From: sashiko-bot@kernel.org
To: "Vikash Garodia" <vikash.garodia@oss.qualcomm.com>
Cc: robh@kernel.org, conor+dt@kernel.org, media-ci@linuxtv.org,
devicetree@vger.kernel.org
Subject: Re: [PATCH 12/22] arm64: dts: qcom: agatti: Reserve low IOVA range for Venus
Date: Fri, 07 Aug 2026 08:57:29 +0000 [thread overview]
Message-ID: <20260807085730.953011F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260807-iris_iova_600mb_fix-v1-12-3996f67e33f9@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Multiple parsing vulnerabilities in `of_iommu_get_resv_regions` when processing `iommu-addresses`.
--
--- Patch [12]: [PATCH 12/22] arm64: dts: qcom: agatti: Reserve low IOVA range for Venus ---
commit ce9067cc6b514ef4e9f906bcee46fa8222f6c18b
Author: Vikash Garodia <vikash.garodia@oss.qualcomm.com>
arm64: dts: qcom: agatti: Reserve low IOVA range for Venus
This commit reserves IOVA addresses below 0x25800000 for the Venus VPU.
This prevents unhandled SMMU page faults and spontaneous reboots when
other stream IDs DMA into that range.
Fixes: 7a37bf31e3a7 ("arm64: dts: qcom: qcm2290: Add Venus video node")
Cc: stable@vger.kernel.org
> diff --git a/arch/arm64/boot/dts/qcom/agatti.dtsi b/arch/arm64/boot/dts/qcom/agatti.dtsi
> index 590bd2432d85b..6ae66ef882363 100644
> --- a/arch/arm64/boot/dts/qcom/agatti.dtsi
> +++ b/arch/arm64/boot/dts/qcom/agatti.dtsi
[ ... ]
> @@ -381,6 +381,17 @@ rmtfs_mem: memory@89b01000 {
> qcom,client-id = <1>;
> qcom,vmid = <QCOM_SCM_VMID_MSS_MSA QCOM_SCM_VMID_NAV>;
> };
> +
> + /*
> + * The Venus VPU reserves IOVA below 0x25800000 (600MB),
> + * primarily for non-pixel buffers using different Stream IDs.
> + * DMA into that range triggers unhandled SMMU faults and
> + * spontaneous reboots, so reserve it to keep IOMMU
> + * allocations above this boundary.
> + */
> + venus_iova: venus-iova {
> + iommu-addresses = <&venus 0x0 0x0 0x0 0x25800000>;
> + };
[Severity: High]
This isn't a bug introduced by this patch, but using the iommu-addresses
property here exposes multiple parsing vulnerabilities in
of_iommu_get_resv_regions() in drivers/iommu/of_iommu.c.
First, if a memory-region specifies iommu-addresses with entries for
multiple devices, the loop reads the first phandle. If it doesn't match
dev->of_node, it continues without advancing the maps pointer by the
required address and size cells (na + ns):
drivers/iommu/of_iommu.c:of_iommu_get_resv_regions() {
...
phandle = be32_to_cpup(maps++);
np = of_find_node_by_phandle(phandle);
if (np == dev->of_node) {
...
}
Does this cause the next iteration to incorrectly interpret the remaining
address and size cells as a phandle?
Second, if of_translate_dma_region() fails because there is no DMA parent,
it returns null. The stack variable length remains uninitialized. If length
is not zero, the loop proceeds.
drivers/iommu/of_iommu.c:of_iommu_get_resv_regions() {
...
maps = of_translate_dma_region(np, maps, &iova, &length);
if (length == 0)
continue;
...
}
Since maps is null, will this trigger a fatal null pointer dereference on
the next maps++ ?
Finally, there appears to be no bounds check before of_translate_dma_region()
reads na + ns cells from the maps pointer.
Should these parser issues in of_iommu_get_resv_regions() be fixed before
or alongside introducing this iommu-addresses usage?
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260807-iris_iova_600mb_fix-v1-0-3996f67e33f9@oss.qualcomm.com?part=12
next prev parent reply other threads:[~2026-08-07 8:57 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <5BXSXMNl656WiJPJAMmHvb3I2NzYMshRZuGuub3CxEXvdCUlIDKYbnv5jUq-pa6P1NibBLkO3njnKGxi7Al3jQ==@protonmail.internalid>
2026-08-07 8:24 ` [PATCH 00/22] media: iris: Restrict lower IOVA range for Venus and Iris VPUs Vikash Garodia
2026-08-07 8:24 ` [PATCH 01/22] dt-bindings: media: qcom,venus-common: Allow IOVA reservation memory-region Vikash Garodia
2026-08-07 8:49 ` sashiko-bot
2026-08-07 8:51 ` Vikash Garodia
2026-08-07 8:24 ` [PATCH 02/22] dt-bindings: media: qcom,sm8550-iris: " Vikash Garodia
2026-08-07 8:40 ` sashiko-bot
2026-08-07 9:01 ` Dmitry Baryshkov
2026-08-07 8:24 ` [PATCH 03/22] dt-bindings: media: qcom,sc7180-venus: " Vikash Garodia
2026-08-07 8:24 ` [PATCH 04/22] arm64: dts: qcom: hamoa: Reserve low IOVA range for Iris Vikash Garodia
2026-08-07 8:45 ` sashiko-bot
2026-08-07 9:03 ` Dmitry Baryshkov
2026-08-07 9:26 ` Vikash Garodia
2026-08-07 10:00 ` Dmitry Baryshkov
2026-08-07 10:22 ` Vikash Garodia
2026-08-07 13:18 ` Bryan O'Donoghue
2026-08-07 16:24 ` Rob Herring
2026-08-08 4:37 ` Vishnu Reddy
2026-08-07 8:24 ` [PATCH 05/22] arm64: dts: qcom: lemans: " Vikash Garodia
2026-08-07 8:44 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 06/22] arm64: dts: qcom: monaco: " Vikash Garodia
2026-08-07 8:47 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 07/22] arm64: dts: qcom: sc8280xp: " Vikash Garodia
2026-08-07 8:44 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 08/22] arm64: dts: qcom: sm8350: " Vikash Garodia
2026-08-07 8:50 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 09/22] arm64: dts: qcom: sm8550: " Vikash Garodia
2026-08-07 8:46 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 10/22] arm64: dts: qcom: sm8650: " Vikash Garodia
2026-08-07 8:42 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 11/22] arm64: dts: qcom: sm8750: " Vikash Garodia
2026-08-07 8:54 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 12/22] arm64: dts: qcom: agatti: Reserve low IOVA range for Venus Vikash Garodia
2026-08-07 8:57 ` sashiko-bot [this message]
2026-08-07 8:24 ` [PATCH 13/22] arm64: dts: qcom: kodiak: " Vikash Garodia
2026-08-07 8:54 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 14/22] arm64: dts: qcom: msm8916: " Vikash Garodia
2026-08-07 8:58 ` sashiko-bot
2026-08-07 8:24 ` [PATCH 15/22] arm64: dts: qcom: msm8996: " Vikash Garodia
2026-08-07 8:25 ` [PATCH 16/22] arm64: dts: qcom: msm8998: " Vikash Garodia
2026-08-07 8:25 ` [PATCH 17/22] arm64: dts: qcom: sc7180: " Vikash Garodia
2026-08-07 8:59 ` sashiko-bot
2026-08-07 8:25 ` [PATCH 18/22] arm64: dts: qcom: sdm630: " Vikash Garodia
2026-08-07 9:00 ` sashiko-bot
2026-08-07 8:25 ` [PATCH 19/22] arm64: dts: qcom: sdm845: " Vikash Garodia
2026-08-07 8:25 ` [PATCH 20/22] arm64: dts: qcom: sm6115: " Vikash Garodia
2026-08-07 9:05 ` sashiko-bot
2026-08-07 8:25 ` [PATCH 21/22] arm64: dts: qcom: sm8250: " Vikash Garodia
2026-08-07 8:25 ` [PATCH 22/22] arm64: dts: qcom: talos: " Vikash Garodia
2026-08-07 9:08 ` sashiko-bot
2026-08-07 8:51 ` [PATCH 00/22] media: iris: Restrict lower IOVA range for Venus and Iris VPUs Bryan O'Donoghue
2026-08-07 8:59 ` Dmitry Baryshkov
2026-08-07 9:05 ` Vikash Garodia
2026-08-07 10:01 ` Dmitry Baryshkov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260807085730.953011F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=media-ci@linuxtv.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vikash.garodia@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox