From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-vk1-f181.google.com (mail-vk1-f181.google.com [209.85.221.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1D02347F2CB for ; Fri, 15 May 2026 12:00:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778846440; cv=none; b=FYjH9HnLCTHQwZQLs5FlKhdqAYfGM3OeQyllBo8w0+RZFqwXQBu0/xsxopUIJCQu6oqZOypOtIqMzDwAez/OHKrolAGbHgScjnu3EjifICHRrmyCRi5HntV5KVcsY8OsqXYLabiJ0rPJacmsFp3gvtpl/TMcYuIv/V/9stvPXLI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778846440; c=relaxed/simple; bh=X9fTQABNwTvMa0RxcaX3nuN2SeZovYr4xCXjp1SUWOA=; h=MIME-Version:References:In-Reply-To:From:Date:Message-ID:Subject: To:Cc:Content-Type; b=qRYWbTgzTiYzG4vxB9VVbFUpyYy1dPZmpfpf9E8vR2tChmJ84ZBBkHXtatCIpJoCygF+gAyIbYDG31kG0iDyv3ECuqzWOTW5gKSouREL3L3/ZuRNKULi9kZ0DQ0bERfSaLnm25vlB2ZjRTrAC75HqbcbizDSIVj5wBE+ZKqJIzo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=linux-m68k.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.221.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=linux-m68k.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-vk1-f181.google.com with SMTP id 71dfb90a1353d-57611a6a69eso133370e0c.3 for ; Fri, 15 May 2026 05:00:38 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1778846438; x=1779451238; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=OeqLkT6YmhpaIvM6KqI+mX2KVKU2AF95h98UORdYbio=; b=aXAvneLK/yug10kH2+ztNmYkGcLuVRbiV1usqXL30SUM1IVHTnGGqCyBRhcWqqFEan 8QOIQZ5+IibkY1ZYAM1QfJ6XO9zBKIq6R7e6C9jyyilo9RpetNN4hifLzRMy6xd4pA7O DpO+XUsHkpSlFvRaBKMtTFBTnGq4cnbYIFjj+ndd6mLs0211W7RQbFUNGzPIDGK0QusA 5TdtUMgkYRBrYMilt5QLAqvWb/YCwTQ0vFkgqK0ZtC18x30Bn5LfgcvbdeBVkF/Q32BM mNDvgY2HUex+Ob0vCdm+j+bEvdRWCvFTPLL0dcVud0xvfHxecTMHpCs8zFzwgSIVj4/8 ibOg== X-Forwarded-Encrypted: i=1; AFNElJ+uj03B/36FsrRu+nAOJGRuinGuIlmrc7QgSRoBTGTYhMw1BLdcxqX3GTThRGZYU6/wz7JCG+KC7ldbOms=@vger.kernel.org X-Gm-Message-State: AOJu0Ywd7yArFX4QkWY8RWTbRhn5F3qkYWOMSPic3wmTWooqDzr12+De 5sPaJBC6qWbzljx2lrcglxmGXPe8FsGIZ3wlqPmF/ELzzNx3i1GwDOmCzNC/qHaw X-Gm-Gg: Acq92OEnm7g3PlOLaGtT7EGWywg+edpJSo5JtogVMZOWqTCtBYBQUHphaWQoGdmBOTs zK12YnCTvllkQiKX0pz7sJk1Idto5bSul1JCW/QQ1V4JDZ9I/qJ6x4bkSFvAPALw2cz1wDKQP9+ nsy8LkgteV9BYytvdKO7Vh1H9pQz4ylfhAsxiyNIPC1sx6TQnaUNGbx3MPmF68cJFD+VNTt3WAs luj4nWcCLjWJc/yQYOXLooyyb1FR+FgBb/tNf+46D5ZVk6F0JoACqH+3bskO8hTtDa8aL6qWZuF pHjyopBtynAQT2EIC1pv/zs1farMS9P7vUfWtN/oYeqrVFJb5MkOITB9OtOnGkR0Fymi/MkyRWw NlfiYlJGxr5RlsemuR3UyoOHSJQPkjRm6HQBMjxANfZ6/Fm7UnHWXJ1NA1fhizFV6mbwkEAXB6/ n2EFLvODrxzZYhbIFEeSTVO/11WaGZueY2ieqkeOUClmoK6tyj/WWkn6j7VVA0wi30dvb4uKI= X-Received: by 2002:a05:6122:338f:b0:56e:e68e:9fc2 with SMTP id 71dfb90a1353d-5760c013b50mr1998137e0c.10.1778846438039; Fri, 15 May 2026 05:00:38 -0700 (PDT) Received: from mail-vs1-f43.google.com (mail-vs1-f43.google.com. [209.85.217.43]) by smtp.gmail.com with ESMTPSA id 71dfb90a1353d-5760f3031b0sm1197310e0c.0.2026.05.15.05.00.37 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 15 May 2026 05:00:37 -0700 (PDT) Received: by mail-vs1-f43.google.com with SMTP id ada2fe7eead31-6312a0d556cso3514912137.3 for ; Fri, 15 May 2026 05:00:37 -0700 (PDT) X-Forwarded-Encrypted: i=1; AFNElJ/keJ8FlbpnCBTusDadX5QynD16PGVtcgNu38bJsvvhCZ82xHHpCmkhNOMV6l/UZbwo71NYRGuqdvYwTHw=@vger.kernel.org X-Received: by 2002:a05:6102:304d:b0:62f:2f1f:599b with SMTP id ada2fe7eead31-63a3d21f6e7mr1529435137.7.1778846436927; Fri, 15 May 2026 05:00:36 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 References: <75caae28bdffb55199a0bc6cac5df112a966c608.1778838987.git.geert+renesas@glider.be> In-Reply-To: From: Geert Uytterhoeven Date: Fri, 15 May 2026 14:00:24 +0200 X-Gmail-Original-Message-ID: X-Gm-Features: AVHnY4J92Za9USCx0Iqrdp0VKNlh7Aqvg8Y1zHpQUS0Wj660oR8QKip2za8oQmo Message-ID: Subject: Re: [PATCH] firmware: arm_scmi: Fix OOB in scmi_power_name_get() To: Cristian Marussi Cc: Dan Carpenter , Sudeep Holla , arm-scmi@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" Hi Cristian, On Fri, 15 May 2026 at 13:46, Cristian Marussi wrote: > On Fri, May 15, 2026 at 01:29:27PM +0200, Geert Uytterhoeven wrote: > > On Fri, 15 May 2026 at 12:28, Dan Carpenter wrote: > > > On Fri, May 15, 2026 at 11:59:15AM +0200, Geert Uytterhoeven wrote: > > > > scmi_power_name_get() does not validate the domain number passed by the > > > > external caller, which may lead to an out-of-bounds access. > > > > > > Is an external caller an out of tree caller? So far as I can see this > > > > I meant a caller outside drivers/firmware/arm_scmi/. > > > > > is only called by scmi_pm_domain_probe(). > > > > > > scmi_pd->name = power_ops->name_get(ph, i); > > > > > > where i < num_domains. > > > > You are right. But this seems to be only API implementation in > > drivers/firmware/arm_scmi/ that does not validate the passed domain > > number. > > Yes we tend to validate protocol operations calls even if apparently > safe from teh caller perspective...indeed I have this fixed locally > since ages in an horrible patch, that does a lot more, and that I > never posted :P > > Usually, if it is worth, we also build an internal domain get helper to > reuse across the protocol unit...but here really there are only 2 call-sites. > > What I am not sure is what to return: "unknown" is safer as of now than NULL > for sure, but really, what happened is NOT that the name was "unknown" (which > by itself would be out-of-spec behaviour) it is more that the whole domain that > was referred to that was invalid and NOT existent... > > ....mmm I suppose we are opening another can of worms here :P Like scmi_perf_info_get() returning ERR_PTR(-EINVAL) instead of NULL, and scmi_perf_domain_probe() never checking the return value anyway? Gr{oetje,eeting}s, Geert -- Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org In personal conversations with technical people, I call myself a hacker. But when I'm talking to journalists I just say "programmer" or something like that. -- Linus Torvalds