[PATCH] lib: sbi: dbtr: validate complete shared memory range

liutong liutong at iscas.ac.cn
Thu Sep 10 18:59:19 PDT 2026


Hi Pengpeng,

On Thu, Aug 27, 2026 at 07:58:33PM +0800, Pengpeng Hou wrote:
> -	if (dom && !sbi_domain_check_addr(dom,
> -		  DBTR_SHMEM_MAKE_PHYS(shmem_phys_hi, shmem_phys_lo), smode,
> -		  SBI_DOMAIN_READ | SBI_DOMAIN_WRITE))
> +	shmem_addr = DBTR_SHMEM_MAKE_PHYS(shmem_phys_hi, shmem_phys_lo);
> +	shmem_size = hart_state->total_trigs *
> +		     sizeof(union sbi_dbtr_shmem_entry);
> +	if (dom && !sbi_domain_check_addr_range(dom, shmem_addr, shmem_size,
> +					        smode,
> +					        SBI_DOMAIN_READ |
> +					        SBI_DOMAIN_WRITE))
>  		return SBI_ERR_INVALID_ADDRESS;

The range extension looks correct. One thing worth noting: Himanshu
pointed out on my v2 3/6, which fixed the same single-address check,
that the "dom &&" guard skips the validation entirely when dom is
NULL [1]. The same applies here — with dom == NULL the new range
check is never reached, so the shared memory address goes
unvalidated.

sbi_hartindex_to_domain() can return NULL when domain_hart_ptr_offset
has not been set or when the scratch area is unavailable. Whether that
is reachable after init completes may depend on platform configuration,
but since this patch is tightening the address validation it seems
worth closing that gap in the same change.

One option would be to return an error when dom is NULL rather than
silently skipping:

	if (!dom || !sbi_domain_check_addr_range(dom, shmem_addr,
						 shmem_size, smode,
						 SBI_DOMAIN_READ |
						 SBI_DOMAIN_WRITE))
		return SBI_ERR_INVALID_ADDRESS;

The same "dom &&" pattern exists in the is_assigned_hart check a few
lines above, so both may need updating together.

[1] https://lore.kernel.org/opensbi/apk3ZCJv9cupAzTL@hu-himchau-blr.qualcomm.com/

Regards,
liutong




More information about the opensbi mailing list