From: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
To: intel-xe@lists.freedesktop.org, daniele.ceraolospurio@intel.com,
alan.previn.teres.alexis@intel.com, julia.filipchuk@intel.com
Subject: [PATCH 2/2] drm/xe/guc: Sanity check GuC-reported hwconfig table size
Date: Tue, 8 Sep 2026 16:18:57 -0700 [thread overview]
Message-ID: <20260908231854.1218934-6-umesh.nerlige.ramappa@intel.com> (raw)
In-Reply-To: <20260908231854.1218934-4-umesh.nerlige.ramappa@intel.com>
The size of the hwconfig table is reported by the GuC in the DATA0 field
of the GET_HWCONFIG MMIO response. That field is 28 bits wide, so
theoretically the firmware can claim a table of up to ~256MB, but in
reality the table is much smaller.
Use an upper bound of 4K to check the returned size.
Fixes: dd08ebf6c352 ("drm/xe: Introduce a new DRM driver for Intel GPUs")
Reported-by: Martin Hodo <martin.hodo@intel.com>
Signed-off-by: Umesh Nerlige Ramappa <umesh.nerlige.ramappa@intel.com>
Assisted-by: Claude:claude-opus-5
---
drivers/gpu/drm/xe/xe_guc_hwconfig.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/drivers/gpu/drm/xe/xe_guc_hwconfig.c b/drivers/gpu/drm/xe/xe_guc_hwconfig.c
index b300901dbb8e..fb8caf6e9240 100644
--- a/drivers/gpu/drm/xe/xe_guc_hwconfig.c
+++ b/drivers/gpu/drm/xe/xe_guc_hwconfig.c
@@ -5,16 +5,29 @@
#include "xe_guc_hwconfig.h"
+#include <linux/sizes.h>
+
#include <drm/drm_managed.h>
#include <drm/drm_print.h>
#include "abi/guc_actions_abi.h"
#include "xe_bo.h"
#include "xe_device_types.h"
+#include "xe_gt_printk.h"
#include "xe_gt_types.h"
#include "xe_guc.h"
#include "xe_map.h"
+/*
+ * The hwconfig table is a small KLV blob, but its length is reported by the
+ * GuC in the 28-bit DATA0 field of the MMIO response, i.e. it can claim up to
+ * 256MB. Since the reported size drives both a GGTT-pinned BO allocation that
+ * lives for the whole device lifetime and several kzalloc()s in the readers,
+ * sanity check it against a generous upper bound instead of trusting the
+ * firmware value blindly.
+ */
+#define XE_GUC_HWCONFIG_MAX_SIZE SZ_4K
+
static int send_get_hwconfig(struct xe_guc *guc, u64 ggtt_addr, u32 size)
{
u32 action[] = {
@@ -34,6 +47,12 @@ static int guc_hwconfig_size(struct xe_guc *guc, u32 *size)
if (ret < 0)
return ret;
+ if (ret > XE_GUC_HWCONFIG_MAX_SIZE) {
+ xe_gt_err(guc_to_gt(guc), "GuC reported invalid hwconfig table size %u (max %u)\n",
+ ret, (u32)XE_GUC_HWCONFIG_MAX_SIZE);
+ return -EPROTO;
+ }
+
*size = ret;
return 0;
}
--
2.53.0
next prev parent reply other threads:[~2026-09-08 23:18 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-08 23:18 [PATCH 0/2] Some error handling improvements in GuC Umesh Nerlige Ramappa
2026-09-08 23:18 ` [PATCH 1/2] drm/xe/guc: Reject a duplicate deregister-done G2H Umesh Nerlige Ramappa
2026-09-08 23:32 ` sashiko-bot
2026-09-08 23:18 ` Umesh Nerlige Ramappa [this message]
2026-09-08 23:26 ` [PATCH 2/2] drm/xe/guc: Sanity check GuC-reported hwconfig table size sashiko-bot
2026-09-08 23:26 ` ✗ CI.checkpatch: warning for Some error handling improvements in GuC Patchwork
2026-09-08 23:28 ` ✓ CI.KUnit: success " Patchwork
2026-09-09 0:14 ` ✓ Xe.CI.BAT: " Patchwork
2026-09-09 8:17 ` ✗ Xe.CI.FULL: failure " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260908231854.1218934-6-umesh.nerlige.ramappa@intel.com \
--to=umesh.nerlige.ramappa@intel.com \
--cc=alan.previn.teres.alexis@intel.com \
--cc=daniele.ceraolospurio@intel.com \
--cc=intel-xe@lists.freedesktop.org \
--cc=julia.filipchuk@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.