From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from SN4PR2101CU001.outbound.protection.outlook.com (mail-southcentralusazon11012010.outbound.protection.outlook.com [40.93.195.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F1A8D2E764D for ; Wed, 26 Aug 2026 21:32:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.93.195.10 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779931; cv=fail; b=Liu+fVvX0vLvA8QHfBs9LaQov7uMT9HIuJyWgUcfsK/Df08It4A7jCcA6i+PYXZMzmPRv9NwKYmso6cKqprrYm2BBdfp5O3wB2/wJ3Gkb0nHou7zIyuIqc4Zu8RfwPFySUNYvBev4/ahTu4n6rtz2e+3Otmt9PBLQlee6EjRbV4= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779931; c=relaxed/simple; bh=9PAk2z0wqTkse80Q2nBTjecXq21UIr0VX+0QRgYGPLQ=; h=Message-ID:Date:MIME-Version:Subject:To:CC:References:From: In-Reply-To:Content-Type; b=PCzAwzYRpCQhd8UqVw7AoMoo5lsqbCclLj6F+BkKztfPHhyUzLf+kyytu9M0P2i73lg5CgVTf/v2QzkE7UKJ+C3/UHIJ1h6xbEBZI2kT2PiV7d+oQ6ZLncrFxAKjITxkyDnLNdFtNMI0m/u5WHA8xZUczgQmD7cPwm6qgGNhgbo= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=wxLL2yq0; arc=fail smtp.client-ip=40.93.195.10 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="wxLL2yq0" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=qGkAzN7ni7Y0ILqTseiAsQKdwXlDLJxDSoOGm6JA+0OgC6zTeC1CxWyaunjSJ1aIF4FWdyYAu42GiZjZzvXxH9D7pZTsApDyKuYq0pQb2EyBahbi4AEJw4mJ0DVmo3brgvqJHDuS7QYxEKLy/C2Kbkn5cgznElceMxDBxMNBN3aWn2h9p7G6hg1Baan1/Wn1rvrnmwrWIPU6upTVbIwevwVCZMH71Ly49dkwIACChKOEu4Qf4ojYanrUYp6vdm5bYKduPzOHKkgRNeKv/CMc8/FAxL3hdFJx+Iw7iudZ3keHwr2ns3U6Z/kJMAR7vqER+f4ja8ULxRVicRwXLlaKBw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=KBZk7+f98P0qQHKmVxiGq4fQan4Uj/KDECggQksYB3c=; b=hkqWrHU7Pl5/JwL77jfVQ/7pjzMncpdcU8NgB3P3t2M7nXpy+OQJ6OyxaGfqscgO+tGEg101WFn4rTo0gaRmAXZmZRFmA/Uj+MNZywzRy52fawx01pxrqnhJiaqVoTtD1PXvXELXJCT6BAERKj2S+snaQv0CMQKGxPyAy+raEK2xvQPaW8/vCuJ7vnip3CxTfvvzGK2uxsWgM452sW+/C4i25pBvSkcMo873NtOsU6KJi/jTDk4CW5OUoYGOWXZGE36aaxDqGGknb1d8U73m2nFS6b6Zttmdcg2t+CcsvOxujZBysh1gVk84C4tJ03m2oo9zNrBG4HWBUhr/Bik85A== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=softfail (sender ip is 149.199.90.133) smtp.rcpttodomain=kaitmazov.com smtp.mailfrom=amd.com; dmarc=fail (p=quarantine sp=quarantine pct=100) action=quarantine header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=KBZk7+f98P0qQHKmVxiGq4fQan4Uj/KDECggQksYB3c=; b=wxLL2yq03HTOBjDbyOqrSjOI7AtPLN8LnGE/0Diap4YZkbdBJzAxiezKbkPcc70GRBWh3S/uvDLzPSqQZTB2bPoEzLrP/xDWe/RbtjtbZpqRUPGLRDOyZxC3pZSsaVDoxMqfllOkQv34kRoe7Z0A0n4wh/3ZppRmb4v1Xat9wTw= Received: from CH0PR03CA0385.namprd03.prod.outlook.com (2603:10b6:610:119::20) by DM4PR12MB6398.namprd12.prod.outlook.com (2603:10b6:8:b5::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.8; Wed, 26 Aug 2026 21:32:06 +0000 Received: from CH3PEPF00000018.namprd21.prod.outlook.com (2603:10b6:610:119:cafe::4c) by CH0PR03CA0385.outlook.office365.com (2603:10b6:610:119::20) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.360.10 via Frontend Transport; Wed, 26 Aug 2026 21:32:06 +0000 X-MS-Exchange-Authentication-Results: spf=softfail (sender IP is 149.199.90.133) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=fail action=quarantine header.from=amd.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning amd.com discourages use of 149.199.90.133 as permitted sender) Received: from satlexmb07.amd.com (149.199.90.133) by CH3PEPF00000018.mail.protection.outlook.com (10.167.244.123) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.0 via Frontend Transport; Wed, 26 Aug 2026 21:32:05 +0000 Received: from satlexmb08.amd.com (10.181.42.217) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 26 Aug 2026 16:32:05 -0500 Received: from [172.19.71.207] (10.180.168.240) by satlexmb08.amd.com (10.181.42.217) with Microsoft SMTP Server id 15.2.2562.45 via Frontend Transport; Wed, 26 Aug 2026 16:32:04 -0500 Message-ID: Date: Wed, 26 Aug 2026 14:32:04 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.11.0 Subject: Re: [PATCH v2 1/2] accel/amdxdna: check the command chain payload before using it Content-Language: en-US To: Taimuraz Kaitmazov , Min Ma , Oded Gabbay CC: , References: <20260826143036.100089-1-taimuraz@kaitmazov.com> <20260826153121.133507-1-taimuraz@kaitmazov.com> <20260826153121.133507-2-taimuraz@kaitmazov.com> From: Lizhi Hou In-Reply-To: <20260826153121.133507-2-taimuraz@kaitmazov.com> Content-Type: text/plain; charset="UTF-8"; format=flowed Content-Transfer-Encoding: 7bit X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CH3PEPF00000018:EE_|DM4PR12MB6398:EE_ X-MS-Office365-Filtering-Correlation-Id: e62816ea-9b96-4844-f720-08df03b97a05 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|376014|82310400026|1800799024|36860700016|56012099006|10067099003|18002099003|22082099003|4143699003|11063799006|5023799004; X-Microsoft-Antispam-Message-Info: VN+/Y62xdmAzqnLqjjM3euZPwqOAWDxh7Dk8nyZoIt3YPEw0tWT8i+hPx1bPr00CrGwZYNfLyql+Wn9DMHvIi3tqRsA1RLgNA7NCt1s2aevI8sR05cor49VywvwBs1wrpLg5wyPGR5n1jgUJ1EGEgNhtePL69KpUcWyczuhGkSzOcnMqGlUx7xyRf7uIlbqYquSxTnjHWWIIKxVT4LlNkRoJLRbCIodNIzyloPOEoJEO6Y99t/7d41hGfxdj0JpY/yInMuNTepE/q/X9vLVpjsWrm9K5M9SuQPs6MVzeYpPHvEGMwZjqCWaj0OCe03HrqHrJ5IRn7H3qEuE9uutKHL031vASthoRMQLOV+KUN+i4nyST/Ty5TfEVcf8jE7qt9sW1gnbq8T1quL9IeVmirdkX8sHkf8h27PujnvEhzBOSNgKigeMDknEo8gN7VVFlciNPIXx3kenDOofBtTbJ+1bCDcCUf7PkZgjlVbj74Y2H9KG8pozhMDA9kCal0e9eSEtwLjBcLTn8Zh7UdrhN1Hdou4gNm/VQDBfgGy9CPDS4e8B+XNn2kPQvguirwgx8aJWy4YsigR0ArXmgt9h1fdE/idSEIY5Jac+yqhm6OFoXRV8xtIYNEwyf6mbR5Iip4mbsGH0DVILasXJD1U1MxfxRFlrwkx4cW8ZMEBCHP3/ygfrgnb735eYLLFT4R5lAs6zm3Tpq8huzs138rJs+Iw== X-Forefront-Antispam-Report: CIP:149.199.90.133;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:unknown-90-133.xilinx.com;CAT:NONE;SFS:(13230040)(23010399003)(376014)(82310400026)(1800799024)(36860700016)(56012099006)(10067099003)(18002099003)(22082099003)(4143699003)(11063799006)(5023799004);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: zr65L0Wyn0GS+Xc2JW5P3sILAqy7s2xmMa/+J+haPypUbh+oL76LFkUT/f5WX368RyspP3fqrS16hEEEf/7mSlHZRyAwvHvMjWA+F9/o91bYtQQVwfcgssnltLhtRuiscBCFR6i+7Ml63YR1D3KazgE+UDDO6AvjrPhMnTsxeofEdd2nPpkJHB9QbMhT2okzWdjEnq2pqe2jes1Xd0niO2ySA3IBvSBtJ5boDgdzFBP3IwPI0qin3xBm0IstNL+1zGB1RWKdrJPwyN/YVRIyZgNktt8FykKcbpdSheWeTh89KdFrGXzZ+D+xdqSrt8dt7AZdUbHuo2iA9Oo/U68lBPZAag2yWe/2w3uzd+hLpAx5yK/vtfjiiwejemrWIMWC8MQ6ICrAZJirm3qhg9mlOHbkRT2iE4EOxEzXayaD/8/D5y/g1/l2vEjEcFHW4QFn X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Aug 2026 21:32:05.9550 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: e62816ea-9b96-4844-f720-08df03b97a05 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[149.199.90.133];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: CH3PEPF00000018.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM4PR12MB6398 On 8/26/26 08:31, Taimuraz Kaitmazov wrote: > amdxdna_cmd_get_payload() only bounds-checks the payload when a size > pointer is passed, so its two callers get different guarantees from one > function. amdxdna_cmd_set_error() takes the unchecked form and then reads > cc->command_count and cc->data[0], neither of which has been shown to > lie inside the BO. AMDXDNA_CMD_EXTRA_CU_MASK is 2 bits. So cc->command_count and cc->data[0] will be in the BO scope. This is IO path. I would change it only when there is a real issue. Thanks, Lizhi > > Make the size mandatory and add amdxdna_cmd_get_chain(), which returns > the chain only once the declared command count is known to fit. > > Signed-off-by: Taimuraz Kaitmazov > --- > drivers/accel/amdxdna/amdxdna_ctx.c | 51 ++++++++++++++++++++++------- > drivers/accel/amdxdna/amdxdna_ctx.h | 2 ++ > 2 files changed, 41 insertions(+), 12 deletions(-) > > diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/amdxdna_ctx.c > index 855da8c79a1c..9f44e3918bc1 100644 > --- a/drivers/accel/amdxdna/amdxdna_ctx.c > +++ b/drivers/accel/amdxdna/amdxdna_ctx.c > @@ -125,20 +125,42 @@ void *amdxdna_cmd_get_payload(struct amdxdna_gem_obj *abo, u32 *size) > else > num_masks = 1 + FIELD_GET(AMDXDNA_CMD_EXTRA_CU_MASK, cmd->header); > > - if (size) { > - count = FIELD_GET(AMDXDNA_CMD_COUNT, cmd->header); > - if (unlikely(count <= num_masks || > - count * sizeof(u32) + > - offsetof(struct amdxdna_cmd, data[0]) > > - abo->mem.size)) { > - *size = 0; > - return NULL; > - } > - *size = (count - num_masks) * sizeof(u32); > + count = FIELD_GET(AMDXDNA_CMD_COUNT, cmd->header); > + if (unlikely(count <= num_masks || > + count * sizeof(u32) + > + offsetof(struct amdxdna_cmd, data[0]) > > + abo->mem.size)) { > + *size = 0; > + return NULL; > } > + *size = (count - num_masks) * sizeof(u32); > + > return &cmd->data[num_masks]; > } > > +/* > + * Returns the chain payload of @abo, with @count set to a command count that > + * has been checked to fit. The chain fields live in a BO user space keeps > + * mapped, so nothing may read them without going through here. > + */ > +struct amdxdna_cmd_chain * > +amdxdna_cmd_get_chain(struct amdxdna_gem_obj *abo, u32 *count) > +{ > + struct amdxdna_cmd_chain *cc; > + u32 len, ccnt; > + > + cc = amdxdna_cmd_get_payload(abo, &len); > + if (!cc || len < sizeof(*cc)) > + return NULL; > + > + ccnt = READ_ONCE(cc->command_count); > + if (len < struct_size(cc, data, ccnt)) > + return NULL; > + > + *count = ccnt; > + return cc; > +} > + > u32 amdxdna_cmd_get_cu_idx(struct amdxdna_gem_obj *abo) > { > struct amdxdna_cmd *cmd = amdxdna_gem_vmap(abo); > @@ -177,8 +199,13 @@ int amdxdna_cmd_set_error(struct amdxdna_gem_obj *abo, > cmd->header |= FIELD_PREP(AMDXDNA_CMD_STATE, error_state); > > if (amdxdna_cmd_get_op(abo) == ERT_CMD_CHAIN) { > - cc = amdxdna_cmd_get_payload(abo, NULL); > - cc->error_index = (cmd_idx < cc->command_count) ? cmd_idx : 0; > + u32 ccnt; > + > + cc = amdxdna_cmd_get_chain(abo, &ccnt); > + if (!cc || !ccnt) > + return -EINVAL; > + > + cc->error_index = (cmd_idx < ccnt) ? cmd_idx : 0; > abo = amdxdna_gem_get_obj(client, cc->data[0], AMDXDNA_BO_SHARE); > if (!abo) > return -EINVAL; > diff --git a/drivers/accel/amdxdna/amdxdna_ctx.h b/drivers/accel/amdxdna/amdxdna_ctx.h > index b6bef3af7dab..f6529d512217 100644 > --- a/drivers/accel/amdxdna/amdxdna_ctx.h > +++ b/drivers/accel/amdxdna/amdxdna_ctx.h > @@ -196,6 +196,8 @@ amdxdna_cmd_get_state(struct amdxdna_gem_obj *abo) > } > > void *amdxdna_cmd_get_payload(struct amdxdna_gem_obj *abo, u32 *size); > +struct amdxdna_cmd_chain * > +amdxdna_cmd_get_chain(struct amdxdna_gem_obj *abo, u32 *count); > u32 amdxdna_cmd_get_cu_idx(struct amdxdna_gem_obj *abo); > int amdxdna_cmd_set_error(struct amdxdna_gem_obj *abo, > struct amdxdna_sched_job *job, u32 cmd_idx,