From: Stuart Summers <stuart.summers@intel.com>
Cc: intel-xe@lists.freedesktop.org, rodrigo.vivi@intel.com,
matthew.brost@intel.com, umesh.nerlige.ramappa@intel.com,
gustavo.sousa@intel.com, matthew.d.roper@intel.com,
daniele.ceraolospurio@intel.com, shuicheng.lin@intel.com,
Stuart Summers <stuart.summers@intel.com>
Subject: [PATCH 02/15] drm/xe/configfs: Fix out-of-bounds read in parse_wa_bb_lines()
Date: Mon, 5 Oct 2026 19:06:12 +0000 [thread overview]
Message-ID: <20261005190611.332940-19-stuart.summers@intel.com> (raw)
In-Reply-To: <20261005190611.332940-17-stuart.summers@intel.com>
The outer loop advances the cursor unconditionally at the end of each
iteration. When the last token of a line is terminated by the NUL rather
than by whitespace, e.g. "echo -n 'rcs cmd 1'", the cursor is already on
the NUL and the increment steps past the end of the buffer, so the loop
condition reads out of bounds. The leading strspn(p, " \t\n") already
skips the line separators, and every iteration consumes at least the
engine class token, so dropping the increment keeps the loop making
progress.
Fixes: 39ac06f70062 ("drm/xe/configfs: Add post context restore bb")
Signed-off-by: Stuart Summers <stuart.summers@intel.com>
Assisted-by: LLM
---
drivers/gpu/drm/xe/xe_configfs.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/xe/xe_configfs.c b/drivers/gpu/drm/xe/xe_configfs.c
index e1cf5af958bc..1c7a096aa046 100644
--- a/drivers/gpu/drm/xe/xe_configfs.c
+++ b/drivers/gpu/drm/xe/xe_configfs.c
@@ -820,7 +820,11 @@ static ssize_t parse_wa_bb_lines(const char *lines,
ssize_t dwords = 0, ret;
const char *p;
- for (p = lines; *p; p++) {
+ /*
+ * Each iteration consumes at least the engine class token if it doesn't
+ * error out, so the loop always makes progress without advancing @p.
+ */
+ for (p = lines; *p;) {
const struct engine_info *info = NULL;
u32 val, val2;
--
2.43.0
next prev parent reply other threads:[~2026-10-05 19:06 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 19:06 [PATCH 00/15] Add new debug infrastructure for configfs Stuart Summers
2026-10-05 19:06 ` [PATCH 01/15] drm/xe: Guard configfs attribute reads in getters Stuart Summers
2026-10-05 19:06 ` Stuart Summers [this message]
2026-10-05 19:06 ` [PATCH 03/15] drm/xe/configfs: Copy wa_bb out under the configfs lock Stuart Summers
2026-10-05 19:06 ` [PATCH 04/15] drm/xe: Invert vram_page_offline configfs attribute Stuart Summers
2026-10-05 19:06 ` [PATCH 05/15] drm/xe: Make survivability_mode configfs attribute a bitmap Stuart Summers
2026-10-05 19:06 ` [PATCH 06/15] drm/xe: Sort xe_config_device fields Stuart Summers
2026-10-05 19:06 ` [PATCH 07/15] drm/xe: Split out configfs data structures Stuart Summers
2026-10-05 19:06 ` [PATCH 08/15] drm/xe: Add a new debug focused configfs group Stuart Summers
2026-10-05 19:06 ` [PATCH 09/15] drm/xe: Move debug configfs entries to xe_configfs_debug.c Stuart Summers
2026-10-05 19:06 ` [PATCH 10/15] drm/xe/guc: Add configfs support for guc_log_level Stuart Summers
2026-10-05 19:06 ` [PATCH 11/15] drm/xe/guc: Add support for NPK as a GuC log target Stuart Summers
2026-10-05 19:06 ` [PATCH 12/15] drm/xe: Add infrastructure for debug configfs parameters Stuart Summers
2026-10-05 19:06 ` [PATCH 13/15] drm/xe: Migrate existing debug configfs entries to params infrastructure Stuart Summers
2026-10-05 19:06 ` [PATCH 14/15] drm/xe: Taint kernel when debug configfs parameters are set Stuart Summers
2026-10-05 19:06 ` [PATCH 15/15] drm/xe: Add enable_media module parameter Stuart Summers
2026-10-05 19:26 ` ✗ CI.checkpatch: warning for Add new debug infrastructure for configfs (rev9) Patchwork
2026-10-05 19:28 ` ✓ CI.KUnit: success " Patchwork
2026-10-05 20:05 ` ✗ Xe.CI.BAT: failure " Patchwork
2026-10-05 20:34 ` [PATCH 00/15] Add new debug infrastructure for configfs Summers, Stuart
-- strict thread matches above, loose matches on Subject: below --
2026-10-05 22:06 Stuart Summers
2026-10-05 22:06 ` [PATCH 02/15] drm/xe/configfs: Fix out-of-bounds read in parse_wa_bb_lines() Stuart Summers
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005190611.332940-19-stuart.summers@intel.com \
--to=stuart.summers@intel.com \
--cc=daniele.ceraolospurio@intel.com \
--cc=gustavo.sousa@intel.com \
--cc=intel-xe@lists.freedesktop.org \
--cc=matthew.brost@intel.com \
--cc=matthew.d.roper@intel.com \
--cc=rodrigo.vivi@intel.com \
--cc=shuicheng.lin@intel.com \
--cc=umesh.nerlige.ramappa@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox