| Message ID | 20260312011931.1352239-1-xujiakai2025@iscas.ac.cn |
|---|---|
| Headers | show
Return-Path:
<kvm-riscv-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org>
X-Original-To: incoming@patchwork.ozlabs.org
Delivered-To: patchwork-incoming@legolas.ozlabs.org
Authentication-Results: legolas.ozlabs.org;
dkim=pass (2048-bit key;
secure) header.d=lists.infradead.org header.i=@lists.infradead.org
header.a=rsa-sha256 header.s=bombadil.20210309 header.b=OkXQWzO3;
dkim-atps=neutral
Authentication-Results: legolas.ozlabs.org;
spf=none (no SPF record) smtp.mailfrom=lists.infradead.org
(client-ip=2607:7c80:54:3::133; helo=bombadil.infradead.org;
envelope-from=kvm-riscv-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org;
receiver=patchwork.ozlabs.org)
Received: from bombadil.infradead.org (bombadil.infradead.org
[IPv6:2607:7c80:54:3::133])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)
(No client certificate requested)
by legolas.ozlabs.org (Postfix) with ESMTPS id 4fWVCf18xsz1y02
for <incoming@patchwork.ozlabs.org>; Thu, 12 Mar 2026 12:19:58 +1100 (AEDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.infradead.org; s=bombadil.20210309; h=Sender:
Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post:
List-Archive:List-Unsubscribe:List-Id:MIME-Version:Message-Id:Date:Subject:Cc
:To:From:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:
List-Owner; bh=sruszXuiraT6dEVCmTr7HnDesa8YZECIrW4jCgQJCdg=; b=OkXQWzO3GIybVN
j4aWvQZ0TMYRmQkNlMT2L65vI2lVF+OwF1uGiJYyEMt+VzY/6HVkm+SdxgOfLsEDHG5PybZbhndYB
Wd3QzbuxpQx28BiWyuLN3TpG383eqLZjo+qSWQxRm4MUfibYQnQO9Xqmpnbq6dhBLkGwYic4BpQ5n
jVNrnfdPga2lejecpUsLZA6pIp/2v3T5ripbukhxAd8lVLcW1AGn0e3SB5drYqsdekwauCc+V90xh
u0S79+YKEkKWr0NPzmdkwwd3MWdBYtYntAqSSdwomH7jvBp2E6ka6wIy6NOZDhMoe4Ep/8e6Xhr8H
vTZkyn6aQNYlfKEXBBxA==;
Received: from localhost ([::1] helo=bombadil.infradead.org)
by bombadil.infradead.org with esmtp (Exim 4.98.2 #2 (Red Hat Linux))
id 1w0UiS-0000000CzIp-4AQu;
Thu, 12 Mar 2026 01:19:56 +0000
Received: from smtp25.cstnet.cn ([159.226.251.25] helo=cstnet.cn)
by bombadil.infradead.org with esmtps (Exim 4.98.2 #2 (Red Hat Linux))
id 1w0UiN-0000000CzH6-2h1Q;
Thu, 12 Mar 2026 01:19:54 +0000
Received: from fric.. (unknown [210.73.43.101])
by APP-05 (Coremail) with SMTP id zQCowAAntwqkFLJpB6U4Cg--.65391S2;
Thu, 12 Mar 2026 09:19:33 +0800 (CST)
From: Jiakai Xu <xujiakai2025@iscas.ac.cn>
To: kvm-riscv@lists.infradead.org,
kvm@vger.kernel.org,
linux-kernel@vger.kernel.org,
linux-kselftest@vger.kernel.org,
linux-riscv@lists.infradead.org
Cc: Albert Ou <aou@eecs.berkeley.edu>,
Alexandre Ghiti <alex@ghiti.fr>,
Andrew Jones <ajones@ventanamicro.com>,
Anup Patel <anup@brainfault.org>,
Atish Patra <atish.patra@linux.dev>,
Palmer Dabbelt <palmer@dabbelt.com>,
Paolo Bonzini <pbonzini@redhat.com>,
Paul Walmsley <pjw@kernel.org>,
Shuah Khan <shuah@kernel.org>,
Jiakai Xu <xujiakai2025@iscas.ac.cn>
Subject: [PATCH v4 0/2] RISC-V: KVM: Fix array out-of-bounds in firmware
counter reads
Date: Thu, 12 Mar 2026 01:19:29 +0000
Message-Id: <20260312011931.1352239-1-xujiakai2025@iscas.ac.cn>
X-Mailer: git-send-email 2.34.1
MIME-Version: 1.0
X-CM-TRANSID: zQCowAAntwqkFLJpB6U4Cg--.65391S2
X-Coremail-Antispam: 1UD129KBjvJXoW7CF4fXw45Cry8Ar47tF4DXFb_yoW8Xr1fpF
W3Ka4YkrykJrs7t343A3yktw15Xrs5Ca98GryxGF18Cr45ZryfXr1qkwnxt3WrCrsYqw1Y
ya1Igas7CFy5Za7anT9S1TB71UUUUjDqnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2
9KBjDU0xBIdaVrnRJUUUQ014x267AKxVW8JVW5JwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0
rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2AK02
1l84ACjcxK6xIIjxv20xvE14v26F1j6w1UM28EF7xvwVC0I7IYx2IY6xkF7I0E14v26F4j
6r4UJwA2z4x0Y4vEx4A2jsIE14v26r4UJVWxJr1l84ACjcxK6I8E87Iv6xkF7I0E14v26F
4UJVW0owAaw2AFwI0_JF0_Jw1lnxkEFVAIw20F6cxK64vIFxWle2I262IYc4CY6c8Ij28I
cVAaY2xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2WlYx0E2Ix0cI8IcVAFwI0_JF0_Jw1lYx
0Ex4A2jsIE14v26r1j6r4UMcvjeVCFs4IE7xkEbVWUJVW8JwACjcxG0xvY0x0EwIxGrwAC
jI8F5VA0II8E6IAqYI8I648v4I1lFIxGxcIEc7CjxVA2Y2ka0xkIwI1lc7CjxVAaw2AFwI
0_GFv_Wrylc2xSY4AK67AK6w4l42xK82IYc2Ij64vIr41l4I8I3I0E4IkC6x0Yz7v_Jr0_
Gr1l4IxYO2xFxVAFwI0_JF0_Jw1lx2IqxVAqx4xG67AKxVWUJVWUGwC20s026x8GjcxK67
AKxVWUGVWUWwC2zVAF1VAY17CE14v26r1q6r43MIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8I
cVAFwI0_Gr0_Xr1lIxAIcVC0I7IYx2IY6xkF7I0E14v26r4j6F4UMIIF0xvE42xK8VAvwI
8IcIk0rVWUJVWUCwCI42IY6I8E87Iv67AKxVW8JVWxJwCI42IY6I8E87Iv6xkF7I0E14v2
6r4j6r4UJbIYCTnIWIevJa73UjIFyTuYvjTRNeOpDUUUU
X-Originating-IP: [210.73.43.101]
X-CM-SenderInfo: 50xmxthndljiysv6x2xfdvhtffof0/1tbiCQ4ECWmx5mWOZAACs5
X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3
X-CRM114-CacheID: sfid-20260311_181952_055963_76EE454B
X-CRM114-Status: UNSURE ( 6.76 )
X-CRM114-Notice: Please train this message.
X-Spam-Score: 0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "bombadil.infradead.org",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: When a guest reads a firmware PMU counter via
SBI_EXT_PMU_COUNTER_FW_READ
or SBI_EXT_PMU_COUNTER_FW_READ_HI without first configuring it with
SBI_EXT_PMU_COUNTER_CFG_MATCH,
the counter's event_idx rem [...]
Content analysis details: (0.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no
trust
[159.226.251.25 listed in list.dnswl.org]
0.9 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[159.226.251.25 listed in sa-accredit.habeas.com]
0.8 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[159.226.251.25 listed in
bl.score.senderscore.com]
0.4 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[159.226.251.25 listed in
sa-trusted.bondedsender.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1%
[score: 0.0000]
X-BeenThere: kvm-riscv@lists.infradead.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: <kvm-riscv.lists.infradead.org>
List-Unsubscribe: <http://lists.infradead.org/mailman/options/kvm-riscv>,
<mailto:kvm-riscv-request@lists.infradead.org?subject=unsubscribe>
List-Archive: <http://lists.infradead.org/pipermail/kvm-riscv/>
List-Post: <mailto:kvm-riscv@lists.infradead.org>
List-Help: <mailto:kvm-riscv-request@lists.infradead.org?subject=help>
List-Subscribe: <http://lists.infradead.org/mailman/listinfo/kvm-riscv>,
<mailto:kvm-riscv-request@lists.infradead.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: "kvm-riscv" <kvm-riscv-bounces@lists.infradead.org>
Errors-To: kvm-riscv-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org
|
| Series |
RISC-V: KVM: Fix array out-of-bounds in firmware counter reads
|
expand
|
When a guest reads a firmware PMU counter via SBI_EXT_PMU_COUNTER_FW_READ or SBI_EXT_PMU_COUNTER_FW_READ_HI without first configuring it with SBI_EXT_PMU_COUNTER_CFG_MATCH, the counter's event_idx remains SBI_PMU_EVENT_IDX_INVALID (0xFFFFFFFF). get_event_code() extracts the lower 16 bits from event_idx, yielding 0xFFFF, which is then used to index into kvpmu->fw_event[]. Since the fw_event array only contains RISCV_KVM_MAX_FW_CTRS entries, this results in an out-of-bounds access that can be detected by UBSAN. Patch 1 fixes the issue by validating the firmware event code before accessing the fw_event array and returning -EINVAL for invalid values. After fixing the kernel behavior, the existing KVM selftest (sbi_pmu_test) fails because it attempts to read firmware counters without configuring them first. Patch 2 updates the selftest to configure a firmware event before reading the counter and adds a negative test to ensure that reading an unconfigured firmware counter fails gracefully. Jiakai Xu (2): RISC-V: KVM: Fix array out-of-bounds in pmu_ctr_read() and pmu_fw_ctr_read_hi() RISC-V: KVM: selftests: Fix firmware counter read in sbi_pmu_test arch/riscv/kvm/vcpu_pmu.c | 14 +++++++ .../testing/selftests/kvm/include/riscv/sbi.h | 37 +++++++++++++++++++ .../selftests/kvm/riscv/sbi_pmu_test.c | 20 +++++++++- 3 files changed, 70 insertions(+), 1 deletion(-)