Re: [PATCH v2] drm/amdgpu/discovery: validate table offset before IP discovery header cast

kernel test robot <[email protected]>
Newsgroups org.freedesktop.lists.amd-gfx,dev.linux.lists.oe-kbuild-all,org.freedesktop.lists.dri-devel,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
Hi Pavitra,

kernel test robot noticed the following build errors:

[auto build test ERROR on drm-misc/drm-misc-next]
[also build test ERROR on linus/master v7.2-rc7 next-20260810]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]

url:    https://github.com/intel-lab-lkp/linux/commits/Pavitra-Jha/drm-amdgpu-discovery-validate-table-offset-before-IP-discovery-header-cast/20260812-100224
base:   https://gitlab.freedesktop.org/drm/misc/kernel.git drm-misc-next
patch link:    https://lore.kernel.org/r/20260708061835.111986-1-jhapavitra98%40gmail.com
patch subject: [PATCH v2] drm/amdgpu/discovery: validate table offset before IP discovery header cast
config: alpha-allyesconfig (https://download.01.org/0day-ci/archive/20260812/[email protected]/config)
compiler: alpha-linux-gcc (GCC) 16.1.0
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260812/[email protected]/reproduce)

If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <[email protected]>
| Closes: https://lore.kernel.org/oe-kbuild-all/[email protected]/

All errors (new ones prefixed by >>):

   In file included from include/linux/byteorder/little_endian.h:5,
                    from arch/alpha/include/uapi/asm/byteorder.h:5,
                    from include/asm-generic/bitops/le.h:6,
                    from arch/alpha/include/asm/bitops.h:472,
                    from include/linux/bitops.h:67,
                    from include/linux/thread_info.h:27,
                    from include/asm-generic/preempt.h:5,
                    from ./arch/alpha/include/generated/asm/preempt.h:1,
                    from include/linux/preempt.h:79,
                    from include/linux/spinlock.h:56,
                    from include/linux/mmzone.h:8,
                    from include/linux/gfp.h:7,
                    from include/linux/firmware.h:8,
                    from drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:24:
   drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c: In function 'amdgpu_discovery_verify_npsinfo':
>> drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:534:32: error: invalid type argument of '->' (have 'struct table_info')
     534 |         if (le16_to_cpu((*info)->offset) >= adev->discovery.size) {
         |                                ^~
   include/uapi/linux/byteorder/little_endian.h:37:51: note: in definition of macro '__le16_to_cpu'
      37 | #define __le16_to_cpu(x) ((__force __u16)(__le16)(x))
         |                                                   ^
   drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:534:13: note: in expansion of macro 'le16_to_cpu'
     534 |         if (le16_to_cpu((*info)->offset) >= adev->discovery.size) {
         |             ^~~~~~~~~~~
   drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:536:44: error: invalid type argument of '->' (have 'struct table_info')
     536 |                         le16_to_cpu((*info)->offset), table_id);
         |                                            ^~
   include/uapi/linux/byteorder/little_endian.h:37:51: note: in definition of macro '__le16_to_cpu'
      37 | #define __le16_to_cpu(x) ((__force __u16)(__le16)(x))
         |                                                   ^
   include/linux/dev_printk.h:154:9: note: in expansion of macro 'dev_printk_index_wrap'
     154 |         dev_printk_index_wrap(_dev_err, KERN_ERR, dev, dev_fmt(fmt), ##__VA_ARGS__)
         |         ^~~~~~~~~~~~~~~~~~~~~
   drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:535:17: note: in expansion of macro 'dev_err'
     535 |                 dev_err(adev->dev, "invalid table offset %u for table_id %u\n",
         |                 ^~~~~~~
   In file included from include/linux/device.h:15,
                    from include/drm/drm_print.h:31,
                    from drivers/gpu/drm/amd/amdgpu/amdgpu_ring.h:29,
                    from drivers/gpu/drm/amd/amdgpu/amdgpu_ctx.h:30,
                    from drivers/gpu/drm/amd/amdgpu/amdgpu.h:37,
                    from drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:27:
>> drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:536:55: error: 'table_id' undeclared (first use in this function); did you mean 'table_info'?
     536 |                         le16_to_cpu((*info)->offset), table_id);
         |                                                       ^~~~~~~~
   include/linux/dev_printk.h:110:37: note: in definition of macro 'dev_printk_index_wrap'
     110 |                 _p_func(dev, fmt, ##__VA_ARGS__);                       \
         |                                     ^~~~~~~~~~~
   drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:535:17: note: in expansion of macro 'dev_err'
     535 |                 dev_err(adev->dev, "invalid table offset %u for table_id %u\n",
         |                 ^~~~~~~
   drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:536:55: note: each undeclared identifier is reported only once for each function it appears in
   include/linux/dev_printk.h:110:37: note: in definition of macro 'dev_printk_index_wrap'
     110 |                 _p_func(dev, fmt, ##__VA_ARGS__);                       \
         |                                     ^~~~~~~~~~~
   drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c:535:17: note: in expansion of macro 'dev_err'
     535 |                 dev_err(adev->dev, "invalid table offset %u for table_id %u\n",
         |                 ^~~~~~~


vim +534 drivers/gpu/drm/amd/amdgpu/amdgpu_discovery.c

   508	
   509	static int amdgpu_discovery_verify_npsinfo(struct amdgpu_device *adev,
   510						   struct table_info *info)
   511	{
   512		uint8_t *discovery_bin = adev->discovery.bin;
   513		uint16_t checksum;
   514		uint16_t offset;
   515	
   516		offset = le16_to_cpu(info->offset);
   517		checksum = le16_to_cpu(info->checksum);
   518	
   519		struct nps_info_header *nhdr =
   520			(struct nps_info_header *)(discovery_bin + offset);
   521	
   522		if (le32_to_cpu(nhdr->table_id) != NPS_INFO_TABLE_ID) {
   523			dev_dbg(adev->dev, "invalid ip discovery nps info table id\n");
   524			return -EINVAL;
   525		}
   526	
   527		if (!amdgpu_discovery_verify_checksum(adev, discovery_bin + offset,
   528						      le32_to_cpu(nhdr->size_bytes),
   529						      checksum)) {
   530			dev_dbg(adev->dev, "invalid nps info data table checksum\n");
   531			return -EINVAL;
   532		}
   533	
 > 534		if (le16_to_cpu((*info)->offset) >= adev->discovery.size) {
   535			dev_err(adev->dev, "invalid table offset %u for table_id %u\n",
 > 536				le16_to_cpu((*info)->offset), table_id);
   537			return -EINVAL;
   538		}
   539	
   540		return 0;
   541	}
   542	

--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.