dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rob Herring (Arm)" <robh@kernel.org>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v3 11/22] accel: ethosu: Validate secondary streams
Date: Tue, 08 Sep 2026 22:22:11 +0000	[thread overview]
Message-ID: <20260908222212.5F58E1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260908-ethosu-fixes-v3-11-490fe215286f@kernel.org>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

New issues:
- [Critical] Bypass of bounds validation for secondary weight and scale streams due to 'optional' logic, allowing use of stale register values.

Pre-existing issues:
- [Critical] Missing bounds validation for the scale stream in elementwise operations.
--

commit 097571887d553c034763bdb8261594ca466ee7e8
Author: Rob Herring (Arm) <robh@kernel.org>

accel: ethosu: Validate secondary streams

The command-stream validator records the additional U65 scale and weight
stream addresses and the U85 weight decoder addresses, but only checked
stream 0 against its region buffer. This commit checks every configured
secondary stream against the matching weight or scale region before
accepting a kernel operation.

> diff --git a/drivers/accel/ethosu/ethosu_gem.c b/drivers/accel/ethosu/ethosu_gem.c
> index 6f6712f4efd1f..abfb173e10080 100644
> --- a/drivers/accel/ethosu/ethosu_gem.c
> +++ b/drivers/accel/ethosu/ethosu_gem.c
> @@ -436,13 +436,17 @@ static u64 feat_matrix_length(struct ethosu_device *edev,
>  
>  static int buffer_size(struct ethosu_validated_cmdstream_info *info,
>  		       struct cmd_state *st, struct buffer *buf, s8 region,
> -		       u16 region_cmd, u16 base_cmd, u16 length_cmd)
> +		       u16 region_cmd, u16 base_cmd, u16 length_cmd, bool optional)
>  {
>  	u64 end;
> +	bool base_set = cmd_state_reg_is_set(st, base_cmd);
> +	bool length_set = cmd_state_reg_is_set(st, length_cmd);
> +
> +	if (optional && !base_set && !length_set)
> +		return 0;

[Severity: Critical]
Does this logic allow omitted streams to bypass bounds validation while
the hardware might still use them?

If a userspace application omits the base and length commands for secondary
streams that are inherently required by an operation (such as a multi-core
convolution), this check returns 0 and skips bounds validation.

Since Ethos-U NPUs retain register state between jobs, the hardware might
execute the operation using stale offsets from a previous job. Could this
lead to an out-of-bounds memory access by the NPU if the current job's
regions are smaller than those of the previous job?

[ ... ]

[Severity: Critical]
This is a pre-existing issue, but does calc_sizes_elemwise() miss bounds
validation for the scale stream?

In ethosu_gem_cmdstream_copy_and_validate(), a use_scale variable is
computed but completely ignored when calling calc_sizes_elemwise():

drivers/accel/ethosu/ethosu_gem.c:ethosu_gem_cmdstream_copy_and_validate() {
    ...
    ret = calc_sizes_elemwise(ddev, info, cmd, &st, use_ifm, use_ifm2);
    ...
}

And calc_sizes_elemwise() entirely lacks logic to validate the st.scale
buffers.

If an unprivileged userspace application provides arbitrary, out-of-bounds
NPU_SET_SCALE_BASE and LENGTH values in the command stream for an
NPU_OP_ELEMENTWISE operation, the hardware will read from the unvalidated
offset. Can this allow an attacker to access arbitrary NPU-mapped memory?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260908-ethosu-fixes-v3-0-490fe215286f@kernel.org?part=11

  reply	other threads:[~2026-09-08 22:22 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08 22:04 [PATCH v3 00/22] accel: ethosu: Another batch of fixes Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 01/22] accel: ethosu: Suspend after initialization Rob Herring (Arm)
2026-09-08 22:18   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 02/22] accel: ethosu: Ensure suspended on removal Rob Herring (Arm)
2026-09-08 22:19   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 03/22] accel: ethosu: Fix probe error cleanup Rob Herring (Arm)
2026-09-08 22:18   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 04/22] accel: ethosu: Disable clocks on PM setup failure Rob Herring (Arm)
2026-09-08 22:18   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 05/22] accel: ethosu: Quiesce jobs before scheduler teardown Rob Herring (Arm)
2026-09-08 22:20   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 06/22] accel: ethosu: Prevent command stream export Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 07/22] accel: ethosu: Move DMA mode to src/dst struct Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 08/22] accel: ethosu: Track command stream register setup Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 09/22] accel: ethosu: Factor buffer bounds checks Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 10/22] accel: ethosu: Fix NHCWB16 bounds calculation Rob Herring (Arm)
2026-09-08 22:19   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 11/22] accel: ethosu: Validate secondary streams Rob Herring (Arm)
2026-09-08 22:22   ` sashiko-bot [this message]
2026-09-08 22:04 ` [PATCH v3 12/22] accel: ethosu: Reject unsupported commands Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 13/22] accel: ethosu: Validate all feature map tiles Rob Herring (Arm)
2026-09-08 22:14   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 14/22] accel: ethosu: Account for feature map element size Rob Herring (Arm)
2026-09-08 22:20   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 15/22] accel: ethosu: Validate convolution parameter Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 16/22] accel: ethosu: Account for kernel dilation in IFM size Rob Herring (Arm)
2026-09-08 22:14   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 17/22] accel: ethosu: Reject reserved command encodings Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 18/22] accel: ethosu: Validate accumulator input Rob Herring (Arm)
2026-09-08 22:23   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 19/22] accel: ethosu: Restrict dynamic IFM2 weights Rob Herring (Arm)
2026-09-08 22:24   ` sashiko-bot
2026-09-08 22:04 ` [PATCH v3 20/22] accel: ethosu: Split U65 and U85 DMA length validation Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 21/22] accel: ethosu: Validate OFM transpose Rob Herring (Arm)
2026-09-08 22:04 ` [PATCH v3 22/22] accel: ethosu: Validate resize operations Rob Herring (Arm)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260908222212.5F58E1F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox