Re: [PATCH v2] drm/cirrus-qemu: Validate BAR0 size during probe

Thomas Zimmermann <[email protected]>
Newsgroups dev.linux.lists.virtualization,dev.linux.lists.syzbot,org.freedesktop.lists.dri-devel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hi

Am 25.08.26 um 14:07 schrieb Slawomir Stepien:
> The `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate
> framebuffer sizes. However, during PCI probe, the driver mapped BAR0
> without verifying that its size matches `CIRRUS_VRAM_SIZE`.
>
> If a PCI device with a BAR0 smaller than 4 MB is bound to the driver, the
> mapped VRAM will be smaller than expected. Because validation checks assume
> 4 MB VRAM, framebuffers larger than the mapped memory can be created.
>
> When the display plane is updated (e.g. during release),
> `cirrus_primary_plane_helper_atomic_update()` copies the framebuffer to
> VRAM using `drm_fb_memcpy()`. Writing past the end of the mapped I/O memory
> causes a supervisor write page fault:
>
> BUG: unable to handle page fault for address: ffffc9000389c000
> ...
> RIP: 0010:memcpy_toio+0x7c/0xe0 arch/x86/lib/iomem.c:110
> ...
> Call Trace:
>   <TASK>
>   iosys_map_memcpy_to include/linux/iosys-map.h:285 [inline]
>   drm_fb_memcpy+0x325/0x5d0 drivers/gpu/drm/drm_format_helper.c:442
>   cirrus_primary_plane_helper_atomic_update+0x98a/0xb00
>   drivers/gpu/drm/tiny/cirrus-qemu.c:358
>   drm_atomic_helper_commit_planes+0x626/0xea0
>   drivers/gpu/drm/drm_atomic_helper.c:3038
>   drm_atomic_helper_commit_tail+0x60/0x510
>   drivers/gpu/drm/drm_atomic_helper.c:1989
>   commit_tail+0x2b1/0x3c0 drivers/gpu/drm/drm_atomic_helper.c:2074
>   drm_atomic_helper_commit+0xa77/0xb10
>   drivers/gpu/drm/drm_atomic_helper.c:2312
>
> Fix this by validating in `cirrus_pci_probe()` that the PCI BAR0 resource
> is not less than `CIRRUS_VRAM_SIZE`, returning `-ENODEV` if it is less.
>
> Fixes: ab3e023b1b4c ("drm/cirrus: rewrite and modernize driver.")
> Assisted-by: Gemini:gemini-3.6-flash Gemini:gemini-3.1-pro-preview syzbot
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=2442951a6abb004df963
> Link: https://syzkaller.appspot.com/ai_job?id=ba262a3a-bccf-4ad8-a1b0-583c55d34fd6
> Signed-off-by: Slawomir Stepien <[email protected]>

Reviewed-by: Thomas Zimmermann <[email protected]>

Thanks for fixing this issue.

Best regards
Thomas

> ---
> v2:
> * move the check before aperture_remove_conflicting_pci_devices() as suggested by sashiko.
> * check if the pci_resource_len() for BAR0 is less than CIRRUS_VRAM_SIZE as suggested by Thomas. The
>    qemu emulates 4, (8 and 16 MB for compatibility) - never less than 4MB.
>
> v1:
> * https://lore.kernel.org/all/[email protected]/T/
> ---
>   drivers/gpu/drm/tiny/cirrus-qemu.c | 3 +++
>   1 file changed, 3 insertions(+)
>
> diff --git a/drivers/gpu/drm/tiny/cirrus-qemu.c b/drivers/gpu/drm/tiny/cirrus-qemu.c
> index 075221b431d3..3bf23fcf6574 100644
> --- a/drivers/gpu/drm/tiny/cirrus-qemu.c
> +++ b/drivers/gpu/drm/tiny/cirrus-qemu.c
> @@ -582,6 +582,9 @@ static int cirrus_pci_probe(struct pci_dev *pdev,
>   	struct cirrus_device *cirrus;
>   	int ret;
>   
> +	if (pci_resource_len(pdev, 0) < CIRRUS_VRAM_SIZE)
> +		return -ENODEV;
> +
>   	ret = aperture_remove_conflicting_pci_devices(pdev, cirrus_driver.name);
>   	if (ret)
>   		return ret;

-- 
--
Thomas Zimmermann
Graphics Driver Developer
SUSE Software Solutions Germany GmbH
Frankenstr. 146, 90461 Nürnberg, Germany, www.suse.com
GF: Jochen Jaser, Andrew McDonald, (HRB 36809, AG Nürnberg)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.