On Thu, Jun 25, 2026 at 5:19 PM Bokun Zhang <[email protected]> wrote: > > - There is a bug that the host CPER response struct may > contain bad data so that it will lead to guest side > memory access out of bound > > - Must move the variable to a dedicated variable > and compare the boundary > > Signed-off-by: Bokun Zhang <[email protected]>
Series is: Reviewed-by: Alex Deucher <[email protected]> > --- > drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c | 7 ++++++- > 1 file changed, 6 insertions(+), 1 deletion(-) > > diff --git a/drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c > b/drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c > index c6e7aa6ecb8f..6049b3392a9d 100644 > --- a/drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c > +++ b/drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c > @@ -204,6 +204,7 @@ static int amdgpu_virt_ras_get_batch_records(struct > ras_core_context *ras_core, > .batch_num = RAS_CMD_MAX_BATCH_NUM, > }; > struct ras_cmd_batch_trace_record_rsp *rsp = rsp_cache; > + uint32_t rsp_start_batch_id; > struct batch_ras_trace_info *batch; > uint32_t trace_num; > uint32_t offset; > @@ -220,7 +221,11 @@ static int amdgpu_virt_ras_get_batch_records(struct > ras_core_context *ras_core, > return -EPIPE; > } > > - batch = &rsp->batchs[batch_id - rsp->start_batch_id]; > + rsp_start_batch_id = rsp->start_batch_id; > + if ((batch_id < rsp_start_batch_id) || ((batch_id - > rsp_start_batch_id) >= RAS_CMD_MAX_BATCH_NUM)) > + return -ENODATA; > + > + batch = &rsp->batchs[batch_id - rsp_start_batch_id]; > if (batch_id != batch->batch_id) > return -ENODATA; > > -- > 2.51.0 >
