[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v4 4/4] xen/arm: handle irq_set_type() failures


  • To: "Orzel, Michal" <michal.orzel@xxxxxxx>
  • From: Mykola Kvach <mykola_kvach@xxxxxxxx>
  • Date: Wed, 23 Sep 2026 12:27:06 +0300
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=mzz31HR74OJnBFNuOq07IWwxoGymFus80+Ak97b2Aok=; b=YM/j08g6+e25E7UEwLSdhkVyOD/QvBDmexGLo2HSNqJM0WdqlBFgDDgibDEISpUI8lbkJVPrXEVgrMxF//yNpMH01b7ZPbm5//piGFmtmLyjGirPnWpv1gSCu/K+ixN4C6q8vTapSqxMucolOB8jEKD+j7nUqvFVt/9FQmdJDgr7ThSMp9vujKQAQIKvOcELeUwCxhlgPAsh6rejMGvMZDNvIXhP4exfDod4Zt6wAeFwUiy7v98ALiQ3q2cOXSIwu4MsoMEquxHzvO9OQnuh1kJLbnOFqAjfOFquIS5eHfYmHBi0SS0R2CtP2C0b2OSGvoyQOickR2wC4KFHFdqcnw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=QxFdpci3RoA9C7TP2s4ZZb6CPLB20PSrd9+T+F659rdOJQhe1Aww0Wkikeig9GocVTkfwiARhddv2AU3GABIlLTnO/Vo5bHmWz4tXlCU7m6lUPPaYzKBjEQa4pTnJzcQTKNvheFVs6nBQuCV5rloWllx4Kgka9NR17T6VxPJk5zrDszKhwfugpxcyl2s2011uI4Pomh66C3Hbux2fc4DsWhiWwfZBJczUvOw833gWRJCxC3h3D6odfQgoTRJBxS7qfn9NCs/XvX8+g1zrmtUBsLaMN8XgZMrX3Bga6Y+DOgmCp4ynTmrUkyvqUvoET4Rl4qVcd4uzxzjItjx4wfSpQ==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: xen-devel@xxxxxxxxxxxxxxxxxxxx, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>, Jens Wiklander <jenswi@xxxxxxxxxx>
  • Delivery-date: Wed, 23 Sep 2026 09:27:21 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Mail-followup-to: "Orzel, Michal" <michal.orzel@xxxxxxx>, xen-devel@xxxxxxxxxxxxxxxxxxxx, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>, Jens Wiklander <jenswi@xxxxxxxxxx>

On Tue, Sep 22, 2026 at 04:24:59PM +0200, Orzel, Michal wrote:
> 
> 
> On 22-Sep-26 08:39, Mykola Kvach wrote:
> > Several Arm firmware initialization paths discard irq_set_type()'s return
> > value, violating MISRA C Rule 17.7. If trigger configuration fails,
> > initialization continues with an IRQ that was not configured as requested.
> > 
> > GTDT and MADT retain rejected timer and maintenance INTIDs.
> > check_timer_irq_cfg() and release_irq() later perform unconditional
> > descriptor lookups on those values. Xen has no backing descriptors for
> > INTIDs 1024 through 4095, so retaining one can cause an out-of-bounds
> > access.
> > 
> > Check the return value in the GTDT, MADT, SPCR, and FF-A paths. Store timer
> > INTIDs only after successful trigger configuration, make GTDT parsing
> > failure fatal, and stop UART or notification setup when trigger
> > configuration fails.
> > 
> > Signed-off-by: Mykola Kvach <mykola_kvach@xxxxxxxx>
> > Reviewed-by: Volodymyr Babchuk <volodymyr_babchuk@xxxxxxxx>
> > Reviewed-by: Michal Orzel <michal.orzel@xxxxxxx>
> I asked you on v3 to reorder the patches, so that this one comes first 
> (usually
> when sending the series, fixes, improvements should come first so that they 
> can
> be immediately taken).

Sure, I'll reorder the series in v5 so that this patch comes first.
Thanks for the reminder.

Best regards,
Mykola



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.