From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9658B45C71F; Fri, 31 Jul 2026 23:28:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785540521; cv=none; b=o4dMzISr6lCWcSqvZDo7dwVwt7hyIr0WAsLrRuSCoV6Ffpw0REz6jtu5onZugD14kIvO+3LxpDT4MNaAempefoQ0n3TYx+8oqIbj92RhHc+QWHFl9cD38jeG33jT9hONfr64JpaknShWUsI2ODpKCA17FUr+bAyBnAVB2wr8TC0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785540521; c=relaxed/simple; bh=p+2uLfN8TGABuGFrWeshlzr/HfPk5G7pzBLtuloXBYQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=NDUwVVTFxqzk5LVgDGMBeAN8f916164wGq9Ox4Ov/cpVEiMhFGqzc04p+axF8R8wGCOqrT/S/FIiDXkaG6ZdioLd16KnGn7StZTB01dMEFP01xkAJOvKYLbN/TSnYNvyZ6zPskXBEGAhfUmn+TGIYcBx32hLXgev603PV4alEcg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 35C5B1F00AC4; Fri, 31 Jul 2026 23:28:40 +0000 (UTC) From: Dave Jiang To: linux-cxl@vger.kernel.org, linux-perf-users@vger.kernel.org Cc: jic23@kernel.org, will@kernel.org, mark.rutland@arm.com, dave@stgolabs.net, robin.murphy@arm.com, sashiko-bot@kernel.org, Jonathan Cameron Subject: [PATCH v3 8/9] perf/cxl: Validate the hardware-reported counter width Date: Fri, 31 Jul 2026 16:28:26 -0700 Message-ID: <20260731232827.401447-9-dave.jiang@intel.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260731232827.401447-1-dave.jiang@intel.com> References: <20260731232827.401447-1-dave.jiang@intel.com> Precedence: bulk X-Mailing-List: linux-perf-users@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit cxl_pmu_parse_caps() takes the Counter Width straight from the CPMU Capability register without a bounds check. The Counter Data register is 64 bits wide, so a device reporting 0 or more than 64 is reporting nonsense, and GENMASK_ULL(width - 1, 0) in the read path then shifts out of range. That is undefined behaviour, and a UBSAN splat where it is enabled. Reject a counter width outside 1..64 at probe. Fixes: 5d7107c72796 ("perf: CXL Performance Monitoring Unit driver") Reported-by: sashiko-bot@kernel.org Closes: https://sashiko.dev/#/patchset/20260715191454.459673-1-dave@stgolabs.net?part=1 Assisted-by: Claude:claude-opus-4-8 Reviewed-by: Jonathan Cameron Signed-off-by: Dave Jiang --- v3: - No change; picked up review tag. --- drivers/perf/cxl_pmu.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/perf/cxl_pmu.c b/drivers/perf/cxl_pmu.c index 580a75bc9210..37742ce43d9f 100644 --- a/drivers/perf/cxl_pmu.c +++ b/drivers/perf/cxl_pmu.c @@ -142,6 +142,15 @@ static int cxl_pmu_parse_caps(struct device *dev, struct cxl_pmu_info *info) info->num_counters = FIELD_GET(CXL_PMU_CAP_NUM_COUNTERS_MSK, val) + 1; info->counter_width = FIELD_GET(CXL_PMU_CAP_COUNTER_WIDTH_MSK, val); + /* + * The Counter Data register is 64 bits wide, so a Counter Width of 0 or + * >64 is invalid. Reject it rather than let GENMASK_ULL(width - 1, 0) in + * the read path shift out of range. + */ + if (info->counter_width == 0 || info->counter_width > 64) { + dev_err(dev, "Invalid counter width %d\n", info->counter_width); + return -ENODEV; + } info->num_event_capabilities = FIELD_GET(CXL_PMU_CAP_NUM_EVN_CAP_REG_SUP_MSK, val) + 1; info->filter_hdm = FIELD_GET(CXL_PMU_CAP_FILTERS_SUP_MSK, val) & CXL_PMU_FILTER_HDM; -- 2.55.0