From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ed1-f50.google.com (mail-ed1-f50.google.com [209.85.208.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8AD6C42046D for ; Fri, 24 Jul 2026 09:44:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784886275; cv=none; b=IwY88PjkfoF5W0ZslREkpYjHugv1oeCHfrMhvhfcGVK2r2bNxq+fWZLK7tr2JWnAjztKNWt0h4A6Et390ESOl5OwWV/24OV2iZbX/FHlmIJGRMqtCRKVpG8cGnaltZPPlg1T9ICW719z8kbyGDox3pAMY0i0C2hGNHHUoKzcUwU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784886275; c=relaxed/simple; bh=H5N5sy21MKlfRcNnXzrMqAK4+OX58u35diz43V104Z4=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References; b=TqXppnmW8xfC+7J0X8hWv7Kz9e3IoHuKwlN0UsCcXwfnxzEiNz9AVRKFPdOr/1YOYXVorkaRVWsdaxXBxLXhLkyTRlrXlLSL8S9NpTz9MZvgzKqKjfKwSoMl3ttikdzOscx42lPNDY7TycCYPzjuQzmA6u4e6lldxmekfIabOQ4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YeyDRVQa; arc=none smtp.client-ip=209.85.208.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YeyDRVQa" Received: by mail-ed1-f50.google.com with SMTP id 4fb4d7f45d1cf-698bf053053so324112a12.3 for ; Fri, 24 Jul 2026 02:44:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784886272; x=1785491072; darn=vger.kernel.org; h=references:in-reply-to:message-id:date:subject:cc:to:from:from:to :cc:subject:date:message-id:reply-to:content-type; bh=uOxeeeUe03Lp2o+lDboMOBPZatL9F/0sqHMnsrQyzRw=; b=YeyDRVQajLrfPLWtT3Bs3X+MD+hBh0QY3Ryi4t1hHHxAeg68Shqj2KBHKQSRXjxSOJ r5DY3PmiUlVuTk5/htKQt/BZEV7xbKxAJGa1uWDZrq4I6tFkBmnsa6VTNMTHvLUPbxIB DQ01ZZPzSvK8fZMPFRACmcWboI6st+k8LljRU4GQdCia+bNpUA/rWWTxkiZerLnFUkup m/u66VuiK3DU2lhhmurYo59MkO0xXU8Ll+90GCxm9g4ZmVr2DuPnYGA8sNxxmpw2Pitd vtijM7IONOmWNNk7GO7joxX+o9Pyb16T+nFexO2/DlL+YKVymv9P4BoPas2NrVey3HI2 z3Lw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784886272; x=1785491072; h=references:in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=uOxeeeUe03Lp2o+lDboMOBPZatL9F/0sqHMnsrQyzRw=; b=MBMIwW4i39Kk3pKYuVx+PiIqvLsKgDs4ykB3F3k+/HI0TipRy6HBzsipyTzz8p+EuX Tufut7m6qHL4gMK8CPMC2ZrGkx906C4Qi8pUIZzIO/iCpu6wRBegYnZE02ze4LS6Fdr+ KB9yVNGfCFYj/LCFP/Dq9dF7nEN9+xfMXapssMRWTt+mv9VLJTCkdF6XxhQ7hhBeaSSD q9nazZpDgeE0vOH1QaU+m11gpX9Qf+9E7Fw/9Mg2E/pycB+ZBvbf3jP/EW9CWMO7I80W Lgm3LI8heMvNt5CPqvwdaADlNHd0aDTl0kqDaY4QqGlEetBhMlohKuIhzLpK40wKWf74 oc4A== X-Forwarded-Encrypted: i=1; AHgh+RqL0I/hZZzB9soUFmBVjIakSczt2EKC54JEZyoMtHnR+4EP3egDwPhWgtI6xWJ50fKdZ6ujO1uRjiH5GrY=@vger.kernel.org X-Gm-Message-State: AOJu0Yx9spV2+MgnKfUuGqRXRfuUqhVWZ8fzFb9ixjAFWf2eVw3ocNmh dkBg4Ian/Y7bouLR7VH5+3ou5Gi0ZzvM+3k8DoAxMaTYzaess0sTro6m X-Gm-Gg: AR+sD10Jv/3123zCD5Ob4mFOx8H8O9gkQOJu684/YhXx9PbnTtVjNJw34vZ2P8q6NwH 2ru7efsInsql+aC4tHAYWUyzGetCqOkB2KDpVy50AnCmwokFEKXtWEBOdQnnJbHEHYEOlGPZLTY JTaYs2IOg9+RM7lChHNCGR5OAZO7tRwTeY0lLu4Llz2uUiNL87uAw+wofeccBmYoMcg0878/mfI uWCc93LtmFfu0gkYz1oLSooF5QkVgl62L0p1g0Cn/cw6r+XFEyYpO3LTDDhmQZrD4rbX7ia5akC K2M7UyIRm8HFMxN5RoHcVdbsfONMVmU/Z7tibcDPh+NbYwQRYdcddih1+wEx9DOrsWIP3w1AKC7 7WioToxjS6Q0nKFzIYmn1wodjKThHm/V6vfmyHVf+p4unZmGlyScwpH14zLXbBgpwRH1PS1cfEv NtYhu+c3zdZ07uxX0+bGxv7LxUM3/v2OYVvMw6Td+3 X-Received: by 2002:a17:906:794c:b0:c15:f26a:342f with SMTP id a640c23a62f3a-c1c507b60d9mr268791266b.23.1784886271501; Fri, 24 Jul 2026 02:44:31 -0700 (PDT) Received: from localhost (c-85-228-45-68.bbcust.telenor.se. [85.228.45.68]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c902d2sm319070866b.34.2026.07.24.02.44.30 (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Fri, 24 Jul 2026 02:44:31 -0700 (PDT) From: Eli Billauer To: gregkh@linuxfoundation.org Cc: arnd@arndb.de, linux-kernel@vger.kernel.org, corbet@lwn.net, Eli Billauer Subject: [PATCH v3 6/7] char: xillybus: Add defensive sanity checks Date: Fri, 24 Jul 2026 11:43:01 +0200 Message-Id: <20260724094302.50761-7-eli.billauer@gmail.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20260724094302.50761-1-eli.billauer@gmail.com> References: <20260724094302.50761-1-eli.billauer@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Add validation checks for values derived from hardware or user input to prevent incorrect behavior with malformed data. Assisted-by: Deepseek:v4-pro Kimi:K2.6 ChatGPT:GPT-5.5 Claude:Sonnet-4.6 Signed-off-by: Eli Billauer --- Notes: Changes v2->v3: -- Add Assisted-by tag to description Changes v1->v2: -- xillybus_class.c: Assign @rc a value before goto in xillybus_init_chrdev(). -- xillybus_class.c: Improve check on @inode in xillybus_find_inode(). -- xillybus_of.c: Remove redundant dev_err(), as platform_get_irq() outputs an error message if necessary. drivers/char/xillybus/xillybus_class.c | 18 +++++++++++-- drivers/char/xillybus/xillybus_class.h | 4 +++ drivers/char/xillybus/xillybus_core.c | 37 ++++++++++++++++++++++++-- drivers/char/xillybus/xillybus_of.c | 3 +++ drivers/char/xillybus/xillyusb.c | 29 +++++++++++++++++++- 5 files changed, 86 insertions(+), 5 deletions(-) diff --git a/drivers/char/xillybus/xillybus_class.c b/drivers/char/xillybus/xillybus_class.c index 5e8f03b77064..f7e0da233e2a 100644 --- a/drivers/char/xillybus/xillybus_class.c +++ b/drivers/char/xillybus/xillybus_class.c @@ -57,6 +57,9 @@ int xillybus_init_chrdev(struct device *dev, size_t namelen; struct xilly_unit *unit, *u; + if (num_nodes <= 0 || num_nodes > XILLYBUS_MAX_NODES || !idt || !prefix || !dev) + return -ENODEV; + unit = kzalloc_obj(*unit); if (!unit) @@ -68,6 +71,12 @@ int xillybus_init_chrdev(struct device *dev, snprintf(unit->name, UNITNAMELEN, "%s", prefix); for (i = 0; enumerate; i++) { + if (i > 99) { + dev_err(dev, "Failed to obtain unique unit name\n"); + rc = -ENODEV; + goto fail_obtain; + } + snprintf(unit->name, UNITNAMELEN, "%s_%02d", prefix, i); @@ -215,10 +224,15 @@ EXPORT_SYMBOL(xillybus_cleanup_chrdev); int xillybus_find_inode(struct inode *inode, void **private_data, int *index) { - int minor = iminor(inode); - int major = imajor(inode); + int minor, major; struct xilly_unit *unit = NULL, *iter; + if (!inode || !private_data || !index) + return -ENODEV; + + minor = iminor(inode); + major = imajor(inode); + mutex_lock(&unit_mutex); list_for_each_entry(iter, &unit_list, list_entry) diff --git a/drivers/char/xillybus/xillybus_class.h b/drivers/char/xillybus/xillybus_class.h index 5dbfdfc95c65..264b9f6d6793 100644 --- a/drivers/char/xillybus/xillybus_class.h +++ b/drivers/char/xillybus/xillybus_class.h @@ -8,6 +8,10 @@ #ifndef __XILLYBUS_CLASS_H #define __XILLYBUS_CLASS_H +#define XILLYBUS_MAX_COUNT (((unsigned int) ~0x1ffff) >> 1) +#define XILLYBUS_MAX_NODES 1024 +#define XILLYBUS_MAX_IDT 1048576 + #include #include #include diff --git a/drivers/char/xillybus/xillybus_core.c b/drivers/char/xillybus/xillybus_core.c index b264578b2572..3436f16092e0 100644 --- a/drivers/char/xillybus/xillybus_core.c +++ b/drivers/char/xillybus/xillybus_core.c @@ -351,6 +351,12 @@ static int xilly_get_dma_buffers(struct xilly_endpoint *ep, struct device *dev = ep->dev; struct xilly_buffer *this_buffer = NULL; /* Init to silence warning */ + if (bytebufsize == 0 || bytebufsize > 0x40000000) { + dev_err(ep->dev, + "Illegal buffer size requested in IDT. Aborting.\n"); + return -ENODEV; + } + if (buffers) { /* Not the message buffer */ this_buffer = devm_kcalloc(dev, bufnum, sizeof(struct xilly_buffer), @@ -623,6 +629,12 @@ static int xilly_scan_idt(struct xilly_endpoint *endpoint, return -ENODEV; } + if (count == 0 || count > XILLYBUS_MAX_NODES) { + dev_err(endpoint->dev, + "Unreasonable number of channels. Aborting.\n"); + return -ENODEV; + } + idt_handle->entries = len >> 2; endpoint->num_channels = count; @@ -707,6 +719,9 @@ static ssize_t xillybus_read(struct file *filp, char __user *userbuf, if (channel->endpoint->fatal_error) return -EIO; + if (count > XILLYBUS_MAX_COUNT) + count = XILLYBUS_MAX_COUNT; + deadline = jiffies + 1 + XILLY_RX_TIMEOUT; rc = mutex_lock_interruptible(&channel->wr_mutex); @@ -725,8 +740,18 @@ static ssize_t xillybus_read(struct file *filp, char __user *userbuf, bufidx = channel->wr_host_buf_idx; bufpos = channel->wr_host_buf_pos; howmany = ((channel->wr_buffers[bufidx]->end_offset - + 1) << channel->log2_element_size) - - bufpos; + + 1) << channel->log2_element_size); + + if (howmany > channel->wr_buf_size || + howmany < bufpos) { + dev_err(channel->endpoint->dev, + "Illegal buffer fill level from hardware\n"); + channel->endpoint->fatal_error = 1; + spin_unlock_irqrestore(&channel->wr_spinlock, flags); + break; + } + + howmany -= bufpos; /* Update wr_host_* to its post-operation state */ if (howmany > bytes_to_do) { @@ -1216,6 +1241,9 @@ static ssize_t xillybus_write(struct file *filp, const char __user *userbuf, if (channel->endpoint->fatal_error) return -EIO; + if (count > XILLYBUS_MAX_COUNT) + count = XILLYBUS_MAX_COUNT; + rc = mutex_lock_interruptible(&channel->rd_mutex); if (rc) return rc; @@ -1902,6 +1930,11 @@ int xillybus_endpoint_discovery(struct xilly_endpoint *endpoint) return -ENODEV; } + if (endpoint->idtlen < 4 || endpoint->idtlen > XILLYBUS_MAX_IDT) { + dev_err(endpoint->dev, "Invalid IDT length. Aborting.\n"); + return -ENODEV; + } + /* Enable DMA */ iowrite32((u32) (0x0002 | (endpoint->dma_using_dac & 0x0001)), endpoint->registers + fpga_dma_control_reg); diff --git a/drivers/char/xillybus/xillybus_of.c b/drivers/char/xillybus/xillybus_of.c index 46e1046abfca..44b0c754deb2 100644 --- a/drivers/char/xillybus/xillybus_of.c +++ b/drivers/char/xillybus/xillybus_of.c @@ -53,6 +53,9 @@ static int xilly_drv_probe(struct platform_device *op) irq = platform_get_irq(op, 0); + if (irq < 0) + return irq; + rc = devm_request_irq(dev, irq, xillybus_isr, 0, xillyname, endpoint); if (rc) diff --git a/drivers/char/xillybus/xillyusb.c b/drivers/char/xillybus/xillyusb.c index aa08206a18ef..7459ec9295af 100644 --- a/drivers/char/xillybus/xillyusb.c +++ b/drivers/char/xillybus/xillyusb.c @@ -396,6 +396,10 @@ static int fifo_init(struct xillyfifo *fifo, fifo->size = fifo->bufnum * fifo->bufsize; fifo->buf_order = buf_order; + if (!fifo->size || /* Unsigned integer overflow */ + fifo->size > 0x40000000) /* Stay clear from signed int issues */ + return -ENOMEM; /* Reported as greed for memory */ + fifo->mem = kmalloc_array(fifo->bufnum, sizeof(void *), GFP_KERNEL); if (!fifo->mem) @@ -888,6 +892,7 @@ static int process_in_opcode(struct xillyusb_dev *xdev, struct xillyusb_channel *chan; struct device *dev = xdev->dev; int chan_idx = chan_num >> 1; + struct xillyfifo *in_fifo; if (chan_idx >= xdev->num_channels) { dev_err(dev, "Received illegal channel ID %d from FPGA\n", @@ -912,7 +917,10 @@ static int process_in_opcode(struct xillyusb_dev *xdev, */ smp_wmb(); WRITE_ONCE(chan->read_data_ok, 0); - wake_up_interruptible(&chan->in_fifo->waitq); + + in_fifo = READ_ONCE(chan->in_fifo); + if (in_fifo) + wake_up_interruptible(&in_fifo->waitq); break; case OPCODE_REACHED_CHECKPOINT: @@ -1443,6 +1451,9 @@ static ssize_t xillyusb_read(struct file *filp, char __user *userbuf, bool sent_set_push = false; int rc; + if (count > XILLYBUS_MAX_COUNT) + count = XILLYBUS_MAX_COUNT; + deadline = jiffies + 1 + XILLY_RX_TIMEOUT; rc = mutex_lock_interruptible(&chan->in_mutex); @@ -1649,6 +1660,9 @@ static ssize_t xillyusb_write(struct file *filp, const char __user *userbuf, struct xillyfifo *fifo = &chan->out_ep->fifo; int rc; + if (count > XILLYBUS_MAX_COUNT) + count = XILLYBUS_MAX_COUNT; + rc = mutex_lock_interruptible(&chan->out_mutex); if (rc) @@ -2072,6 +2086,13 @@ static int xillyusb_discovery(struct usb_interface *interface) } idt_len = READ_ONCE(idt_fifo.fill); + + if (idt_len < 4 || idt_len > XILLYBUS_MAX_IDT) { + rc = -ENODEV; + dev_err(&interface->dev, "Invalid IDT length. Aborting.\n"); + goto unfifo; + } + idt = kmalloc(idt_len, GFP_KERNEL); if (!idt) { @@ -2106,6 +2127,12 @@ static int xillyusb_discovery(struct usb_interface *interface) goto unidt; } + if (num_channels == 0 || num_channels > XILLYBUS_MAX_NODES) { + dev_err(&interface->dev, "Unreasonable number of channels. Aborting.\n"); + rc = -ENODEV; + goto unidt; + } + rc = setup_channels(xdev, (void *)idt + 3, num_channels); if (rc) -- 2.34.1