From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3DA5A41CB56 for ; Mon, 3 Aug 2026 14:31:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767482; cv=none; b=J1MZY0x49V/LdI1AytkLggFPKtdQp7B6RBRowKqtWPdAWBxQ5rGnZXHo/kgUsFi/ELks9X4hkN7rFZRN6J3wLkBmP1fHxclUXK2PlOIgRaRydqzdlEvyOI8ftOM4HUmfpK68phsTQZALbBkPPXwMcKxepayDjJSLQcgcZMGXMgA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767482; c=relaxed/simple; bh=aPETE3o1r0HQZA9wDBA5bpXSmM050p/rQxyZ/Pt3L2A=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=n5HLfgU1P8z/zLQBqWfzQfnDtPo7y+jEY+oVtU+QyTqNScajVT0n3sFypG7BXhGPDlIniNZCMqeb9TygkEsft8Jb/2ywGPevSh9oIFC93p0GCIgMzzmeYMw4nW85ocnS1ZhFJGwmOGdFYTDBaH05b7vYy2/ayynY8Op9J/qxqjU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SO9oVCpM; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SO9oVCpM" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-495437bb891so18186935e9.1 for ; Mon, 03 Aug 2026 07:31:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767477; x=1786372277; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=I5CCpAh+m8Fx6ANrpP0jbYMsqCo/QP0tlHJ61+yZOVU=; b=SO9oVCpMeQguxxIa7MiRXp4c3nPHW255XH42M41WT9dEgHK3ATVNKn5ZmPCoyJ8uXq Y1AmMfEDRq9UcFMCoTga5OlmQD9nJKP+ClvI3BMP+8w9wdzmdi29qx1u9bOUXg8eNlOi bKGIVHgM9XyAwbELlpROyPAOlIVghdxEV7LYqsvzdLivbdSImmzSX2Jg+oj6S1lBCM6Z uE+ma7uVFXOk/dm1agvyrjCEU5uf8vYONW5//HjfEUZTOXv6a77qS632FoQE+UyrzlEg i7oAfQoijAUj/mKVo2wyRPKTJZDv4qtGqVJvgmHrvUE/oQayHhW27n1S2J8KXMW1P1NA rA/w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767477; x=1786372277; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=I5CCpAh+m8Fx6ANrpP0jbYMsqCo/QP0tlHJ61+yZOVU=; b=SVWgqhMLSm8zgdcO1dw1PRQvTWx/6EzurTT2K5qhQqQ8YtGvgCEYZwkoc1/XxEnsdP V8qwAkm9v3xVYItVkx4PHJTPB5jT5qedsyClVC8cymX8iqfF/Kuj6Yel1yaJD8cO7pKY 0lh2nqVsCuBrTJ7EgOjnCA42ze9GYI98CLAtqHRb4AwCiH/4zGnITeQ+8E95yQLL2BV/ QWWpKCa2/ypuNDkKmT0e8rZfa0Gt/tinsZjwJs628YvXsIFXqUf5SEEVzRLE7M6LAT1Z 7vAGjKczuGJMHuHXs00g//7DS21Jg0W4eDyZugVqtcU4AjFHpFmg6vwi3AXpasEz/ZWr DmDQ== X-Forwarded-Encrypted: i=1; AHgh+RrGhFqPqqPt+2Qr4CQCeOv0XmPwo4xslUZRbw4TmHDNI7lfwm0pu8GVavgm+8VdFq1hW7Y7/ZJkznMDzYE=@vger.kernel.org X-Gm-Message-State: AOJu0YwmAiwTGzDSB9O6020O00HbnTNlfSCIc0mesq1KieJs4n9KWVFK nXmU5w6nudW4e+SAhb59IQcmmj5RpQXtP6PUeMfmBmm62L8NBiKM8ZGW X-Gm-Gg: AR+sD12Y8ALIbQO61GOEu7mbZ8ik/YqxZBXxiJL+MlT70wSITbuBtd14LQr5JSc8+tB SobNQ6+YS1AH3/lzgCwtNmofa23ZDIjsH5uaB9tBN/uzXNyp7KCuUZitpBSJuaTrUHS9lQrsJbi dPGn6WTIPP2LEUEfwW2x+cu7QllIaHkqJ08tAUhu7xm8V6mrd8iaNaKNSNIrL8WlGe490UWhA2/ ExZG0J9Avj6RynWax4Ks81Q9IJaiZPnRm4vZdZ0X4nHW5HvO/8ZssXQ7zF8oDm67rTXnGBxUEL9 HJXCFBCw1cV//wHmlS7SW73jhwgusDquFe/86QROVR2cz9V1wR/4PkV5SRSzwN6OkwsSyaxF1Yu /GF5RXKbJ2SJdGIT8vFHbr857WH8ukH7n+qBtqHQvNGwCUlpcLN/e1pVgc21ImSn4yb7FKQQkFN QqEGaY6kD7lFAlLLIzMwHfm8I8U4MoF9+ACmxmhpLKmFuvZBgRmPVLILyCt/HmbNVBAb1FHBK1R X5NIE+Eqo+aMPN9Erk6Izh+fSJsfRMMptdz6o3/9g== X-Received: by 2002:a05:600c:46c3:b0:494:1f7:8057 with SMTP id 5b1f17b1804b1-4980eb8d081mr174789585e9.1.1785767476532; Mon, 03 Aug 2026 07:31:16 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:15 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 09/13] platform/x86: hp-bioscfg: advance elem past consumed array elements in enum-attributes Date: Mon, 3 Aug 2026 19:30:32 +0500 Message-ID: <20260803143037.93105-10-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The outer parsing loop advances "elem" (the index into the ACPI package's element array) by exactly one per iteration: for (elem = 1, eloc = 1; elem < enum_obj_count; elem++, eloc++) { but the PREREQUISITES and ENUM_POSSIBLE_VALUES cases each consume "size" consecutive elements (elem, elem + 1, ..., elem + size - 1) to populate an array, without adjusting "elem" to account for the extra elements consumed beyond the first. The next outer iteration then re-reads a leftover element from the array just consumed instead of the next real property, and the type check against expected_enum_types[eloc] fails on that stale element, aborting the parse with -EIO. This produces exactly the failure visible in dmesg on the test hardware, on every boot: Error expected type 2 for elem 13, but got type 1 instead hp_bioscfg: Returned error 0x3, "Invalid command value/Feature not supported" Note: this exact message string is shared by more than one file in this driver (see the companion patches to int-attributes.c, string-attributes.c, order-list-attributes.c, and passwdobj-attributes.c in this series, which fix the identical pattern), so this dmesg line cannot be attributed to this file alone without further instrumentation; it is included here as evidence that this class of bug is live and reachable on real hardware, not as proof this specific instance is the one firing. Fix by advancing "elem" by (size - 1) after each of the two loops, so the outer loop's own "elem++" lands on the correct next element. "eloc" is intentionally left alone, it indexes the logical property schema (expected_enum_types[]), not the physical element array, and each of PREREQUISITES/ENUM_POSSIBLE_VALUES is still exactly one logical property regardless of how many physical elements it spans. Fixes: 6b2770bfd6f9 ("platform/x86: hp-bioscfg: enum-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c index af4d1920d488..43beb639051e 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c @@ -227,6 +227,8 @@ static int hp_populate_enumeration_elements_from_package(union acpi_object *enum kfree(str_value); str_value = NULL; } + if (size) + elem += size - 1; break; case SECURITY_LEVEL: @@ -280,6 +282,8 @@ static int hp_populate_enumeration_elements_from_package(union acpi_object *enum kfree(str_value); str_value = NULL; } + if (size) + elem += (size < MAX_VALUES_SIZE ? size : MAX_VALUES_SIZE) - 1; break; default: pr_warn("Invalid element: %d found in Enumeration attribute or data may be malformed\n", elem); -- 2.55.0