From: sashiko-bot@kernel.org
To: "Rob Herring (Arm)" <robh@kernel.org>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v3 11/22] accel: ethosu: Validate secondary streams
Date: Tue, 08 Sep 2026 22:22:11 +0000 [thread overview]
Message-ID: <20260908222212.5F58E1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260908-ethosu-fixes-v3-11-490fe215286f@kernel.org>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [Critical] Bypass of bounds validation for secondary weight and scale streams due to 'optional' logic, allowing use of stale register values.
Pre-existing issues:
- [Critical] Missing bounds validation for the scale stream in elementwise operations.
--
commit 097571887d553c034763bdb8261594ca466ee7e8
Author: Rob Herring (Arm) <robh@kernel.org>
accel: ethosu: Validate secondary streams
The command-stream validator records the additional U65 scale and weight
stream addresses and the U85 weight decoder addresses, but only checked
stream 0 against its region buffer. This commit checks every configured
secondary stream against the matching weight or scale region before
accepting a kernel operation.
> diff --git a/drivers/accel/ethosu/ethosu_gem.c b/drivers/accel/ethosu/ethosu_gem.c
> index 6f6712f4efd1f..abfb173e10080 100644
> --- a/drivers/accel/ethosu/ethosu_gem.c
> +++ b/drivers/accel/ethosu/ethosu_gem.c
> @@ -436,13 +436,17 @@ static u64 feat_matrix_length(struct ethosu_device *edev,
>
> static int buffer_size(struct ethosu_validated_cmdstream_info *info,
> struct cmd_state *st, struct buffer *buf, s8 region,
> - u16 region_cmd, u16 base_cmd, u16 length_cmd)
> + u16 region_cmd, u16 base_cmd, u16 length_cmd, bool optional)
> {
> u64 end;
> + bool base_set = cmd_state_reg_is_set(st, base_cmd);
> + bool length_set = cmd_state_reg_is_set(st, length_cmd);
> +
> + if (optional && !base_set && !length_set)
> + return 0;
[Severity: Critical]
Does this logic allow omitted streams to bypass bounds validation while
the hardware might still use them?
If a userspace application omits the base and length commands for secondary
streams that are inherently required by an operation (such as a multi-core
convolution), this check returns 0 and skips bounds validation.
Since Ethos-U NPUs retain register state between jobs, the hardware might
execute the operation using stale offsets from a previous job. Could this
lead to an out-of-bounds memory access by the NPU if the current job's
regions are smaller than those of the previous job?
[ ... ]
[Severity: Critical]
This is a pre-existing issue, but does calc_sizes_elemwise() miss bounds
validation for the scale stream?
In ethosu_gem_cmdstream_copy_and_validate(), a use_scale variable is
computed but completely ignored when calling calc_sizes_elemwise():
drivers/accel/ethosu/ethosu_gem.c:ethosu_gem_cmdstream_copy_and_validate() {
...
ret = calc_sizes_elemwise(ddev, info, cmd, &st, use_ifm, use_ifm2);
...
}
And calc_sizes_elemwise() entirely lacks logic to validate the st.scale
buffers.
If an unprivileged userspace application provides arbitrary, out-of-bounds
NPU_SET_SCALE_BASE and LENGTH values in the command stream for an
NPU_OP_ELEMENTWISE operation, the hardware will read from the unvalidated
offset. Can this allow an attacker to access arbitrary NPU-mapped memory?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260908-ethosu-fixes-v3-0-490fe215286f@kernel.org?part=11
next prev parent reply other threads:[~2026-09-08 22:22 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-08 22:04 [PATCH v3 00/22] accel: ethosu: Another batch of fixes Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 01/22] accel: ethosu: Suspend after initialization Rob Herring (Arm)
2026-09-08 22:18 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 02/22] accel: ethosu: Ensure suspended on removal Rob Herring (Arm)
2026-09-08 22:19 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 03/22] accel: ethosu: Fix probe error cleanup Rob Herring (Arm)
2026-09-08 22:18 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 04/22] accel: ethosu: Disable clocks on PM setup failure Rob Herring (Arm)
2026-09-08 22:18 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 05/22] accel: ethosu: Quiesce jobs before scheduler teardown Rob Herring (Arm)
2026-09-08 22:20 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 06/22] accel: ethosu: Prevent command stream export Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 07/22] accel: ethosu: Move DMA mode to src/dst struct Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 08/22] accel: ethosu: Track command stream register setup Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 09/22] accel: ethosu: Factor buffer bounds checks Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 10/22] accel: ethosu: Fix NHCWB16 bounds calculation Rob Herring (Arm)
2026-09-08 22:19 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 11/22] accel: ethosu: Validate secondary streams Rob Herring (Arm)
2026-09-08 22:22 ` sashiko-bot [this message]
2026-09-08 22:04 ` [PATCH v3 12/22] accel: ethosu: Reject unsupported commands Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 13/22] accel: ethosu: Validate all feature map tiles Rob Herring (Arm)
2026-09-08 22:14 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 14/22] accel: ethosu: Account for feature map element size Rob Herring (Arm)
2026-09-08 22:20 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 15/22] accel: ethosu: Validate convolution parameter Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 16/22] accel: ethosu: Account for kernel dilation in IFM size Rob Herring (Arm)
2026-09-08 22:14 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 17/22] accel: ethosu: Reject reserved command encodings Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 18/22] accel: ethosu: Validate accumulator input Rob Herring (Arm)
2026-09-08 22:23 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 19/22] accel: ethosu: Restrict dynamic IFM2 weights Rob Herring (Arm)
2026-09-08 22:24 ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 20/22] accel: ethosu: Split U65 and U85 DMA length validation Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 21/22] accel: ethosu: Validate OFM transpose Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 22/22] accel: ethosu: Validate resize operations Rob Herring (Arm)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260908222212.5F58E1F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox