Re: [PATCH 3/6] powerpc/spufs: bound NPC against local store size

Junrui Luo <[email protected]>
Newsgroups org.ozlabs.lists.linuxppc-dev,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
On Mon, Aug 03, 2026 at 11:14:03AM +0200, Arnd Bergmann wrote:
> On Sun, Aug 2, 2026, at 17:51, Junrui Luo via B4 Relay wrote:
> > From: Junrui Luo <[email protected]>
> >
> > spu_process_callback() masks the low bits of the NPC register and uses
> > the result as an offset into the SPU local store: `ls_pointer = in_be32(ls
> > + npc)`. The following guard validates ls_pointer against LS_SIZE, but npc
> > itself is never bounds-checked.
> >
> > Fix by rejecting npc greater than LS_SIZE - sizeof(ls_pointer) before the
> > read, mirroring the adjacent ls_pointer guard and returning the same
> > -EFAULT.
> 
> This one seems wrong: npc is a hardware register value that can't
> go out of range, unlike the ls_pointer value. I don't think there
> is any use for the check.
> 
>      Arnd

Thanks for the review. I didn't establish that it can actually go
out of range. Please drop this one.

Thanks,
Junrui Luo
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.