From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1196D29BDAA for ; Mon, 3 Aug 2026 14:12:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785766322; cv=none; b=PysJGG/mn+xNJLqSzEx2w70ITO6vHtoUbwGss8hA+Hl6hcwPzieSx45FFeepwr7Igs5BMqKthoXfBHHfQdT2MgTSGD/K1QXUpfVLsyu5ex+r3SOnCJs2GxnOSgSDFhqRbrI6JzmzzJCZWVlgpaE9IhHMUOd6jXApcM3GHE1gtQY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785766322; c=relaxed/simple; bh=6n8paqcUFa58A89VhaCIqVvWkiJdvTn42GF3249Ia7c=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=IbhlD6p+PUyXf7WQrTX/7tKAO20SYm0xl8zBm4csWRNyAxDw5ngrzgIydGXWiV0SUNoNpfcxd4WBORgCvzXqeig6Efy9B4VBlWr/4nYXNQWz9/r8t0uMjjvC/6G9tjffyeNtv/o3cVtNGtQ9Gpm9opuyKMpnDeu94CO2PCPbklU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ZIer9YTz; arc=none smtp.client-ip=209.85.128.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ZIer9YTz" Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-495635a85d2so20048865e9.0 for ; Mon, 03 Aug 2026 07:12:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785766319; x=1786371119; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ri6+Lm8RQVb+XPY7XH6+RgGkE3WKXcXpIGv8fON2pYg=; b=ZIer9YTzmQY2ftUOPWHA9VX2pZeMuTRK9C9VNiGxntPu6MNbXjDDuOnc7UkzWUrV1r jmY9MGttccmw8ZNQIuI9h5ZIFeNVK7eA9ywcGUEwMGqOooXQdAB9/HoIk3Y+7PAr76q/ RYCv66MkEUlt2IP+NHk5iW2iJja+GDdAMrUMsaE0W6p9/6zWupo9uucTqbAgrB42IiWM 13DZP1O2GoKIjbd3QBHqNGvRXcS0XBWt2oZn+UFRaNHo/1Yurn8pFZ4uQ3Edn5yaKLZP rDideewEwDOJYM36I0SrM1oB9vrAuyKpRVYYP9otyH8fua4Mk7A+KMTrBsNSGmH301Ey Ys8Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785766319; x=1786371119; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ri6+Lm8RQVb+XPY7XH6+RgGkE3WKXcXpIGv8fON2pYg=; b=VFeKw3+hBlM5RpXXcd5t9m75T6zOa0kTLybKKBN4D3b79gatf0FJfclDPLrVC4Y3og oprrT6JuUXqVe6oYZdeN7TApXao7VEOFox4bh7VWE1+kY5ee7QaEx1cBOh66parb3HmU 8c+heXpfSg+Kon3nChOKI9vmTMCFnIQig9PtpiF+/znuTDOb80SEopvvrdlyN9uhBhlH 5kvNPkX7WzkLy2PXyAY855CW5b8Vu4YolL4dnDcsPVCwOblEXRfUI9N9k6DKS6zdNCp/ CDqfeqLD/A7woLGpRG/qV8daEZWJLklJUN4e3yJqEXM33KFVlAhB3sVQcU384f9oPAVT HP5g== X-Forwarded-Encrypted: i=1; AHgh+RpiVexUxyUCCnjIk0LutL3zNvWgPzqO6OkEC4IwmbWIi+ImLhcdYe7h+NA3eiKovdNEUjDQ60wMqO/6qAA=@vger.kernel.org X-Gm-Message-State: AOJu0YxLmuHuPSzsTR55wtRtnGsRMuCNDJoPZ1DloCL2Pm+K1igtzyHD zZVNZsncBxsjPXSDyuHNkwza5FUHdPRb89Z8nPhugkyuCTtCYl2JhKkl X-Gm-Gg: AR+sD13jxA8ETMag8QreGLfmYSbnBsDOWgJpLt5GSRT5lc7LA7K2ILLH1ZRbQ8halDp ZGGa5aW7/cvJn8KvN5FJ4qrTeTbss+KgyrZuT3rDK8iEmJj7EAn9RD+wXysuMponnmWjG8+9B6v RfCqnL5Rd/Egq2rJqJfv+bGeMrugxp14Nax/ZocQibX3oTqyG97klVFyRXSAPxenIi5joWNHxk5 RJRjgUGHLf+LV2n6gSP6MvGFgtjIwnzoJr8B6zhnqz2/x3QT37zYwKWWQHSXDCzfFwaM5xv2yuA QO5gbBr5PJkQwzV2H6TWbt7Z0o2w0s0QJav0md7e5XD7JzXKmWCfjNIZXgHo4VG9Yf9Xjns05fm h+xv/TEbXgDjJCXLxYTY8XRFXOA3MrwqN8Yj2L8g+m2SBxGELKbwKHzI1eUSFRQ2OA6Sf3cvaSU gTANSl8blVJGplYhmb1UGiNOBy0vOjl1DL7XMq4SIUoG8BdryovnD6Zcxx8i/3O/FL8mlh34x62 NgSrVZ1LW/B6vJCRj9sf7V1 X-Received: by 2002:a05:600c:5914:b0:495:5cda:52ec with SMTP id 5b1f17b1804b1-4980c662d03mr200306225e9.16.1785766318949; Mon, 03 Aug 2026 07:11:58 -0700 (PDT) Received: from osama.. ([2a02:908:185:7e40:3586:7967:eb8:8b0d]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fd41cf404sm32589557f8f.1.2026.08.03.07.11.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:11:58 -0700 (PDT) From: Osama Abdelkader To: Boris Brezillon , Steven Price , Liviu Dudau , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org Cc: Osama Abdelkader Subject: [PATCH v3] drm/panthor: use local variables for firmware interface counts Date: Mon, 3 Aug 2026 16:11:49 +0200 Message-ID: <20260803141149.68182-1-osama.abdelkader@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260803153555.70ca46de@fedora1.home> References: <20260803153555.70ca46de@fedora1.home> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The firmware exposes the global group count and per-group stream count in the shared control interface. These values are validated before being used as loop bounds. Read each count once with READ_ONCE() and store it in a local variable. This avoids reading the same control section field twice and makes it explicit that the loop uses the same value that passed validation to protect against self-modifying control sections. Signed-off-by: Osama Abdelkader Reviewed-by: Steven Price --- v3: - Add comments explaining the READ_ONCE() usage. drivers/gpu/drm/panthor/panthor_fw.c | 24 ++++++++++++++++++------ 1 file changed, 18 insertions(+), 6 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_fw.c b/drivers/gpu/drm/panthor/panthor_fw.c index 8411c468bdac..b2ccb81f280c 100644 --- a/drivers/gpu/drm/panthor/panthor_fw.c +++ b/drivers/gpu/drm/panthor/panthor_fw.c @@ -954,6 +954,7 @@ static int panthor_init_csg_iface(struct panthor_device *ptdev, u64 shared_section_sz = panthor_kernel_bo_size(ptdev->fw->shared_section->mem); u64 iface_offset = CSF_GROUP_CONTROL_OFFSET + ((u64)csg_idx * glb_iface->control->group_stride); + u32 stream_num; unsigned int i; if (iface_offset > shared_section_sz || @@ -967,8 +968,13 @@ static int panthor_init_csg_iface(struct panthor_device *ptdev, csg_iface->output = iface_fw_to_cpu_addr(ptdev, csg_iface->control->output_va, sizeof(*csg_iface->output)); - if (csg_iface->control->stream_num < MIN_CS_PER_CSG || - csg_iface->control->stream_num > MAX_CS_PER_CSG) + /* + * To protect against self-modifying control sections + * take a single snapshot from the control section so validation and + * iteration use the same value. + */ + stream_num = READ_ONCE(csg_iface->control->stream_num); + if (stream_num < MIN_CS_PER_CSG || stream_num > MAX_CS_PER_CSG) return -EINVAL; if (!csg_iface->input || !csg_iface->output) { @@ -986,7 +992,7 @@ static int panthor_init_csg_iface(struct panthor_device *ptdev, } } - for (i = 0; i < csg_iface->control->stream_num; i++) { + for (i = 0; i < stream_num; i++) { int ret = panthor_init_cs_iface(ptdev, csg_idx, i); if (ret) @@ -1010,6 +1016,7 @@ static int panthor_fw_init_ifaces(struct panthor_device *ptdev) { struct panthor_fw_global_iface *glb_iface = &ptdev->fw->iface.global; u64 shared_section_sz = panthor_kernel_bo_size(ptdev->fw->shared_section->mem); + u32 group_num; unsigned int i; if (!ptdev->fw->shared_section->mem->kmap) @@ -1035,13 +1042,18 @@ static int panthor_fw_init_ifaces(struct panthor_device *ptdev) return -EINVAL; } - if (glb_iface->control->group_num > MAX_CSGS || - glb_iface->control->group_num < MIN_CSGS) { + /* + * To protect against self-modifying control sections + * take a single snapshot from the control section so validation and + * iteration use the same value. + */ + group_num = READ_ONCE(glb_iface->control->group_num); + if (group_num > MAX_CSGS || group_num < MIN_CSGS) { drm_err(&ptdev->base, "Invalid number of control groups"); return -EINVAL; } - for (i = 0; i < glb_iface->control->group_num; i++) { + for (i = 0; i < group_num; i++) { int ret = panthor_init_csg_iface(ptdev, i); if (ret) -- 2.43.0