[PATCH] lib: sbi: dbtr: validate complete shared memory range

Pengpeng Hou pengpeng at iscas.ac.cn
Thu Aug 27 04:58:33 PDT 2026


The DBTR shared memory contains total_trigs entries, but setup currently
checks domain access for only its first byte.  A supervisor can place that
base near a domain boundary so later entries extend into inaccessible or
M-mode-only memory.

Validate the complete specification-defined shared-memory extent with
sbi_domain_check_addr_range().  Also reject an install count prohibited by
the DBTR specification before mapping or reading that many entries.

This patch intentionally does not alter sbi_dbtr_read_trig().  Its equality
predicate follows the current DBTR error table even though the surrounding
half-open-range prose is inconsistent; that specification issue is a
separate decision.

Fixes: 97f234f15c96 ("lib: sbi: Introduce the SBI debug triggers extension support")

Signed-off-by: Pengpeng Hou <pengpeng at iscas.ac.cn>
---
Base-commit: 4e79fd7de59f1b2899092c1a84ce68c8ebc68f93

 lib/sbi/sbi_dbtr.c | 14 +++++++++++---
 1 file changed, 11 insertions(+), 3 deletions(-)

diff --git a/lib/sbi/sbi_dbtr.c b/lib/sbi/sbi_dbtr.c
index 0104796..41d5e6f 100644
--- a/lib/sbi/sbi_dbtr.c
+++ b/lib/sbi/sbi_dbtr.c
@@ -263,6 +263,7 @@ int sbi_dbtr_setup_shmem(const struct sbi_domain *dom, unsigned long smode,
 			 unsigned long shmem_phys_lo,
 			 unsigned long shmem_phys_hi)
 {
+	unsigned long shmem_addr, shmem_size;
 	struct sbi_dbtr_hart_triggers_state *hart_state;
 
 	if (dom && !sbi_domain_is_assigned_hart(dom, current_hartindex())) {
@@ -304,9 +305,13 @@ int sbi_dbtr_setup_shmem(const struct sbi_domain *dom, unsigned long smode,
 	if (shmem_phys_hi)
 		return SBI_EINVALID_ADDR;
 
-	if (dom && !sbi_domain_check_addr(dom,
-		  DBTR_SHMEM_MAKE_PHYS(shmem_phys_hi, shmem_phys_lo), smode,
-		  SBI_DOMAIN_READ | SBI_DOMAIN_WRITE))
+	shmem_addr = DBTR_SHMEM_MAKE_PHYS(shmem_phys_hi, shmem_phys_lo);
+	shmem_size = hart_state->total_trigs *
+		     sizeof(union sbi_dbtr_shmem_entry);
+	if (dom && !sbi_domain_check_addr_range(dom, shmem_addr, shmem_size,
+						smode,
+						SBI_DOMAIN_READ |
+						SBI_DOMAIN_WRITE))
 		return SBI_ERR_INVALID_ADDRESS;
 
 	hart_state->shmem.phys_lo = shmem_phys_lo;
@@ -619,6 +624,9 @@ int sbi_dbtr_install_trig(unsigned long smode,
 	if (sbi_dbtr_shmem_disabled(hs))
 		return SBI_ERR_NO_SHMEM;
 
+	if (trig_count >= hs->total_trigs)
+		return SBI_ERR_BAD_RANGE;
+
 	shmem_base = hart_shmem_base(hs);
 	sbi_hart_protection_map_range((unsigned long)shmem_base,
 				      trig_count * sizeof(*entry));
-- 
2.50.1 (Apple Git-155)




More information about the opensbi mailing list