[PATCH] lib: sbi: dbtr: validate complete shared memory range
Himanshu Chauhan
himanshu.chauhan at oss.qualcomm.com
Wed Sep 2 20:36:40 PDT 2026
On Thu, Aug 27, 2026 at 5:28 PM Pengpeng Hou <pengpeng at iscas.ac.cn> wrote:
>
> The DBTR shared memory contains total_trigs entries, but setup currently
> checks domain access for only its first byte. A supervisor can place that
> base near a domain boundary so later entries extend into inaccessible or
> M-mode-only memory.
>
> Validate the complete specification-defined shared-memory extent with
> sbi_domain_check_addr_range(). Also reject an install count prohibited by
> the DBTR specification before mapping or reading that many entries.
>
> This patch intentionally does not alter sbi_dbtr_read_trig(). Its equality
> predicate follows the current DBTR error table even though the surrounding
> half-open-range prose is inconsistent; that specification issue is a
> separate decision.
>
> Fixes: 97f234f15c96 ("lib: sbi: Introduce the SBI debug triggers extension support")
>
> Signed-off-by: Pengpeng Hou <pengpeng at iscas.ac.cn>
> ---
> Base-commit: 4e79fd7de59f1b2899092c1a84ce68c8ebc68f93
>
> lib/sbi/sbi_dbtr.c | 14 +++++++++++---
> 1 file changed, 11 insertions(+), 3 deletions(-)
>
> diff --git a/lib/sbi/sbi_dbtr.c b/lib/sbi/sbi_dbtr.c
> index 0104796..41d5e6f 100644
> --- a/lib/sbi/sbi_dbtr.c
> +++ b/lib/sbi/sbi_dbtr.c
> @@ -263,6 +263,7 @@ int sbi_dbtr_setup_shmem(const struct sbi_domain *dom, unsigned long smode,
> unsigned long shmem_phys_lo,
> unsigned long shmem_phys_hi)
> {
> + unsigned long shmem_addr, shmem_size;
> struct sbi_dbtr_hart_triggers_state *hart_state;
>
> if (dom && !sbi_domain_is_assigned_hart(dom, current_hartindex())) {
> @@ -304,9 +305,13 @@ int sbi_dbtr_setup_shmem(const struct sbi_domain *dom, unsigned long smode,
> if (shmem_phys_hi)
> return SBI_EINVALID_ADDR;
>
> - if (dom && !sbi_domain_check_addr(dom,
> - DBTR_SHMEM_MAKE_PHYS(shmem_phys_hi, shmem_phys_lo), smode,
> - SBI_DOMAIN_READ | SBI_DOMAIN_WRITE))
> + shmem_addr = DBTR_SHMEM_MAKE_PHYS(shmem_phys_hi, shmem_phys_lo);
> + shmem_size = hart_state->total_trigs *
> + sizeof(union sbi_dbtr_shmem_entry);
> + if (dom && !sbi_domain_check_addr_range(dom, shmem_addr, shmem_size,
> + smode,
> + SBI_DOMAIN_READ |
> + SBI_DOMAIN_WRITE))
> return SBI_ERR_INVALID_ADDRESS;
>
> hart_state->shmem.phys_lo = shmem_phys_lo;
> @@ -619,6 +624,9 @@ int sbi_dbtr_install_trig(unsigned long smode,
> if (sbi_dbtr_shmem_disabled(hs))
> return SBI_ERR_NO_SHMEM;
>
> + if (trig_count >= hs->total_trigs)
> + return SBI_ERR_BAD_RANGE;
> +
Looks good to me.
Reviewed-by: Himanshu Chauhan <himanshu.chauhan at oss.qualcomm.com>
Himanshu
> shmem_base = hart_shmem_base(hs);
> sbi_hart_protection_map_range((unsigned long)shmem_base,
> trig_count * sizeof(*entry));
> --
> 2.50.1 (Apple Git-155)
>
More information about the opensbi
mailing list