[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v3 2/4] xen/arm: validate IRQs before descriptor lookup


  • To: Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>
  • From: Mykola Kvach <mykola_kvach@xxxxxxxx>
  • Date: Tue, 22 Sep 2026 08:11:36 +0300
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=VPCuvSRLUYD57vrjBunyS6HWGCVwnF9nbgRZK71kh2g=; b=lHEcjqSKj/gpaYOkkClmbYE4P1ytQEEnw+II0uvWioHsfSrmKSgn4NsZn00UhJ1+li7/MEDsGsfHeMUANHELa8RTEbELf2LDwXPGGDWfnQhNk4KZgxdNrIs+Z4uD2Y2lxMhYm8MtmbS9d2UJ1eNPA/+UmNYIoj/h/671eiHP1G5C8knoZ7tEOGeKWwN3zILZg7wlolCVTne3RLGbQj3w/hHvKD1xUfrOu3lZPpCamMoWS5iNa4a/VRIOyGlmldxaRAzYLQ271R8UIM5gWmGzK7SFdUKgFIqZsL0BvywWDEa7qlDFDYp4HkE6L2f/kLnV+2KD+lxMqyGk8spiXLhRGw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=xRKFM+zIqEPS2Pr/L9Rr3+LP7fF9dY4J4BcaQzhKy6cs5TOGkFH8OSQmHs2OlWUucbPVLbEMGyToxaJQU08bCxiaZZ6BaXRDqnaFM2jkPvlxTa4JEGTJEkJGfyfuJj2jtisW2wWUaZAs8CHIHSL9y2p1siH1XR1MCr4cbdP1i03/2i4kvDhXiaT3NVZTrCo44ut3qeWSMGuN3ab/i6PhoiDCLvhdhqv/XwZD+OtBZdTGJM//zWM3YS54AD0es3HCAdg9FvzSj/VcUmHkCv/NK4CcsQ6Tqx0x4dweVLSHanYnRut99lCL1UW3lYAYOMEgQiaTrFPARC7dbI4gTga5Wg==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>
  • Delivery-date: Tue, 22 Sep 2026 05:11:51 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Mail-followup-to: Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>, "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>

On Tue, Aug 25, 2026 at 03:30:43AM +0300, Volodymyr Babchuk wrote:
> Hi,
> 
> Mykola Kvach <mykola_kvach@xxxxxxxx> writes:
> 
> > GICv3 eSPI support makes nr_irqs span the architectural INTID namespace
> > through ESPI_MAX_INTID, but descriptor storage is sparse. local_irq_desc[]
> > and irq_desc[] cover INTIDs below NR_IRQS, while espi_desc[] covers eSPIs.
> > INTIDs 1024 through 4095 have no backing descriptors.
> >
> > Validation based only on nr_irqs accepts an INTID in this gap.
> > __irq_to_desc() then indexes beyond irq_desc[], and callers may lock or
> > update unrelated Xen memory.
> >
> > Reject INTIDs that the GIC reports as unimplemented in setup_irq() before
> > looking up a descriptor. irq_set_spi_type() can run before the implemented
> > GIC line counts are available, so validate descriptor-backed ranges there
> > before looking up a descriptor.
> >
> > Assert the regular descriptor bound in __irq_to_desc() so direct callers
> > cannot silently index the sparse gap in debug builds.
> >
> > Fixes: 98f7060b9ed5 ("xen/arm/irq: add handling for IRQs in the eSPI range")
> > Signed-off-by: Mykola Kvach <mykola_kvach@xxxxxxxx>
> > ---
> > Changes in v3:
> > - Add the requested bound assertion and retain the SPI-only comment.
> >
> > Changes in v2:
> > - Validate descriptor-backed ranges in irq_set_spi_type().
> > - Validate implemented GIC lines in setup_irq().
> > - Preserve is_espi() validation with CONFIG_GICV3_ESPI disabled.
> > ---
> >  xen/arch/arm/irq.c | 26 ++++++++++++++++++++++----
> >  1 file changed, 22 insertions(+), 4 deletions(-)
> >
> > diff --git a/xen/arch/arm/irq.c b/xen/arch/arm/irq.c
> > index 73e58a5108..bf14180f97 100644
> > --- a/xen/arch/arm/irq.c
> > +++ b/xen/arch/arm/irq.c
> > @@ -23,6 +23,12 @@ const unsigned int nr_irqs = 
> > IS_ENABLED(CONFIG_GICV3_ESPI) ?
> >                                          (ESPI_MAX_INTID + 1) :
> >                                          NR_IRQS;
> >  
> > +static bool irq_has_desc(unsigned int irq)
> 
> You are using this function only in one place, where you are actually
> testing for SPI. So, maybe introduce irq_is_spi() helper instead? And
> use it below?

I will keep irq_has_desc() and use it in __irq_to_desc() too,
as Michal suggested. This will keep the range checks in sync.

> 
> > +{
> > +    return irq < NR_IRQS ||
> > +           (IS_ENABLED(CONFIG_GICV3_ESPI) && is_espi(irq));
> > +}
> > +
> >  static unsigned int local_irqs_type[NR_LOCAL_IRQS];
> >  static DEFINE_SPINLOCK(local_irqs_type_lock);
> >  
> > @@ -76,7 +82,6 @@ static int __init init_espi_data(void)
> >      return 0;
> >  }
> >  #else
> > -
> 
> Please, no unnecessary changes

Ack.

Best regards,
Mykola



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.