All of lore.kernel.org
 help / color / mirror / Atom feed
From: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
To: intel-xe@lists.freedesktop.org, daniele.ceraolospurio@intel.com,
	alan.previn.teres.alexis@intel.com, julia.filipchuk@intel.com
Subject: [PATCH 2/2] drm/xe/guc: Sanity check GuC-reported hwconfig table size
Date: Tue,  8 Sep 2026 16:18:57 -0700	[thread overview]
Message-ID: <20260908231854.1218934-6-umesh.nerlige.ramappa@intel.com> (raw)
In-Reply-To: <20260908231854.1218934-4-umesh.nerlige.ramappa@intel.com>

The size of the hwconfig table is reported by the GuC in the DATA0 field
of the GET_HWCONFIG MMIO response. That field is 28 bits wide, so
theoretically the firmware can claim a table of up to ~256MB, but in
reality the table is much smaller.

Use an upper bound of 4K to check the returned size.

Fixes: dd08ebf6c352 ("drm/xe: Introduce a new DRM driver for Intel GPUs")
Reported-by: Martin Hodo <martin.hodo@intel.com>
Signed-off-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Assisted-by: Claude:claude-opus-5
---
 drivers/gpu/drm/xe/xe_guc_hwconfig.c | 19 +++++++++++++++++++
 1 file changed, 19 insertions(+)

diff --git a/drivers/gpu/drm/xe/xe_guc_hwconfig.c b/drivers/gpu/drm/xe/xe_guc_hwconfig.c
index b300901dbb8e..fb8caf6e9240 100644
--- a/drivers/gpu/drm/xe/xe_guc_hwconfig.c
+++ b/drivers/gpu/drm/xe/xe_guc_hwconfig.c
@@ -5,16 +5,29 @@
 
 #include "xe_guc_hwconfig.h"
 
+#include <linux/sizes.h>
+
 #include <drm/drm_managed.h>
 #include <drm/drm_print.h>
 
 #include "abi/guc_actions_abi.h"
 #include "xe_bo.h"
 #include "xe_device_types.h"
+#include "xe_gt_printk.h"
 #include "xe_gt_types.h"
 #include "xe_guc.h"
 #include "xe_map.h"
 
+/*
+ * The hwconfig table is a small KLV blob, but its length is reported by the
+ * GuC in the 28-bit DATA0 field of the MMIO response, i.e. it can claim up to
+ * 256MB. Since the reported size drives both a GGTT-pinned BO allocation that
+ * lives for the whole device lifetime and several kzalloc()s in the readers,
+ * sanity check it against a generous upper bound instead of trusting the
+ * firmware value blindly.
+ */
+#define XE_GUC_HWCONFIG_MAX_SIZE	SZ_4K
+
 static int send_get_hwconfig(struct xe_guc *guc, u64 ggtt_addr, u32 size)
 {
 	u32 action[] = {
@@ -34,6 +47,12 @@ static int guc_hwconfig_size(struct xe_guc *guc, u32 *size)
 	if (ret < 0)
 		return ret;
 
+	if (ret > XE_GUC_HWCONFIG_MAX_SIZE) {
+		xe_gt_err(guc_to_gt(guc), "GuC reported invalid hwconfig table size %u (max %u)\n",
+			  ret, (u32)XE_GUC_HWCONFIG_MAX_SIZE);
+		return -EPROTO;
+	}
+
 	*size = ret;
 	return 0;
 }
-- 
2.53.0


  parent reply	other threads:[~2026-09-08 23:18 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08 23:18 [PATCH 0/2] Some error handling improvements in GuC Umesh Nerlige Ramappa
2026-09-08 23:18 ` [PATCH 1/2] drm/xe/guc: Reject a duplicate deregister-done G2H Umesh Nerlige Ramappa
2026-09-08 23:32   ` sashiko-bot
2026-09-08 23:18 ` Umesh Nerlige Ramappa [this message]
2026-09-08 23:26   ` [PATCH 2/2] drm/xe/guc: Sanity check GuC-reported hwconfig table size sashiko-bot
2026-09-08 23:26 ` ✗ CI.checkpatch: warning for Some error handling improvements in GuC Patchwork
2026-09-08 23:28 ` ✓ CI.KUnit: success " Patchwork
2026-09-09  0:14 ` ✓ Xe.CI.BAT: " Patchwork
2026-09-09  8:17 ` ✗ Xe.CI.FULL: failure " Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260908231854.1218934-6-umesh.nerlige.ramappa@intel.com \
    --to=umesh.nerlige.ramappa@intel.com \
    --cc=alan.previn.teres.alexis@intel.com \
    --cc=daniele.ceraolospurio@intel.com \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=julia.filipchuk@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.