kgsl: gmu: Use num_vma for safe GMU VMAs array access

Use num_vma to bound GMU VMAs array access instead of GMU_MEM_TYPE_MAX,
preventing out-of-bounds reads when the array size is less than the
enum maximum.

Change-Id: Iffb587e5eb3fa70356872eb0f56d065d1b58f27c
Signed-off-by: Shiv Kumar <shikum@qti.qualcomm.com>
Signed-off-by: Sushmita Gollena <sgollena@qti.qualcomm.com>
Signed-off-by: Nagababu Pamarthi <npamarth@qti.qualcomm.com>
This commit is contained in:
Shiv Kumar 2025-09-10 21:55:15 +05:30 • committed by Kishor Buchi
commit 491b8e69be
2 changed files with 8 additions and 3 deletions

View file

@ -593,7 +593,7 @@ static int find_vma_block(struct a6xx_gmu_device *gmu, u32 addr, u32 size)
{
int i;
for (i = 0; i < GMU_MEM_TYPE_MAX; i++) {
for (i = 0; i < gmu->num_vmas; i++) {
struct gmu_vma_entry *vma = &gmu->vma[i];
if ((addr >= vma->start) &&
@ -2685,10 +2685,13 @@ int a6xx_gmu_probe(struct kgsl_device *device,
if (ret)
goto error;
if (adreno_is_a650_family(adreno_dev))
if (adreno_is_a650_family(adreno_dev)) {
gmu->vma = a6xx_gmu_vma;
else
gmu->num_vmas = ARRAY_SIZE(a6xx_gmu_vma);
} else {
gmu->vma = a6xx_gmu_vma_legacy;
gmu->num_vmas = ARRAY_SIZE(a6xx_gmu_vma_legacy);
}
/* Map and reserve GMU CSRs registers */
ret = a6xx_gmu_reg_probe(adreno_dev);

View file

@ -187,6 +187,8 @@ struct a6xx_gmu_device {
/** @global_entries: To keep track of number of gmu buffers */
u32 global_entries;
struct gmu_vma_entry *vma;
/** @num_vmas: Number of entries in the @vma array */
u32 num_vmas;
unsigned int log_wptr_retention;
/** @cm3_fault: whether gmu received a cm3 fault interrupt */
atomic_t cm3_fault;