From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail.mindbit.ro (xs1.mindbit.ro [80.86.107.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 671772773D8 for ; Sat, 25 Jul 2026 16:13:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=80.86.107.70 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784996008; cv=none; b=RuvXhv4lbnAhf4OqpyRM1lh38J3XfKVqr20orD4x2OOIZGnefVfB0869j6BLTSCdaVRnXBdS7v/PxdkkuidkhKCDvlV3KIYUIPgubJwa6cNhNHMsCMPiwWQ8JfS2lzGZIxPrQFZPBVKTBUaJfmU6edxNHnVABHn6dmvBDCouSvI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784996008; c=relaxed/simple; bh=0HHxJswlMwgRC5Vq8b6zvrfqWZ1if5FDZ7+J+LpNeqQ=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=N4wcymtU5LCQWx45snPYAt1iDjdq285CqRuA4uNozgv8tBHY2jDaSBjNIoC5zwjSKTs5+dUzmnwe4kLntulwDrvovXUfSmocgjj1knJfoR6XvPaxIGlDde+6GHZZO6dto0hnGEIjqnYp/ulfUTzK9lWkrDJJ0Aw9PHikkmSPvR0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=rendec.net; spf=pass smtp.mailfrom=rendec.net; dkim=pass (2048-bit key) header.d=rendec.net header.i=@rendec.net header.b=hOU8HOw4; arc=none smtp.client-ip=80.86.107.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=rendec.net Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=rendec.net Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=rendec.net header.i=@rendec.net header.b="hOU8HOw4" Received: from dog.kanata.rendec.net (pool-174-112-193-187.cpe.net.cable.rogers.com [174.112.193.187]) by mail.mindbit.ro (Postfix) with ESMTPSA id E7E86C289F; Sat, 25 Jul 2026 19:13:21 +0300 (EEST) DKIM-Filter: OpenDKIM Filter v2.11.0 mail.mindbit.ro E7E86C289F DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rendec.net; s=default; t=1784996003; bh=YI32JWrMTg8CystnwVwPIZbj+64IR2ZStKiHxrt8NMk=; h=Subject:From:To:Cc:Date:In-Reply-To:References:From; b=hOU8HOw48svZKptUQRFuMvQJ0atEuRvEQEBVEhjdV4kHqq7HWn05uv6Gi4yNYKCC6 8o2Sv9+zu5uxdI3E+M/GRxj1oo15iW/kpRSurmGoLuTaoOtW4OO2PTNxdzFCpbZEGI E61lCiyX715tyqEg1Iht7msBmaU/nTqZ27lnmKIIlXId5rwPZtW+LPm3Z619z9NE5H N/yKz9o/ewdh8gf+QB44uCD7PtmDpr/8ABG/zJC4hky5i9xNzXntIqyLWDSU7ABfn2 jToMNLcZvVku5mviq1KZUehJbr6Y78HJUlmQz++iO4KtbDAmXWzc9QILwisyiS5NYm wLOr0U8gMdStw== Message-ID: <7a124c80a48d2ada6ad21c1ac27e9fd888ae1a56.camel@rendec.net> Subject: Re: [PATCH 01/16] irqchip/riscv-imsic: fix MMIO lookup OOB and NULL cleanup From: Radu Rendec To: Haofeng Li , tglx@kernel.org Cc: linux-kernel@vger.kernel.org, Haofeng Li <13266079573@163.com>, Anup Patel , Paul Walmsley , Palmer Dabbelt , Albert Ou , Alexandre Ghiti , =?ISO-8859-1?Q?Bj=F6rn_T=F6pel?= , linux-riscv@lists.infradead.org Date: Sat, 25 Jul 2026 12:13:20 -0400 In-Reply-To: <20260714122351.3274006-2-lihaofeng@kylinos.cn> References: <20260714122351.3274006-1-lihaofeng@kylinos.cn> <20260714122351.3274006-2-lihaofeng@kylinos.cn> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.58.3 (3.58.3-1.fc43) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Tue, 2026-07-14 at 20:23 +0800, Haofeng Li wrote: > The MSI page lookup loop uses: >=20 > for (j =3D 0; nr_mmios; j++) >=20 > When nr_mmios is non-zero the condition is always true, so j is never > bounded. If reloff does not fall in any MMIO region the loop indexes > past mmios[] and may hang or fault. >=20 > Also, mmios_va starts as NULL. If its allocation fails, the out_iounmap > path indexes mmios_va[i] and NULL-dereferences. >=20 > Bound the loop with j < nr_mmios, and guard the iounmap/kfree cleanup > with if (mmios_va). >=20 > Fixes: 21a8f8a0eb35 ("irqchip: Add RISC-V incoming MSI controller early d= river") > Signed-off-by: Haofeng Li > --- > =C2=A0drivers/irqchip/irq-riscv-imsic-state.c | 12 +++++++----- > =C2=A01 file changed, 7 insertions(+), 5 deletions(-) >=20 > diff --git a/drivers/irqchip/irq-riscv-imsic-state.c b/drivers/irqchip/ir= q-riscv-imsic-state.c > index b8d1bbbf42f7..19f74cf79988 100644 > --- a/drivers/irqchip/irq-riscv-imsic-state.c > +++ b/drivers/irqchip/irq-riscv-imsic-state.c > @@ -896,7 +896,7 @@ int __init imsic_setup_state(struct fwnode_handle *fw= node, void *opaque) > =C2=A0 index =3D nr_mmios; > =C2=A0 reloff =3D i * BIT(global->guest_index_bits) * > =C2=A0 IMSIC_MMIO_PAGE_SZ; > - for (j =3D 0; nr_mmios; j++) { > + for (j =3D 0; j < nr_mmios; j++) { > =C2=A0 if (reloff < resource_size(&mmios[j])) { > =C2=A0 index =3D j; > =C2=A0 break; > @@ -953,11 +953,13 @@ int __init imsic_setup_state(struct fwnode_handle *= fwnode, void *opaque) > =C2=A0out_local_cleanup: > =C2=A0 imsic_local_cleanup(); > =C2=A0out_iounmap: > - for (i =3D 0; i < nr_mmios; i++) { > - if (mmios_va[i]) > - iounmap(mmios_va[i]); > + if (mmios_va) { > + for (i =3D 0; i < nr_mmios; i++) { > + if (mmios_va[i]) > + iounmap(mmios_va[i]); > + } > + kfree(mmios_va); > =C2=A0 } > - kfree(mmios_va); > =C2=A0 kfree(mmios); > =C2=A0out_free_local: > =C2=A0 free_percpu(imsic->global.local); Reviewed-by: Radu Rendec