Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Lee Trager <lee@trager.us>
To: Andre Przywara <andre.przywara@arm.com>,
	Lorenzo Pieralisi <lpieralisi@kernel.org>,
	Hanjun Guo <guohanjun@huawei.com>,
	Sudeep Holla <sudeep.holla@kernel.org>,
	Catalin Marinas <catalin.marinas@arm.com>,
	Will Deacon <will@kernel.org>,
	"Rafael J . Wysocki" <rafael@kernel.org>,
	Len Brown <lenb@kernel.org>, James Morse <james.morse@arm.com>,
	Ben Horgan <ben.horgan@arm.com>,
	Reinette Chatre <reinette.chatre@intel.com>,
	Fenghua Yu <fenghuay@nvidia.com>
Cc: Jonathan Cameron <jic23@kernel.org>,
	Srivathsa L Rao <srivathsa.rao@oss.qualcomm.com>,
	Ganapatrao Kulkarni <ganapatrao.kulkarni@oss.qualcomm.com>,
	Trilok Soni <tsoni@quicinc.com>,
	Srinivas Ramana <sramana@qti.qualcomm.com>,
	Niyas Sait <niyas.sait@arm.com>,
	linux-acpi@vger.kernel.org, linux-arm-kernel@lists.infradead.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH v5 10/10] arm_mpam: detect and enable MPAM-Fb PCC support
Date: Wed, 29 Jul 2026 18:34:11 -0700	[thread overview]
Message-ID: <ec478b24-0a30-4b63-b191-08d05f606bad@trager.us> (raw)
In-Reply-To: <20260729134124.2506269-11-andre.przywara@arm.com>

On 7/29/26 6:41 AM, Andre Przywara wrote:

> @@ -2231,7 +2316,7 @@ static void mpam_msc_drv_remove(struct platform_device *pdev)
>   static struct mpam_msc *do_mpam_msc_drv_probe(struct platform_device *pdev)
>   {
>   	int err;
> -	u32 tmp;
> +	u32 pcc_subspace_id;
>   	struct mpam_msc *msc;
>   	struct resource *msc_res;
>   	struct device *dev = &pdev->dev;
> @@ -2279,7 +2364,7 @@ static struct mpam_msc *do_mpam_msc_drv_probe(struct platform_device *pdev)
>   	if (err)
>   		return ERR_PTR(err);
>   
> -	if (device_property_read_u32(&pdev->dev, "pcc-channel", &tmp))
> +	if (device_property_read_u32(dev, "pcc-channel", &pcc_subspace_id))
>   		msc->iface = MPAM_IFACE_MMIO;
>   	else
>   		msc->iface = MPAM_IFACE_PCC;
> @@ -2295,6 +2380,36 @@ static struct mpam_msc *do_mpam_msc_drv_probe(struct platform_device *pdev)
>   		}
>   		msc->mapped_hwpage_sz = msc_res->end - msc_res->start;
>   		msc->mapped_hwpage = io;
> +	} else if (msc->iface == MPAM_IFACE_PCC) {
> +		int ret;
> +
> +		msc->pcc_chan = mpam_pcc_chan_get(dev, pcc_subspace_id);
> +		if (IS_ERR(msc->pcc_chan)) {
> +			pr_err("Failed to request MSC PCC channel\n");
> +			return ERR_CAST(msc->pcc_chan);
> +		}
> +
> +		if (msc->pcc_chan->pcc_chan->shmem_size < MPAM_FB_MAX_MSG_SIZE) {

I think the PCC shared-memory size undercounts the required region. From 
my understanding shmem_size is the length of the complete PCC 
shared-memory region advertised by the PCCT and mapped by the PCC 
driver. MPAM_FB_MAX_MSG_SIZE is the 4-byte protocol header stored in 
pcc_shmem->command + the 16-byte write payload.

However, mpam_fb_build_write_message() places the payload after the 
complete 16 byte struct acpi_pcct_ext_pcc_shared_memory. The largest 
request therefore occupies 32 bytes of shared memory region(16-byte PCC 
header+ 16-byte write payload). Thus a firmware region between 20 and 31 
bytes currently passes the check but overruns when constructing a write 
request. I think this should be

if (msc->pcc_chan->pcc_chan->shmem_size <

     sizeof(struct acpi_pcct_ext_pcc_shared_memory) +
     MPAM_FB_MAX_MSG_SIZE - MPAM_FB_PROT_HEADER_LEN)

>   
> diff --git a/drivers/resctrl/mpam_internal.h b/drivers/resctrl/mpam_internal.h
> index a2193e7df57c..e926b7feb72a 100644
> --- a/drivers/resctrl/mpam_internal.h
> +++ b/drivers/resctrl/mpam_internal.h
> @@ -77,7 +77,6 @@ struct mpam_msc {
>   	/* Not modified after mpam_is_enabled() becomes true */
>   	enum mpam_msc_iface	iface;
>   	struct mpam_pcc_chan	*pcc_chan;
> -	int			mpam_fb_msc_id;	/* in its own name space */
>   	u32			nrdy_usec;
>   	cpumask_t		accessibility;
>   	bool			has_extd_esr;
> @@ -532,6 +531,11 @@ int mpam_fb_send_write_request(struct mpam_msc *msc, u16 reg, u32 value);
>   int mpam_fb_get_protocol_version(struct mpam_msc *msc);
>   
>   #define MPAM_FB_PROT_HEADER_LEN		sizeof(u32)
> +/* The longest message is MPAM_MSC_WRITE, with 4 parameters. */
> +#define MPAM_FB_MAX_MSG_SIZE	(MPAM_FB_PROT_HEADER_LEN + 4 * sizeof(u32))
> +
> +#define MPAM_FB_VERSION_MAJOR_MASK	GENMASK(31, 16)
> +#define MPAM_FB_VERSION_MINOR_MASK	GENMASK(15, 0)
>   
>   /*
>    * MPAM MSCs have the following register layout. See:


  reply	other threads:[~2026-07-30  1:34 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-29 13:41 [PATCH v5 00/10] arm_mpam: Add MPAM-Fb firmware support Andre Przywara
2026-07-29 13:41 ` [PATCH v5 01/10] arm_mpam: let low level MSC accessors return an error Andre Przywara
2026-07-30 11:20   ` Ben Horgan
2026-07-29 13:41 ` [PATCH v5 02/10] arm_mpam: propagate MSC access errors for hw_probe functions Andre Przywara
2026-07-30 11:21   ` Ben Horgan
2026-07-29 13:41 ` [PATCH v5 03/10] arm_mpam: propagate MSC access errors for MBWU counters Andre Przywara
2026-07-30  1:33   ` Lee Trager
2026-07-30  8:20     ` Ben Horgan
2026-07-30 11:23   ` Ben Horgan
2026-07-29 13:41 ` [PATCH v5 04/10] arm_mpam: propagate MSC access errors for msmon helpers Andre Przywara
2026-07-30 11:25   ` Ben Horgan
2026-07-29 13:41 ` [PATCH v5 05/10] arm_mpam: propagate MSC access errors for __ris_msmon_read() Andre Przywara
2026-07-30  9:52   ` Ben Horgan
2026-07-29 13:41 ` [PATCH v5 06/10] arm_mpam: propagate MSC access errors for state saving function Andre Przywara
2026-07-30 11:28   ` Ben Horgan
2026-07-29 13:41 ` [PATCH v5 07/10] arm_mpam: prepare mon_sel locking for MPAM-Fb Andre Przywara
2026-07-29 13:41 ` [PATCH v5 08/10] arm_mpam: add MPAM-Fb MSC firmware access support Andre Przywara
2026-07-29 14:51   ` Ben Horgan
2026-07-29 15:17     ` Andre Przywara
2026-07-29 16:10   ` Ben Horgan
2026-07-30 12:54     ` Andre Przywara
2026-07-29 16:13   ` Srivathsa L Rao
2026-07-30  9:55     ` Andre Przywara
2026-07-30 10:59   ` Ben Horgan
2026-07-30 12:28     ` Andre Przywara
2026-07-29 13:41 ` [PATCH v5 09/10] arm_mpam: change error IRQ to use a threaded IRQ handler Andre Przywara
2026-07-29 15:23   ` Ben Horgan
2026-07-30 12:07     ` Andre Przywara
2026-07-29 13:41 ` [PATCH v5 10/10] arm_mpam: detect and enable MPAM-Fb PCC support Andre Przywara
2026-07-30  1:34   ` Lee Trager [this message]
2026-07-30 12:47     ` Andre Przywara
2026-07-30  9:58   ` Srivathsa L Rao
2026-07-30 10:05     ` Andre Przywara
2026-07-30 11:06 ` [PATCH v5 00/10] arm_mpam: Add MPAM-Fb firmware support Ritwick Sharma

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ec478b24-0a30-4b63-b191-08d05f606bad@trager.us \
    --to=lee@trager.us \
    --cc=andre.przywara@arm.com \
    --cc=ben.horgan@arm.com \
    --cc=catalin.marinas@arm.com \
    --cc=fenghuay@nvidia.com \
    --cc=ganapatrao.kulkarni@oss.qualcomm.com \
    --cc=guohanjun@huawei.com \
    --cc=james.morse@arm.com \
    --cc=jic23@kernel.org \
    --cc=lenb@kernel.org \
    --cc=linux-acpi@vger.kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lpieralisi@kernel.org \
    --cc=niyas.sait@arm.com \
    --cc=rafael@kernel.org \
    --cc=reinette.chatre@intel.com \
    --cc=sramana@qti.qualcomm.com \
    --cc=srivathsa.rao@oss.qualcomm.com \
    --cc=sudeep.holla@kernel.org \
    --cc=tsoni@quicinc.com \
    --cc=will@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox