From: sashiko-bot@kernel.org
To: alistair23@gmail.com
Cc: linux-cxl@vger.kernel.org, ojeda@kernel.org, linux-pci@vger.kernel.org
Subject: Re: [PATCH v3 18/21] lib: rspdm: Support SPDM get_certificate
Date: Tue, 01 Sep 2026 01:21:58 +0000 [thread overview]
Message-ID: <20260901012159.0B5BF1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260901010347.2614656-19-alistair.francis@wdc.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] `request.length` is byte-swapped to little-endian but then immediately used as a native `usize` for buffer resizing, leading to incorrect sizing on big-endian architectures.
- [High] Potential integer underflow and kernel panic if `self.transport_sz` is less than the GetCertificateRsp header size (8 bytes).
- [Medium] Inconsistent masking of SPDM reserved bits in param1 causes spurious authentication failures.
--
commit 3d050ea39968a6dc6cb0a982af8f1746df8a12b6
Author: Alistair Francis <alistair@alistair23.me>
lib: rspdm: Support SPDM get_certificate
Support the GET_CERTIFICATE SPDM command.
The kernel will send a GET_CERTIFICATE request to the the responder and
then iterate over all of the certificates returned.
> diff --git a/lib/rspdm/state.rs b/lib/rspdm/state.rs
> index 131c22319b262..1e8a4402e6342 100644
> --- a/lib/rspdm/state.rs
> +++ b/lib/rspdm/state.rs
[ ... ]
> @@ -690,4 +703,147 @@ pub(crate) fn get_digests(&mut self) -> Result<(), Error> {
[ ... ]
> + pub(crate) fn get_certificate(&mut self, slot: u8) -> Result<(), Error> {
> + let mut request = GetCertificateReq::default();
> + request.version = self.version;
> + request.param1 = slot;
> +
> + let req_sz = core::mem::size_of::<GetCertificateReq>();
> + let rsp_sz = (core::mem::size_of::<GetCertificateRsp>() as u32 + u16::MAX as u32)
> + .min(self.transport_sz) as usize;
> +
> + request.offset = 0;
> + request.length = ((rsp_sz - core::mem::size_of::<GetCertificateRsp>()) as u16).to_le();
[Severity: High]
Can this subtraction underflow and cause a kernel panic?
If a malicious or misconfigured device advertises a data transfer size during
the capabilities exchange that is smaller than 8 bytes, self.transport_sz
will be smaller than core::mem::size_of::<GetCertificateRsp>().
This would cause rsp_sz - core::mem::size_of::<GetCertificateRsp>() to
underflow and panic.
> +
> + // SAFETY: `request` is repr(C) and packed, so we can convert it to a slice
> + let request_buf = unsafe { from_raw_parts_mut(&mut request as *mut _ as *mut u8, req_sz) };
> +
> + let mut response_vec: KVec<u8> = KVec::from_elem(0u8, rsp_sz, GFP_KERNEL)?;
> +
> + let response = self.get_cert_exchange(request_buf, &mut response_vec)?;
> +
> + if response.param1 != slot {
[Severity: Medium]
Will this initial slot verification erroneously reject valid responses?
Unlike the check inside the while loop below which uses
(response.param1 & 0xF) != slot, this check strictly compares param1
without masking reserved bits.
If a compliant external device sets bits 4-7 in param1 during a
certificate response, this will cause spurious authentication failures.
> + pr_err!("Invalid slot response\n");
> + return Err(EPROTO);
> + }
> +
> + let portion_length = response.portion_length;
> + let rem_length = response.remainder_length;
[ ... ]
> + while remainder_length > 0 {
> + request.offset = offset.to_le();
> + request.length =
> + ((remainder_length.min(rsp_sz - core::mem::size_of::<GetCertificateRsp>())) as u16)
[Severity: High]
Does this underflow the same way as the first request if rsp_sz is less than
core::mem::size_of::<GetCertificateRsp>()?
> + .to_le();
> +
> + let request_buf =
> + unsafe { from_raw_parts_mut(&mut request as *mut _ as *mut u8, req_sz) };
> +
> + response_vec.resize(
> + request.length as usize + core::mem::size_of::<GetCertificateRsp>(),
[Severity: High]
Does this correctly resize the buffer on big-endian architectures?
Since request.length was just byte-swapped to little-endian using .to_le()
above, reading it directly as a native usize on a big-endian system will
produce an incorrectly large or small size.
This could lead to ENOMEM, out-of-bounds logic failures, or panics.
> + 0,
> + GFP_KERNEL,
> + )?;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260901010347.2614656-1-alistair.francis@wdc.com?part=18
next prev parent reply other threads:[~2026-09-01 1:22 UTC|newest]
Thread overview: 57+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 1:03 [PATCH v3 00/21] lib: Rust implementation of SPDM alistair23
2026-09-01 1:03 ` [PATCH v3 01/21] rust: transmute: add `cast_slice[_mut]` functions alistair23
2026-09-01 1:11 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 02/21] rust: create basic untrusted data API alistair23
2026-09-01 1:19 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 03/21] rust: validate: add `Validate` trait alistair23
2026-09-01 1:16 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 04/21] X.509: Make certificate parser public alistair23
2026-09-01 1:12 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 05/21] X.509: Parse Subject Alternative Name in certificates alistair23
2026-09-01 1:12 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 06/21] X.509: Move certificate length retrieval into new helper alistair23
2026-09-01 1:10 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 07/21] rust: add bindings for hash.h alistair23
2026-09-01 1:10 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 08/21] rust: error: impl From<FromBytesWithNulError> for Kernel Error alistair23
2026-09-01 1:10 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 09/21] lib: rspdm: Initial commit of Rust SPDM alistair23
2026-09-01 1:17 ` sashiko-bot
2026-09-08 22:57 ` Jonathan Cameron
2026-09-01 1:03 ` [PATCH v3 10/21] PCI/TSM: Rename pf0 to host alistair23
2026-09-01 1:16 ` sashiko-bot
2026-09-08 23:01 ` Jonathan Cameron
2026-09-11 5:00 ` Alistair
2026-09-01 1:03 ` [PATCH v3 11/21] PCI/TSM: Support connecting to PCIe CMA devices alistair23
2026-09-01 1:25 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 12/21] PCI/CMA: Add a PCI TSM CMA driver using SPDM alistair23
2026-09-01 1:20 ` sashiko-bot
2026-09-08 23:21 ` Jonathan Cameron
2026-09-01 1:03 ` [PATCH v3 13/21] PCI/CMA: Validate Subject Alternative Name in certificates alistair23
2026-09-01 1:15 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 14/21] lib: rspdm: Support SPDM get_version alistair23
2026-09-01 1:17 ` sashiko-bot
2026-09-08 23:40 ` Jonathan Cameron
2026-09-01 1:03 ` [PATCH v3 15/21] lib: rspdm: Support SPDM get_capabilities alistair23
2026-09-01 1:15 ` sashiko-bot
2026-09-08 23:47 ` Jonathan Cameron
2026-09-01 1:03 ` [PATCH v3 16/21] lib: rspdm: Support SPDM negotiate_algorithms alistair23
2026-09-01 1:30 ` sashiko-bot
2026-09-04 5:01 ` Aksh Garg
2026-09-09 0:17 ` Jonathan Cameron
2026-09-11 4:53 ` Alistair
2026-09-01 1:03 ` [PATCH v3 17/21] lib: rspdm: Support SPDM get_digests alistair23
2026-09-01 1:20 ` sashiko-bot
2026-09-09 0:36 ` Jonathan Cameron
2026-09-09 0:31 ` Jonathan Cameron
2026-09-01 1:03 ` [PATCH v3 18/21] lib: rspdm: Support SPDM get_certificate alistair23
2026-09-01 1:21 ` sashiko-bot [this message]
2026-09-01 1:03 ` [PATCH v3 19/21] lib: rspdm: Support SPDM certificate validation alistair23
2026-09-01 1:22 ` sashiko-bot
2026-09-09 0:46 ` Jonathan Cameron
2026-09-01 1:03 ` [PATCH v3 20/21] rust: allow extracting the buffer from a CString alistair23
2026-09-01 1:19 ` sashiko-bot
2026-09-01 1:03 ` [PATCH v3 21/21] lib: rspdm: Support SPDM challenge alistair23
2026-09-01 1:31 ` sashiko-bot
2026-09-09 1:37 ` Jonathan Cameron
2026-09-11 3:46 ` Alistair
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260901012159.0B5BF1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=alistair23@gmail.com \
--cc=linux-cxl@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=ojeda@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.