[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v3 2/4] xen/arm: validate IRQs before descriptor lookup


  • To: "Orzel, Michal" <michal.orzel@xxxxxxx>
  • From: Mykola Kvach <mykola_kvach@xxxxxxxx>
  • Date: Tue, 22 Sep 2026 08:19:55 +0300
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=vGDhDbXuVaAP6C+unbfLmIltTL5fRqzXWcgSLJjMI1Y=; b=SXl+v6jkPs4vadNlWpjOa6qnQzOCtBNpMphSSVeT/g3XXlsEPfrDaszZoG7AHc3A88I01yHKBYGlsHbc/lUhwoJ7OrmtH4Zr50j5A9uhuEj3KgijTKxrRVvZtUJOwMfY8TajAofR/qMRgqeAiBCNSb0Xy0jd6bJycJCv2uAYi4gAX79tmQnHWhxqNi0DcK0YFFf88w8Hc/yXEpl6/17Qu11vbwFL3nS77Le0yI7oYuinOpoX0u+fIUWbx9KJjiO3VdZGJNggVbTO8ufxlTsRv06fh3/0SfNf+QPdzny+T9N9UJgccYvbFNvc61YYfwZo1/GZtfdggjuzlO3cnexikA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=yNeFeRPj5ZpsZ8bp4hqEWSlNg13z5NKjJt1eUBuKptJaaTS6ngwo+UwAdJUAXnpNnJ9Et7I6vYsEsSDk99UBuh6G8Xkww8VsQKDy6RMFP2Z6/fYOb3HhHKdrkiJSpYo67f6jZyTT01Oj3IxRzN7RSObjPpPhO9vtlaAtSBZ56sGTcJ2pPKTqOtmw+o/OhYKkMaA/M+xxCJuqjeRcD2Ull3wPYqsxig2Y4nMc2D9vHmP+0riXbhevnVUBy0XiSk0HDTGwvKIsD5Uq0r1l7vb/PlVwn6cnFGoGiyAa58RZaZjKjKcFRsI9FstFJzCiTaBAX0PwwF/xFjHIQPNoS64Z7Q==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>, "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>
  • Delivery-date: Tue, 22 Sep 2026 05:20:09 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Mail-followup-to: "Orzel, Michal" <michal.orzel@xxxxxxx>, Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>, "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>

On Mon, Sep 14, 2026 at 05:20:44PM +0200, Orzel, Michal wrote:
> 
> 
> On 25-Aug-26 02:30, Volodymyr Babchuk wrote:
> > Hi,
> > 
> > Mykola Kvach <mykola_kvach@xxxxxxxx> writes:
> > 
> >> GICv3 eSPI support makes nr_irqs span the architectural INTID namespace
> >> through ESPI_MAX_INTID, but descriptor storage is sparse. local_irq_desc[]
> >> and irq_desc[] cover INTIDs below NR_IRQS, while espi_desc[] covers eSPIs.
> >> INTIDs 1024 through 4095 have no backing descriptors.
> >>
> >> Validation based only on nr_irqs accepts an INTID in this gap.
> >> __irq_to_desc() then indexes beyond irq_desc[], and callers may lock or
> >> update unrelated Xen memory.
> >>
> >> Reject INTIDs that the GIC reports as unimplemented in setup_irq() before
> >> looking up a descriptor. irq_set_spi_type() can run before the implemented
> >> GIC line counts are available, so validate descriptor-backed ranges there
> >> before looking up a descriptor.
> >>
> >> Assert the regular descriptor bound in __irq_to_desc() so direct callers
> >> cannot silently index the sparse gap in debug builds.
> >>
> >> Fixes: 98f7060b9ed5 ("xen/arm/irq: add handling for IRQs in the eSPI 
> >> range")
> >> Signed-off-by: Mykola Kvach <mykola_kvach@xxxxxxxx>
> >> ---
> >> Changes in v3:
> >> - Add the requested bound assertion and retain the SPI-only comment.
> >>
> >> Changes in v2:
> >> - Validate descriptor-backed ranges in irq_set_spi_type().
> >> - Validate implemented GIC lines in setup_irq().
> >> - Preserve is_espi() validation with CONFIG_GICV3_ESPI disabled.
> >> ---
> >>  xen/arch/arm/irq.c | 26 ++++++++++++++++++++++----
> >>  1 file changed, 22 insertions(+), 4 deletions(-)
> >>
> >> diff --git a/xen/arch/arm/irq.c b/xen/arch/arm/irq.c
> >> index 73e58a5108..bf14180f97 100644
> >> --- a/xen/arch/arm/irq.c
> >> +++ b/xen/arch/arm/irq.c
> >> @@ -23,6 +23,12 @@ const unsigned int nr_irqs = 
> >> IS_ENABLED(CONFIG_GICV3_ESPI) ?
> >>                                          (ESPI_MAX_INTID + 1) :
> >>                                          NR_IRQS;
> >>  
> >> +static bool irq_has_desc(unsigned int irq)
> > 
> > You are using this function only in one place, where you are actually
> > testing for SPI. So, maybe introduce irq_is_spi() helper instead? And
> > use it below?
> It can stay as is but:
>  - move it next to __irq_to_desc(),
>  - use it also as ASSERT(irq_has_desc(irq)) in __irq_to_desc() instead of the
> assertion you just added.
> This way the two stay in sync.

I will move irq_has_desc() next to __irq_to_desc() and add
ASSERT(irq_has_desc(irq)) at the start of __irq_to_desc().

> 
> > 
> >> +{
> >> +    return irq < NR_IRQS ||
> >> +           (IS_ENABLED(CONFIG_GICV3_ESPI) && is_espi(irq));
> >> +}
> >> +
> >>  static unsigned int local_irqs_type[NR_LOCAL_IRQS];
> >>  static DEFINE_SPINLOCK(local_irqs_type_lock);
> >>  
> >> @@ -76,7 +82,6 @@ static int __init init_espi_data(void)
> >>      return 0;
> >>  }
> >>  #else
> >> -
> > 
> > Please, no unnecessary changes
> > 
> >>  static int __init init_espi_data(void)
> >>  {
> >>      return 0;
> >> @@ -95,6 +100,8 @@ struct irq_desc *__irq_to_desc(unsigned int irq)
> >>          return espi_to_desc(irq);
> >>  #endif
> >>  
> >> +    ASSERT(irq < NR_IRQS);
> check_timer_irq_cfg() in time.c calls irq_to_desc() on timer_irq[], and on the
> GTDT path those are not validated.

Patch 4 already handles this. It checks irq_set_type() before saving
each timer IRQ and stops boot if GTDT setup fails.

> 
> >> +
> >>      return &irq_desc[irq-NR_LOCAL_IRQS];
> >>  }
> >>  
> >> @@ -416,6 +423,9 @@ int setup_irq(unsigned int irq, unsigned int irqflags, 
> >> struct irqaction *new)
> >>      struct irq_desc *desc;
> >>      bool disabled;
> >>  
> >> +    if ( !gic_is_valid_line(irq) )
> Please add a printk message to inform the user.

Ack.

Best regards,
Mykola



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.