Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [Medium] gpu: panthor: UB in GENMASK due to unvalidated MMU_FEATURES.AS_COUNT
--

commit f2f7bbf0c9994aff62f62839c8644ec4028839eb
Author: Karunika Choo <[email protected]>
Subject: drm/panthor: Add Mali v15 hardware support

This commit adds hardware support for Mali v15 GPUs in the panthor driver.
It introduces device matching, register definitions, and logic for populating
GPU information for the v15 architecture.

> diff --git a/drivers/gpu/drm/panthor/panthor_hw.c 
> b/drivers/gpu/drm/panthor/panthor_hw.c
> index 13090ff6db7b5..9d539f5f80158 100644
> --- a/drivers/gpu/drm/panthor/panthor_hw.c
> +++ b/drivers/gpu/drm/panthor/panthor_hw.c
[ ... ]
> @@ -260,12 +304,55 @@ static int panthor_gpu_info_init(struct panthor_device 
> *ptdev)
[ ... ]
> +static void panthor_gpu_info_v15_init(struct panthor_device *ptdev)
> +{
[ ... ]
> +     ptdev->gpu_info.core_features = gpu_read(ptdev->iomem, 
> DISCOVER_CORE_FEATURES);
> +
> +     /* AS_PRESENT register removed on v15+ create virtual mask from 
> MMU_FEATURES.AS_COUNT */
> +     ptdev->gpu_info.as_present = GENMASK(
> +             MMU_FEATURES_AS_COUNT(ptdev->gpu_info.mmu_features) - 1, 0);

[Severity: Medium]
Can this result in undefined behavior if the hardware reports an AS_COUNT
of 0?

If the DISCOVER_MMU_FEATURES register returns 0 (e.g., due to a hardware
fault, PCI/bus read failure, or uninitialized clock state),
MMU_FEATURES_AS_COUNT(ptdev->gpu_info.mmu_features) will evaluate to 0.
This would cause the code to evaluate GENMASK(-1, 0).

The GENMASK(h, l) macro invokes undefined behavior when h < l because it
results in a shift out of bounds (shifting ~UL(0) by BITS_PER_LONG). This
could produce an unpredictable value for the as_present bitmask, which may
lead to crashes or out-of-bounds accesses if the driver later attempts to
initialize non-existent address spaces based on a garbage mask.

> +
> +     ptdev->gpu_info.l2_present = gpu_read64(pwr_iomem, PWR_L2_PRESENT);
> +     ptdev->gpu_info.tiler_present = gpu_read64(pwr_iomem, 
> PWR_TILER_PRESENT);
> +     ptdev->gpu_info.shader_present = gpu_read64(pwr_iomem, 
> PWR_SHADER_PRESENT);
> +}

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=8

Reply via email to