[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v2 1/3] xen/arm: validate IRQs before descriptor lookup


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Mykola Kvach <mykola_kvach@xxxxxxxx>
  • Date: Mon, 10 Aug 2026 21:38:45 +0300
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=kVyUwzxHfI4tTSVlImEGxF+daEm0IvBED5qt0xYcoeM=; b=a1lvWneZW2ld6z2L4txc4Av537scTG3wBQ0HEn3pWvxgd21Dts0/lp4zJ17yWCjMwMWiWYTvJsVQuQNIL8A3dFtVFsOKXYsoSaJ3g03qv+/IabUMIWdE3+lKzizXSB4QT4jQBfaFNtrxrD+LAWIpzmy1Erdke0TYXInfTNFD68eAQj/Ey9XLeCvZeA6MffSexNZiKpPNd/io8YyLzjq6+DQ8rU4Yvof8dfXRSd90LaWwhP/wqAK7pOZYI/SWWyQHpHVz9Y7RjdqCskhXzPB4yEo/kFjeNLVtrAy5R4nmu6uYQJpG3t6A6H5wJ/dfPto7yuoSEouQtRanPawcc0qUtA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=MkuD/4uC1xz1LgDqjFjLm9BB+pFe8iDtLQSjSZXM2QWKDdVM1RdmJMsOBx8vOx8W4GfD5iMXOAer1k9NOoqEErYMO54CcCiWJMG8AyfLOvLBIAVIwLg8U3/2NutkHV/lGh0jTDw0Uy61O2GOKa/WDoD3YuhHRcoEB9jAhyMdOq/ivqxlty33oAfCvMkd1NUzUzaEPSEsToSib+olYEYCDN4WQ/G63BAVmj2CSIhUlKJimw2Q40du4oL8dn4jmGrZU8WCsz9vlnNpCiRsPzT2wCVhoHo++Nn742Q28A5kkeKxqqUAsuvR6iHXVKUvFsA3z32VRIhELKQQF2j2SiFUQA==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>, Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>
  • Delivery-date: Mon, 10 Aug 2026 18:39:15 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

GICv3 eSPI support makes nr_irqs span the architectural INTID namespace
through ESPI_MAX_INTID, but descriptor storage is sparse. local_irq_desc[]
and irq_desc[] cover INTIDs below NR_IRQS, while espi_desc[] covers eSPIs.
INTIDs 1024 through 4095 have no backing descriptors.

Validation based only on nr_irqs accepts an INTID in this gap.
__irq_to_desc() then indexes beyond irq_desc[], and callers may lock or
update unrelated Xen memory.

Reject INTIDs that the GIC reports as unimplemented in setup_irq() before
looking up a descriptor. irq_set_spi_type() can run before the implemented
GIC line counts are available, so validate descriptor-backed ranges there
before looking up a descriptor.

Call is_espi() unconditionally in __irq_to_desc() and provide an
espi_to_desc() stub when eSPI support is disabled. This preserves the
is_espi() debug check for eSPI-range INTIDs when support is disabled.

Fixes: 98f7060b9ed5 ("xen/arm/irq: add handling for IRQs in the eSPI range")
Signed-off-by: Mykola Kvach <mykola_kvach@xxxxxxxx>
---
Changes in v2:
- Validate descriptor-backed ranges in irq_set_spi_type().
- Validate implemented GIC lines in setup_irq().
- Preserve is_espi() validation with CONFIG_GICV3_ESPI disabled.
---
 xen/arch/arm/irq.c | 29 ++++++++++++++++++++++++-----
 1 file changed, 24 insertions(+), 5 deletions(-)

diff --git a/xen/arch/arm/irq.c b/xen/arch/arm/irq.c
index 73e58a5108..0f5d3496bf 100644
--- a/xen/arch/arm/irq.c
+++ b/xen/arch/arm/irq.c
@@ -23,6 +23,12 @@ const unsigned int nr_irqs = IS_ENABLED(CONFIG_GICV3_ESPI) ?
                                         (ESPI_MAX_INTID + 1) :
                                         NR_IRQS;
 
+static bool irq_has_desc(unsigned int irq)
+{
+    return irq < NR_IRQS ||
+           (IS_ENABLED(CONFIG_GICV3_ESPI) && is_espi(irq));
+}
+
 static unsigned int local_irqs_type[NR_LOCAL_IRQS];
 static DEFINE_SPINLOCK(local_irqs_type_lock);
 
@@ -77,6 +83,12 @@ static int __init init_espi_data(void)
 }
 #else
 
+static struct irq_desc *espi_to_desc(unsigned int irq)
+{
+    ASSERT_UNREACHABLE();
+    return NULL;
+}
+
 static int __init init_espi_data(void)
 {
     return 0;
@@ -90,10 +102,8 @@ struct irq_desc *__irq_to_desc(unsigned int irq)
     if ( irq < NR_LOCAL_IRQS )
         return &this_cpu(local_irq_desc)[irq];
 
-#ifdef CONFIG_GICV3_ESPI
     if ( is_espi(irq) )
         return espi_to_desc(irq);
-#endif
 
     return &irq_desc[irq-NR_LOCAL_IRQS];
 }
@@ -416,6 +426,9 @@ int setup_irq(unsigned int irq, unsigned int irqflags, 
struct irqaction *new)
     struct irq_desc *desc;
     bool disabled;
 
+    if ( !gic_is_valid_line(irq) )
+        return -EINVAL;
+
     desc = irq_to_desc(irq);
 
     spin_lock_irqsave(&desc->lock, flags);
@@ -647,13 +660,19 @@ static bool irq_validate_new_type(unsigned int curr, 
unsigned int new)
 int irq_set_spi_type(unsigned int spi, unsigned int type)
 {
     unsigned long flags;
-    struct irq_desc *desc = irq_to_desc(spi);
+    struct irq_desc *desc;
     int ret = -EBUSY;
 
-    /* This function should not be used for other than SPIs */
-    if ( spi < NR_LOCAL_IRQS )
+    /*
+     * The implemented GIC line counts are not available when early
+     * callers configure IRQ types. Check descriptor storage here; setup_irq()
+     * validates the implemented line before the interrupt is used.
+     */
+    if ( spi < NR_LOCAL_IRQS || !irq_has_desc(spi) )
         return -EINVAL;
 
+    desc = irq_to_desc(spi);
+
     spin_lock_irqsave(&desc->lock, flags);
 
     if ( !irq_validate_new_type(desc->arch.type, type) )
-- 
2.43.0




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.