g4=; b=eBVoh+a612D0lf/+nLjtEretYR2KG8IvlOR8cUqm08Hxt9HvNq7ByvXpgJU0rDTwGG x57S2qB8aE/PA6FdZjNPvDM1hhhC/uLd22K1mUVwSEKw7RAEtwCXpeRRSNEfV9yujftK kASdLlt+5hPlOzFTkvrxtw28Vr7fCD8hWvTGEz+fXZIdTi9HLa2gbgwUwXTQ7X3DF0aj ljsEZbN5ov1ifn64XxyxmLKB0yP/soi52Kc8EmqiWzp2JmbEIg7CnBQ8Z7DG8PmtCS6N FY4KV31Fs3kryi6N1jIzAB7GIKnSDbbrTBroe0agDWJ7cf0iCjvQ4FItoc+zBo5r/Jf7 wVOg== X-Forwarded-Encrypted: i=1; AHgh+Rqe5IGCUJcG6dMSgTtnQIaAipWk7mfXakpuBpRURgFpT+Ta9GB0cnVwS1zxojKHPYvUtHTDxkLkSKfw+mE=@vger.kernel.org X-Gm-Message-State: AOJu0YxUvVvCejYRl4ehs5Vl0uIXN8QAe3bQcOFHlGwkc5y+BA7nD/zQ UCQGHMqkbn3itfGpY2evKp017ghEva8gw8IlB9zX9kNHzUB1vJFlyTZd X-Gm-Gg: AfdE7clch4Ss+l8WtjKz1TxR6nQ2fo0rXabf3NrHfK3CTFOoa8KUiLxs4CzzUjTGQXe UWgZMXpaSSVPj7cAvMRC1v3UF54YMmc6Yz3dC2xWOfJFd4vlchhdIie2uzhXkFwpLqNihFAu2Pf h7QulX4Czq3kfuqg8dZVyBoRT4teBi/dOkS+0+kcRdPAF7ctd0z/C6pQ8+2TRPKARDB60MaL5Rp qFxOE1h660y6IRIpa+/FwV7NZ+iR3G7ruzc7GfM2sdSFuDdAQQlKd+Hyg6UpgrzIMVNMUVz5jFx Ym/yBiWf5pssk1FXaoTU8ZeVGGqGumOx5OIpID1XONr2ZP3cSNSRaXooL0wDhf86fL9+lpZonH5 imoTmno0K5fQb3wJTxuFUNYBA8ZyTbZuGJuq7m/Xr5QQQsBH8uR73VLiKun3xeHBLAusFl16WwN Y1uQBIpYwupdx1anZiyn/3NWuZJfxXGpMivKuuhl/9cEBInvKdfBPrU0oXWGc5JK4= X-Received: by 2002:a17:907:d15:b0:c15:9350:dfa6 with SMTP id a640c23a62f3a-c15ce21e09dmr319755066b.60.1783616358766; Thu, 09 Jul 2026 09:59:18 -0700 (PDT) Received: from node ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c15c79f2a3fsm329902666b.49.2026.07.09.09.59.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Jul 2026 09:59:18 -0700 (PDT) From: Muhammad Bilal To: Hans de Goede , =?UTF-8?q?Ilpo=20J=C3=A4rvinen?= , Jorge Lopez , =?UTF-8?q?Thomas=20Wei=C3=9Fschuh?= , platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org Cc: stable@vger.kernel.org, Mario Limonciello , Armin Wolf , Muhammad Bilal Subject: [PATCH v5 4/4] platform/x86: hp-bioscfg: warn on element type mismatch instead of failing Date: Thu, 9 Jul 2026 21:58:59 +0500 Message-ID: <20260709165900.30615-5-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260709165900.30615-1-meatuni001@gmail.com> References: <20260709165900.30615-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_populate_enumeration_elements_from_package() returns -EIO and aborts enumeration of the entire attribute when any single element has an unexpected ACPI type. This is observed on HP EliteBook 840 G2 when the BIOS returns malformed ACPI data following a failed WMI query: ACPI BIOS Error (bug): AE_AML_BUFFER_LIMIT, Index (0x000000032) is beyond end of object (length 0x32) ACPI Error: Aborting method \_SB.WMID.WQBE due to previous error Error expected type 2 for elem 13, but got type 1 instead hp_bioscfg: Returned error 0x3, "Invalid command value/Feature not supported" Aborting immediately discards the attribute entirely. Warn about the unexpected element type, free the temporary string, skip the offending element, and continue parsing the remaining package instead of failing the whole attribute. Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c b/drivers= /platform/x86/hp/hp-bioscfg/enum-attributes.c index de156a9f88a18..21077d17113b9 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c @@ -163,10 +163,11 @@ static int hp_populate_enumeration_elements_from_pack= age(union acpi_object *enum =20 /* Check that both expected and read object type match */ if (expected_enum_types[eloc] !=3D enum_obj[elem].type) { - pr_err("Error expected type %d for elem %d, but got type %d instead\n", - expected_enum_types[eloc], elem, enum_obj[elem].type); + pr_warn("Unexpected element type at elem %d: expected %d, got %d, skipp= ing\n", + elem, expected_enum_types[eloc], enum_obj[elem].type); kfree(str_value); - return -EIO; + str_value =3D NULL; + continue; } =20 /* Assign appropriate element value to corresponding field */ --=20 2.55.0