From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ed1-f54.google.com (mail-ed1-f54.google.com [209.85.208.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2A4332F1FD7 for ; Wed, 5 Aug 2026 09:35:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.54 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785922556; cv=none; b=hxUcG67GdlpT6TBn+7qd9xmK87buElmLGS851BkgmUD5WQzBWqORAq8vF1pfOd+vinVkDUN0buYdIxVGvSfscUZs7knIITxgtPhofVzuqT0bewZzJvvGv7KcwJ8x/do5sg4uQSvecHE7SAMid4N8mBvpx7C5UiE3zPVbiypx7Dc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785922556; c=relaxed/simple; bh=LEeciKp1jtVCyABoz9P0zidQ5UQx4Himxqp1lDk5wjI=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References; b=C0mV0f/Vr8ms8gzfJMF9olr7cWOzM+29KprBIQeSq+kGqBjvHWTT706qMI1AhVmJkujjKwqlstOhJajDwg+hdYZeWzvgUNwEk9WVpM0DGHf6r46gPUh4Vff1tEbDguKD2Wl9Q5u4+sPSz9Bn6gAVNZiji98YfrUUbsCLEhDgLPc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=JHADHolC; arc=none smtp.client-ip=209.85.208.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="JHADHolC" Received: by mail-ed1-f54.google.com with SMTP id 4fb4d7f45d1cf-6a0a4a17f91so1135155a12.1 for ; Wed, 05 Aug 2026 02:35:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785922552; x=1786527352; darn=vger.kernel.org; h=references:in-reply-to:message-id:date:subject:cc:to:from:from:to :cc:subject:date:message-id:reply-to:content-type; bh=jDIj1IB1toOapiL1j0cj+fCCXDxdvdYq1IsWpOS35sg=; b=JHADHolCVnmq1qaGzFnaSobe1OjjrnTo3ez3oBwFbeo8HI2sSkR0L124rlsk/PcHnU j4yS2jlQGmrivTUQ3OPG5l6z8UW5b9gwmdqtWoTs70hNXFzH5QhVI9wxKoQ9ENnCTseB 7a5Wx9yfeFwYFCOVoKtsnaeAOVjJ+xZHsMKOMU04cAkn/D/MssCWZ1IACycuzHdEIkMp O41RvnMC8O48n8DDYOuALFiGxsN3uKEvYkAnQhJksCX/ZqFOScyYF3LH8PTqZr2LDeX2 bGGx50eftUF3QH6WnkA7SzpY2X6q/S/CNme758Nb/AYrgUcAJ0V1l99gK7hrAMY7qUMg qS4A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785922552; x=1786527352; h=references:in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=jDIj1IB1toOapiL1j0cj+fCCXDxdvdYq1IsWpOS35sg=; b=Z6UQgDlUQwxFJuP9mT1/g95YkW7XuQbNT4TAhgMxyYp87oQvsq+f3l/0gaxDH7rYre oYKLreQ/yw/ScbVJLhFt8bInlTXkKKkdGwdH8zMTxGyM45wtsX0fEhbdicRh+TAAf+hz 9rpccBuBxqrcnFsmxss8PkiGyqBShYMncyXQmodunIte9dYhO3tatlzXCPftluHsL1+/ DKo305ANpkXmUvOVyB4xStySGLO04VeiC0/8D90IpHX6IHnB28FtPuVQ+6DAkgzEP8cg vtQcyx0VtBLPBhOV8l2BAWekL+rh2ezhVSm5v8u58tXxqFKt7H5V8S22sVpw5w9MEsNO BaHA== X-Forwarded-Encrypted: i=1; AHgh+Ro1FLR7Ebf6rQ03cZDAxVFyPoyETLy/HMcJLHII0gKgnyszYj6hcv/NxivpME/XjCE01aXuuEQv3pp7Ugc=@vger.kernel.org X-Gm-Message-State: AOJu0YzPQrEUPtNM25KU17/ZMamieAMQD4ExjlzCfPp58We8j0XYGhA0 7hWSJD6ZwJtoyBog7qK+eVJxbKdKD7wdsUDNNLCm20HrjWCyBezwDXak X-Gm-Gg: AR+sD13jKEadPprWG48pzgUdOJn0xLHeysnViYc84GoJcyN2fTVgsq5OpCcwf9waokf JmeS8pGem74BWlThprpUzMO7YFrjg0+tZiE8BhZCE6D3vwZr5Pn1Ly8mK1BECAhhf9tac/2d18b Frn8mjSjYkEBsZ+h82WXBfGci0LnPkEUs6SAtCZZ6GSFk8RSyiBxJXSCrPe2xWRJ9jFYUGDzYVT 98DCPsFJcZtYEz5J1NuK2Zi/0QqjWKgkz6j2AOvccc2BwoV78GPVWSam5mdQQ4muzL6dUirL6M6 QETLT5h+i1R1iYSarUNiRDG5YAMW+NoicxNaC4CgrFqdL6HaxUCgGfo5gIedIXLJbGoDMU1to+Z NmqIBcfMLpdZ/vUiuzuQr+6qAE2kmkaGYjL1fyd3ZJAWC95KIpIGEkX3RwD6PkxtpRp7djz5P6g CoDvgW2eBUCaPJEfCqFm25KJA2+zNnOJ98ZeKjP6XZIqLvfdZGzslxcPwkCq3TWmbSiQ91WXEhd 95U9z88TkAZvylq4k1mE+WfypQ= X-Received: by 2002:a05:6402:5416:b0:6a0:8885:e6f0 with SMTP id 4fb4d7f45d1cf-6a14f07cfd1mr2788626a12.3.1785922550020; Wed, 05 Aug 2026 02:35:50 -0700 (PDT) Received: from localhost (c-85-228-45-68.bbcust.telenor.se. [85.228.45.68]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a1453d3825sm1729416a12.0.2026.08.05.02.35.49 (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Wed, 05 Aug 2026 02:35:49 -0700 (PDT) From: Eli Billauer To: gregkh@linuxfoundation.org Cc: arnd@arndb.de, linux-kernel@vger.kernel.org, corbet@lwn.net, Eli Billauer Subject: [PATCH v4 6/7] char: xillybus: Add defensive sanity checks Date: Wed, 5 Aug 2026 11:34:35 +0200 Message-Id: <20260805093436.59740-7-eli.billauer@gmail.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20260805093436.59740-1-eli.billauer@gmail.com> References: <20260805093436.59740-1-eli.billauer@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Add validation checks for values derived from hardware or user input to prevent incorrect behavior with malformed data. Assisted-by: Deepseek:v4-pro Kimi:K2.6 ChatGPT:GPT-5.5 Claude:Sonnet-4.6 Signed-off-by: Eli Billauer --- Notes: Changelog: ========= Changes v3->v4: -- xillyusb.c: Use mutex_unlock() in response to sanity check failure in fifo_init(), as guard() isn't used anymore on this mutex. -- xillyusb.c and xillybus_core.c: Remove sanity check on data count on read() and write() fops methods, as this check is already done by the kernel's vfs_read() and vfs_write(). Changes v2->v3: -- Add Assisted-by tag to description Changes v1->v2: -- xillybus_class.c: Assign @rc a value before goto in xillybus_init_chrdev(). -- xillybus_class.c: Improve check on @inode in xillybus_find_inode(). -- xillybus_of.c: Remove redundant dev_err(), as platform_get_irq() outputs an error message if necessary. drivers/char/xillybus/xillybus_class.c | 18 +++++++++++++-- drivers/char/xillybus/xillybus_class.h | 3 +++ drivers/char/xillybus/xillybus_core.c | 31 ++++++++++++++++++++++++-- drivers/char/xillybus/xillybus_of.c | 3 +++ drivers/char/xillybus/xillyusb.c | 25 ++++++++++++++++++++- 5 files changed, 75 insertions(+), 5 deletions(-) diff --git a/drivers/char/xillybus/xillybus_class.c b/drivers/char/xillybus/xillybus_class.c index 5e8f03b77064..f7e0da233e2a 100644 --- a/drivers/char/xillybus/xillybus_class.c +++ b/drivers/char/xillybus/xillybus_class.c @@ -57,6 +57,9 @@ int xillybus_init_chrdev(struct device *dev, size_t namelen; struct xilly_unit *unit, *u; + if (num_nodes <= 0 || num_nodes > XILLYBUS_MAX_NODES || !idt || !prefix || !dev) + return -ENODEV; + unit = kzalloc_obj(*unit); if (!unit) @@ -68,6 +71,12 @@ int xillybus_init_chrdev(struct device *dev, snprintf(unit->name, UNITNAMELEN, "%s", prefix); for (i = 0; enumerate; i++) { + if (i > 99) { + dev_err(dev, "Failed to obtain unique unit name\n"); + rc = -ENODEV; + goto fail_obtain; + } + snprintf(unit->name, UNITNAMELEN, "%s_%02d", prefix, i); @@ -215,10 +224,15 @@ EXPORT_SYMBOL(xillybus_cleanup_chrdev); int xillybus_find_inode(struct inode *inode, void **private_data, int *index) { - int minor = iminor(inode); - int major = imajor(inode); + int minor, major; struct xilly_unit *unit = NULL, *iter; + if (!inode || !private_data || !index) + return -ENODEV; + + minor = iminor(inode); + major = imajor(inode); + mutex_lock(&unit_mutex); list_for_each_entry(iter, &unit_list, list_entry) diff --git a/drivers/char/xillybus/xillybus_class.h b/drivers/char/xillybus/xillybus_class.h index 5dbfdfc95c65..4dbed9adcaf8 100644 --- a/drivers/char/xillybus/xillybus_class.h +++ b/drivers/char/xillybus/xillybus_class.h @@ -8,6 +8,9 @@ #ifndef __XILLYBUS_CLASS_H #define __XILLYBUS_CLASS_H +#define XILLYBUS_MAX_NODES 1024 +#define XILLYBUS_MAX_IDT 1048576 + #include #include #include diff --git a/drivers/char/xillybus/xillybus_core.c b/drivers/char/xillybus/xillybus_core.c index b264578b2572..6bc72d9dfb16 100644 --- a/drivers/char/xillybus/xillybus_core.c +++ b/drivers/char/xillybus/xillybus_core.c @@ -351,6 +351,12 @@ static int xilly_get_dma_buffers(struct xilly_endpoint *ep, struct device *dev = ep->dev; struct xilly_buffer *this_buffer = NULL; /* Init to silence warning */ + if (bytebufsize == 0 || bytebufsize > 0x40000000) { + dev_err(ep->dev, + "Illegal buffer size requested in IDT. Aborting.\n"); + return -ENODEV; + } + if (buffers) { /* Not the message buffer */ this_buffer = devm_kcalloc(dev, bufnum, sizeof(struct xilly_buffer), @@ -623,6 +629,12 @@ static int xilly_scan_idt(struct xilly_endpoint *endpoint, return -ENODEV; } + if (count == 0 || count > XILLYBUS_MAX_NODES) { + dev_err(endpoint->dev, + "Unreasonable number of channels. Aborting.\n"); + return -ENODEV; + } + idt_handle->entries = len >> 2; endpoint->num_channels = count; @@ -725,8 +737,18 @@ static ssize_t xillybus_read(struct file *filp, char __user *userbuf, bufidx = channel->wr_host_buf_idx; bufpos = channel->wr_host_buf_pos; howmany = ((channel->wr_buffers[bufidx]->end_offset - + 1) << channel->log2_element_size) - - bufpos; + + 1) << channel->log2_element_size); + + if (howmany > channel->wr_buf_size || + howmany < bufpos) { + dev_err(channel->endpoint->dev, + "Illegal buffer fill level from hardware\n"); + channel->endpoint->fatal_error = 1; + spin_unlock_irqrestore(&channel->wr_spinlock, flags); + break; + } + + howmany -= bufpos; /* Update wr_host_* to its post-operation state */ if (howmany > bytes_to_do) { @@ -1902,6 +1924,11 @@ int xillybus_endpoint_discovery(struct xilly_endpoint *endpoint) return -ENODEV; } + if (endpoint->idtlen < 4 || endpoint->idtlen > XILLYBUS_MAX_IDT) { + dev_err(endpoint->dev, "Invalid IDT length. Aborting.\n"); + return -ENODEV; + } + /* Enable DMA */ iowrite32((u32) (0x0002 | (endpoint->dma_using_dac & 0x0001)), endpoint->registers + fpga_dma_control_reg); diff --git a/drivers/char/xillybus/xillybus_of.c b/drivers/char/xillybus/xillybus_of.c index 46e1046abfca..44b0c754deb2 100644 --- a/drivers/char/xillybus/xillybus_of.c +++ b/drivers/char/xillybus/xillybus_of.c @@ -53,6 +53,9 @@ static int xilly_drv_probe(struct platform_device *op) irq = platform_get_irq(op, 0); + if (irq < 0) + return irq; + rc = devm_request_irq(dev, irq, xillybus_isr, 0, xillyname, endpoint); if (rc) diff --git a/drivers/char/xillybus/xillyusb.c b/drivers/char/xillybus/xillyusb.c index e2270a64b659..5b6a15962885 100644 --- a/drivers/char/xillybus/xillyusb.c +++ b/drivers/char/xillybus/xillyusb.c @@ -396,6 +396,12 @@ static int fifo_init(struct xillyfifo *fifo, fifo->size = fifo->bufnum * fifo->bufsize; fifo->buf_order = buf_order; + if (!fifo->size || /* Unsigned integer overflow */ + fifo->size > 0x40000000) { /* Avoid signed int issues */ + mutex_unlock(&fifo_buf_order_mutex); + return -ENOMEM; /* Reported as greed for memory */ + } + fifo->mem = kmalloc_array(fifo->bufnum, sizeof(void *), GFP_KERNEL); if (!fifo->mem) { @@ -893,6 +899,7 @@ static int process_in_opcode(struct xillyusb_dev *xdev, struct xillyusb_channel *chan; struct device *dev = xdev->dev; int chan_idx = chan_num >> 1; + struct xillyfifo *in_fifo; if (chan_idx >= xdev->num_channels) { dev_err(dev, "Received illegal channel ID %d from FPGA\n", @@ -917,7 +924,10 @@ static int process_in_opcode(struct xillyusb_dev *xdev, */ smp_wmb(); WRITE_ONCE(chan->read_data_ok, 0); - wake_up_interruptible(&chan->in_fifo->waitq); + + in_fifo = READ_ONCE(chan->in_fifo); + if (in_fifo) + wake_up_interruptible(&in_fifo->waitq); break; case OPCODE_REACHED_CHECKPOINT: @@ -2077,6 +2087,13 @@ static int xillyusb_discovery(struct usb_interface *interface) } idt_len = READ_ONCE(idt_fifo.fill); + + if (idt_len < 4 || idt_len > XILLYBUS_MAX_IDT) { + rc = -ENODEV; + dev_err(&interface->dev, "Invalid IDT length. Aborting.\n"); + goto unfifo; + } + idt = kmalloc(idt_len, GFP_KERNEL); if (!idt) { @@ -2111,6 +2128,12 @@ static int xillyusb_discovery(struct usb_interface *interface) goto unidt; } + if (num_channels == 0 || num_channels > XILLYBUS_MAX_NODES) { + dev_err(&interface->dev, "Unreasonable number of channels. Aborting.\n"); + rc = -ENODEV; + goto unidt; + } + rc = setup_channels(xdev, (void *)idt + 3, num_channels); if (rc) -- 2.34.1