From: Michal Wajdeczko <michal.wajdeczko@intel.com>
To: Satyanarayana K V P <satyanarayana.k.v.p@intel.com>,
<intel-xe@lists.freedesktop.org>
Subject: Re: [PATCH v10 07/10] drm/xe/vf: Add bounds checking for queried GGTT base and size
Date: Mon, 21 Sep 2026 16:36:47 +0200 [thread overview]
Message-ID: <a4ccbd29-56bb-4a5e-b4d1-83137298d6ac@intel.com> (raw)
In-Reply-To: <20260921092101.1243989-19-satyanarayana.k.v.p@intel.com>
On 9/21/2026 11:21 AM, Satyanarayana K V P wrote:
> Add explicit bounds checks for GGTT base and size which can detect
> and reject invalid configuration data from a misconfigured or
> malfunctioning PF, preventing protocol violations and protecting VF
> initialization.
>
> Signed-off-by: Satyanarayana K V P <satyanarayana.k.v.p@intel.com>
> Cc: Michal Wajdeczko <michal.wajdeczko@intel.com>
> ---
> V9 -> V10:
> - Updated vf_get_ggtt_alignment() function (Sashiko).
>
> V8 -> V9:
> - Align GGTT base and size to XE_PAGE_SIZE (Sashiko).
>
> V7 -> V8:
> - Align GGTT base and size to PAGE_SIZE (Michal W).
>
> V6 -> V7:
> - Added new helper to get ggtt alignment.
> - Rearranged the base and sizes checks (Sashiko, Michal W).
>
> V5 -> V6:
> - Updated error codes for unaligned GGTT base and size (Michal W).
> - Fixed review comments (Michal W).
>
> V4 -> V5:
> - New commit.
> ---
> drivers/gpu/drm/xe/xe_gt_sriov_vf.c | 45 ++++++++++++++++++++++++++---
> 1 file changed, 41 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/gpu/drm/xe/xe_gt_sriov_vf.c b/drivers/gpu/drm/xe/xe_gt_sriov_vf.c
> index 715dfb04a1f3..1d79bde2ad73 100644
> --- a/drivers/gpu/drm/xe/xe_gt_sriov_vf.c
> +++ b/drivers/gpu/drm/xe/xe_gt_sriov_vf.c
> @@ -15,6 +15,7 @@
> #include "abi/guc_klvs_abi.h"
> #include "abi/guc_relay_actions_abi.h"
> #include "regs/xe_gt_regs.h"
> +#include "regs/xe_gtt_defs.h"
> #include "regs/xe_guc_regs.h"
>
> #include "xe_assert.h"
> @@ -486,26 +487,62 @@ u32 xe_gt_sriov_vf_gmdid(struct xe_gt *gt)
> return value;
> }
>
> +static u64 vf_get_ggtt_alignment(struct xe_gt *gt)
> +{
> + return xe_sriov_ggtt_alignment(gt_to_xe(gt));
> +}
> +
> static int vf_get_ggtt_info(struct xe_gt *gt)
> {
> + u64 alignment = vf_get_ggtt_alignment(gt);
> struct xe_tile *tile = gt_to_tile(gt);
> struct xe_guc *guc = >->uc.guc;
> - u64 start, size, ggtt_size;
> + u64 start, size, ggtt_size, end;
> + u64 start_query, size_query;
> int err;
>
> xe_gt_assert(gt, IS_SRIOV_VF(gt_to_xe(gt)));
>
> - err = guc_action_query_single_klv64(guc, GUC_KLV_VF_CFG_GGTT_START_KEY, &start);
> + err = guc_action_query_single_klv64(guc, GUC_KLV_VF_CFG_GGTT_START_KEY, &start_query);
do we really need/want to rename existing vars?
> if (unlikely(err))
> return err;
shouldn't we immediately check here for 4K misalignment?
it is a clear VF provisioning violation, see [1]:
if (!IS_ALIGNED(start, XE_PAGE_SIZE))
return -EINVAL; // or -EUCLEAN or -EDOM or -ERANGE
[1] https://elixir.bootlin.com/linux/v7.3-rc3/source/drivers/gpu/drm/xe/abi/guc_klvs_abi.h#L280
>
> - err = guc_action_query_single_klv64(guc, GUC_KLV_VF_CFG_GGTT_SIZE_KEY, &size);
> + err = guc_action_query_single_klv64(guc, GUC_KLV_VF_CFG_GGTT_SIZE_KEY, &size_query);
> if (unlikely(err))
> return err;
ditto
>
> - if (!size)
> + if (!size_query)
> return -ENODATA;
>
> + start = ALIGN(start_query, alignment);
not needed, as it looks any 64K alignment is handled on the per-object basis
by the xe_ggtt layer
> + if (check_add_overflow(start_query, size_query, &end)) {
> + xe_gt_sriov_err(gt, "GGTT range overflow: base %#llx, size %#llx\n",
> + start_query, size_query);
we are not so verbose for other error cases,
maybe demote to dbg/dbg_verbose or drop completely?
> + return -ERANGE;
> + }
> +
> + end = ALIGN_DOWN(end, alignment);
not needed, see above
> + if (end <= start) {
impossible now, as at this point:
both start & size should be already 4K aligned
end = start + size
and size can't be 0
> + xe_gt_sriov_err(gt, "GGTT range too small: base %#llx, size %#llx\n",
> + start_query, size_query);
> + return -ERANGE;
> + }
> +
> + size = end - start;
> +
> + if (start != start_query)
> + xe_gt_sriov_notice(gt, "Unaligned GGTT base %#llx aligned to %#llx\n",
> + start_query, start);
> + if (size != size_query)
> + xe_gt_sriov_notice(gt, "Unaligned GGTT size %#llx aligned to %#llx\n",
> + size_query, size);
will not be needed after adding above checks for 4K alignment right after query
> +
> + if (start < xe_wopcm_size(gt_to_xe(gt)) || end > GUC_GGTT_TOP) {
nit: we can check "start < wopcm" right after query
nit: we can check "end > GUC_TOP" right after query
> + xe_gt_sriov_err(gt, "Out of bounds GGTT configuration: base %#llx, size %#llx\n",
> + start, size);
> + return -ERANGE;
> + }
> +
> xe_tile_sriov_vf_ggtt_base_store(tile, start);
> ggtt_size = xe_tile_sriov_vf_ggtt(tile);
> if (!ggtt_size) {
next prev parent reply other threads:[~2026-09-21 14:36 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 9:20 [PATCH v10 00/10] KUnit test for VF provisioning error handling Satyanarayana K V P
2026-09-21 9:21 ` [PATCH v10 01/10] drm/xe/guc: Allow to replace xe_guc_mmio_send_recv() with KUNIT stub Satyanarayana K V P
2026-09-21 9:21 ` [PATCH v10 02/10] drm/xe/vf: Split submission config query helpers Satyanarayana K V P
2026-09-21 9:21 ` [PATCH v10 03/10] drm/xe/vf: Add bounds checking for queried context and doorbell counts Satyanarayana K V P
2026-09-21 9:21 ` [PATCH v10 04/10] drm/xe: Introduce helpers for VRAM alignment Satyanarayana K V P
2026-09-21 9:21 ` [PATCH v10 05/10] drm/xe/ggtt: Avoid integer overflow when validating VF GGTT range Satyanarayana K V P
2026-09-21 14:03 ` Michal Wajdeczko
2026-09-21 9:21 ` [PATCH v10 06/10] drm/xe/sriov: Add helper for VF GGTT provisioning alignment Satyanarayana K V P
2026-09-21 13:26 ` Michal Wajdeczko
2026-09-21 9:21 ` [PATCH v10 07/10] drm/xe/vf: Add bounds checking for queried GGTT base and size Satyanarayana K V P
2026-09-21 14:36 ` Michal Wajdeczko [this message]
2026-09-21 9:21 ` [PATCH v10 08/10] drm/xe/vf: Add alignment check for queried VRAM size Satyanarayana K V P
2026-09-21 9:21 ` [PATCH v10 09/10] drm/xe/ggtt: Add KUnit stub for xe_ggtt_shift_nodes() Satyanarayana K V P
2026-09-21 14:45 ` Michal Wajdeczko
2026-09-21 9:21 ` [PATCH v10 10/10] drm/xe/tests: Add KUnit tests for VF provisioning error handling Satyanarayana K V P
2026-09-21 16:47 ` Michal Wajdeczko
2026-09-21 9:49 ` ✗ CI.checkpatch: warning for KUnit test for VF provisioning error handling (rev10) Patchwork
2026-09-21 9:51 ` ✓ CI.KUnit: success " Patchwork
2026-09-21 11:32 ` ✗ Xe.CI.BAT: failure " Patchwork
2026-09-21 14:10 ` ✗ Xe.CI.FULL: " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a4ccbd29-56bb-4a5e-b4d1-83137298d6ac@intel.com \
--to=michal.wajdeczko@intel.com \
--cc=intel-xe@lists.freedesktop.org \
--cc=satyanarayana.k.v.p@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox