drm/amd/ras: bound CPER record fetch buffer size
authorCandice Li <candice.li@amd.com>
Wed, 13 May 2026 02:46:01 +0000 (10:46 +0800)
committerAlex Deucher <alexander.deucher@amd.com>
Tue, 19 May 2026 15:51:52 +0000 (11:51 -0400)
Bound CPER record fetch allocation by buffer size.

v2: Drop redundant cap on cper_num and raise
    GET_CPER_RECORD max buffer size.

Suggested-by: YiPeng Chai <YiPeng.Chai@amd.com>
Signed-off-by: Candice Li <candice.li@amd.com>
Reviewed-by: Tao Zhou <tao.zhou1@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
drivers/gpu/drm/amd/ras/ras_mgr/amdgpu_virt_ras_cmd.c
drivers/gpu/drm/amd/ras/rascore/ras_cmd.c
drivers/gpu/drm/amd/ras/rascore/ras_cmd.h

index 4021259..daad99a 100644 (file)
@@ -264,7 +264,8 @@ static int amdgpu_virt_ras_get_cper_records(struct ras_core_context *ras_core,
        if (cmd->input_size != sizeof(struct ras_cmd_cper_record_req))
                return RAS_CMD__ERROR_INVALID_INPUT_SIZE;
 
-       if (!req->buf_size || !req->buf_ptr || !req->cper_num)
+       if (!req->buf_size || !req->buf_ptr || !req->cper_num ||
+           req->buf_size > RAS_CMD_MAX_CPER_BUF_SZ)
                return RAS_CMD__ERROR_INVALID_INPUT_DATA;
 
        trace = kzalloc_objs(*trace, MAX_RECORD_PER_BATCH);
index 4f89810..8303aec 100644 (file)
@@ -214,7 +214,8 @@ static int ras_cmd_get_cper_records(struct ras_core_context *ras_core,
        if (cmd->input_size != sizeof(struct ras_cmd_cper_record_req))
                return RAS_CMD__ERROR_INVALID_INPUT_SIZE;
 
-       if (!req->buf_size || !req->buf_ptr || !req->cper_num)
+       if (!req->buf_size || !req->buf_ptr || !req->cper_num ||
+           req->buf_size > RAS_CMD_MAX_CPER_BUF_SZ)
                return RAS_CMD__ERROR_INVALID_INPUT_DATA;
 
        buffer = kzalloc(req->buf_size, GFP_KERNEL);
index 7ea35a0..a1d4b8b 100644 (file)
@@ -405,6 +405,9 @@ struct batch_ras_trace_info {
 
 #define RAS_CMD_MAX_BATCH_NUM  300
 #define RAS_CMD_MAX_TRACE_NUM  300
+
+/* Upper bounds for RAS_CMD__GET_CPER_RECORD to limit kernel allocations and work. */
+#define RAS_CMD_MAX_CPER_BUF_SZ        (2 * 1024U * 1024U) /* 2 MiB */
 struct ras_cmd_batch_trace_record_rsp {
        uint32_t version;
        uint16_t real_batch_num;