remoteproc: Validate virtqueue alignment

The remote resource table controls the vring alignment, which is used
for pointer rounding without validation. vring_init() rounds the used
ring address with a ~(align - 1) mask, so a zero alignment leaves a
NULL used ring that is dereferenced later.

Reject a zero alignment before calculating the vring size and before
storing the vring metadata taken from the resource table.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
This commit is contained in:
Ben Levinsky
2026-09-22 18:50:37 +02:00
committed by Arnaud Pouliquen
parent d0e5e0d376
commit 4d412df37f
3 changed files with 8 additions and 2 deletions
+1 -1
View File
@@ -94,7 +94,7 @@ void rproc_virtio_remove_vdev(struct virtio_device *vdev);
* @param va vring virtual address
* @param io Pointer to vring I/O region
* @param num_descs Number of descriptors
* @param align vring alignment
* @param align vring alignment, must be nonzero
*
* @return 0 for success, negative value for failure.
*/
+3
View File
@@ -1017,6 +1017,9 @@ remoteproc_create_virtio(struct remoteproc *rproc,
da = vring_rsc->da;
num_descs = vring_rsc->num;
align = vring_rsc->align;
/* A zero alignment makes vring_init() compute a NULL used ring. */
if (!align)
goto err1;
size = vring_size(num_descs, align);
va = remoteproc_mmap(rproc, NULL, &da, size, 0, &io);
if (!va)
+4 -1
View File
@@ -361,8 +361,11 @@ int rproc_virtio_init_vring(struct virtio_device *vdev, unsigned int index,
struct virtio_vring_info *vring_info;
unsigned int num_vrings;
if (!vdev)
return -RPROC_EINVAL;
num_vrings = vdev->vrings_num;
if ((index >= num_vrings) || (num_descs > RPROC_MAX_VRING_DESC))
/* Recheck the resource values before storing the vring metadata. */
if (index >= num_vrings || num_descs > RPROC_MAX_VRING_DESC || !align)
return -RPROC_EINVAL;
vring_info = &vdev->vrings_info[index];
vring_info->io = io;