From nobody Mon Sep 28 15:34:30 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E57D0434E40 for ; Thu, 20 Aug 2026 11:34:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787225681; cv=none; b=hmdQesVbR4B84WhyjCDW836N3vwK/isIXL4Lx6jj6dwbcVIwyOPZhZHA5NgZ9dvdGPuPmn3CMcvV/C3rdG/FXbh/vbydXfYkG8JyjmrKuZF2o6SBhu6AHjHURxKb1h6l2Y7MUOtJgW3CPIU7mvyS5IiJn00myesUd9e9gtC3tXk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787225681; c=relaxed/simple; bh=aIZNn1grO9HSs6qI5Cy7nzAIEIUu6hlW7aGSXmkXxRc=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Z7JtSPbViqebagKt7CXukbS0aWKxk4c9N5b9O/EpuZgZzqglRi4JmJP6iBe8jUSrYmO8qF39SeUmsULqEGNW89djF0pYFBej8lzweAu5mQTIJkLebDZOAih0N2og9R5JXS2hVFB8PFiCu/4m+hQm0r/FJ74v+zfnhahO9gVVHd0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Tm3jIiPn; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Tm3jIiPn" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787225678; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=dm+mN5n3dsTKShEHHzFfg+sTy2TwR60RlXBR7I20CNM=; b=Tm3jIiPn5ZjDFpz0HDgOrNIZtx5jB7FOf8A6ZS7WHKGmdX34iqk0mF4DWU0QGQWmCHqFn9 Whw5WWTUxaDklqIn/SQXJPmHhqIIfqzrXKRXjKRO3Q3xwoPPJs3O4VSU+CankkrlRvnYRm hmZ05SFhq9rWElFC7ZjZ7Uzt5oaw2OA= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-687-hqomTjmkN6S8kl7y-wjCfQ-1; Thu, 20 Aug 2026 07:34:33 -0400 X-MC-Unique: hqomTjmkN6S8kl7y-wjCfQ-1 X-Mimecast-MFC-AGG-ID: hqomTjmkN6S8kl7y-wjCfQ_1787225672 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 64BBA195609E; Thu, 20 Aug 2026 11:34:32 +0000 (UTC) Received: from [192.168.1.153] (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 999F81955F03; Thu, 20 Aug 2026 11:34:30 +0000 (UTC) From: Albert Esteve Date: Thu, 20 Aug 2026 13:34:18 +0200 Subject: [PATCH 1/2] soc: qcom: smem: add boundary checks for partitions Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260820-port-smem-v1-1-d19a45f583bf@redhat.com> References: <20260820-port-smem-v1-0-d19a45f583bf@redhat.com> In-Reply-To: <20260820-port-smem-v1-0-d19a45f583bf@redhat.com> To: Bjorn Andersson , Konrad Dybcio Cc: linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Albert Esteve , Sudeepgoud Patil , Sarannya S , Pranav Mahesh Phansalkar X-Developer-Signature: v=1; a=ed25519-sha256; t=1787225667; l=6648; i=aesteve@redhat.com; s=20260303; h=from:subject:message-id; bh=HW1iRmH6U7tL08ErzMRS7SLan48xvsfAawXA2c2d7x8=; b=kYOqcDAnQDAj7zBYtzWYlNO7zlG0Tma5RZ90aXdqQLG400xwgxcOD6UUXqR4KDRSlVYK8Zj+Q 0iDA3UFQVCbCxGxEwOIPnlJpxPokx1FnkjVoClHXmThCKe0JVaGCRcu X-Developer-Key: i=aesteve@redhat.com; a=ed25519; pk=YSFz6sOHd2L45+Fr8DIvHTi6lSIjhLZ5T+rkxspJt1s= X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 From: Sudeepgoud Patil Add condition check to make sure that the end address of private entry does not go out of partition. Signed-off-by: Sarannya S Signed-off-by: Pranav Mahesh Phansalkar Signed-off-by: Sudeepgoud Patil Signed-off-by: Albert Esteve --- drivers/soc/qcom/smem.c | 105 +++++++++++++++++++++++++++++++++-----------= ---- 1 file changed, 72 insertions(+), 33 deletions(-) diff --git a/drivers/soc/qcom/smem.c b/drivers/soc/qcom/smem.c index afb21a778fe7b..194ffb2ac010f 100644 --- a/drivers/soc/qcom/smem.c +++ b/drivers/soc/qcom/smem.c @@ -2,6 +2,7 @@ /* * Copyright (c) 2015, Sony Mobile Communications AB. * Copyright (c) 2012-2013, The Linux Foundation. All rights reserved. + * Copyright (c) 2023-2024 Qualcomm Innovation Center, Inc. All rights res= erved. */ =20 #include @@ -85,6 +86,17 @@ /* Processor/host identifier for the global partition */ #define SMEM_GLOBAL_HOST 0xfffe =20 +/* Entry range check + * ptr >=3D start : Checks if ptr is greater than the start of access regi= on + * ptr + size >=3D ptr: Check for integer overflow (On 32bit system where = ptr + * and size are 32bits, ptr + size can wrap around to be a small integer) + * ptr + size <=3D end: Checks if ptr+size is less than the end of access = region + */ +#define IN_PARTITION_RANGE(ptr, size, start, end) \ + (((void *)(ptr) >=3D (void *)(start)) && \ + (((void *)(ptr) + (size)) >=3D (void *)(ptr)) && \ + (((void *)(ptr) + (size)) <=3D (void *)(end))) + /** * struct smem_proc_comm - proc_comm communication struct (legacy) * @command: current command to be executed @@ -403,6 +415,7 @@ static int qcom_smem_alloc_private(struct qcom_smem *sm= em, size_t size) { struct smem_private_entry *hdr, *end; + struct smem_private_entry *next_hdr; struct smem_partition_header *phdr; size_t alloc_size; void *cached; @@ -415,19 +428,25 @@ static int qcom_smem_alloc_private(struct qcom_smem *= smem, end =3D phdr_to_last_uncached_entry(phdr); cached =3D phdr_to_last_cached_entry(phdr); =20 - if (WARN_ON((void *)end > p_end || cached > p_end)) + if (WARN_ON(!IN_PARTITION_RANGE(end, 0, phdr, cached) || + cached > p_end)) return -EINVAL; =20 - while (hdr < end) { + while ((hdr < end) && ((hdr + 1) < end)) { if (hdr->canary !=3D SMEM_PRIVATE_CANARY) goto bad_canary; if (le16_to_cpu(hdr->item) =3D=3D item) return -EEXIST; =20 - hdr =3D uncached_entry_next(hdr); + next_hdr =3D uncached_entry_next(hdr); + + if (WARN_ON(next_hdr <=3D hdr)) + return -EINVAL; + + hdr =3D next_hdr; } =20 - if (WARN_ON((void *)hdr > p_end)) + if (WARN_ON((void *)hdr > (void *)end)) return -EINVAL; =20 /* Check that we don't grow into the cached region */ @@ -587,9 +606,11 @@ static void *qcom_smem_get_private(struct qcom_smem *s= mem, unsigned item, size_t *size) { - struct smem_private_entry *e, *end; + struct smem_private_entry *e, *uncached_end, *cached_end; + struct smem_private_entry *next_e; struct smem_partition_header *phdr; void *item_ptr, *p_end; + size_t entry_size =3D 0; u32 padding_data; u32 e_size; =20 @@ -597,67 +618,85 @@ static void *qcom_smem_get_private(struct qcom_smem *= smem, p_end =3D (void *)phdr + part->size; =20 e =3D phdr_to_first_uncached_entry(phdr); - end =3D phdr_to_last_uncached_entry(phdr); + uncached_end =3D phdr_to_last_uncached_entry(phdr); + cached_end =3D phdr_to_last_cached_entry(phdr); + + if (WARN_ON(!IN_PARTITION_RANGE(uncached_end, 0, phdr, cached_end) + || (void *)cached_end > p_end)) + return ERR_PTR(-EINVAL); =20 - while (e < end) { + while ((e < uncached_end) && ((e + 1) < uncached_end)) { if (e->canary !=3D SMEM_PRIVATE_CANARY) goto invalid_canary; =20 if (le16_to_cpu(e->item) =3D=3D item) { - if (size !=3D NULL) { - e_size =3D le32_to_cpu(e->size); - padding_data =3D le16_to_cpu(e->padding_data); + e_size =3D le32_to_cpu(e->size); + padding_data =3D le16_to_cpu(e->padding_data); =20 - if (WARN_ON(e_size > part->size || padding_data > e_size)) - return ERR_PTR(-EINVAL); + if (e_size < part->size && padding_data < e_size) + entry_size =3D e_size - padding_data; + else + return ERR_PTR(-EINVAL); =20 - *size =3D e_size - padding_data; - } + item_ptr =3D uncached_entry_to_item(e); =20 - item_ptr =3D uncached_entry_to_item(e); - if (WARN_ON(item_ptr > p_end)) + if (WARN_ON(!IN_PARTITION_RANGE(item_ptr, entry_size, e, uncached_end))) return ERR_PTR(-EINVAL); =20 + if (size !=3D NULL) + *size =3D entry_size; + return item_ptr; } =20 - e =3D uncached_entry_next(e); - } + next_e =3D uncached_entry_next(e); + if (WARN_ON(next_e <=3D e)) + return ERR_PTR(-EINVAL); =20 - if (WARN_ON((void *)e > p_end)) + e =3D next_e; + } + if (WARN_ON((void *)e > (void *)uncached_end)) return ERR_PTR(-EINVAL); =20 /* Item was not found in the uncached list, search the cached list */ =20 + if (cached_end =3D=3D p_end) + return ERR_PTR(-ENOENT); + e =3D phdr_to_first_cached_entry(phdr, part->cacheline); - end =3D phdr_to_last_cached_entry(phdr); =20 - if (WARN_ON((void *)e < (void *)phdr || (void *)end > p_end)) + if (WARN_ON(!IN_PARTITION_RANGE(cached_end, 0, uncached_end, p_end) || + !IN_PARTITION_RANGE(e, sizeof(*e), cached_end, p_end))) return ERR_PTR(-EINVAL); =20 - while (e > end) { + while (e > cached_end) { if (e->canary !=3D SMEM_PRIVATE_CANARY) goto invalid_canary; =20 if (le16_to_cpu(e->item) =3D=3D item) { - if (size !=3D NULL) { - e_size =3D le32_to_cpu(e->size); - padding_data =3D le16_to_cpu(e->padding_data); + e_size =3D le32_to_cpu(e->size); + padding_data =3D le16_to_cpu(e->padding_data); =20 - if (WARN_ON(e_size > part->size || padding_data > e_size)) - return ERR_PTR(-EINVAL); - - *size =3D e_size - padding_data; - } + if (e_size < part->size && padding_data < e_size) + entry_size =3D e_size - padding_data; + else + return ERR_PTR(-EINVAL); =20 - item_ptr =3D cached_entry_to_item(e); - if (WARN_ON(item_ptr < (void *)phdr)) + item_ptr =3D cached_entry_to_item(e); + if (WARN_ON(!IN_PARTITION_RANGE(item_ptr, entry_size, cached_end, e))) return ERR_PTR(-EINVAL); =20 + if (size !=3D NULL) + *size =3D entry_size; + return item_ptr; } =20 - e =3D cached_entry_next(e, part->cacheline); + next_e =3D cached_entry_next(e, part->cacheline); + if (WARN_ON(next_e >=3D e)) + return ERR_PTR(-EINVAL); + + e =3D next_e; } =20 if (WARN_ON((void *)e < (void *)phdr)) --=20 2.55.0 From nobody Mon Sep 28 15:34:30 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D705843304D for ; Thu, 20 Aug 2026 11:34:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787225692; cv=none; b=l0Rbbm9rvJqQjQL478250K1T7vOwhWdUdvE2AsagUUVp9VlPeQtBblBLr2wXbgc29zY3pB8QbXqORSjsh4H5ERYnJCVb5tx5/tHJwkKP8Jd1QzrAySDHc/ogu6YwrpkmKecWmshSdwQgrjUPNBBMeaR2lkMIaesZKTepwxcnl/g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787225692; c=relaxed/simple; bh=kX1NI3IJs+H8PMIDsWFquDf6o4/8e6qxJaO1HumCajI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=cNo4Q7tW7VGTVbKnSZn/tZlXfQmnM4CTw4mO/0FFpZABAMHtYcx5lhH8yFXEt33PjhlfhHo7s6IGkb5fl3/6LgxUOgtwm7oqMM+4d888SFO3f9Be+s3qHLAG9zcSI+/2P0Jy3oUtD9baXCxepL8eoK6a10pSo/e6B/r1808AxaY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Q5jPrukU; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Q5jPrukU" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787225689; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=vzOCJ3AfRCP7qYMKcW4P8MbxSZzj4hLVHXlSzZIvKQk=; b=Q5jPrukUCaxdVFUUst3/dTS3dScGeqAsIziWV0hUIckMJF57Xad1n7mE9aU5h33zcQA8oL /OEayEdWRZxi2ecj1IYAPpp8npielHggsNPEMOWT1MG3AhEVO3xBTkghCmmjPHQMW7ugXM VHLTouANE+urMYSff5NxpP60S4zI11E= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-400-I1LY6QWIOjGPzDivnyFHSw-1; Thu, 20 Aug 2026 07:34:36 -0400 X-MC-Unique: I1LY6QWIOjGPzDivnyFHSw-1 X-Mimecast-MFC-AGG-ID: I1LY6QWIOjGPzDivnyFHSw_1787225674 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 265A61956089; Thu, 20 Aug 2026 11:34:34 +0000 (UTC) Received: from [192.168.1.153] (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C35721955F03; Thu, 20 Aug 2026 11:34:32 +0000 (UTC) From: Albert Esteve Date: Thu, 20 Aug 2026 13:34:19 +0200 Subject: [PATCH 2/2] soc: qcom: smem: ignore multi remote host partitions Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260820-port-smem-v1-2-d19a45f583bf@redhat.com> References: <20260820-port-smem-v1-0-d19a45f583bf@redhat.com> In-Reply-To: <20260820-port-smem-v1-0-d19a45f583bf@redhat.com> To: Bjorn Andersson , Konrad Dybcio Cc: linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Albert Esteve , Tony Truong X-Developer-Signature: v=1; a=ed25519-sha256; t=1787225667; l=1293; i=aesteve@redhat.com; s=20260303; h=from:subject:message-id; bh=dO3Zm1S4WzpzCMukgmobRRLX4j14YUeoBXAnjCHoIKs=; b=JHEV7CY0eN3KrcnrNYIizBi6haEzIebxv1vKyodvlCMTjRRIAF1LyT/D4opc9GudGZ/uMdOz1 4a6rWDFO13HDMRNjM4tweaj2AkbbyNroF7sYLZvGEx+ZNDQ+gnJ7kxf X-Developer-Key: i=aesteve@redhat.com; a=ed25519; pk=YSFz6sOHd2L45+Fr8DIvHTi6lSIjhLZ5T+rkxspJt1s= X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 From: Tony Truong SMEM now supports more than just 1-to-1 partitions. It is possible for a partition to have multiple remote host and the logic to handle that does not exist. For now, skip all partitions which has multiple remote hosts. Signed-off-by: Tony Truong Signed-off-by: Albert Esteve --- drivers/soc/qcom/smem.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/soc/qcom/smem.c b/drivers/soc/qcom/smem.c index 194ffb2ac010f..8e079d2381535 100644 --- a/drivers/soc/qcom/smem.c +++ b/drivers/soc/qcom/smem.c @@ -86,6 +86,9 @@ /* Processor/host identifier for the global partition */ #define SMEM_GLOBAL_HOST 0xfffe =20 +/* Processor/host identifier for multi host partition */ +#define SMEM_MULTI_HOST 0xfffc + /* Entry range check * ptr >=3D start : Checks if ptr is greater than the start of access regi= on * ptr + size >=3D ptr: Check for integer overflow (On 32bit system where = ptr @@ -1081,6 +1084,9 @@ qcom_smem_enumerate_partitions(struct qcom_smem *smem= , u16 local_host) else continue; =20 + if (remote_host =3D=3D SMEM_MULTI_HOST) + continue; + if (xa_load(&smem->partitions, remote_host)) { dev_err(smem->dev, "duplicate host %u\n", remote_host); return -EINVAL; --=20 2.55.0