Re: [PATCH] accel/amdxdna: reject a command chain that carries no commands

Lizhi Hou <[email protected]>
Newsgroups org.freedesktop.lists.dri-devel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 8/17/26 17:00, Taimuraz Kaitmazov wrote:
> A chain whose command_count is zero passes the payload length check,
> because struct_size(payload, data, 0) is just the header. The fill loop
> then does not run, so offset stays zero and the request is submitted with
> a zero-length buffer.
>
> On firmware without AIE2_NPU_COMMAND that ends at the opcode check, since
> op is still ERT_INVALID_CMD and aie2_get_chain_msg_op() answers
> MSG_OP_MAX_OPCODE. aie2_get_npu_chain_msg_op() answers
> MSG_OP_CHAIN_EXEC_NPU whatever it is given, so there the submission
> continues to drm_clflush_virt_range(cmd_buf, 0), which reads the byte
> before the buffer and faults on the vmap guard page. EXEC_CMD is
> reachable by any process that can open the render node.
>
> Reject the request instead.
>
> Signed-off-by: Taimuraz Kaitmazov <[email protected]>
> ---
> drm_clflush_virt_range() faulting on an empty range is a core problem, and a
> patch for it is on the list separately. This rejects the request in the driver
> regardless, since a chain carrying no commands is not something to submit.
>
>   drivers/accel/amdxdna/aie2_message.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/accel/amdxdna/aie2_message.c b/drivers/accel/amdxdna/aie2_message.c
> index dfe0fbdf066d..b4c49259a1a2 100644
> --- a/drivers/accel/amdxdna/aie2_message.c
> +++ b/drivers/accel/amdxdna/aie2_message.c
> @@ -994,7 +994,7 @@ int aie2_cmdlist_multi_execbuf(struct amdxdna_hwctx *hwctx,
>   	}
>   
>   	ccnt = payload->command_count;
> -	if (payload_len < struct_size(payload, data, ccnt)) {
> +	if (!ccnt || payload_len < struct_size(payload, data, ccnt)) {

Reviewed-by: Lizhi Hou <[email protected]>

I will add a Fixes tag when I merge it.

Thanks,

Lizhi

>   		XDNA_DBG(xdna, "Invalid command count %d", ccnt);
>   		return -EINVAL;
>   	}
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.