On Thu, Aug 27, 2026 at 03:33:07PM -0500, Rob Herring (Arm) wrote:
> The command-stream validator records the additional U65 scale and
> weight stream addresses and the U85 weight decoder addresses, but only
> checked stream 0 against its region buffer.
>
> Check every configured secondary stream against the matching weight or
> scale region before accepting a kernel operation.
>
> Fixes: 5a5e9c0228e6 ("accel: Add Arm Ethos-U NPU driver")
> Cc: [email protected]
> Assisted-by: LLM
> Signed-off-by: Rob Herring (Arm) <[email protected]>
> ---
>  drivers/accel/ethosu/ethosu_gem.c | 15 +++++++++++++++
>  1 file changed, 15 insertions(+)
>
> diff --git a/drivers/accel/ethosu/ethosu_gem.c 
> b/drivers/accel/ethosu/ethosu_gem.c
> index 9fce7caeeb9a..3d1f4121db4f 100644
> --- a/drivers/accel/ethosu/ethosu_gem.c
> +++ b/drivers/accel/ethosu/ethosu_gem.c
> @@ -321,6 +321,15 @@ static int calc_sizes(struct drm_device *ddev,
>                       st->weight[0].base + st->weight[0].length - 1);
>               if (buffer_size(info, &st->weight[0], st->weight[0].region))
>                       return -EINVAL;
> +
> +             for (int i = 1; i < ARRAY_SIZE(st->weight); i++) {

why not also put 0 into this loop?

> +                     if (st->weight[i].base == U64_MAX &&
> +                         st->weight[i].length == U32_MAX)
> +                             continue;
> +
> +                     if (buffer_size(info, &st->weight[i], 
> st->weight[0].region))

Just make sure 0 of st->weight[0].region is not typo, all weight share
one region?

Frank

> +                             return -EINVAL;
> +             }
>       }
>
>       if (scale) {
> @@ -329,6 +338,12 @@ static int calc_sizes(struct drm_device *ddev,
>                       st->scale[0].base + st->scale[0].length - 1);
>               if (buffer_size(info, &st->scale[0], st->scale[0].region))
>                       return -EINVAL;
> +
> +             if (ethosu_is_u65(edev) &&
> +                 (st->scale[1].base != U64_MAX ||
> +                  st->scale[1].length != U32_MAX) &&
> +                 buffer_size(info, &st->scale[1], st->scale[0].region))
> +                     return -EINVAL;
>       }
>
>       len = feat_matrix_length(edev, info, &st->ofm, st->ofm.width,
>
> --
> 2.53.0
>

Reply via email to