[PATCH v3 0/2] thunderbolt: validate DROM entry extents

Pengpeng Hou posted 2 patches 1 month, 2 weeks ago
drivers/thunderbolt/eeprom.c | 18 +++++++++++++++---
1 file changed, 15 insertions(+), 3 deletions(-)
[PATCH v3 0/2] thunderbolt: validate DROM entry extents
Posted by Pengpeng Hou 1 month, 2 weeks ago
The generic DROM walker can read a two-byte entry header from a one-byte
tail and accepts an entry whose declared length is shorter than that
header.  Separately, the USB4 product descriptor parser reads a complete
struct tb_drom_entry_desc without requiring that structure to be present.

Split those contracts into two patches.  The descriptor check now uses
sizeof(*desc), as requested by Mika Westerberg, instead of spelling out
the fields manually.

Changes since v2:
https://lore.kernel.org/all/20260731141700.3-thunderbolt-v2-pengpeng@iscas.ac.cn/
- split the generic entry and USB4 descriptor checks
- validate the USB4 entry with sizeof(*desc)
- rebase and re-review against the current tree

The series was reviewed statically. I did not test it with malformed
device DROM data.

Pengpeng Hou (2):
  thunderbolt: require complete DROM entry headers
  thunderbolt: validate USB4 product descriptor entry size

 drivers/thunderbolt/eeprom.c | 18 +++++++++++++++---
 1 file changed, 15 insertions(+), 3 deletions(-)

base-commit: f5bbbfec59b4e2fb7520a91de3df8a6174325d6a

-- 
2.50.1 (Apple Git-155)
Re: [PATCH v3 0/2] thunderbolt: validate DROM entry extents
Posted by Mika Westerberg 4 weeks, 1 day ago
Hi,

On Thu, Aug 13, 2026 at 11:22:06PM +0800, Pengpeng Hou wrote:
> The generic DROM walker can read a two-byte entry header from a one-byte
> tail and accepts an entry whose declared length is shorter than that
> header.  Separately, the USB4 product descriptor parser reads a complete
> struct tb_drom_entry_desc without requiring that structure to be present.
> 
> Split those contracts into two patches.  The descriptor check now uses
> sizeof(*desc), as requested by Mika Westerberg, instead of spelling out
> the fields manually.
> 
> Changes since v2:
> https://lore.kernel.org/all/20260731141700.3-thunderbolt-v2-pengpeng@iscas.ac.cn/
> - split the generic entry and USB4 descriptor checks
> - validate the USB4 entry with sizeof(*desc)
> - rebase and re-review against the current tree
> 
> The series was reviewed statically. I did not test it with malformed
> device DROM data.
> 
> Pengpeng Hou (2):
>   thunderbolt: require complete DROM entry headers
>   thunderbolt: validate USB4 product descriptor entry size

I dropped the Fixes tag, I think these are more like improvements. In
addition I changed the first patch to use const where possible. Please
check that it makes sense for you.

Both applied to thunderbolt.git/next, thanks!
Re: [PATCH v3 0/2] thunderbolt: validate DROM entry extents
Posted by Mika Westerberg 4 weeks, 1 day ago
Hi,

On Mon, Aug 31, 2026 at 08:52:58AM +0200, Mika Westerberg wrote:
> Hi,
> 
> On Thu, Aug 13, 2026 at 11:22:06PM +0800, Pengpeng Hou wrote:
> > The generic DROM walker can read a two-byte entry header from a one-byte
> > tail and accepts an entry whose declared length is shorter than that
> > header.  Separately, the USB4 product descriptor parser reads a complete
> > struct tb_drom_entry_desc without requiring that structure to be present.
> > 
> > Split those contracts into two patches.  The descriptor check now uses
> > sizeof(*desc), as requested by Mika Westerberg, instead of spelling out
> > the fields manually.
> > 
> > Changes since v2:
> > https://lore.kernel.org/all/20260731141700.3-thunderbolt-v2-pengpeng@iscas.ac.cn/
> > - split the generic entry and USB4 descriptor checks
> > - validate the USB4 entry with sizeof(*desc)
> > - rebase and re-review against the current tree
> > 
> > The series was reviewed statically. I did not test it with malformed
> > device DROM data.
> > 
> > Pengpeng Hou (2):
> >   thunderbolt: require complete DROM entry headers
> >   thunderbolt: validate USB4 product descriptor entry size
> 
> I dropped the Fixes tag, I think these are more like improvements. In
> addition I changed the first patch to use const where possible. Please
> check that it makes sense for you.
> 
> Both applied to thunderbolt.git/next, thanks!

Now I actualy tested this and this:

  thunderbolt: validate USB4 product descriptor entry size

fails now on my test system, I think because the structure is actually
larger due to alignment and so. Dropped this patch now. If you want to
revisit then I think the correct check is against what the spec says for
this entry (e.g it must be 15).