On Thu, Jun 25, 2026 at 5:19 PM Bokun Zhang <[email protected]> wrote:
>
> - There is a bug that the host CPER response struct may
>   contain bad data so that it will lead to guest side
>   memory access out of bound
>
> - Must move the variable to a dedicated variable
>   and compare the boundary
>
> Signed-off-by: Bokun Zhang <[email protected]>

Series is:
Reviewed-by: Alex Deucher <[email protected]>

> ---
>  drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c | 7 ++++++-
>  1 file changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c 
> b/drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c
> index c6e7aa6ecb8f..6049b3392a9d 100644
> --- a/drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c
> +++ b/drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c
> @@ -204,6 +204,7 @@ static int amdgpu_virt_ras_get_batch_records(struct 
> ras_core_context *ras_core,
>                 .batch_num = RAS_CMD_MAX_BATCH_NUM,
>         };
>         struct ras_cmd_batch_trace_record_rsp *rsp = rsp_cache;
> +       uint32_t rsp_start_batch_id;
>         struct batch_ras_trace_info *batch;
>         uint32_t trace_num;
>         uint32_t offset;
> @@ -220,7 +221,11 @@ static int amdgpu_virt_ras_get_batch_records(struct 
> ras_core_context *ras_core,
>                         return -EPIPE;
>         }
>
> -       batch = &rsp->batchs[batch_id - rsp->start_batch_id];
> +       rsp_start_batch_id = rsp->start_batch_id;
> +       if ((batch_id < rsp_start_batch_id) || ((batch_id - 
> rsp_start_batch_id) >= RAS_CMD_MAX_BATCH_NUM))
> +               return -ENODATA;
> +
> +       batch = &rsp->batchs[batch_id - rsp_start_batch_id];
>         if (batch_id != batch->batch_id)
>                 return -ENODATA;
>
> --
> 2.51.0
>

Reply via email to