Add validation to reject register offsets exceeding U32_MAX in the
amdgpu_regs_pcie debugfs read and write functions. PCIE register
addresses are 32-bit values, and allowing larger offsets could lead
to undefined behavior when passed to the underlying register access
functions.

Return -EINVAL when the offset is out of range rather than attempting
to access an invalid register address.

Signed-off-by: Mario Limonciello <[email protected]>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c 
b/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
index deab64765388c..756cd58bc8484 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
@@ -522,6 +522,9 @@ static ssize_t amdgpu_debugfs_regs_pcie_read(struct file 
*f, char __user *buf,
        if (size & 0x3 || *pos & 0x3)
                return -EINVAL;
 
+       if (*pos > U32_MAX)
+               return -EINVAL;
+
        r = pm_runtime_get_sync(adev_to_drm(adev)->dev);
        if (r < 0) {
                pm_runtime_put_autosuspend(adev_to_drm(adev)->dev);
@@ -581,6 +584,9 @@ static ssize_t amdgpu_debugfs_regs_pcie_write(struct file 
*f, const char __user
        if (size & 0x3 || *pos & 0x3)
                return -EINVAL;
 
+       if (*pos > U32_MAX)
+               return -EINVAL;
+
        r = pm_runtime_get_sync(adev_to_drm(adev)->dev);
        if (r < 0) {
                pm_runtime_put_autosuspend(adev_to_drm(adev)->dev);
-- 
2.43.0

Reply via email to