[PATCH] platform/x86/amd/hsmp: Reject negative power cap writes in hwmon

Hemanth Selam posted 1 patch 1 month, 2 weeks ago
drivers/platform/x86/amd/hsmp/hwmon.c | 3 +++
1 file changed, 3 insertions(+)
[PATCH] platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
Posted by Hemanth Selam 1 month, 2 weeks ago
hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long
and assigns "val / MICROWATT_PER_MILLIWATT" to msg.args[0], which is a
__u32.  MICROWATT_PER_MILLIWATT is an unsigned long, so a negative write
to power1_cap (e.g. "echo -1 > power1_cap") is first converted to a huge
unsigned value by the division and then stored into the u32 argument.

As a result a nonsensical, multi-gigawatt socket power limit is sent to
the SMU via HSMP_SET_SOCKET_POWER_LIMIT instead of the write being
rejected.

Reject negative values with -EINVAL before the conversion.

Tested with HSMP enabled:

  CAP=$(dirname $(grep -l amd_hsmp_hwmon \
        /sys/class/hwmon/hwmon*/name | head -1))/power1_cap

  # negative write
  echo -1000000 > $CAP ; echo "ret=$?"
  # valid positive write must still work
  echo 400000000 > $CAP ; echo "ret=$?"

Before:
  # echo -1000000 > $CAP ; echo "ret=$?"
  ret=0                             <- accepted; bogus limit sent to SMU
  # echo 400000000 > $CAP ; echo "ret=$?"
  ret=0

After:
  # echo -1000000 > $CAP ; echo "ret=$?"
  bash: echo: write error: Invalid argument
  ret=1                             <- rejected with -EINVAL
  # echo 400000000 > $CAP ; echo "ret=$?"
  ret=0                             <- valid write still works

Fixes: 92c025db52bb ("platform/x86/amd/hsmp: Report power via hwmon sensors")
Signed-off-by: Hemanth Selam <hemanth.selam@gmail.com>
---
 drivers/platform/x86/amd/hsmp/hwmon.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/platform/x86/amd/hsmp/hwmon.c b/drivers/platform/x86/amd/hsmp/hwmon.c
index 0cc9a742497f..c8314eee06f4 100644
--- a/drivers/platform/x86/amd/hsmp/hwmon.c
+++ b/drivers/platform/x86/amd/hsmp/hwmon.c
@@ -31,6 +31,9 @@ static int hsmp_hwmon_write(struct device *dev, enum hwmon_sensor_types type,
 	if (attr != hwmon_power_cap)
 		return -EOPNOTSUPP;
 
+	if (val < 0)
+		return -EINVAL;
+
 	msg.num_args = 1;
 	msg.args[0] = val / MICROWATT_PER_MILLIWATT;
 	msg.msg_id = HSMP_SET_SOCKET_POWER_LIMIT;
-- 
2.43.7
Re: [PATCH] platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
Posted by Ilpo Järvinen 1 month, 1 week ago
On Wed, 12 Aug 2026 14:30:12 +0530, Hemanth Selam wrote:

> hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long
> and assigns "val / MICROWATT_PER_MILLIWATT" to msg.args[0], which is a
> __u32.  MICROWATT_PER_MILLIWATT is an unsigned long, so a negative write
> to power1_cap (e.g. "echo -1 > power1_cap") is first converted to a huge
> unsigned value by the division and then stored into the u32 argument.
> 
> As a result a nonsensical, multi-gigawatt socket power limit is sent to
> the SMU via HSMP_SET_SOCKET_POWER_LIMIT instead of the write being
> rejected.
> 
> [...]

Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.

FYI [if applicable to your patch], as per Linus' policy change, also
fixes are mostly routed through for-next unless the fix is for a
commit introduced in the most recent cycle or is clearly a regression
fix.

The list of commits applied:
[1/1] platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
      commit: e7dcde6b063703a24deeb64689464b2763fe05b1

--
 i.