From: Osama Abdelkader <osama.abdelkader@gmail.com>
To: Boris Brezillon <boris.brezillon@collabora.com>,
Steven Price <steven.price@arm.com>,
Liviu Dudau <liviu.dudau@arm.com>,
Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
Maxime Ripard <mripard@kernel.org>,
Thomas Zimmermann <tzimmermann@suse.de>,
David Airlie <airlied@gmail.com>, Simona Vetter <simona@ffwll.ch>,
Heiko Stuebner <heiko@sntech.de>,
dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org
Cc: Osama Abdelkader <osama.abdelkader@gmail.com>, stable@vger.kernel.org
Subject: [PATCH] drm/panthor: snapshot firmware interface counts before loops
Date: Mon, 20 Jul 2026 15:55:18 +0200 [thread overview]
Message-ID: <20260720135518.17927-1-osama.abdelkader@gmail.com> (raw)
The firmware exposes the global group count and per-group stream count in
the shared control interface. These values are validated before being used
as loop bounds, but the memory is shared with the MCU firmware and can be
changed after validation.
Read each count once with READ_ONCE() and use the validated snapshot as the
loop bound. This keeps the loop bounds consistent with the validation and
prevents the compiler from reloading a firmware-controlled count during
iteration.
Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
Cc: stable@vger.kernel.org
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
---
drivers/gpu/drm/panthor/panthor_fw.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/gpu/drm/panthor/panthor_fw.c b/drivers/gpu/drm/panthor/panthor_fw.c
index e2fcbd639c3c..6e6da98d795e 100644
--- a/drivers/gpu/drm/panthor/panthor_fw.c
+++ b/drivers/gpu/drm/panthor/panthor_fw.c
@@ -959,6 +959,7 @@ static int panthor_init_csg_iface(struct panthor_device *ptdev,
u64 shared_section_sz = panthor_kernel_bo_size(ptdev->fw->shared_section->mem);
u64 iface_offset = CSF_GROUP_CONTROL_OFFSET +
((u64)csg_idx * glb_iface->control->group_stride);
+ u32 stream_num;
unsigned int i;
if (iface_offset > shared_section_sz ||
@@ -972,8 +973,8 @@ static int panthor_init_csg_iface(struct panthor_device *ptdev,
csg_iface->output = iface_fw_to_cpu_addr(ptdev, csg_iface->control->output_va,
sizeof(*csg_iface->output));
- if (csg_iface->control->stream_num < MIN_CS_PER_CSG ||
- csg_iface->control->stream_num > MAX_CS_PER_CSG)
+ stream_num = READ_ONCE(csg_iface->control->stream_num);
+ if (stream_num < MIN_CS_PER_CSG || stream_num > MAX_CS_PER_CSG)
return -EINVAL;
if (!csg_iface->input || !csg_iface->output) {
@@ -990,7 +991,7 @@ static int panthor_init_csg_iface(struct panthor_device *ptdev,
}
}
- for (i = 0; i < csg_iface->control->stream_num; i++) {
+ for (i = 0; i < stream_num; i++) {
int ret = panthor_init_cs_iface(ptdev, csg_idx, i);
if (ret)
@@ -1015,6 +1016,7 @@ static int panthor_fw_init_ifaces(struct panthor_device *ptdev)
{
struct panthor_fw_global_iface *glb_iface = &ptdev->fw->iface.global;
u64 shared_section_sz = panthor_kernel_bo_size(ptdev->fw->shared_section->mem);
+ u32 group_num;
unsigned int i;
if (!ptdev->fw->shared_section->mem->kmap)
@@ -1034,17 +1036,17 @@ static int panthor_fw_init_ifaces(struct panthor_device *ptdev)
return -EINVAL;
}
- if (glb_iface->control->group_num > MAX_CSGS ||
- glb_iface->control->group_num < MIN_CSGS) {
+ group_num = READ_ONCE(glb_iface->control->group_num);
+ if (group_num > MAX_CSGS || group_num < MIN_CSGS) {
drm_err(&ptdev->base, "Invalid number of control groups");
return -EINVAL;
}
- for (i = 0; i < glb_iface->control->group_num; i++) {
+ for (i = 0; i < group_num; i++) {
int ret = panthor_init_csg_iface(ptdev, i);
if (ret)
return ret;
}
drm_info(&ptdev->base, "CSF FW using interface v%d.%d.%d, Features %#x Instrumentation features %#x",
--
2.43.0
next reply other threads:[~2026-07-20 13:55 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 13:55 Osama Abdelkader [this message]
2026-07-28 15:17 ` [PATCH] drm/panthor: snapshot firmware interface counts before loops Liviu Dudau
2026-07-29 12:00 ` Osama Abdelkader
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720135518.17927-1-osama.abdelkader@gmail.com \
--to=osama.abdelkader@gmail.com \
--cc=airlied@gmail.com \
--cc=boris.brezillon@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=heiko@sntech.de \
--cc=linux-kernel@vger.kernel.org \
--cc=liviu.dudau@arm.com \
--cc=maarten.lankhorst@linux.intel.com \
--cc=mripard@kernel.org \
--cc=simona@ffwll.ch \
--cc=stable@vger.kernel.org \
--cc=steven.price@arm.com \
--cc=tzimmermann@suse.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.