[PATCH 07/18] dbtr: Check for invalid and unsupported triggers in update

liutong liutong at iscas.ac.cn
Mon Sep 21 02:20:17 PDT 2026


Hi Nick,

I hit this independently while auditing DBTR, six months after you -
sorry for not finding your series sooner.

It's still open on current master (5a175017). sbi_dbtr_update_trig()
never calls dbtr_trigger_valid(), so S-mode can install a trigger that
passes install's check and then set mcontrol6.M on it via
TRIGGER_UPDATE. QEMU, single hart, no race:

  install benign (M=0)  : err=0, CSR_TDATA1 = 0x6000000000000014
  update to M=1         : err=0, CSR_TDATA1 = 0x6000000000000054

Pointed at an address OpenSBI executes, the next ecall takes an M-mode
breakpoint, which can't be redirected, and ends in sbi_hart_hang().

Are you planning to resend, either the series or 07/18 alone?

Also, your 01/18 and 18/18 are being re-done piecemeal without the
correction between them. Pengpeng Hou's "validate complete shared
memory range" adds the same install_trig check as your 01/18 -
trig_count >= hs->total_trigs, SBI_ERR_BAD_RANGE - and has a
Reviewed-by; my own v3 1/3 copied that form to avoid conflicting with
it. Neither carries your 18/18 fix, and the effect is measurable: with
total_trigs = 2, install(2) is rejected, so only total_trigs - 1 can be
installed per call. Any news on riscv-sbi-doc#257?

Regards,
liutong




More information about the opensbi mailing list