From nobody Fri Sep 25 12:37:38 2026 Received: from mail-pj2-f13.google.com (mail-pj2-f13.google.com [74.125.227.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D379537B030 for ; Sat, 12 Sep 2026 08:10:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.141 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789200639; cv=none; b=XFNwwVXqAiv7879fHJIefoq41Sl9x4Brvlj2lJGiKoKdTzqS1hbXElQkuFslbtWJwuZq+MC9bISx6ilirDGTaEOjQYfDMC0wqgTBA4YNZui2GdK+ACaZLWwcyPdzs/4OWrkvazgxli3ab5FVmRHSjCYZFpK09VsGLdTwLFssoRA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789200639; c=relaxed/simple; bh=wexs10U6dAtc0VpanErPLRw3l5WrtA3xwH5oCWCKM4g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=rabvBdEZqVEiHfuulqV0U5tytb/lLVm9ypfCBqEgvZf1myu6SRk778mAeItG822OAIpxRLyPj8t1+C6bnj24Px2CX926rLo0oG6QyzuO/ggZJDcZsnkA67at/XOM0LDhk7GCKe3W5XUs4/zA9WXhndomOy01vTSnLu84RkUSroE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XIfWeCO7; arc=none smtp.client-ip=74.125.227.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XIfWeCO7" Received: by mail-pj2-f13.google.com with SMTP id d9443c01a7336-2d747ee1f9bso6674925ad.3 for ; Sat, 12 Sep 2026 01:10:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789200637; x=1789805437; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Ukdiol5JyLif0T2tj02gnGl5hqC6N0TQpHgMhHI8Wqk=; b=XIfWeCO71bTbHhiCm/m2dzQjjBU3jWwISPdoSYVU0ULHMnMijeAKP4SuoNT6kzOYI1 jg9rlnqrFQv7iYK9CVfiQ/zeMRpdD7Ehy71tOCFzjyEJfeTQ+JrVyBoLIlaG5SkK1YlN eUZeeiaYcW/Lfr0hH6/waDdLeXfusdS286hF4CEgGDUGu2Oj9Gw7etPcCCz1by/GszMN siMqQo5gkKJL0PhlXMBHtUwUkYkLP1KVfwaNJDE6JyqF089Yx+en6RmDlwSiC/J3yaxv lg7LaT+X5z2EtZDKQ9dG+kle4xgT0BQdxf214JbgOQf5UVks9/iASCrfByfIGUTBeedU l93g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789200637; x=1789805437; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Ukdiol5JyLif0T2tj02gnGl5hqC6N0TQpHgMhHI8Wqk=; b=esLN8eSY/AqgGNfRgiOH10swRF5VaYij2fzVMfeca/SH3gL50EbUsxo8Mn80hh/3KW CxbXIz5MFKadmTWdUUzaynB1X9Agw2kgMub1PW3os++f3f9ibASoxayaKvUwNIvQXMfA j84prI+QN23n7LIl4Vj7E28waW0GvIyatpSj1QzKruVtE1A+y3W+LayWiw/m0i8NbW6m /uth14xcmyzuRdb1RPYW5gyekEfe7dOLRp2CbItUOqvJs05ofHxAAoJXDggQgyu40E9m Di0X70ayn2BBkYcRQeYfwN0VjqGc1o0rOs+5+qT2Nnv6M3//QQWmg+SweYsEYigdWUnW FNeA== X-Forwarded-Encrypted: i=1; AKwUvBxRhnJvCFwJqtNRrAAVfzJOt3ZXYilwxgKh1Mi+std3G8X8PxVA6NW3+x+rpxgA1wYT+W/MSTM/JTw9ji4=@vger.kernel.org X-Gm-Message-State: AFuF++mGrRE8dDg/ZzK6POk7ssvqXkbzcZMEeFAiLcBFCU5WX3zNSzGQ VuqGcqHSGtBAy7f9nXCnRS8eYZ0+S3Q+crsEWgksXLBLXUaHjKrD/oqW X-Gm-Gg: AYBFou0wvtpk2TWT9NJ7Icai2IFskVmPdNGj/xHdBIEtpYJRks6CE9FhYqmToi691dq NYghnrLcv14VLsyCZ9NX6oMQ1JD2HuCvZP9xjyf1D0AhJ5+huJ1vBjQTLJAPLQ1sdMTSzbJ1kBD Yrg5bakLxKM5R5T+q2zlDa8gAAKY5EsgIvOGLrbjQC5yCJUj5tf7jAmYFPS8kBrllcYEGenMUuX BQdMPRXL4WOoBUmcgTjaShSX/har+pldtjQ+ZRr81zWthMS7YmUDzoVq/JTUolfms3d8JyJ5RkS VTnmFcYKkVVXdWLXfvAkiRqsbMKMHwP5TZt8dKYLY8e+MAl15TWKg7zbyj9u7fxZ+t9Ybo/+eBI lu1O5hBTzyOIOqnJ2ZQg1NRTDWDXEYPYcnJw1TQ96qSP28RxXU3oBLef4YLRnskGzSQ1NYEmpyi 53cWndrO8qKxaYEPnbo1EJyUSKKwUUwzPtq0/ZE6nIXx/mddKQl1Tb+nkAFY7gAOQmlst3DrvrP N3rRGl3FzBZIso3BhZQK7q7pGH1BHNFdOLYH5xsUrYuVQcdCTMriXIHTdTtiBE0ZT2hfARzSt/c New4iKTu5709h1BzzE5kOfL+vXLXDCC+LUJy7DibLl8T X-Received: by 2002:a17:90b:3c03:b0:398:de23:9af6 with SMTP id 98e67ed59e1d1-39d9c1db154mr14531954a91.15.1789200637023; Sat, 12 Sep 2026 01:10:37 -0700 (PDT) Received: from 0xiviel.ip (122-63-135-80.mobile.spark.co.nz. [122.63.135.80]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39db7ae6d25sm982474a91.1.2026.09.12.01.10.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 12 Sep 2026 01:10:36 -0700 (PDT) From: Eva Crystal <0xiviel@gmail.com> To: Min Ma , Lizhi Hou Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Eva Crystal <0xiviel@gmail.com> Subject: [PATCH 1/4] accel/amdxdna: validate the command payload regardless of the size argument Date: Sat, 12 Sep 2026 20:10:09 +1200 Message-ID: <20260912081012.2274075-2-0xiviel@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260912081012.2274075-1-0xiviel@gmail.com> References: <20260912081012.2274075-1-0xiviel@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" amdxdna_cmd_get_payload() performs its bounds check - that the command header's count field does not describe a payload larger than the command BO - only when the caller asks for a size: if (size) { count =3D FIELD_GET(AMDXDNA_CMD_COUNT, cmd->header); if (unlikely(count <=3D num_masks || ... > abo->mem.size)) { *size =3D 0; return NULL; } *size =3D (count - num_masks) * sizeof(u32); } return &cmd->data[num_masks]; A caller passing NULL therefore receives a pointer into the command BO that has never been checked against the BO's size, and no way to learn that the header was malformed. The count field is written by user space: the command BO is mapped into the submitting process and can be rewritten after submission. The one such caller today is amdxdna_cmd_set_error(), which reads cc->command_count, writes cc->error_index and reads cc->data[0] - offsets 4, 12 and 28 into the payload. That is safe as things stand, because a command BO is created through drm_gem_shmem_create() and its size is always PAGE_ALIGN()ed, so any BO that can be vmap()ed is at least PAGE_SIZE; a zero-sized BO fails vmap() and is rejected by the !cmd test one line earlier. This is not a fix for a reachable bug. It is, however, a validation step that a caller can silently opt out of, guarding a structure whose contents user space controls, and the safety of the only NULL caller rests on a page-alignment invariant established three call levels away. Make the check unconditional and report the failure to every caller, so that the guarantee does not depend on which arguments the caller happened to pass. amdxdna_cmd_set_error() is updated to handle the NULL it can now receive. Signed-off-by: Eva Crystal <0xiviel@gmail.com> --- drivers/accel/amdxdna/amdxdna_ctx.c | 23 ++++++++++++++--------- 1 file changed, 14 insertions(+), 9 deletions(-) diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/am= dxdna_ctx.c index 5315466..163b5fc 100644 --- a/drivers/accel/amdxdna/amdxdna_ctx.c +++ b/drivers/accel/amdxdna/amdxdna_ctx.c @@ -106,17 +106,19 @@ void *amdxdna_cmd_get_payload(struct amdxdna_gem_obj = *abo, u32 *size) else num_masks =3D 1 + FIELD_GET(AMDXDNA_CMD_EXTRA_CU_MASK, cmd->header); =20 - if (size) { - count =3D FIELD_GET(AMDXDNA_CMD_COUNT, cmd->header); - if (unlikely(count <=3D num_masks || - count * sizeof(u32) + - offsetof(struct amdxdna_cmd, data[0]) > - abo->mem.size)) { + count =3D FIELD_GET(AMDXDNA_CMD_COUNT, cmd->header); + if (unlikely(count <=3D num_masks || + count * sizeof(u32) + + offsetof(struct amdxdna_cmd, data[0]) > + abo->mem.size)) { + if (size) *size =3D 0; - return NULL; - } - *size =3D (count - num_masks) * sizeof(u32); + return NULL; } + + if (size) + *size =3D (count - num_masks) * sizeof(u32); + return &cmd->data[num_masks]; } =20 @@ -159,6 +161,9 @@ int amdxdna_cmd_set_error(struct amdxdna_gem_obj *abo, =20 if (amdxdna_cmd_get_op(abo) =3D=3D ERT_CMD_CHAIN) { cc =3D amdxdna_cmd_get_payload(abo, NULL); + if (!cc) + return -EINVAL; + cc->error_index =3D (cmd_idx < cc->command_count) ? cmd_idx : 0; abo =3D amdxdna_gem_get_obj(client, cc->data[0], AMDXDNA_BO_SHARE); if (!abo) --=20 2.53.0 From nobody Fri Sep 25 12:37:38 2026 Received: from mail-pj2-f13.google.com (mail-pj2-f13.google.com [74.125.227.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0D031388868 for ; Sat, 12 Sep 2026 08:10:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.141 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789200644; cv=none; b=uxs867cYjv4yjTEW8t90D+VdEPzNDHVeYOBaRW/zlYL90agrbJN6gDGbFxUvQgpwPEjLV4So2DmfT/kIQXWVV/RtI0puh0Jgxp0rSP96jm8u1XF/4YUdnZC8Ff6WRxrJV38jIj9yaesN7of9Wf/xiLtbQ24rf8behvgf+/+lpcU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789200644; c=relaxed/simple; bh=jipvs13dUFb5yrSXQVJH72ueZtpWAQhemw94A0aFTrI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lQMPs7LmTBMrY5/kPaL+aQRYQKrpUG2Xx7rPnminuSdTLElLG0rhly3f5vwkbbAUSjDhrofs2AkpHxhok9vM2Lo9c/+ugRsAZngTAAItoaxeldwLpTHEYrep6S4E92zsh2OYpyXiHdwfCFlBYO8yo9ZO83Eiw1OYKv34Xo16MZQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Z09bmaOE; arc=none smtp.client-ip=74.125.227.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Z09bmaOE" Received: by mail-pj2-f13.google.com with SMTP id 98e67ed59e1d1-39dbdfaef3cso323545a91.1 for ; Sat, 12 Sep 2026 01:10:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789200642; x=1789805442; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=eSYO98oHKaatdSJA86Zv/zyqDt8H9puU2z+h8TsbVQM=; b=Z09bmaOEj18jfB5ioDehIVHBdDd6FRqLjUl6PQ87b0zOp9gfDlDO3UF1ibkErXfk50 cWqdK7meIPHPK6GRAcOiSMOb2JCKu84Xfc9jXTKDBtuOaLdeC6Z+ZFRDjVmXkkrQ8qPw cbvFr50RYs4wapSx8Xbr/ZHW086pHAi/qRw2yNQed4eCMG70zcAGTHoxU1Llz84QhJKK GyQbtcpw0Vt5U+6/5EK4Q5SOHgSNuuzW82AHzsIeYl0NGcMBkPbNWxSpI/2/T6QWOmBD cJZpu44YKq0lnG+gY464w9nGoZP3h38Hs9YiMOtz88Uq08r0bexyuEX6mlnOk7ZtjBBw 5D4g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789200642; x=1789805442; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=eSYO98oHKaatdSJA86Zv/zyqDt8H9puU2z+h8TsbVQM=; b=ZYxpcfUvYt7y8n3oWpuK5xG9LZphZfBwVDfj7Yf2vxPRyqMn77vieih29dB9Wm7Aju J0UrKi3aiVZr0OThOOzYd8lC8+GKRi5Qps+8S3K92B4mSVvoaKJi+WNgx7l5245djyK/ 4LxCHiGjBFTgPO9dw3Dlnc9vSnZEkxKn/5bmJhTgTcTTJnpiSTQ4/rdbiAn8WooNH06e VyHS/+6Y4Yc9c4dMV3nlFDWSkWoHKne5Fg+vPX8kwSMRqbU+GBZhdlG1m8Lv4A2k31fa YvxylEmJ8dSLH6jSOvuLi1W0YV+/Dw4N522s2h74e4wnhM1RSEljTm81zUbRFzU+Yf5q vHzQ== X-Forwarded-Encrypted: i=1; AKwUvBy4mzv3C1bSug5jz+dTj0rTsT1lfE0ovBZqh4yVVMkxG4+w3Kb/1SFag+jZr0tm+rPEqJuTkJqPCAJ0ebU=@vger.kernel.org X-Gm-Message-State: AFuF++mUjcdEA+sYMTnORwB3yM0sgKxYCL/nxqCgAm4aejVaDxNUVdFr sory9MQT7b+uCYwvcrjgwehrReZoQVLtCq8vOHNtGahLnHmKl6X8jocA X-Gm-Gg: AYBFou0RtboEUEXpxK9vEvFbIFhuGgqJflZAW72T9pCVXyorb7Fk1OFJhgZ8rqUP0yE 6v0mjh016St+SLiScP5VkX61RI3PQoe+wnCOCFY8PhELJ0Yku2i9CxyGFi47J3KOh51CTCpLfgE l0dvQJs2JQQ+gKkX8KPE0TObIrXpOd4746YohmfhbLiBRccBXssnRayb3s3EQvaqKOSasDBmPRY r3RpEhf5T+E9gJMcIkyda0e3MusdTX2poyCmitQZmkC1pA/kmRtnDS0ZLVVE2kuqJ0fbq5aLaOx 6xyWWyZmmrDQob08Aka4swgWqYOB/KOcTEo9V7IthXYuppvZWKjwcRVqc7Z8KJcfJy2syYkMxvt DEANk/xlPBPNRPZDS8qCoAsTsvKkE3FNkWX+V3UJepHBWFdLLwX0mlks/3yiTB7Izr3sifDof9h mdMz2g5ej28oNr+sR+XLGrzdcX6WiZi7+KjdAFQVkYlcLkhq/yCnUZrC1TOi77oAQYFimbKMBFm kFt8dVB9qgUty7O3csuc/dxVcv/8XcX7yzD/sezqhDZ2BpfS7MrXFU8wpkKk1e3MLr+Mb5rfiAk cF77QQ5zWBSAIEF6PnLSJgp/1d9BM59rDfohca5biYW9 X-Received: by 2002:a17:90b:28cd:b0:38e:c7b0:84ad with SMTP id 98e67ed59e1d1-39d9b983602mr13970959a91.0.1789200642156; Sat, 12 Sep 2026 01:10:42 -0700 (PDT) Received: from 0xiviel.ip (122-63-135-80.mobile.spark.co.nz. [122.63.135.80]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39db7ae6d25sm982474a91.1.2026.09.12.01.10.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 12 Sep 2026 01:10:41 -0700 (PDT) From: Eva Crystal <0xiviel@gmail.com> To: Min Ma , Lizhi Hou Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Eva Crystal <0xiviel@gmail.com> Subject: [PATCH 2/4] accel/amdxdna: bound the command error payload length Date: Sat, 12 Sep 2026 20:10:10 +1200 Message-ID: <20260912081012.2274075-3-0xiviel@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260912081012.2274075-1-0xiviel@gmail.com> References: <20260912081012.2274075-1-0xiviel@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" amdxdna_cmd_set_error() computes the length of the region it scribbles over from the BO size, without a floor: memset(cmd->data, 0xff, abo->mem.size - sizeof(*cmd)); if (err_data) memcpy(cmd->data, err_data, min(size, abo->mem.size - sizeof(*cmd))); abo->mem.size is a size_t and sizeof(struct amdxdna_cmd) is 4 - the struct is a u32 header followed by a flexible array. A BO smaller than four bytes therefore turns both lengths into a value near SIZE_MAX, and the min() in the memcpy offers no protection because the underflowed value is the larger operand. No such BO can reach this function today. Command BOs are created by drm_gem_shmem_create(), which PAGE_ALIGN()s the size, so mem.size is either 0 or at least PAGE_SIZE. Zero is reachable - PAGE_ALIGN() wraps for sizes above ULLONG_MAX - PAGE_SIZE + 1, and nothing rejects it on the share-BO path - but a zero-sized BO cannot be vmap()ed, because vmap() refuses a zero-page mapping, so amdxdna_gem_vmap() returns NULL and the !cmd test above rejects the BO before the subtraction. This is not a fix for a reachable bug. That leaves an unguarded size_t subtraction feeding a memset() length, whose safety depends on a property of a different allocator and on vmap()'s behaviour for a zero-page request. Compute the length once, reject a BO too small to hold the header, and use the result for both the memset() and the memcpy() bound. Signed-off-by: Eva Crystal <0xiviel@gmail.com> --- drivers/accel/amdxdna/amdxdna_ctx.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/am= dxdna_ctx.c index 163b5fc..c24bf1c 100644 --- a/drivers/accel/amdxdna/amdxdna_ctx.c +++ b/drivers/accel/amdxdna/amdxdna_ctx.c @@ -152,6 +152,7 @@ int amdxdna_cmd_set_error(struct amdxdna_gem_obj *abo, struct amdxdna_client *client =3D job->hwctx->client; struct amdxdna_cmd *cmd =3D amdxdna_gem_vmap(abo); struct amdxdna_cmd_chain *cc =3D NULL; + size_t data_size; =20 if (!cmd) return -ENOMEM; @@ -173,9 +174,16 @@ int amdxdna_cmd_set_error(struct amdxdna_gem_obj *abo, return -ENOMEM; } =20 - memset(cmd->data, 0xff, abo->mem.size - sizeof(*cmd)); + if (abo->mem.size < sizeof(*cmd)) { + if (cc) + amdxdna_gem_put_obj(abo); + return -EINVAL; + } + data_size =3D abo->mem.size - sizeof(*cmd); + + memset(cmd->data, 0xff, data_size); if (err_data) - memcpy(cmd->data, err_data, min(size, abo->mem.size - sizeof(*cmd))); + memcpy(cmd->data, err_data, min(size, data_size)); =20 if (cc) amdxdna_gem_put_obj(abo); --=20 2.53.0 From nobody Fri Sep 25 12:37:38 2026 Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 475283A1D05 for ; Sat, 12 Sep 2026 08:10:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.140 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789200648; cv=none; b=ZDYoHOw5WhxVVRi5ToLN+TaoRbErMbzIrWz5sF68NCGf4gr5prdWSmLBpnl8HxbnkDe0WsF3LF6yuhwl6cA4vnWhsiboE1uXqH57daF8a8sIuT7JOrg3zce6UL0CjSvVun+/bBJgF1ereiEmNp9NzH+rXdO8zApEyGLolOULL+U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789200648; c=relaxed/simple; bh=mUKHHlQooGLT59Ah3RqD2AYxc1c/y9A2ALw5tBIdqtU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=E1kJZ8N8HaU3CqrHdEE462hti20tYFupXdKN+HTSrasAOblkDNyDY6yCwhAd8w+MQR8F5aMwajWlc9FoxpEMYbU0ovuOTIM3QEzbIbqKifvVUNZqBLuJaknocdMPx4/5ep3arO2RTmvqvdApgmLKtq+dWO8GYQL6LiIDsyYbDXQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FDeOOpX0; arc=none smtp.client-ip=74.125.227.140 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FDeOOpX0" Received: by mail-pj2-f12.google.com with SMTP id 98e67ed59e1d1-39d654f02baso302049a91.3 for ; Sat, 12 Sep 2026 01:10:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789200646; x=1789805446; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qekC0MqEXMTW5BJCD+Nqo9MkepvtatwwVDmZuLTl4rg=; b=FDeOOpX0FJG+9c1566VUXdQTzGODd7YY8f7YKjXJEz5g9eGwmueU6iFjvcZCV3+9n8 d93l+nVpbYrrsVQ9rdBPZtWaVKfyHvJKvyVT4919NbsSG+0oxI576ju87SQfPl3ukiJO kfUWSr6wntmlp6d2b1K+7PAOEcGbueJRdzO9uerOURGRLoH5CydmanWVt/PuGqCcAt5H 7HYBIwEi1M+T23NaSvBQTmwjjzOWxornarBLXVSRN7zlUzt2X9VPwm0SI2b6ejzc1WWo Li1dlloLvImVWUWC0/i6S/4hoxIjnq2DJ/ysgWEQBTh0Vw+AM8mHYWjaYWHcQSUIjLsh b9jg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789200646; x=1789805446; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=qekC0MqEXMTW5BJCD+Nqo9MkepvtatwwVDmZuLTl4rg=; b=MQfKwvEilWSUOd/5m0lWX+2j9gpHQbQyuvTRM7M8lPMQsJ8yUnwSP9dXzOSzqWXPfV YWlXeoy1yl6rPGHBf/CkH2IVriPuqVpVc7v2PExk+y8mPLfuqajs4kbcXa1l2VwJ6xlD UCdRDlcNt/7zmGMsHAnsrUPz5dXU82naUG5/hqbTRMM8QEFfgT0CdXbud7AZVP1ou5xl y3H4wntNPaVi0E2zSqXOSQrMnIRRL4gKptJBRtK9NTRsfChi8E1Sk6fIGRG9ySgehya7 lhwP/HD+++fs5gadCkKe49JFDqphZk2QAWQ+lsTH4p8ZYBbP43u0eiU8jHEk5wpcyisz E9eg== X-Forwarded-Encrypted: i=1; AKwUvBxU2US5qUGRbjzYgs7WUhmra06td0tmACJ+VnYf0UchLqBNNmVDedImKwfKiCNHsTCfXj4BX9p2qWtqkrM=@vger.kernel.org X-Gm-Message-State: AFuF++kmd1GyKSRcVRfxskYqUKsLfoxKvBdEB682TQS0TiTRqEKpTduH z1PNjtkgjsJ3dt4Ta/yMCqEKxTOOTFoc2TYLDSWFJDuN2uuVMVAXKUuyGUuXnsuYbFU= X-Gm-Gg: AYBFou2WPz9wo0axCbCe/jXwMneDBTt9jAlbfKXnw3eW9MfsAsFemvNJPVtfRBQzJyA VeUh2z4M3z+5+OKKsLUA37+2ZU6w4q3LPXwYCAdUhl4yWc6fJb65QM8UhRGwmtilBvDYHuxQshO EMGj27EM0qj6d1v0ppazGcmXOGmFY6INMIcKlpaEl6ZvWBVqv/rFrmi082lpN+pdD5OC98tmSgN 3vWWOCIizaDysMmjqz+8hbQInOJUoXcH2eGeFMAkrySwCEzbpiQchUs8Bo22sba4WMsw4l9NXHw z9sHBecdF1VNwTass3J7+qZ/x0qEgWkfLGkAiLFBdLwLwDfEvtuT/LE+ztemxevkSiQZq9Ld8f4 JIHZPz13AGiqJ2cgsBQg1iINGbpFVKgGUQqzUYhOBv68M25t/3/BoTjpZ8SZye+ChUHCWuOlpUM tjgoib2z1cUg+XabWq7Yje5VJXjYwDsPw56KiR/39AsxepDg7FWhbOZiYzV/N2O2396U4GN8OCj daXDlCCmOhplq92wsJGpITDFpb68y1wUOhTl+XYIdpmXrxazvqQLOmyu4Fi9Ev+zYaFTNla1AN7 2wj2spF1dcEc0RMXC4Ek/MIgkfyCnGj+Hyjf0qsDSXGT X-Received: by 2002:a17:90b:57c6:b0:381:a766:efc9 with SMTP id 98e67ed59e1d1-39dbbeb57a5mr3434433a91.7.1789200646524; Sat, 12 Sep 2026 01:10:46 -0700 (PDT) Received: from 0xiviel.ip (122-63-135-80.mobile.spark.co.nz. [122.63.135.80]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39db7ae6d25sm982474a91.1.2026.09.12.01.10.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 12 Sep 2026 01:10:46 -0700 (PDT) From: Eva Crystal <0xiviel@gmail.com> To: Min Ma , Lizhi Hou Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Eva Crystal <0xiviel@gmail.com> Subject: [PATCH 3/4] accel/amdxdna: release the chained command BO when vmap fails Date: Sat, 12 Sep 2026 20:10:11 +1200 Message-ID: <20260912081012.2274075-4-0xiviel@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260912081012.2274075-1-0xiviel@gmail.com> References: <20260912081012.2274075-1-0xiviel@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When amdxdna_cmd_set_error() follows a command chain it takes a reference on the BO named by the chain: abo =3D amdxdna_gem_get_obj(client, cc->data[0], AMDXDNA_BO_SHARE); if (!abo) return -EINVAL; cmd =3D amdxdna_gem_vmap(abo); if (!cmd) return -ENOMEM; and drops it at the end of the function under "if (cc)". The -ENOMEM path returns before reaching that, so the reference taken by amdxdna_gem_get_obj() is leaked and the GEM object is never freed. amdxdna_gem_vmap() fails only if drm_gem_vmap() fails, which needs memory pressure or an exporter that refuses the mapping, so this is a small leak on a rare path rather than something a caller can drive at will. It is still a leak, and the chain BO handle comes from a command buffer user space can write. Drop the reference before returning. Signed-off-by: Eva Crystal <0xiviel@gmail.com> --- drivers/accel/amdxdna/amdxdna_ctx.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/am= dxdna_ctx.c index c24bf1c..7a61e83 100644 --- a/drivers/accel/amdxdna/amdxdna_ctx.c +++ b/drivers/accel/amdxdna/amdxdna_ctx.c @@ -170,8 +170,10 @@ int amdxdna_cmd_set_error(struct amdxdna_gem_obj *abo, if (!abo) return -EINVAL; cmd =3D amdxdna_gem_vmap(abo); - if (!cmd) + if (!cmd) { + amdxdna_gem_put_obj(abo); return -ENOMEM; + } } =20 if (abo->mem.size < sizeof(*cmd)) { --=20 2.53.0 From nobody Fri Sep 25 12:37:38 2026 Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D9D2B37FF6D for ; Sat, 12 Sep 2026 08:10:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.140 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789200653; cv=none; b=m3SsVBqRZtaipDkcNpKBd9+EGUKGAV/C/4jJc5b/X4fMz0AJJqE9Fjzkc0f5pOVU7k9pWqdwSy0eDbDrH1iYsC/G9xr8taQXnE2vlFf6aD3yrusYLsAmRZIpwSjDSm1TQurfli36CcUVbxL1ggUuDHFTJyAPEVhnis+SMKuLIFY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789200653; c=relaxed/simple; bh=PEAuDrza3Y5SfFxch680LxNXRvad81aZFzbJXkuqqNg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=FJSKzYFHnaJOopktCWTY6kAIo52FzW4GW589H9nf7Vxnqe0a4A+F2rvKQSRzsrlPewuRdXSvKMyp8FjvL3vWZY48URUOKxFwqQDpUXN6g9fSNocBFWYT5fjmzm/kBVkoR9cRqwBDIqeunjnJ9BCOBvkR6IHV2bbqjKIiSy4CZGU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PdLdxd3x; arc=none smtp.client-ip=74.125.227.140 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PdLdxd3x" Received: by mail-pj2-f12.google.com with SMTP id d9443c01a7336-2db1ca069c8so3066315ad.3 for ; Sat, 12 Sep 2026 01:10:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789200651; x=1789805451; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0GoExsibafFWCOKZx2T64mk+4e5+1pi6zhVko5O9cFc=; b=PdLdxd3x82JHgWwp9kLIMk8pb6LAetk/Dm0o1OZ3tMue1Jw2ciaKQB86dxM+weJJqd T5YH3S+2UrLRLoAuTqqGN/98GdyUz3sFLFwR4R2rHtqOc6MITT14rjk47KvruJ8eW/a2 6ODPmiACmbjwVSnpKpVchcFOjEHvCKhXMWi0n5v5uVNWAf3zxyZuyyZzF1cfN+kXhugj rfunve3bJtSZKq6ZZlFUGdsMPQF3ORUc8to7pghCo1/8TdMoiurCHwqxdydYvxhTYFBU b6LquAlJhb+CSE1y4AGbOhHbSe/TtUiKG9z+Enhhh9zGvm3P4WlLgfEPbA8VpRZMd+4B 63DA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789200651; x=1789805451; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=0GoExsibafFWCOKZx2T64mk+4e5+1pi6zhVko5O9cFc=; b=dRcNyuoESrdRinZTWaWBKXoVqM4l5iP8xMRihWlruxpetf7fPyHABvE3t1cq+cFImh 8pBY6xZ2Ae58bJN7kcJUBHNnvGwKYlDzjR4by2kcWo6em9SopflAsZiNqIxdlGeVG+yB oDMJaL+71ESuknOvFxl7vuNaHLl2dxWoRpNktijm82Y+kCRBImGWEpecvZ8ewIqgmbIN XbmvTtFMwKzCAZmP4BGnYQd60az1a/y5g4j/OVdL5MYHrxwMVf2SLxtN1Eq1/yZQYEOQ nP4UNUKveP6lrL/5oURJfN8jGCu492WI32wO2B8dDtmS7cKQSYj+A2oMNJl/84X64/sC 3IAw== X-Forwarded-Encrypted: i=1; AKwUvBwgL2gV6gvKanICANoPklpt4u/jsqYjl6KtNadhnKOYRtR8Xal3hsSgw1Kt3kv/O44USwJcKmG+5oL3WXI=@vger.kernel.org X-Gm-Message-State: AFuF++n+hk5a/toaRB5YHpxNCqLIM7sNtqzKgpFKng3nJ/hQ7oJsoc5C YRVPAhc9QM7cvgOJi8whU89hjAmzqLyUNJNLgoX0EubkaFyZzco6vBkG X-Gm-Gg: AYBFou1NUJoQnGSFiIrJBbQD450S0YrCmYCGlAdve46kKBxIomFAiXMAaczcINLau2N eqXp4dXknl6GyMnxIWC7fqAVZVS3SokxXp7qMnT6jqA4mKepgQzPRPBTpX905qxpkU7i/2ceD3o 2dm1j+65rAz3SlA/T2phD5LpehSmMoMFIYG/yv1+DBuGSoDic7UfAEsfRxGEkeOszXKXeXGVlaC aLVl56GvGIOFOpVZbgdh0Yp6A3ydgZjgNQ4ZyySKrK80+G0a0XeEhqcMQ9hoxbZRRqGJerw+mmC r/HeDd9XentsDbwRNkcF47wRCXpLp+WNDQR2sd6X5YJG6csASV0YQYLgqX03sUnV0popysH0vg+ W7Epgg9OD74zNstEK7ycaSS7ixxur9ICVQx2jj8yS/2Ge2xkp+Ni14cMcbidPWPPXkgQTgQO5kK E6G5cTEIHyx4Qf5w6yoY6EPccNDptYVyL5Fxg2g8XI4RZDIUOAP29eCQetjrs7YNJQL/vsPNtQz PvfyDkpLC/LxuWVBL18Xku6Lb1d2nZjza4e2csgDF4auZOsEkIfwFQIb1u6dM7HkUj0OW2gNmpA 6lnfhcah8gCzV3mTBoN25XmllaP2QeLui9HiPHGRjvs1 X-Received: by 2002:a17:90b:1d82:b0:381:1c96:829b with SMTP id 98e67ed59e1d1-39dbbe8b88bmr3419988a91.3.1789200650925; Sat, 12 Sep 2026 01:10:50 -0700 (PDT) Received: from 0xiviel.ip (122-63-135-80.mobile.spark.co.nz. [122.63.135.80]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39db7ae6d25sm982474a91.1.2026.09.12.01.10.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 12 Sep 2026 01:10:50 -0700 (PDT) From: Eva Crystal <0xiviel@gmail.com> To: Min Ma , Lizhi Hou Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Eva Crystal <0xiviel@gmail.com> Subject: [PATCH 4/4] accel/amdxdna: check the command payload before using it in the exec requests Date: Sat, 12 Sep 2026 20:10:12 +1200 Message-ID: <20260912081012.2274075-5-0xiviel@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260912081012.2274075-1-0xiviel@gmail.com> References: <20260912081012.2274075-1-0xiviel@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" aie2_init_exec_dpu_req() takes the payload of a command BO and subtracts the fixed header from its length before establishing that the length covers the header at all: sn =3D amdxdna_cmd_get_payload(cmd_bo, &cmd_len); if (cmd_len - sizeof(*sn) > sizeof(dpu_req->payload)) return -EINVAL; ... dpu_req->inst_buf_addr =3D sn->buffer; memcpy(dpu_req->payload, sn->prop_args, cmd_len - sizeof(*sn)); It also dereferences sn without testing it, although amdxdna_cmd_get_payload() returns NULL for a command header whose count field does not fit the BO, setting cmd_len to 0 as it does so. Both work out today, and for the same reason: cmd_len is a u32 and sizeof() is a size_t, so the subtraction is evaluated in 64-bit. A short command produces a value near 2^64, which is larger than the payload field, so the test returns -EINVAL before sn is dereferenced and before the memcpy. The NULL case is caught by the same comparison, because cmd_len is then 0. The guarantee is therefore supplied entirely by the operand types. A later change that computes the difference into a u32 first - as the sibling slot-filling functions in this file already do - would truncate the underflow to a small value, and the function would dereference NULL and copy from a short payload. Those siblings, aie2_cmdlist_fill_dpu() and friends, all carry an explicit "cmd_len < sizeof(*sn)" test for exactly this reason; this path was left without one. Add the explicit length and NULL tests here, matching the siblings, and add the missing NULL test to aie2_init_exec_cu_req(), which copies cmd_len bytes from a pointer it likewise never checks. No behavioural change is intended: every input rejected by the new tests is already rejected today. Signed-off-by: Eva Crystal <0xiviel@gmail.com> --- drivers/accel/amdxdna/aie2_message.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/drivers/accel/amdxdna/aie2_message.c b/drivers/accel/amdxdna/a= ie2_message.c index 3028968..ab9e7c4 100644 --- a/drivers/accel/amdxdna/aie2_message.c +++ b/drivers/accel/amdxdna/aie2_message.c @@ -556,7 +556,7 @@ static int aie2_init_exec_cu_req(struct amdxdna_gem_obj= *cmd_bo, void *req, void *cmd; =20 cmd =3D amdxdna_cmd_get_payload(cmd_bo, &cmd_len); - if (cmd_len > sizeof(cu_req->payload)) + if (!cmd || cmd_len > sizeof(cu_req->payload)) return -EINVAL; =20 cu_req->cu_idx =3D amdxdna_cmd_get_cu_idx(cmd_bo); @@ -578,7 +578,8 @@ static int aie2_init_exec_dpu_req(struct amdxdna_gem_ob= j *cmd_bo, void *req, u32 cmd_len; =20 sn =3D amdxdna_cmd_get_payload(cmd_bo, &cmd_len); - if (cmd_len - sizeof(*sn) > sizeof(dpu_req->payload)) + if (!sn || cmd_len < sizeof(*sn) || + cmd_len - sizeof(*sn) > sizeof(dpu_req->payload)) return -EINVAL; =20 dpu_req->cu_idx =3D amdxdna_cmd_get_cu_idx(cmd_bo); --=20 2.53.0