On Mon, Aug 03, 2026 at 11:14:03AM +0200, Arnd Bergmann wrote: > On Sun, Aug 2, 2026, at 17:51, Junrui Luo via B4 Relay wrote: > > From: Junrui Luo <[email protected]> > > > > spu_process_callback() masks the low bits of the NPC register and uses > > the result as an offset into the SPU local store: `ls_pointer = in_be32(ls > > + npc)`. The following guard validates ls_pointer against LS_SIZE, but npc > > itself is never bounds-checked. > > > > Fix by rejecting npc greater than LS_SIZE - sizeof(ls_pointer) before the > > read, mirroring the adjacent ls_pointer guard and returning the same > > -EFAULT. > > This one seems wrong: npc is a hardware register value that can't > go out of range, unlike the ls_pointer value. I don't think there > is any use for the check. > > Arnd
Thanks for the review. I didn't establish that it can actually go out of range. Please drop this one. Thanks, Junrui Luo
