From: Yin Li <yin.li@oss.qualcomm.com>
To: Andre Przywara <andre.przywara@arm.com>,
"Rafael J. Wysocki" <rafael@kernel.org>,
Shanker Donthineni <sdonthineni@nvidia.com>,
Conor Dooley <conor+dt@kernel.org>,
Fenghua Yu <fenghuay@nvidia.com>,
Krzysztof Kozlowski <krzk+dt@kernel.org>,
Rob Herring <robh@kernel.org>,
Reinette Chatre <reinette.chatre@intel.com>,
Konrad Dybcio <konradybcio@kernel.org>,
James Morse <james.morse@arm.com>,
Ben Horgan <ben.horgan@arm.com>,
Bjorn Andersson <andersson@kernel.org>,
Danilo Krummrich <dakr@kernel.org>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: linux-arm-msm@vger.kernel.org,
ganapatrao.kulkarni@oss.qualcomm.com,
trilok.soni@oss.qualcomm.com, devicetree@vger.kernel.org,
driver-core@lists.linux.dev,
Srivathsa L Rao <srivathsa.rao@oss.qualcomm.com>,
Huang Yiwei <huang.yiwei@oss.qualcomm.com>,
aiqun.yu@oss.qualcomm.com, linux-kernel@vger.kernel.org
Subject: Re: [PATCH RFC 08/15] arm_mpam: Fix ris_idx type to prevent range check bypass on truncation
Date: Fri, 4 Sep 2026 10:42:29 +0800 [thread overview]
Message-ID: <3f67a5dd-e567-409c-ba93-8931ffadf75b@oss.qualcomm.com> (raw)
In-Reply-To: <bf973056-590b-45d4-a66c-d61b480ce229@arm.com>
On 9/3/2026 9:27 PM, Andre Przywara wrote:
> Hi,
>
> On 9/3/26 11:42, Yin Li wrote:
>>
>>
>> On 9/3/2026 12:22 AM, Andre Przywara wrote:
>>> Hi,
>>>
>>> On 8/11/26 15:30, Yin Li wrote:
>>>> The RIS index is read from device tree as u64 via
>>>> of_property_read_reg(),
>>>
>>> what does it do that using an u64, actually? Do you refer to the reg
>>> property of the ris subnode, which has a limit of 0xf in the DT
>>> binding? So shouldn't it be an u8 all along, and we fix the types up
>>> at the sources, rather than widening everything needlessly to u64?
>>>
>>
>> Hi Andre,
>>
>> Thanks for the review.
>>
>> Yes, this is the reg property of the ris subnode. The reason it starts
>> as u64 is that it's read via of_property_read_reg(), whose API takes a
>
> Yes, I figured as much, *after* hitting the Send button ;-)
>
😜
>> u64* for the value — so ris_idx has to be u64 at that point, regardless
>> of the 0xf limit in the binding.
>
> Which actually makes me wonder whether this is the right function to
> use, since there would be no translation (as indeed guaranteed by this
> function), but also no size, and I guess no cell size requirements
> beyond 1. I think it has the added benefit of checking #address-cells
> and #size-cells, but technically a standard of_property_read_u32() would
> do as well? Though this probably has the same problem, just with u32 ...
>
>> If ris_idx were narrowed to u8 before reaching the range check in
>> mpam_ris_create_locked() (ris_idx >= MPAM_MSC_MAX_NUM_RIS), an
>> out-of-range value such as 0x100 would be truncated to 0x00 and silently
>> bypass that check. Keeping the wider type through the chain lets that
>> check see the real value and reject invalid indices.
>>
>> If you feel an explicit check right after of_property_read_reg() (with
>> the downstream types kept as u8) is cleaner, I'm glad to go that way —
>> whichever you prefer.
>
> Yeah, I feel it's sane to already check the limit directly after parsing
> from the DT, not only in mpam_ris_create() later. Do you know of any
> particular reason this is done so late?
> If there is none, I think the cleanest is to keep of_property_read_reg()
> and check against the limit already in that function. Then we can use a
> u8 all along.
>
Hi Andre,
No particular reason for the late check — it just followed the existing
structure, where mpam_ris_create() already does the range check for both
the ACPI and DT paths. Nothing requires it to happen there.
And agreed on keeping of_property_read_reg(): the #address-cells /
#size-cells validation is worth having, and of_property_read_u32()
wouldn't avoid the truncation anyway.
I'll check the limit right after of_property_read_reg() and use u8
throughout the downstream path. Checking before the narrowing avoids the
truncation concern at the source, and drops the needless widening. Will
do this in the next version.
> Cheers,
> Andre
>
>>>> but was narrowed to u32 when passed to mpam_dt_parse_resource() and
>>>> further to u8 when passed to mpam_ris_create(). A value exceeding
>>>> MPAM_MSC_MAX_NUM_RIS could be silently truncated to a small index that
>>>> passes the range check in mpam_ris_create_locked(), leading to
>>>> incorrect
>>>> RIS creation.
>>>>
>>>> Widen the ris_idx parameter through mpam_dt_parse_resource(),
>>>> mpam_ris_create_locked(), and mpam_ris_create() to u64 so the value
>>>> is preserved until the range check in mpam_ris_create_locked() rejects
>>>> out-of-range indices.
>>>>
>>>> Signed-off-by: Yin Li <yin.li@oss.qualcomm.com>
>>>> ---
>>>> drivers/resctrl/mpam_devices.c | 6 +++---
>>>> include/linux/arm_mpam.h | 4 ++--
>>>> 2 files changed, 5 insertions(+), 5 deletions(-)
>>>>
>>>> diff --git a/drivers/resctrl/mpam_devices.c b/drivers/resctrl/
>>>> mpam_devices.c
>>>> index cc9fa1d78925..1e082fb60e30 100644
>>>> --- a/drivers/resctrl/mpam_devices.c
>>>> +++ b/drivers/resctrl/mpam_devices.c
>>>> @@ -260,7 +260,7 @@ static int mpam_dt_count_msc(void)
>>>> }
>>>> static int mpam_dt_parse_resource(struct mpam_msc *msc, struct
>>>> device_node *np,
>>>> - u32 ris_idx)
>>>> + u64 ris_idx)
>>>> {
>>>> int err = 0;
>>>> u32 class_id = 0;
>>>> @@ -712,7 +712,7 @@ static int mpam_ris_get_affinity(struct mpam_msc
>>>> *msc, cpumask_t *affinity,
>>>> return 0;
>>>> }
>>>> -static int mpam_ris_create_locked(struct mpam_msc *msc, u8 ris_idx,
>>>> +static int mpam_ris_create_locked(struct mpam_msc *msc, u64 ris_idx,
>>>> enum mpam_class_types type, u8 class_id,
>>>> int component_id)
>>>> {
>>>> @@ -799,7 +799,7 @@ static void mpam_ris_destroy(struct mpam_msc_ris
>>>> *ris)
>>>> mpam_vmsc_destroy(vmsc);
>>>> }
>>>> -int mpam_ris_create(struct mpam_msc *msc, u8 ris_idx,
>>>> +int mpam_ris_create(struct mpam_msc *msc, u64 ris_idx,
>>>> enum mpam_class_types type, u8 class_id, int
>>>> component_id)
>>>> {
>>>> int err;
>>>> diff --git a/include/linux/arm_mpam.h b/include/linux/arm_mpam.h
>>>> index f92a36187a52..30461cd71199 100644
>>>> --- a/include/linux/arm_mpam.h
>>>> +++ b/include/linux/arm_mpam.h
>>>> @@ -39,10 +39,10 @@ static inline int acpi_mpam_count_msc(void)
>>>> { return -EINVAL; }
>>>> #endif
>>>> #ifdef CONFIG_ARM64_MPAM_DRIVER
>>>> -int mpam_ris_create(struct mpam_msc *msc, u8 ris_idx,
>>>> +int mpam_ris_create(struct mpam_msc *msc, u64 ris_idx,
>>>> enum mpam_class_types type, u8 class_id, int
>>>> component_id);
>>>> #else
>>>> -static inline int mpam_ris_create(struct mpam_msc *msc, u8 ris_idx,
>>>> +static inline int mpam_ris_create(struct mpam_msc *msc, u64 ris_idx,
>>>> enum mpam_class_types type, u8 class_id,
>>>> int component_id)
>>>> {
>>>>
>>>
>>
>
--
Thx and BRs,
Yin
next prev parent reply other threads:[~2026-09-04 2:42 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 13:30 [PATCH RFC 00/15] arm-mpam: Add basic device tree support for resctrl Yin Li
2026-08-11 13:30 ` [PATCH RFC 01/15] dt-bindings: arm: Add MPAM MSC binding Yin Li
2026-09-03 10:03 ` Ben Horgan
2026-08-11 13:30 ` [PATCH RFC 02/15] cacheinfo: Expose the code to generate a cache-id from a device_node Yin Li
2026-08-25 19:11 ` Drew Fustini
2026-08-31 5:43 ` Yin Li
2026-08-11 13:30 ` [PATCH RFC 03/15] arm_mpam: Add device tree support for MSC probing Yin Li
2026-08-11 13:30 ` [PATCH RFC 04/15] arm_mpam: Add support for memory controller MSC on DT platforms Yin Li
2026-08-11 13:30 ` [PATCH RFC 05/15] arm_mpam: Fix device_node refcount in DT resource parsing Yin Li
2026-09-02 13:29 ` Andre Przywara
2026-09-03 8:07 ` Yin Li
2026-08-11 13:30 ` [PATCH RFC 06/15] arm_mpam: Fix cache ID sentinel from ~0UL to U32_MAX to match u32 return type Yin Li
2026-09-02 13:49 ` Andre Przywara
2026-09-04 3:27 ` Yin Li
2026-08-11 13:30 ` [PATCH RFC 07/15] arm_mpam: Fix the RIS index range check in mpam_ris_create_locked Yin Li
2026-09-02 14:50 ` Andre Przywara
2026-09-03 8:18 ` Yin Li
2026-08-11 13:30 ` [PATCH RFC 08/15] arm_mpam: Fix ris_idx type to prevent range check bypass on truncation Yin Li
2026-09-02 16:22 ` Andre Przywara
2026-09-03 9:42 ` Yin Li
2026-09-03 13:27 ` Andre Przywara
2026-09-04 2:42 ` Yin Li [this message]
2026-08-11 13:30 ` [PATCH RFC 09/15] arm_mpam: Fix MSC MMIO window size to use resource_size() instead of end - start Yin Li
2026-09-02 13:16 ` Andre Przywara
2026-09-03 9:45 ` Yin Li
2026-09-03 10:20 ` Ben Horgan
2026-09-03 13:23 ` Ben Horgan
2026-09-04 3:12 ` Yin Li
2026-08-11 13:30 ` [PATCH RFC 10/15] arm_mpam: Fix update_msc_accessibility() return type to void Yin Li
2026-08-11 13:30 ` [PATCH RFC 11/15] arm_mpam: Fix mpam_dt_create_foundling_msc() to create MSC platform devices Yin Li
2026-08-11 13:30 ` [PATCH RFC 12/15] arm_mpam: Fix get_cpumask_from_cache() to clear mask on error Yin Li
2026-09-02 16:03 ` Andre Przywara
2026-09-03 9:59 ` Yin Li
2026-08-11 13:30 ` [PATCH RFC 13/15] dt-bindings: arm: Fix MPAM MSC binding schema and examples Yin Li
2026-08-11 13:30 ` [PATCH RFC 14/15] arm_mpam: Support MSC accessibility derivation from RIS nodes Yin Li
2026-08-11 13:30 ` [PATCH DNM RFC 15/15] arm64: dts: qcom: kaanapali: Add MPAM MSC nodes for the L2 caches Yin Li
2026-08-25 8:27 ` [PATCH RFC 00/15] arm-mpam: Add basic device tree support for resctrl Yin Li
2026-09-03 10:11 ` Ben Horgan
2026-09-04 2:52 ` Yin Li
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3f67a5dd-e567-409c-ba93-8931ffadf75b@oss.qualcomm.com \
--to=yin.li@oss.qualcomm.com \
--cc=aiqun.yu@oss.qualcomm.com \
--cc=andersson@kernel.org \
--cc=andre.przywara@arm.com \
--cc=ben.horgan@arm.com \
--cc=conor+dt@kernel.org \
--cc=dakr@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=driver-core@lists.linux.dev \
--cc=fenghuay@nvidia.com \
--cc=ganapatrao.kulkarni@oss.qualcomm.com \
--cc=gregkh@linuxfoundation.org \
--cc=huang.yiwei@oss.qualcomm.com \
--cc=james.morse@arm.com \
--cc=konradybcio@kernel.org \
--cc=krzk+dt@kernel.org \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=rafael@kernel.org \
--cc=reinette.chatre@intel.com \
--cc=robh@kernel.org \
--cc=sdonthineni@nvidia.com \
--cc=srivathsa.rao@oss.qualcomm.com \
--cc=trilok.soni@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox