[PATCH v2 0/6] Fix input validation issues in SBI ecall handlers
liutong <[email protected]> Fri, 31 Jul 2026 10:33:59 +0000
| Newsgroups | org.infradead.lists.opensbi |
|---|---|
| Message-ID | <[email protected]> |
This series fixes input validation and shared memory handling issues found across multiple SBI extension handlers: DBTR, PMU, SSE, and MPXY. The fixes fall into three categories: 1. Integer overflow in bounds checks (patches 1, 4, 6) Arithmetic overflow in endpoint calculations allows out-of-bounds access from S-mode via crafted ecall parameters. 2. TOCTOU / double-fetch from shared memory (patches 2, 5) S-mode shared memory is read twice --once to validate, once to apply. S-mode can modify the memory between reads, bypassing M-mode validation. 3. Insufficient address range validation (patch 3) Single-address domain check does not cover the full shared memory region, allowing cross-domain access. These patches were previously sent individually. Per reviewer feedback, they are now consolidated into a single series. Changes in v2: - Reorganized as a unified patch series (per Rahul Pathak's suggestion) - All patches now include Fixes tags - install_trig: fixed rollback to also cover SBI_ERR_NOT_SUPPORTED path liutong (6): lib: sbi_dbtr: fix integer overflow in read_trig bounds check lib: sbi_dbtr: fix shared memory double-fetch in install_trig lib: sbi_dbtr: use range check for shared memory domain validation lib: sbi_pmu: fix integer overflow and zero-address in event_get_info lib: sbi_sse: fix shared memory double-fetch in sse_write_attrs lib: sbi_mpxy: fix integer overflow in attribute range endpoint lib/sbi/sbi_dbtr.c | 91 +++++++++++++++++++++++----------------------- lib/sbi/sbi_mpxy.c | 6 ++- lib/sbi/sbi_pmu.c | 10 ++++- lib/sbi/sbi_sse.c | 14 ++++--- 4 files changed, 66 insertions(+), 55 deletions(-) -- 2.34.1 -- opensbi mailing list [email protected] http://lists.infradead.org/mailman/listinfo/opensbi