dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Aldo Ariel Panzardo" <qwe.aldo@gmail.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v2] drm/amdgpu: prevent parameter-space underflow in nested ATOM table calls
Date: Wed, 23 Sep 2026 15:39:43 +0000	[thread overview]
Message-ID: <20260923153943.E505C1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923152912.1296884-1-qwe.aldo@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] drm/amdgpu: silent bypass of oversized ATOM table execution fails to abort
--

commit 6b59921539d22666969d301a49ef26fc67ab007b
Author: Aldo Ariel Panzardo <qwe.aldo@gmail.com>

drm/amdgpu: prevent parameter-space underflow in nested ATOM table calls

atom_op_calltable() invokes a child ATOM table, forwarding the parent's
parameter space with an offset. The previous logic mixed units (dwords vs
bytes) when subtracting the offset from the remaining capacity. This commit
fixes the unit mismatch by converting ps_shift to bytes.

> diff --git a/drivers/gpu/drm/amd/amdgpu/atom.c b/drivers/gpu/drm/amd/amdgpu/atom.c
> index 1a599d5cf6a5c..7db0118e654c0 100644
> --- a/drivers/gpu/drm/amd/amdgpu/atom.c
> +++ b/drivers/gpu/drm/amd/amdgpu/atom.c
> @@ -646,8 +646,8 @@ static void atom_op_calltable(atom_exec_context *ctx, int *ptr, int arg)
>  		SDEBUG("   table: %d (%s)\n", idx, atom_table_names[idx]);
>  	else
>  		SDEBUG("   table: %d\n", idx);
> -	if (U16(ctx->ctx->cmd_table + 4 + 2 * idx))
> -		r = amdgpu_atom_execute_table_locked(ctx->ctx, idx, ctx->ps + ctx->ps_shift, ctx->ps_size - ctx->ps_shift);
> +	if (U16(ctx->ctx->cmd_table + 4 + 2 * idx) && ctx->ps_shift * 4 <= ctx->ps_size)
> +		r = amdgpu_atom_execute_table_locked(ctx->ctx, idx, ctx->ps + ctx->ps_shift, ctx->ps_size - ctx->ps_shift * 4);

[Severity: High]
Does this code silently skip the table execution without aborting when the
parameter space request is oversized?

Looking at atom_op_calltable(), the variable r is initialized to 0. When
a child table requests an oversized parameter space where
ctx->ps_shift * 4 > ctx->ps_size, the new condition prevents the call to
amdgpu_atom_execute_table_locked(), leaving r as 0.

>  	if (r) {
>  		ctx->abort = true;
>  	}

This means the check above will evaluate to false, failing to abort the
interpreter. The parent table will continue execution assuming the child
table executed successfully, which could lead to using uninitialized
data or skipping critical hardware setup.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923152912.1296884-1-qwe.aldo@gmail.com?part=1

  reply	other threads:[~2026-09-23 15:39 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 14:50 [PATCH] drm/amdgpu: prevent parameter-space underflow in nested ATOM table calls Aldo Ariel Panzardo
2026-09-23 15:04 ` sashiko-bot
2026-09-23 15:29 ` [PATCH v2] " Aldo Ariel Panzardo
2026-09-23 15:39   ` sashiko-bot [this message]
2026-09-23 15:43   ` [PATCH v3] " Aldo Ariel Panzardo
2026-09-24 21:52     ` Alex Deucher

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923153943.E505C1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=qwe.aldo@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox