[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH v4 2/4] xen/arm: validate IRQs before descriptor lookup
- To: Mykola Kvach <mykola_kvach@xxxxxxxx>, <xen-devel@xxxxxxxxxxxxxxxxxxxx>
- From: "Orzel, Michal" <michal.orzel@xxxxxxx>
- Date: Tue, 22 Sep 2026 16:16:59 +0200
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=epam.com smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0)
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=GiyKKdJUOBT3vXd8bxwGTLEbTo7Dtuy1RwvOHLYnLek=; b=Anmro2vnonKxOjhARTn1FBWA+SH5t/EbrZLJuxK029BxjmNaltOAWBrjHqjFIWv9ooLZ+OfWQVwcuF5+dL6Dyb+23Dab5aMdI7i8xca+Cd9jRvz0VlIR2NBlQw6vhEDzXyBMoQHd3Uin1qYDOAEi/6hyOknScDZpf11nkpc0iZ+HpyfJJcfSHt0q/sC4SJBjqncb7TUmSPn6lWE+W4yyKYSt5aBuE7tIQwW580covjDQGx4Rew/lZ7+to/kL5xfSl10stYPpybcze+jffvjiht1y780Dd8CkmIwyWl7kvHmWcP4mI/yxvuCdCpwyD16BVsvoSKZlUa0isz15ziHn+g==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=YNx0BNli/zoVpHkZph6wjpPURvRBwU4lKmmJUmwObJ8h7GCGcuymjyWCT6vDSBqJLLFGmNrKjfMPx5bvOt95QF+GL6XSeXKRTgUKLmJdf1PYAtG2ryTQiOtW3frzwQ18bpVC1llhuN2K4BEfWMIp6uxUHNbQosYlXXEuRZysbpT0cGeo7CQ3ruDQRroJ7/2MaqBbFUyjHxihrhAQQG+fGN8+9TKjU5BOVZwBDrHVQFk4di+Nbp+89Sto2iAMd+G2I7yt3tGH2zdBp1HRWNzuWCZhwUJ6N37dO0hx7qHujj3U8WXfcrG8iw051RkiII7TT54H0EKqCdjqLlkLiQIHjQ==
- Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=amd.com header.i="@amd.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
- Cc: Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, "Volodymyr Babchuk" <Volodymyr_Babchuk@xxxxxxxx>
- Delivery-date: Tue, 22 Sep 2026 14:17:24 +0000
- List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
On 22-Sep-26 08:39, Mykola Kvach wrote:
> GICv3 eSPI support makes nr_irqs span the architectural INTID namespace
> through ESPI_MAX_INTID, but descriptor storage is sparse. local_irq_desc[]
> and irq_desc[] cover INTIDs below NR_IRQS, while espi_desc[] covers eSPIs.
> INTIDs 1024 through 4095 have no backing descriptors.
>
> Validation based only on nr_irqs accepts an INTID in this gap.
> __irq_to_desc() then indexes beyond irq_desc[], and callers may lock or
> update unrelated Xen memory.
>
> Reject INTIDs that the GIC reports as unimplemented in setup_irq() before
> looking up a descriptor. irq_set_spi_type() can run before the implemented
> GIC line counts are available, so validate descriptor-backed ranges there
> before looking up a descriptor.
>
> Use the same descriptor range check in irq_set_spi_type() and the
> assertion in __irq_to_desc() to keep them in sync. Log the IRQ number
> when setup_irq() rejects an invalid line.
>
> Fixes: 98f7060b9ed5 ("xen/arm/irq: add handling for IRQs in the eSPI range")
> Signed-off-by: Mykola Kvach <mykola_kvach@xxxxxxxx>
Reviewed-by: Michal Orzel <michal.orzel@xxxxxxx>
~Michal
|