From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C85C53B8920 for ; Wed, 29 Jul 2026 20:52:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785358375; cv=none; b=dzAFhmFU/3bI9odruJ6Z8RG+YcobhhXSCq1fH6BHSrNk9X0gQ9QRJjDGmhFq7rOXBAK7VvLYOyBl7qTHv4WipFAPkCwFe7hFaUiwyMjBfagwVwDFw2MR0eaCVw9FdvzZaSqaZGYKOQfC3qhB6aqhBC4yASIm486668pQ0qlAFo4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785358375; c=relaxed/simple; bh=vD/s6wza0g9D+mKcX5bzPQ93KpB79g9VydwRgG15eM8=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=Jfb0tv/QhD8vm17v0bjYFG7HepYjdBW2qrt4Lv++00agvFetXI2lYdXo4EgcY80b9ZZNjL2dHKASqIxLPvpG6gePkpceOB5h2i1bniJN28aAGXsQBvhmyXvRXliR25BZUtYLED4/obYo0FEVVb+H8g9+kTj//jhFJew8nXxwOyA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Od9m5I16; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=XcoHCiF7; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Od9m5I16"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="XcoHCiF7" Received: from pps.filterd (m0279864.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66TJq8e12354533 for ; Wed, 29 Jul 2026 20:52:54 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= critbA2mnXZKO3iDwpU36SfNN90IioeFvggdcTePRqw=; b=Od9m5I16gMZP8va2 BWOWBBeX1lTjGgULKVTorUrJorHn+qPo+FYF/S/1+i/dj2Bbo3tWt25xVkxNL0o1 gDNqIeP4VbGOCiKkIe/PGHJx1G8XZYA//FnSTyWc/9hpJ5suiuURaW8t/EFBz9EW w7V8a2qhpB1UzwDPwENGla9fbqNUEK35VxharlBmcjLXQv5NQvXJ5l4A4zeLopJf dW52PZKEBORHRQZzF7mzyqrus3HGeMVrFU+nQeF813oWza/bQlF8NmTx61Qvnyll KCjCG02TeBTe8L2UIF3p2gW30KuAFWeRywK4jzIWCf1ZYCqtLcxGiN2Nt71Yi41p KfH8Nw== Received: from mail-pf1-f198.google.com (mail-pf1-f198.google.com [209.85.210.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fqr2887tu-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 29 Jul 2026 20:52:53 +0000 (GMT) Received: by mail-pf1-f198.google.com with SMTP id d2e1a72fcca58-8484ba00601so1577210b3a.1 for ; Wed, 29 Jul 2026 13:52:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785358373; x=1785963173; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=critbA2mnXZKO3iDwpU36SfNN90IioeFvggdcTePRqw=; b=XcoHCiF7OBgmlL0nJ7cJDk/ST+JSi2i8mCxtoanw9U/gpZ9KmcergOiSICKwWd4DLo 8IwZVcTxkbpjiNfd1tSbCPlQnZvUonYthBAVX9YtUUO5ryJ40sQrv5Zma/PDUwlCfdrh vi6zzEf3dEAdD6NcnEHyeNVnU4VMeu7vUwTFyOdX8vXl9WDw/sGCOyejjR3P7IrmFHlk qTIoUoijFpXm2cUA0aWt0wg/YFNEIX5y52NCLrttEnmvCXUcvQXAqlslHIYsDq9R5DbD nPCHUSuzLu88nbp0OotcJSklp3XG1z7fsL8FVJoNQjasPmEBhcDbdBhoFeCYAXcwwxK5 +4OQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785358373; x=1785963173; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=critbA2mnXZKO3iDwpU36SfNN90IioeFvggdcTePRqw=; b=GHtIvToIDmQBQU+S6DNM6ch2OV/PZuaJphpFtXBA+vT2T9gZeCIxSzz8xm23MNIF1J Y225gVZX7wj9dNSsBaNlQgrxbqxLUBwxvh74jHLPWRiGoIzeUiFnWYYILet5Dxk6J0SC XWfxcmoazKLxb3mMlx6HsZCZfk22PlSW67yxyc8L+f/QlN96STfDrsYEQEPOohCcYa0T 9/5GOCS3fAQ4AmBaCQ4nTg5ppIuOnhwCOOpmHUF6k2YOdTuBCUM9h0xNqR2cQ1daa+el 7ACu6QsQwCYlnGdMnp6R1j7c+9imGdQ2hKc+LRDgSof9sL4QKSAD4MzNI+OWZJeep+aa M86A== X-Forwarded-Encrypted: i=1; AHgh+RrnbHiHPj24pvtuThg+5kpDcre2W4ISf0/YqcrwCmXg71oTl7SOlt/LAW3DfDWEbzQa7YxMtNXwpudSWHg=@vger.kernel.org X-Gm-Message-State: AOJu0YyETdm7q40mk0P+Ogz7o7bplR1HMlXd8aI7OEFyqR5CflYX82md cEV8LS3X+wfxEaTZwuh04Ap529IeKWcg1v4hMyryHDUrhdl3jAYlJGXmaC0SU2FU9aUW65OqTQn QAiXbWr7WvZBnWnhM3WzjJcqV5SxlJj5+a0UfTFWOUy2RT2r2MPehE/27L8H4e2QVRVE= X-Gm-Gg: AR+sD10R2IajeDdL//ntewL5Dhzp+lZhOPpdlekqe3ixABylRho8l+v9ripu1cmWvss pjNAFBmVkawNPN2TkFgQST/BAIVHBcqnA5LgHxFYkSRRqso87h7z9LSSN6YfaFZvgw4DjtIe1OV js1J9BMGFF/JALED9qtSQz87tCaLjc3kcNAVIlp0AvAd7QyjsoiVipa9rUk2n6cLKf7H7cWBaO1 kwum50wi3qp7xcYIGHrKQ13d1sKHBlXGq/Kp3xf4hD+nL9EomupQxAX2VM1cMFiaEFb1WvNX+fE IXmQm+1mWhXvx+i7mynTuVkDSTnYFs4sSMnJPaE6C82SRxuSyH5wgoBuD/ZCF266gSXIKBmeFsd CXnE+GIr7S90x6WYpZ0Oa+oCSZ3y302q/raPsXxY5svvjWMTu03Hw4g== X-Received: by 2002:a05:6a20:6a0e:b0:3c3:6544:6083 with SMTP id adf61e73a8af0-3c89cadcdbbmr9304001637.0.1785358373340; Wed, 29 Jul 2026 13:52:53 -0700 (PDT) X-Received: by 2002:a05:6a20:6a0e:b0:3c3:6544:6083 with SMTP id adf61e73a8af0-3c89cadcdbbmr9303973637.0.1785358372886; Wed, 29 Jul 2026 13:52:52 -0700 (PDT) Received: from [10.226.59.182] (i-global254.qualcomm.com. [199.106.103.254]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-31504b10cdcsm13512172eec.3.2026.07.29.13.52.51 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 29 Jul 2026 13:52:52 -0700 (PDT) Message-ID: <187d7b00-748c-4056-aec6-b498044fe1c7@oss.qualcomm.com> Date: Wed, 29 Jul 2026 14:52:50 -0600 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] accel/qaic: use sizeof(*trans_hdr) for transaction length check To: Muhammad Bilal Cc: carl.vanderlip@oss.qualcomm.com, ogabbay@kernel.org, dan.carpenter@linaro.org, linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org References: <20260617212520.59801-1-meatuni001@gmail.com> Content-Language: en-US From: Jeff Hugo In-Reply-To: <20260617212520.59801-1-meatuni001@gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Proofpoint-ORIG-GUID: O_ySf9ZS4w9xjkdnw90-j3CZfrsslVpe X-Proofpoint-Spam-Info: AW1haW4tMjYwNzI5MDE1OCBTYWx0ZWRfXyKeZt0N6a+bU OjA+RY7xTyv69vsR+pbn4+xSliOXUZGPNYdHRUG+2+pB6636kyf+wfdcaLoPP9cxcYJY/pwxen5 cHrvgym3nxCxsMwWeoIwdXSytNmSjEg= X-Authority-Analysis: v=2.4 cv=A79c+aWG c=1 sm=1 tr=0 ts=6a6a6825 cx=c_pps a=m5Vt/hrsBiPMCU0y4gIsQw==:117 a=JYp8KDb2vCoCEuGobkYCKw==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=DJpcGTmdVt4CTyJn9g5Z:22 a=pGLkceISAAAA:8 a=EUspDBNiAAAA:8 a=GD8_rapH8p4utXL01xcA:9 a=QEXdDO2ut3YA:10 a=zgiPjhLxNE0A:10 a=IoOABgeZipijB_acs4fv:22 X-Proofpoint-GUID: O_ySf9ZS4w9xjkdnw90-j3CZfrsslVpe X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzI5MDE1OCBTYWx0ZWRfXwNXKFNttGuFX aiv9TBIDJPIvV+9+oMPZXgukw/YycCcoYSjLHbexNe6Wg79lDWlpzEWgErNiA2Hvi4fe6HNUXQu 4T0yhHUWKdsA5m0GorN8oAveMZ7bhtY6iNzek5Qa+cq6Vc5iJSsg+O4Fi0CX3FspBJebRcGjh7c l4Frd+dOre4RYsIwCJJjFAiFFw1dIwzZi+i1SjpgkJ6X2TqsnkWF8ZuSdPVixJgPQJkoUlOQtPw Spt8uasne/NYAq5q3zAp0r9+X5KtVc/y7DXszg4SIzE0Bs3iKlrSUengBQZb2W0rwoCCcxkt+x8 ZQVuGmoxOjInyFR+es5mXy72WwS0lZoTQBraQTFe7/Gc99IxiDWRQhztDqDIjMkI5aaPAayZKc9 r5p4GgzOLhTMxVje1r/ldOE/KzYMaOj0z8cbOVL50qcCaTNlvvoT1HZMqXbbk+YdGjFwO8Heu8S Squ2USZPYs+GEa96BVA== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-29_07,2026-07-29_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 phishscore=0 suspectscore=0 bulkscore=0 adultscore=0 priorityscore=1501 spamscore=0 clxscore=1011 impostorscore=0 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607290158 On 6/17/2026 3:25 PM, Muhammad Bilal wrote: > In encode_message() the per-transaction lower-bound check compares > trans_hdr->len against sizeof(trans_hdr), i.e. the size of the pointer, > instead of sizeof(*trans_hdr), the size of struct qaic_manage_trans_hdr. > > Every other length check in this file (encode_message() at the loop > guard, decode_message(), etc.) correctly uses sizeof(*trans_hdr), so > this is an inconsistency. On 64-bit builds the pointer and the struct > are both 8 bytes, so the check is correct by coincidence and there is > no behavioural change. On 32-bit builds the pointer is 4 bytes, which > weakens the minimum-length check below the 8-byte header size. > > Use sizeof(*trans_hdr) so the check validates against the actual > transaction header size on all builds. > > Fixes: ea33cb6fc278 ("accel/qaic: tighten bounds checking in encode_message()") > Signed-off-by: Muhammad Bilal Reviewed-by: Jeff Hugo