Intel-XE Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Stuart Summers <stuart.summers@intel.com>
Cc: intel-xe@lists.freedesktop.org, rodrigo.vivi@intel.com,
	matthew.brost@intel.com, umesh.nerlige.ramappa@intel.com,
	gustavo.sousa@intel.com, matthew.d.roper@intel.com,
	daniele.ceraolospurio@intel.com, shuicheng.lin@intel.com,
	Stuart Summers <stuart.summers@intel.com>
Subject: [PATCH 02/16] drm/xe/configfs: Fix out-of-bounds read in parse_wa_bb_lines()
Date: Thu, 24 Sep 2026 23:01:21 +0000	[thread overview]
Message-ID: <20260924230120.389685-20-stuart.summers@intel.com> (raw)
In-Reply-To: <20260924230120.389685-18-stuart.summers@intel.com>

The outer loop advances the cursor unconditionally at the end of each
iteration. When the last token of a line is terminated by the NUL rather
than by whitespace, e.g. "echo -n 'rcs cmd 1'", the cursor is already on
the NUL and the increment steps past the end of the buffer, so the loop
condition reads out of bounds. The leading strspn(p, " \t\n") already
skips the line separators, and every iteration consumes at least the
engine class token, so dropping the increment keeps the loop making
progress.

Fixes: 39ac06f70062 ("drm/xe/configfs: Add post context restore bb")

Signed-off-by: Stuart Summers <stuart.summers@intel.com>
Assisted-by: Copilot:claude-opus-5
---
 drivers/gpu/drm/xe/xe_configfs.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/xe/xe_configfs.c b/drivers/gpu/drm/xe/xe_configfs.c
index 9ff39ec8c07d..c4ef151c9008 100644
--- a/drivers/gpu/drm/xe/xe_configfs.c
+++ b/drivers/gpu/drm/xe/xe_configfs.c
@@ -776,7 +776,11 @@ static ssize_t parse_wa_bb_lines(const char *lines,
 	ssize_t dwords = 0, ret;
 	const char *p;
 
-	for (p = lines; *p; p++) {
+	/*
+	 * Each iteration consumes at least the engine class token if it doesn't
+	 * error out, so the loop always makes progress without advancing @p.
+	 */
+	for (p = lines; *p;) {
 		const struct engine_info *info = NULL;
 		u32 val, val2;
 
-- 
2.43.0


  parent reply	other threads:[~2026-09-24 23:01 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 23:01 [PATCH 00/16] Add new debug infrastructure for configfs Stuart Summers
2026-09-24 23:01 ` [PATCH 01/16] drm/xe: Guard configfs attribute reads in getters Stuart Summers
2026-09-24 23:01 ` Stuart Summers [this message]
2026-09-24 23:01 ` [PATCH 03/16] drm/xe/configfs: Copy wa_bb out under the configfs lock Stuart Summers
2026-09-24 23:01 ` [PATCH 04/16] drm/xe: Require CONFIGFS_FS Stuart Summers
2026-09-25 23:16   ` Matt Roper
2026-09-28 16:46     ` Summers, Stuart
2026-09-24 23:01 ` [PATCH 05/16] drm/xe: Invert vram_page_offline configfs attribute Stuart Summers
2026-09-24 23:01 ` [PATCH 06/16] drm/xe: Make survivability_mode configfs attribute a bitmap Stuart Summers
2026-09-24 23:01 ` [PATCH 07/16] drm/xe: Sort xe_config_device fields Stuart Summers
2026-09-24 23:01 ` [PATCH 08/16] drm/xe: Split out configfs data structures Stuart Summers
2026-09-24 23:01 ` [PATCH 09/16] drm/xe: Add a new debug focused configfs group Stuart Summers
2026-09-24 23:01 ` [PATCH 10/16] drm/xe: Move debug configfs entries to xe_configfs_debug.c Stuart Summers
2026-09-24 23:01 ` [PATCH 11/16] drm/xe/guc: Add configfs support for guc_log_level Stuart Summers
2026-09-24 23:01 ` [PATCH 12/16] drm/xe/guc: Add support for NPK as a GuC log target Stuart Summers
2026-09-24 23:01 ` [PATCH 13/16] drm/xe: Add infrastructure for debug configfs parameters Stuart Summers
2026-09-24 23:01 ` [PATCH 14/16] drm/xe: Migrate existing debug configfs entries to params infrastructure Stuart Summers
2026-09-24 23:01 ` [PATCH 15/16] drm/xe: Taint kernel when debug configfs parameters are set Stuart Summers
2026-09-24 23:01 ` [PATCH 16/16] drm/xe: Add enable_media module parameter Stuart Summers
2026-09-24 23:08 ` ✗ CI.checkpatch: warning for Add new debug infrastructure for configfs (rev8) Patchwork
2026-09-24 23:10 ` ✓ CI.KUnit: success " Patchwork
2026-09-24 23:27 ` ✗ CI.checksparse: warning " Patchwork
2026-09-25  0:28 ` ✓ Xe.CI.BAT: success " Patchwork
2026-09-25 13:34 ` ✗ Xe.CI.FULL: failure " Patchwork
2026-09-28  3:34 ` [PATCH 00/16] Add new debug infrastructure for configfs Matthew Brost
2026-09-28 17:07   ` Summers, Stuart
2026-09-28 19:20     ` Rodrigo Vivi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924230120.389685-20-stuart.summers@intel.com \
    --to=stuart.summers@intel.com \
    --cc=daniele.ceraolospurio@intel.com \
    --cc=gustavo.sousa@intel.com \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=matthew.brost@intel.com \
    --cc=matthew.d.roper@intel.com \
    --cc=rodrigo.vivi@intel.com \
    --cc=shuicheng.lin@intel.com \
    --cc=umesh.nerlige.ramappa@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox