From: "Christian König" <christian.koenig@amd.com>
To: "Deucher, Alexander" <Alexander.Deucher@amd.com>,
Alex Deucher <alexdeucher@gmail.com>
Cc: Denis Arefev <arefev@swemel.ru>, David Airlie <airlied@gmail.com>,
Simona Vetter <simona@ffwll.ch>,
Andrey Grodzovsky <andrey.grodzovsky@amd.com>,
Chunming Zhou <david1.zhou@amd.com>,
"amd-gfx@lists.freedesktop.org" <amd-gfx@lists.freedesktop.org>,
"dri-devel@lists.freedesktop.org"
<dri-devel@lists.freedesktop.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"lvc-project@linuxtesting.org" <lvc-project@linuxtesting.org>,
"stable@vger.kernel.org" <stable@vger.kernel.org>
Subject: Re: [PATCH v2] drm/amdgpu: check a user-provided number of BOs in list
Date: Wed, 23 Apr 2025 16:29:46 +0200 [thread overview]
Message-ID: <9e4700f6-df58-4685-b4fe-6b53fc1c5222@amd.com> (raw)
In-Reply-To: <BL1PR12MB5144467CB7C017E030A4C3E3F7BB2@BL1PR12MB5144.namprd12.prod.outlook.com>
On 4/22/25 18:26, Deucher, Alexander wrote:
> [Public]
>
>> -----Original Message-----
>> From: Alex Deucher <alexdeucher@gmail.com>
>> Sent: Tuesday, April 22, 2025 9:46 AM
>> To: Koenig, Christian <Christian.Koenig@amd.com>
>> Cc: Denis Arefev <arefev@swemel.ru>; Deucher, Alexander
>> <Alexander.Deucher@amd.com>; David Airlie <airlied@gmail.com>; Simona Vetter
>> <simona@ffwll.ch>; Andrey Grodzovsky <andrey.grodzovsky@amd.com>;
>> Chunming Zhou <david1.zhou@amd.com>; amd-gfx@lists.freedesktop.org; dri-
>> devel@lists.freedesktop.org; linux-kernel@vger.kernel.org; lvc-
>> project@linuxtesting.org; stable@vger.kernel.org
>> Subject: Re: [PATCH v2] drm/amdgpu: check a user-provided number of BOs in list
>>
>> Applied. Thanks!
>
> This change beaks the following IGT tests:
>
> igt@amdgpu/amd_vcn@vcn-decoder-create-decode-destroy@vcn-decoder-create
> igt@amdgpu/amd_vcn@vcn-decoder-create-decode-destroy@vcn-decoder-decode
> igt@amdgpu/amd_vcn@vcn-decoder-create-decode-destroy@vcn-decoder-destroy
> igt@amdgpu/amd_jpeg_dec@amdgpu_cs_jpeg_decode
> igt@amdgpu/amd_cs_nop@cs-nops-with-nop-compute0@cs-nop-with-nop-compute0
> igt@amdgpu/amd_cs_nop@cs-nops-with-sync-compute0@cs-nop-with-sync-compute0
> igt@amdgpu/amd_cs_nop@cs-nops-with-fork-compute0@cs-nop-with-fork-compute0
> igt@amdgpu/amd_cs_nop@cs-nops-with-sync-fork-compute0@cs-nop-with-sync-fork-compute0
> igt@amdgpu/amd_basic@userptr-with-ip-dma@userptr
> igt@amdgpu/amd_basic@cs-compute-with-ip-compute@cs-compute
> igt@amdgpu/amd_basic@cs-sdma-with-ip-dma@cs-sdma
> igt@amdgpu/amd_basic@eviction-test-with-ip-dma@eviction_test
> igt@amdgpu/amd_cp_dma_misc@gtt_to_vram-amdgpu_hw_ip_compute0
> igt@amdgpu/amd_cp_dma_misc@vram_to_gtt-amdgpu_hw_ip_compute0
> igt@amdgpu/amd_cp_dma_misc@vram_to_vram-amdgpu_hw_ip_compute0
Could it be that we used BO list with zero entries for those?
Christian.
>
> Alex
>
>>
>> On Tue, Apr 22, 2025 at 5:13 AM Koenig, Christian <Christian.Koenig@amd.com>
>> wrote:
>>>
>>> [AMD Official Use Only - AMD Internal Distribution Only]
>>>
>>> Reviewed-by: Christian König <christian.koenig@amd.com>
>>>
>>> ________________________________________
>>> Von: Denis Arefev <arefev@swemel.ru>
>>> Gesendet: Freitag, 18. April 2025 10:31
>>> An: Deucher, Alexander
>>> Cc: Koenig, Christian; David Airlie; Simona Vetter; Andrey Grodzovsky;
>>> Chunming Zhou; amd-gfx@lists.freedesktop.org;
>>> dri-devel@lists.freedesktop.org; linux-kernel@vger.kernel.org;
>>> lvc-project@linuxtesting.org; stable@vger.kernel.org
>>> Betreff: [PATCH v2] drm/amdgpu: check a user-provided number of BOs in
>>> list
>>>
>>> The user can set any value to the variable ‘bo_number’, via the ioctl
>>> command DRM_IOCTL_AMDGPU_BO_LIST. This will affect the arithmetic
>>> expression ‘in->bo_number * in->bo_info_size’, which is prone to
>>> overflow. Add a valid value check.
>>>
>>> Found by Linux Verification Center (linuxtesting.org) with SVACE.
>>>
>>> Fixes: 964d0fbf6301 ("drm/amdgpu: Allow to create BO lists in CS ioctl
>>> v3")
>>> Cc: stable@vger.kernel.org
>>> Signed-off-by: Denis Arefev <arefev@swemel.ru>
>>> ---
>>> V1 -> V2:
>>> Set a reasonable limit 'USHRT_MAX' for 'bo_number' it as Christian
>>> König <christian.koenig@amd.com> suggested
>>>
>>> drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c | 3 +++
>>> 1 file changed, 3 insertions(+)
>>>
>>> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
>>> b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
>>> index 702f6610d024..85f7ee1e085d 100644
>>> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
>>> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
>>> @@ -189,6 +189,9 @@ int amdgpu_bo_create_list_entry_array(struct
>> drm_amdgpu_bo_list_in *in,
>>> struct drm_amdgpu_bo_list_entry *info;
>>> int r;
>>>
>>> + if (!in->bo_number || in->bo_number > USHRT_MAX)
>>> + return -EINVAL;
>>> +
>>> info = kvmalloc_array(in->bo_number, info_size, GFP_KERNEL);
>>> if (!info)
>>> return -ENOMEM;
>>> --
>>> 2.43.0
>>>
next prev parent reply other threads:[~2025-04-23 14:29 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-18 8:31 Denis Arefev
2025-04-22 9:12 ` AW: " Koenig, Christian
2025-04-22 13:46 ` Alex Deucher
2025-04-22 16:26 ` Deucher, Alexander
2025-04-23 14:29 ` Christian König [this message]
2025-04-24 13:40 ` Alex Deucher
2025-04-28 14:53 ` Christian König
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=9e4700f6-df58-4685-b4fe-6b53fc1c5222@amd.com \
--to=christian.koenig@amd.com \
--cc=Alexander.Deucher@amd.com \
--cc=airlied@gmail.com \
--cc=alexdeucher@gmail.com \
--cc=amd-gfx@lists.freedesktop.org \
--cc=andrey.grodzovsky@amd.com \
--cc=arefev@swemel.ru \
--cc=david1.zhou@amd.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lvc-project@linuxtesting.org \
--cc=simona@ffwll.ch \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®