Skip to content

DBTR: avoid unsigned range-check wraparound in sbi_dbtr_read_trig() #427

Description

@GraceDyer

Problem

sbi_dbtr_read_trig() currently validates the requested trigger range with:

if (trig_idx_base >= hs->total_trigs ||
    trig_idx_base + trig_count >= hs->total_trigs)
        return SBI_ERR_INVALID_PARAM;

Both trig_idx_base and trig_count are unsigned values. Their addition can wrap before the comparison, allowing an out-of-range request to pass the guard.

The function then uses trig_count for shared-memory mapping and entry iteration.

Observed result

In a local RV64 QEMU virt test with DBTR enabled, the normal control case returned successfully. An overflow-inducing boundary case passed the range check and subsequently caused an M-mode store access fault while writing DBTR shared memory.

Expected result

A request whose range exceeds hs->total_trigs, or whose endpoint cannot be represented, should be rejected before shared-memory mapping or iteration.

Suggested fix

Avoid forming the unchecked sum. After validating trig_idx_base, compare trig_count against hs->total_trigs - trig_idx_base, or use an equivalent checked-add helper.

The endpoint comparison should also be kept consistent with the intended DBTR specification semantics.

Scope

I have validated the firmware fault behavior on QEMU. I am not claiming a broader impact beyond this memory-safety and availability issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions