From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f169.google.com (mail-qt1-f169.google.com [209.85.160.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 16AEC3DD513 for ; Mon, 25 May 2026 09:28:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779701341; cv=none; b=AR9SdbbbdhD6WzubHw3oJLmnQciOVcLSja0H/6rG0xB21DnUH764YnLvEDPCp5bcGYILSdt18xrY8SxnScWbMeUQef7DXMsntNazMWs23IDZTRZxlD5PhXQGjfAQWdsZZGJT9ecjSokRVcgfnR8sUWlfSgy+7FbC6XmmRzlYo/s= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779701341; c=relaxed/simple; bh=ZvshB2ooF1g8TGrIn+ikDHiQxOs9MPOpKhXgUDDQHR8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Oj/2+SEVY8M103j+hLoGifUaRqP35Ey6rCOfOY2/DyBi6MypPAdT2MOBO2TxA6k/esdeU4CJmhEeLy8W3fsX4potXpSSE2ZkdxF1XZvyh/BrTltgfJmUj5v1FwYHjtIN16JOIrHeelLR4WkUjFdtkkOcwgrrgOECbsMSUldPOFg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ToYbmhyA; arc=none smtp.client-ip=209.85.160.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ToYbmhyA" Received: by mail-qt1-f169.google.com with SMTP id d75a77b69052e-512f750d4b2so103756711cf.1 for ; Mon, 25 May 2026 02:28:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779701339; x=1780306139; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=b+TrKzH8rOxpTql1iz6i/KxFDzEdUSC9ltFm8VOZKto=; b=ToYbmhyA9BBZUTmiomwGIdfy4FP0KjTGboohKa22VxJw3beh08u7E4KRCiyr+A1ZFn OqdUHuSerOITEr52d28GOOzUBqvFBLfc7JyJu5uOm4UJnlocZ0eJXbQSlvgCGTcAWjXv bwwyQUZx4/NnilyADPH/af1LxOTbFxApKCK0KALVV/Dzd0lI6SbASUr2ShDuSoBvy4Eb cIuxpUs4lnZVUSRsNSnVrL9lxTDkRcO+5D7zEFzVE7yY5OiN/gj/jqmjHlgk1V2mznR7 j3nmEUEjeUe37C8a21bLEIWlUqmMWjk8F4vaxRkOMe5JTvGxc7pI2rXT7Vl1nrM33+9i FEfw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779701339; x=1780306139; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=b+TrKzH8rOxpTql1iz6i/KxFDzEdUSC9ltFm8VOZKto=; b=J0dGgxpV9SziUT5/dlUj+3yMj6ydbVM/kGRIx8Y+pXVBzanVOYfpImErvGctg5It5q egegInbPGyzAz1UxEe7LuemJIL2huvabHlaZILdKGXS+QuFIbXkmVog31FoZpk8Exf8j koYjYdBIJ776mUCY+WPWsnOLQlaUw9jnP05bqXo5pFRL9t098BHmj0KqhnES1CRY2k+U j9MaKr6sLp977gVEQDLjdC+1Ecx8FvxR6spUfkjopsrBTQgwGcZ3c/zhuJNvc0QdgM3j cW5mgwMRe3pKgZShmUcXwP2aywoI4cHjFwbS1CM8qv7rDQ6HAXaVpVR0tnX2cAM/yy5c 4OoQ== X-Forwarded-Encrypted: i=1; AFNElJ/1qjn67bejT31JG9R46MP88sWDDF6VyM91eFLpVbcupnzkxM87YAm68ckdbs40WWxZubNp/w9iWLaK8gw=@vger.kernel.org X-Gm-Message-State: AOJu0YxmBv6PUDav/rFkrF4gAoUVE1mk1gaa/fM0IiLSAqohutqmE6jo roZEx21nLAX7j10MBYRDRZZE4c4R2+b+xz9XDzE2PPAT/wI5L4o9B3UG X-Gm-Gg: Acq92OH5aM+LjHhJRH8PsuvNh1kmVnkuf1orlWc6KKgAMvBBBfFRHgi/COSwI3fTnif lnHfypivho87UlV021ralld58b9/ztOMEIcXdkT0gr/gZ8jY3+c2AFJ2KlAFE9xq1S/eiFakyrW X20ehwcpxJqX4UYP7t8lppm27e0ZIbuM6JidI5XIuKj+YdnWq6w9NhFdz85lwVgnj/xUhE8IhNo LLs6hvZS+CXDrogzACxmUEgf5Fh0WJc+pPuXgxY1xU2IJ1HUTWCV667mJ8vb54W91SbnsYR1xxN RWPFBK6GbyuW2A3XzqU+dIDK4eskBYQsYwzPrtKlV5oTEemi2KbLKdXwueE3Bl46JzEgC2CckqH u0mg814KjNGCNDbIZBj0cKRmmN0frAweMYvxkBFrb2oCZ7LXqmnNbIDnmtZ2akxV3rZ8GW5/IN7 zyXX7LMEzbaUL/PTSId/D+WnoW8+1SdGOl0xZnpvpge+JYEZcz0W41aaNo1R0Wm8LlScM/UFVG4 mQLEh6ys1zWmR0RBcZY/uoWSHHY/K4Ey3rOeoI32Vg= X-Received: by 2002:ac8:7f8a:0:b0:516:889b:ac9b with SMTP id d75a77b69052e-516d4368673mr178951211cf.39.1779701338829; Mon, 25 May 2026 02:28:58 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8cc80dcf4a9sm104255826d6.2.2026.05.25.02.28.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 02:28:58 -0700 (PDT) From: Michael Bommarito To: Mika Westerberg , Andreas Noever , Yehezkel Bernat Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 0/6] thunderbolt: harden XDomain property exchange Date: Mon, 25 May 2026 05:28:24 -0400 Message-ID: <20260525092830.735472-1-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7bit This series fixes 4 memory-safety defects and 1 data-handling hardening issue in the Thunderbolt XDomain property exchange path (property.c and xdomain.c) and adds KUnit regression tests. All are reachable from an adjacent Thunderbolt peer without authentication. The XDomain protocol runs automatically on cable insertion regardless of the configured security level, unless disabled with thunderbolt.xdomain=0. Patches: 1/6 - reject zero-length property entries in validator 2/6 - bound root directory content to block size 3/6 - clamp XDomain response data copy to allocation size 4/6 - validate XDomain request packet size before type cast 5/6 - limit XDomain response copy to actual frame size 6/6 - add KUnit tests for property parser bounds checks Tested with KASAN on v7.1-rc3 and over Thunderbolt 4 hardware. KUnit regression tests (patch 6) confirm the fixes and existing tb_test_property_* tests pass on the patched tree. Based-on: thunderbolt/fixes (928abe19fbf01) Michael Bommarito (6): thunderbolt: reject zero-length property entries in validator thunderbolt: bound root directory content to block size thunderbolt: clamp XDomain response data copy to allocation size thunderbolt: validate XDomain request packet size before type cast thunderbolt: limit XDomain response copy to actual frame size thunderbolt: test: add KUnit tests for property parser bounds checks drivers/thunderbolt/property.c | 6 ++++++ drivers/thunderbolt/test.c | 40 ++++++++++++++++++++++++++++++++++++++++ drivers/thunderbolt/xdomain.c | 14 +++++++++++--- 3 files changed, 57 insertions(+), 3 deletions(-)