From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ed1-f47.google.com (mail-ed1-f47.google.com [209.85.208.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 731FA432BE3 for ; Wed, 5 Aug 2026 11:14:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.47 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785928449; cv=none; b=XeZnx+gP14KWvuNq7s006mtDSKkjcNiaM211yYOBHvcvifSaiStuRu83Bpbkv/G2oloolpRSUgMYg7uqAP09hm60T8J7ZcuB9biEqpC/jyCxI/PjZyHts4MiRLtHPExZB2RAd5AgCY3ldV4+7ViF8jSnJ2U8do0SjpDgXfWCDMI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785928449; c=relaxed/simple; bh=Jo/AsdzuGi6AwyHY7kedSutWW51rq4D6xxEDvPXtQuc=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References; b=bxEZn/g5zFaHQyoXytVLSqUoJqeE8h+xETgsK4fwEJRCRW7Fj83mnSpF3VVi39DrK1VR9Ik+O3JXtwg2M07QoLMbuqkyyvf/bnZWJPSCng40B3YwQrKIMCk34a78Nrl13zzcjtTEa6ixGpPXYV3l3NWm3gZj+i31j/eJ11+69yY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=O0g7yoRT; arc=none smtp.client-ip=209.85.208.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="O0g7yoRT" Received: by mail-ed1-f47.google.com with SMTP id 4fb4d7f45d1cf-6983f20a8bfso1353788a12.1 for ; Wed, 05 Aug 2026 04:14:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785928446; x=1786533246; darn=vger.kernel.org; h=references:in-reply-to:message-id:date:subject:cc:to:from:from:to :cc:subject:date:message-id:reply-to:content-type; bh=fAwxijsOB25NoBSDeTerpI8z8eF1PLas5teFEBq0ElE=; b=O0g7yoRTrK52aOn9M06h6BHNz+8azRe8+rlB0velhKz1oZP4uq0t1xZ7DmL+YYBAHZ T68Z7uzOPbRuOFPWy7RTNU6uIDiZOCA4dgA7TxY5T/8KVi2fm2k965xA/8JXl6BXW2Or bC/CgKk9oY6gDFI9X2ifqfg9IxmfYWs7QaJFx98OCLLhS2yX76Q4XwvZWN4Ybz3FV9Ab KJFf65m0N8agUrL+gaxh64xPCK1IiM0eMcNgUKJrfq97Yclr9uvpVimYz57SKnNuonQ+ RkdPq5g4yusMVVJeoJdynAxAhdKD7qUsKuh03D1bBHZqis54Qs0rSdo1VRxJ+lIZv650 /KMw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785928446; x=1786533246; h=references:in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=fAwxijsOB25NoBSDeTerpI8z8eF1PLas5teFEBq0ElE=; b=l+arWZ9m8BcWGMkwg28wQWIx71wTm8B1crdz3A3B2fplb/fpNQ7ME0AgDzjxreSSw/ B7vcBKWi38LWzmYgpEXG87N98ngt0cXdQzYP3p+R8YYiTz0PistDYGR47lpFoz5oBSti DYUQP4g7cSma7wI6s6IKlSenM581khtwEYhYcL0ocQs239Rbo3L8dJjhYuDEmxS7jsxE B1w7z79b5OQO9q+vB7TIvMXyVw1/pr+B+TzB/L6ssKLWHhDHtyxI7uGQ+ZINyAFvQ971 eoa8fTOxkgMZDTaZ8182Qwja/cvQEXxnKYHXf7F62QMEgHqLDMh+sJK9+B4QZ9H/W1QE YeDg== X-Forwarded-Encrypted: i=1; AHgh+Rq15oA7xb34YBq6VCHrAkoKufRHdzdtyLdiwqWUbYS3wjODFFLvOwY8ly7Nxb2OTklGg7xbbvPCuw3BndA=@vger.kernel.org X-Gm-Message-State: AOJu0Yx6mLPCtbDQjspXsN1cYguEaxAcQHPaW5ejx/VI4YWyS2uF7J56 ORmzca1QN/wRJ0pPBaZjKVWn47psjoWlQuGpB1XA/efZ25lAgdWRrJb7RefbK0Ka X-Gm-Gg: AR+sD13eIlQTF5kPb6NFuBNFzvON5Rw2PbnZrdA7vBtZRXYizh7yp8etcFiqW6Y6qWo 6F1KcXo+Cqzlzv4XOasnOOTCc7zb/bcXhlCQGiQtY7ooOnbHIMEmL2iKF6VvGY6F+4QvMyzLWrg OC6p7oC/QrN37cHwa870ht+xVMKGuAAZxze74HJHIZgPPKoj62+hKHLzuxQvva21l2jgcgGsiEq HRnW8yJ5xgI6JWgeTp81uDuLhwjxMyp+FeSU8DS+KGgZHbjPiZCOLbZCQRiMQ3j6AFqd2Vd7Amx RgTSPN9bhBNSkMrvwrDob4EzyWa86f4qi0eZb6YDQqdP1STsCrsmfTcmZWrV3NnZFo6sXOmqQaV JRs4wJnt92NHPIPuqOaAtljIjJ7+6ZVaUhzc5tjxGac0ZKRUHByG3ViEAIKMxYi6Zr7nA/wQkyK le2ZOhFIGuXMuqoQBkyZO4reZUlwgYfB8ipNLHemygu/KgTaLrYAwo/88Toa2Zv99j8HMhqHo6g YLTXS0+8Jvi7nbt X-Received: by 2002:a05:6402:4515:b0:6a0:33f6:13b4 with SMTP id 4fb4d7f45d1cf-6a14f13c34dmr3120438a12.13.1785928445506; Wed, 05 Aug 2026 04:14:05 -0700 (PDT) Received: from localhost (c-85-228-45-68.bbcust.telenor.se. [85.228.45.68]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a17d6216cesm485106a12.31.2026.08.05.04.14.03 (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Wed, 05 Aug 2026 04:14:04 -0700 (PDT) From: Eli Billauer To: gregkh@linuxfoundation.org Cc: arnd@arndb.de, linux-kernel@vger.kernel.org, corbet@lwn.net, Eli Billauer Subject: [PATCH v5 6/7] char: xillybus: Add defensive sanity checks Date: Wed, 5 Aug 2026 13:13:36 +0200 Message-Id: <20260805111337.69178-7-eli.billauer@gmail.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20260805111337.69178-1-eli.billauer@gmail.com> References: <20260805111337.69178-1-eli.billauer@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Add validation checks for values derived from hardware or user input to prevent incorrect behavior with malformed data. Assisted-by: Deepseek:v4-pro Kimi:K2.6 ChatGPT:GPT-5.5 Claude:Sonnet-4.6 Signed-off-by: Eli Billauer --- Notes: Changelog: ========= No change on v4->v5. Changes v3->v4: -- xillyusb.c: Use mutex_unlock() in response to sanity check failure in fifo_init(), as guard() isn't used anymore on this mutex. -- xillyusb.c and xillybus_core.c: Remove sanity check on data count on read() and write() fops methods, as this check is already done by the kernel's vfs_read() and vfs_write(). Changes v2->v3: -- Add Assisted-by tag to description Changes v1->v2: -- xillybus_class.c: Assign @rc a value before goto in xillybus_init_chrdev(). -- xillybus_class.c: Improve check on @inode in xillybus_find_inode(). -- xillybus_of.c: Remove redundant dev_err(), as platform_get_irq() outputs an error message if necessary. drivers/char/xillybus/xillybus_class.c | 18 +++++++++++++-- drivers/char/xillybus/xillybus_class.h | 3 +++ drivers/char/xillybus/xillybus_core.c | 31 ++++++++++++++++++++++++-- drivers/char/xillybus/xillybus_of.c | 3 +++ drivers/char/xillybus/xillyusb.c | 25 ++++++++++++++++++++- 5 files changed, 75 insertions(+), 5 deletions(-) diff --git a/drivers/char/xillybus/xillybus_class.c b/drivers/char/xillybus/xillybus_class.c index 5e8f03b77064..f7e0da233e2a 100644 --- a/drivers/char/xillybus/xillybus_class.c +++ b/drivers/char/xillybus/xillybus_class.c @@ -57,6 +57,9 @@ int xillybus_init_chrdev(struct device *dev, size_t namelen; struct xilly_unit *unit, *u; + if (num_nodes <= 0 || num_nodes > XILLYBUS_MAX_NODES || !idt || !prefix || !dev) + return -ENODEV; + unit = kzalloc_obj(*unit); if (!unit) @@ -68,6 +71,12 @@ int xillybus_init_chrdev(struct device *dev, snprintf(unit->name, UNITNAMELEN, "%s", prefix); for (i = 0; enumerate; i++) { + if (i > 99) { + dev_err(dev, "Failed to obtain unique unit name\n"); + rc = -ENODEV; + goto fail_obtain; + } + snprintf(unit->name, UNITNAMELEN, "%s_%02d", prefix, i); @@ -215,10 +224,15 @@ EXPORT_SYMBOL(xillybus_cleanup_chrdev); int xillybus_find_inode(struct inode *inode, void **private_data, int *index) { - int minor = iminor(inode); - int major = imajor(inode); + int minor, major; struct xilly_unit *unit = NULL, *iter; + if (!inode || !private_data || !index) + return -ENODEV; + + minor = iminor(inode); + major = imajor(inode); + mutex_lock(&unit_mutex); list_for_each_entry(iter, &unit_list, list_entry) diff --git a/drivers/char/xillybus/xillybus_class.h b/drivers/char/xillybus/xillybus_class.h index 5dbfdfc95c65..4dbed9adcaf8 100644 --- a/drivers/char/xillybus/xillybus_class.h +++ b/drivers/char/xillybus/xillybus_class.h @@ -8,6 +8,9 @@ #ifndef __XILLYBUS_CLASS_H #define __XILLYBUS_CLASS_H +#define XILLYBUS_MAX_NODES 1024 +#define XILLYBUS_MAX_IDT 1048576 + #include #include #include diff --git a/drivers/char/xillybus/xillybus_core.c b/drivers/char/xillybus/xillybus_core.c index 3ae95e6b17e9..fc489908c40c 100644 --- a/drivers/char/xillybus/xillybus_core.c +++ b/drivers/char/xillybus/xillybus_core.c @@ -351,6 +351,12 @@ static int xilly_get_dma_buffers(struct xilly_endpoint *ep, struct device *dev = ep->dev; struct xilly_buffer *this_buffer = NULL; /* Init to silence warning */ + if (bytebufsize == 0 || bytebufsize > 0x40000000) { + dev_err(ep->dev, + "Illegal buffer size requested in IDT. Aborting.\n"); + return -ENODEV; + } + if (buffers) { /* Not the message buffer */ this_buffer = devm_kcalloc(dev, bufnum, sizeof(struct xilly_buffer), @@ -623,6 +629,12 @@ static int xilly_scan_idt(struct xilly_endpoint *endpoint, return -ENODEV; } + if (count == 0 || count > XILLYBUS_MAX_NODES) { + dev_err(endpoint->dev, + "Unreasonable number of channels. Aborting.\n"); + return -ENODEV; + } + idt_handle->entries = len >> 2; endpoint->num_channels = count; @@ -725,8 +737,18 @@ static ssize_t xillybus_read(struct file *filp, char __user *userbuf, bufidx = channel->wr_host_buf_idx; bufpos = channel->wr_host_buf_pos; howmany = ((channel->wr_buffers[bufidx]->end_offset - + 1) << channel->log2_element_size) - - bufpos; + + 1) << channel->log2_element_size); + + if (howmany > channel->wr_buf_size || + howmany < bufpos) { + dev_err(channel->endpoint->dev, + "Illegal buffer fill level from hardware\n"); + channel->endpoint->fatal_error = 1; + spin_unlock_irqrestore(&channel->wr_spinlock, flags); + break; + } + + howmany -= bufpos; /* Update wr_host_* to its post-operation state */ if (howmany > bytes_to_do) { @@ -1902,6 +1924,11 @@ int xillybus_endpoint_discovery(struct xilly_endpoint *endpoint) return -ENODEV; } + if (endpoint->idtlen < 4 || endpoint->idtlen > XILLYBUS_MAX_IDT) { + dev_err(endpoint->dev, "Invalid IDT length. Aborting.\n"); + return -ENODEV; + } + /* Enable DMA */ iowrite32((u32) (0x0002 | (endpoint->dma_using_dac & 0x0001)), endpoint->registers + fpga_dma_control_reg); diff --git a/drivers/char/xillybus/xillybus_of.c b/drivers/char/xillybus/xillybus_of.c index 46e1046abfca..44b0c754deb2 100644 --- a/drivers/char/xillybus/xillybus_of.c +++ b/drivers/char/xillybus/xillybus_of.c @@ -53,6 +53,9 @@ static int xilly_drv_probe(struct platform_device *op) irq = platform_get_irq(op, 0); + if (irq < 0) + return irq; + rc = devm_request_irq(dev, irq, xillybus_isr, 0, xillyname, endpoint); if (rc) diff --git a/drivers/char/xillybus/xillyusb.c b/drivers/char/xillybus/xillyusb.c index e2270a64b659..5b6a15962885 100644 --- a/drivers/char/xillybus/xillyusb.c +++ b/drivers/char/xillybus/xillyusb.c @@ -396,6 +396,12 @@ static int fifo_init(struct xillyfifo *fifo, fifo->size = fifo->bufnum * fifo->bufsize; fifo->buf_order = buf_order; + if (!fifo->size || /* Unsigned integer overflow */ + fifo->size > 0x40000000) { /* Avoid signed int issues */ + mutex_unlock(&fifo_buf_order_mutex); + return -ENOMEM; /* Reported as greed for memory */ + } + fifo->mem = kmalloc_array(fifo->bufnum, sizeof(void *), GFP_KERNEL); if (!fifo->mem) { @@ -893,6 +899,7 @@ static int process_in_opcode(struct xillyusb_dev *xdev, struct xillyusb_channel *chan; struct device *dev = xdev->dev; int chan_idx = chan_num >> 1; + struct xillyfifo *in_fifo; if (chan_idx >= xdev->num_channels) { dev_err(dev, "Received illegal channel ID %d from FPGA\n", @@ -917,7 +924,10 @@ static int process_in_opcode(struct xillyusb_dev *xdev, */ smp_wmb(); WRITE_ONCE(chan->read_data_ok, 0); - wake_up_interruptible(&chan->in_fifo->waitq); + + in_fifo = READ_ONCE(chan->in_fifo); + if (in_fifo) + wake_up_interruptible(&in_fifo->waitq); break; case OPCODE_REACHED_CHECKPOINT: @@ -2077,6 +2087,13 @@ static int xillyusb_discovery(struct usb_interface *interface) } idt_len = READ_ONCE(idt_fifo.fill); + + if (idt_len < 4 || idt_len > XILLYBUS_MAX_IDT) { + rc = -ENODEV; + dev_err(&interface->dev, "Invalid IDT length. Aborting.\n"); + goto unfifo; + } + idt = kmalloc(idt_len, GFP_KERNEL); if (!idt) { @@ -2111,6 +2128,12 @@ static int xillyusb_discovery(struct usb_interface *interface) goto unidt; } + if (num_channels == 0 || num_channels > XILLYBUS_MAX_NODES) { + dev_err(&interface->dev, "Unreasonable number of channels. Aborting.\n"); + rc = -ENODEV; + goto unidt; + } + rc = setup_channels(xdev, (void *)idt + 3, num_channels); if (rc) -- 2.34.1