mirror of
https://github.com/torvalds/linux.git
synced 2026-09-12 04:23:03 +02:00
accel/amdxdna: reject a command chain that carries no commands
A chain whose command_count is zero passes the payload length check,
because struct_size(payload, data, 0) is just the header. The fill loop
then does not run, so offset stays zero and the request is submitted with
a zero-length buffer.
On firmware without AIE2_NPU_COMMAND that ends at the opcode check, since
op is still ERT_INVALID_CMD and aie2_get_chain_msg_op() answers
MSG_OP_MAX_OPCODE. aie2_get_npu_chain_msg_op() answers
MSG_OP_CHAIN_EXEC_NPU whatever it is given, so there the submission
continues to drm_clflush_virt_range(cmd_buf, 0), which reads the byte
before the buffer and faults on the vmap guard page. EXEC_CMD is
reachable by any process that can open the render node.
Reject the request instead.
Fixes: 8ed8b02396 ("accel/amdxdna: Add debug prints for command submission")
Signed-off-by: Taimuraz Kaitmazov <taimuraz@kaitmazov.com>
Reviewed-by: Lizhi Hou <lizhi.hou@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260818000019.369366-1-taimuraz@kaitmazov.com
This commit is contained in:
parent
b3709d3545
commit
ef6d27af71
|
|
@ -994,7 +994,7 @@ int aie2_cmdlist_multi_execbuf(struct amdxdna_hwctx *hwctx,
|
|||
}
|
||||
|
||||
ccnt = payload->command_count;
|
||||
if (payload_len < struct_size(payload, data, ccnt)) {
|
||||
if (!ccnt || payload_len < struct_size(payload, data, ccnt)) {
|
||||
XDNA_DBG(xdna, "Invalid command count %d", ccnt);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user