* [Xen-devel] [PATCH v4] xen/arm: domain_build: harden make_cpus_node()
@ 2019-10-10 0:42 Stefano Stabellini
2019-10-10 6:13 ` Jürgen Groß
2019-10-10 9:47 ` Julien Grall
0 siblings, 2 replies; 3+ messages in thread
From: Stefano Stabellini @ 2019-10-10 0:42 UTC (permalink / raw)
To: julien.grall
Cc: jgross, xen-devel, sstabellini, Volodymyr_Babchuk, Stefano Stabellini
make_cpus_node() is using a static buffer to generate the FDT node name.
While mpdir_aff is a 64-bit integer, we only ever use the bits [23:0] as
only AFF{0, 1, 2} are supported for now.
To avoid any potential issues in the future, check that mpdir_aff has
only bits [23:0] set.
Take the opportunity to reduce the size of the buffer. Indeed, only 8
characters are needed to print a 32-bit hexadecimal number. So
sizeof("cpu@") + 8 + 1 (for '\0') = 13 characters is sufficient.
Fixes: c81a791d34 (xen/arm: Set 'reg' of cpu node for dom0 to match MPIDR's affinity)
Signed-off-by: Stefano Stabellini <stefano.stabellini@xilinx.com>
---
Changes in v4:
- commit message
- in-code comments
Changes in v3:
- make sure only [23:0] bits are used in mpidr_aff
- clarify that we only need 32bit for buf writes
Changes in v2:
- patch added
---
xen/arch/arm/domain_build.c | 19 +++++++++++++++++--
1 file changed, 17 insertions(+), 2 deletions(-)
diff --git a/xen/arch/arm/domain_build.c b/xen/arch/arm/domain_build.c
index 921b054520..38adb6e954 100644
--- a/xen/arch/arm/domain_build.c
+++ b/xen/arch/arm/domain_build.c
@@ -788,8 +788,8 @@ static int __init make_cpus_node(const struct domain *d, void *fdt)
unsigned int cpu;
const void *compatible = NULL;
u32 len;
- /* Placeholder for cpu@ + a 32-bit number + \0 */
- char buf[15];
+ /* Placeholder for cpu@ + a 32-bit hexadecimal number + \0 */
+ char buf[13];
u32 clock_frequency;
bool clock_valid;
uint64_t mpidr_aff;
@@ -847,11 +847,26 @@ static int __init make_cpus_node(const struct domain *d, void *fdt)
* the MPIDR's affinity bits. We will use AFF0 and AFF1 when
* constructing the reg value of the guest at the moment, for it
* is enough for the current max vcpu number.
+ *
+ * We only deal with AFF{0, 1, 2} stored in bits [23:0] at the
+ * moment.
*/
mpidr_aff = vcpuid_to_vaffinity(cpu);
+ if ( (mpidr_aff & ~GENMASK_ULL(23, 0)) != 0 )
+ {
+ printk(XENLOG_ERR "Unable to handle MPIDR AFFINITY 0x%"PRIx64"\n",
+ mpidr_aff);
+ return -EINVAL;
+ }
+
dt_dprintk("Create cpu@%"PRIx64" (logical CPUID: %d) node\n",
mpidr_aff, cpu);
+ /*
+ * We use PRIx64 because mpidr_aff is a 64bit integer. However,
+ * only bits [23:0] are used, thus, we are sure it will fit in
+ * buf.
+ */
snprintf(buf, sizeof(buf), "cpu@%"PRIx64, mpidr_aff);
res = fdt_begin_node(fdt, buf);
if ( res )
--
2.17.1
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xenproject.org
https://lists.xenproject.org/mailman/listinfo/xen-devel
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [Xen-devel] [PATCH v4] xen/arm: domain_build: harden make_cpus_node()
2019-10-10 0:42 [Xen-devel] [PATCH v4] xen/arm: domain_build: harden make_cpus_node() Stefano Stabellini
@ 2019-10-10 6:13 ` Jürgen Groß
2019-10-10 9:47 ` Julien Grall
1 sibling, 0 replies; 3+ messages in thread
From: Jürgen Groß @ 2019-10-10 6:13 UTC (permalink / raw)
To: Stefano Stabellini, julien.grall
Cc: xen-devel, Stefano Stabellini, Volodymyr_Babchuk
On 10.10.19 02:42, Stefano Stabellini wrote:
> make_cpus_node() is using a static buffer to generate the FDT node name.
> While mpdir_aff is a 64-bit integer, we only ever use the bits [23:0] as
> only AFF{0, 1, 2} are supported for now.
>
> To avoid any potential issues in the future, check that mpdir_aff has
> only bits [23:0] set.
>
> Take the opportunity to reduce the size of the buffer. Indeed, only 8
> characters are needed to print a 32-bit hexadecimal number. So
> sizeof("cpu@") + 8 + 1 (for '\0') = 13 characters is sufficient.
>
> Fixes: c81a791d34 (xen/arm: Set 'reg' of cpu node for dom0 to match MPIDR's affinity)
> Signed-off-by: Stefano Stabellini <stefano.stabellini@xilinx.com>
Release-acked-by: Juergen Gross <jgross@suse.com>
Juergen
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xenproject.org
https://lists.xenproject.org/mailman/listinfo/xen-devel
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [Xen-devel] [PATCH v4] xen/arm: domain_build: harden make_cpus_node()
2019-10-10 0:42 [Xen-devel] [PATCH v4] xen/arm: domain_build: harden make_cpus_node() Stefano Stabellini
2019-10-10 6:13 ` Jürgen Groß
@ 2019-10-10 9:47 ` Julien Grall
1 sibling, 0 replies; 3+ messages in thread
From: Julien Grall @ 2019-10-10 9:47 UTC (permalink / raw)
To: Stefano Stabellini
Cc: jgross, xen-devel, Stefano Stabellini, Volodymyr_Babchuk
Hi Stefano,
On 10/10/19 1:42 AM, Stefano Stabellini wrote:
> make_cpus_node() is using a static buffer to generate the FDT node name.
> While mpdir_aff is a 64-bit integer, we only ever use the bits [23:0] as
> only AFF{0, 1, 2} are supported for now.
>
> To avoid any potential issues in the future, check that mpdir_aff has
> only bits [23:0] set.
>
> Take the opportunity to reduce the size of the buffer. Indeed, only 8
> characters are needed to print a 32-bit hexadecimal number. So
> sizeof("cpu@") + 8 + 1 (for '\0') = 13 characters is sufficient.
>
> Fixes: c81a791d34 (xen/arm: Set 'reg' of cpu node for dom0 to match MPIDR's affinity)
> Signed-off-by: Stefano Stabellini <stefano.stabellini@xilinx.com>
Reviewed-by: Julien Grall <julien.grall@arm.com>
Cheers,
--
Julien Grall
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xenproject.org
https://lists.xenproject.org/mailman/listinfo/xen-devel
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2019-10-10 9:47 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-10-10 0:42 [Xen-devel] [PATCH v4] xen/arm: domain_build: harden make_cpus_node() Stefano Stabellini
2019-10-10 6:13 ` Jürgen Groß
2019-10-10 9:47 ` Julien Grall
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).