From: Magnus Lindholm <linmag7@gmail.com>
To: richard.henderson@linaro.org, mattst88@gmail.com,
linux-kernel@vger.kernel.org, linux-alpha@vger.kernel.org
Cc: linmag7@gmail.com
Subject: [PATCH v5 3/5] alpha: bound EV6 logout decoding by the processor area
Date: Fri, 9 Oct 2026 13:54:39 +0200 [thread overview]
Message-ID: <20261009115627.969047-4-linmag7@gmail.com> (raw)
In-Reply-To: <20261009115627.969047-1-linmag7@gmail.com>
The ES40 correctable logout frame has only the common CPU registers before
its system area at offset 0x58. The EV6 decoder treats those system words
as extra CPU registers and reads beyond the 0x80-byte frame.
Validate the CPU and system boundaries before decoding or dumping data.
Print the additional CPU registers only when the processor area contains
them. This also rejects truncated processor frames passed by console-log
handlers. See the ES40 Service Guide EK-ES240-SV A01, Table D-19.
Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
---
arch/alpha/kernel/err_ev6.c | 36 ++++++++++++++++++++++++++----------
1 file changed, 26 insertions(+), 10 deletions(-)
diff --git a/arch/alpha/kernel/err_ev6.c b/arch/alpha/kernel/err_ev6.c
index 8144f2045b5b..ec0b63b0f377 100644
--- a/arch/alpha/kernel/err_ev6.c
+++ b/arch/alpha/kernel/err_ev6.c
@@ -190,6 +190,23 @@ ev6_process_logout_frame(struct el_common *mchk_header, int print)
(struct el_common_EV6_mcheck *)mchk_header;
int status = MCHK_DISPOSITION_UNKNOWN_ERROR;
+ /*
+ * ES40 correctable frames end the CPU area before EXC_ADDR (Table
+ * D-19). Validate both regions before decoding or dumping any data.
+ */
+ if (mchk_header->proc_offset != offsetof(struct el_common_EV6_mcheck,
+ I_STAT) ||
+ mchk_header->sys_offset < offsetof(struct el_common_EV6_mcheck,
+ EXC_ADDR) ||
+ mchk_header->sys_offset > mchk_header->size ||
+ ((mchk_header->sys_offset | mchk_header->size) & 7)) {
+ if (print)
+ printk("%s Invalid EV6 logout frame: size %x, CPU %x, system %x\n",
+ err_print_prefix, mchk_header->size,
+ mchk_header->proc_offset, mchk_header->sys_offset);
+ return MCHK_DISPOSITION_UNKNOWN_ERROR;
+ }
+
status |= ev6_parse_ibox(ev6mchk->I_STAT, print);
status |= ev6_parse_mbox(ev6mchk->MM_STAT, ev6mchk->DC_STAT,
ev6mchk->C_STAT, print);
@@ -203,16 +220,15 @@ ev6_process_logout_frame(struct el_common *mchk_header, int print)
if (status != MCHK_DISPOSITION_DISMISS) {
char *saved_err_prefix = err_print_prefix;
- /*
- * Dump some additional information from the frame
- */
- printk("%s EXC_ADDR: 0x%016lx IER_CM: 0x%016lx"
- " ISUM: 0x%016lx\n"
- " PAL_BASE: 0x%016lx I_CTL: 0x%016lx"
- " PCTX: 0x%016lx\n",
- err_print_prefix,
- ev6mchk->EXC_ADDR, ev6mchk->IER_CM, ev6mchk->ISUM,
- ev6mchk->PAL_BASE, ev6mchk->I_CTL, ev6mchk->PCTX);
+ /* These registers are absent from short correctable frames. */
+ if (mchk_header->sys_offset >= sizeof(*ev6mchk))
+ printk("%s EXC_ADDR: 0x%016lx IER_CM: 0x%016lx"
+ " ISUM: 0x%016lx\n"
+ " PAL_BASE: 0x%016lx I_CTL: 0x%016lx"
+ " PCTX: 0x%016lx\n",
+ err_print_prefix,
+ ev6mchk->EXC_ADDR, ev6mchk->IER_CM, ev6mchk->ISUM,
+ ev6mchk->PAL_BASE, ev6mchk->I_CTL, ev6mchk->PCTX);
if (status == MCHK_DISPOSITION_UNKNOWN_ERROR) {
printk("%s UNKNOWN error, frame follows:\n",
--
2.43.0
next prev parent reply other threads:[~2026-10-09 11:58 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 11:54 [PATCH v5 0/5] alpha: improve Tsunami machine check reporting Magnus Lindholm
2026-10-09 11:54 ` [PATCH v5 1/5] alpha: move Tsunami machine check handling to err_tsunami.c Magnus Lindholm
2026-10-09 11:54 ` [PATCH v5 2/5] alpha: describe the Tsunami system machine check frame Magnus Lindholm
2026-10-09 11:54 ` Magnus Lindholm [this message]
2026-10-09 11:54 ` [PATCH v5 4/5] alpha: decode and acknowledge Tsunami system machine checks Magnus Lindholm
2026-10-09 11:54 ` [PATCH v5 5/5] alpha: decode Clipper environmental events and retain Tsunami console logs Magnus Lindholm
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009115627.969047-4-linmag7@gmail.com \
--to=linmag7@gmail.com \
--cc=linux-alpha@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mattst88@gmail.com \
--cc=richard.henderson@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®