Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sven Peter" <sven@kernel.org>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH v2 11/22] thunderbolt: Find Apple VSE capability during startup
Date: Sun, 06 Sep 2026 18:45:47 +0000	[thread overview]
Message-ID: <20260906184547.C88121F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260906-b4-apple-soc-tbt-v2-11-1f80085f93fb@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Infinite loop in capability parsing when a malicious Thunderbolt device presents a config space with a cyclic capability linked list.
--

commit e6dace564d4bffbe73d0c61815b1d55831634e86
Author: Sven Peter <sven@kernel.org>
Date:   Sun Sep 6 18:36:34 2026 +0000

thunderbolt: Find Apple VSE capability during startup

This commit looks up the Apple vendor-specific extended capability during
startup and stores its offset in the root switch. This enables the Apple
NHI driver to program cable information without needing to search the
router capabilities itself.

> diff --git a/drivers/thunderbolt/tb.c b/drivers/thunderbolt/tb.c
> index bf1c192ec10a5..d2832323cc360 100644
> --- a/drivers/thunderbolt/tb.c
> +++ b/drivers/thunderbolt/tb.c
> @@ -3025,6 +3025,10 @@ static int tb_start(struct tb *tb, bool reset)
>  		return dev_err_probe(tb->nhi->dev, PTR_ERR(tb->root_switch),
>  				     "failed to allocate host router\n");
>  
> +	ret = tb_switch_find_vse_cap(tb->root_switch, TB_VSE_CAP_APPLE);

[Severity: High]
This is a pre-existing issue, but does calling tb_switch_find_vse_cap expose
the kernel to an infinite loop if a malicious device is connected?

Looking at tb_switch_find_vse_cap in drivers/thunderbolt/cap.c, the capability
parsing loops indefinitely while following the next capability offset returned
by the hardware:

        do {
                struct tb_cap_any header;
                int ret;

                offset = tb_switch_next_cap(sw, offset);
                if (offset < 0)
                        return offset;
                ...
        } while (offset);

If an untrusted external device presents a configuration space with a cyclic
capability linked list (for example, where capability A points to capability B,
which points back to A), this loop will never terminate. This could cause a
localized denial of service by hanging the Thunderbolt hotplug workqueue
and pegging a CPU core at 100% indefinitely.

Should there be a cycle detection mechanism or an iteration limit added to
the capability traversal logic to prevent this?

> +	if (ret > 0)
> +		tb->root_switch->cap_vsec_apple = ret;
> +

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260906-b4-apple-soc-tbt-v2-0-1f80085f93fb@kernel.org?part=11

  reply	other threads:[~2026-09-06 18:45 UTC|newest]

Thread overview: 52+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-06 18:36 [PATCH v2 00/22] Initial USB4/Thunderbolt support for Apple M1/M2/M3 SoCs Sven Peter
2026-09-06 18:36 ` [PATCH v2 01/22] usb: typec: Add alternate mode state notifiers Sven Peter
2026-09-06 18:48   ` sashiko-bot
2026-09-07 13:27   ` Joshua Peisach
2026-09-08 12:00   ` Heikki Krogerus
2026-09-06 18:36 ` [PATCH v2 02/22] usb: typec: Represent USB4 on the Type-C bus Sven Peter
2026-09-06 18:52   ` sashiko-bot
2026-09-07 13:31   ` Joshua Peisach
2026-09-08 12:07   ` Heikki Krogerus
2026-09-06 18:36 ` [PATCH v2 03/22] usb: typec: tipd: Register a USB4 port mode for CD321x Sven Peter
2026-09-06 18:47   ` sashiko-bot
2026-09-06 18:36 ` [PATCH v2 04/22] usb: typec: tipd: Publish CD321x partner alternate modes Sven Peter
2026-09-06 18:54   ` sashiko-bot
2026-09-06 18:36 ` [PATCH v2 05/22] dt-bindings: thunderbolt: Add Apple USB4/Thunderbolt NHI Sven Peter
2026-09-06 18:36 ` [PATCH v2 06/22] dt-bindings: thunderbolt: Add Apple USB4/Thunderbolt ACIO block Sven Peter
2026-09-06 18:36 ` [PATCH v2 07/22] thunderbolt: Try reading host DROM from device tree first Sven Peter
2026-09-06 18:36 ` [PATCH v2 08/22] thunderbolt: Don't read the UID if we already know it Sven Peter
2026-09-06 19:07   ` sashiko-bot
2026-09-06 18:36 ` [PATCH v2 09/22] thunderbolt: Allocate ring HopID before requesting the ring interrupt Sven Peter
2026-09-06 18:36 ` [PATCH v2 10/22] thunderbolt: Unlock host router ports during startup Sven Peter
2026-09-06 19:03   ` sashiko-bot
2026-09-08  8:22   ` Mika Westerberg
2026-09-06 18:36 ` [PATCH v2 11/22] thunderbolt: Find Apple VSE capability " Sven Peter
2026-09-06 18:45   ` sashiko-bot [this message]
2026-09-07 13:38   ` Joshua Peisach
2026-09-08 20:24     ` Sven Peter
2026-09-06 18:36 ` [PATCH v2 12/22] thunderbolt: Add ring_interrupt_active to tb_nhi_ops Sven Peter
2026-09-06 18:36 ` [PATCH v2 13/22] thunderbolt: Add ring register accessors " Sven Peter
2026-09-08  8:32   ` Mika Westerberg
2026-09-06 18:36 ` [PATCH v2 14/22] thunderbolt: Add ring_interrupt_mask " Sven Peter
2026-09-06 18:36 ` [PATCH v2 15/22] thunderbolt: Add ring_configure " Sven Peter
2026-09-06 18:53   ` sashiko-bot
2026-09-06 18:36 ` [PATCH v2 16/22] thunderbolt: Add add_links " Sven Peter
2026-09-06 18:55   ` sashiko-bot
2026-09-08  8:35   ` Mika Westerberg
2026-09-06 18:36 ` [PATCH v2 17/22] thunderbolt: Add QUIRK_NO_USB3_BW_ALLOC Sven Peter
2026-09-06 18:36 ` [PATCH v2 18/22] thunderbolt: Export symbols required by the Apple Silicon driver Sven Peter
2026-09-06 18:36 ` [PATCH v2 19/22] thunderbolt: Add Apple Silicon support Sven Peter
2026-09-06 18:59   ` sashiko-bot
2026-09-08  9:18   ` Mika Westerberg
2026-09-08 19:02     ` Sven Peter
2026-09-08 19:04       ` Sven Peter
2026-09-09  6:06       ` Mika Westerberg
2026-09-09 15:20         ` Sven Peter
2026-09-09 15:25           ` Sven Peter
2026-09-10  4:52             ` Mika Westerberg
2026-09-10  4:50           ` Mika Westerberg
2026-09-06 18:36 ` [PATCH v2 20/22] arm64: dts: apple: t8103: Add USB4 ACIO and NHI Sven Peter
2026-09-06 18:36 ` [PATCH v2 21/22] arm64: dts: apple: t8112: " Sven Peter
2026-09-06 18:36 ` [PATCH v2 22/22] arm64: dts: apple: t60xx: " Sven Peter
2026-09-06 18:57   ` sashiko-bot
2026-09-07 13:52 ` [PATCH v2 00/22] Initial USB4/Thunderbolt support for Apple M1/M2/M3 SoCs Joshua Peisach

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260906184547.C88121F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sven@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox