Re: [PATCH 3/6] powerpc/spufs: bound NPC against local store size

"Arnd Bergmann" <[email protected]> Mon, 03 Aug 2026 11:14:03 +0200
Newsgroups gmane.linux.ports.ppc.embedded
Message-ID <073a9c41-4545-4bf6-aeb2-1dadf3c222df__11432.7992590674$1785748485$gmane$org@app.fastmail.com>
On Sun, Aug 2, 2026, at 17:51, Junrui Luo via B4 Relay wrote:
> From: Junrui Luo <[email protected]>
>
> spu_process_callback() masks the low bits of the NPC register and uses
> the result as an offset into the SPU local store: `ls_pointer = in_be32(ls
> + npc)`. The following guard validates ls_pointer against LS_SIZE, but npc
> itself is never bounds-checked.
>
> Fix by rejecting npc greater than LS_SIZE - sizeof(ls_pointer) before the
> read, mirroring the adjacent ls_pointer guard and returning the same
> -EFAULT.

This one seems wrong: npc is a hardware register value that can't
go out of range, unlike the ls_pointer value. I don't think there
is any use for the check.

     Arnd