[PATCH v2 0/3] accel/rocket: Validate task regcmd fields

From: Sidong Yang

Date: Sun Oct 04 2026 - 12:48:00 EST


Patch 3 rejects misaligned regcmd addresses and out-of-range regcmd
counts at submission. It is unchanged from v1.

Patches 1 and 2 fix two pre-existing issues from Sashiko's review of
v1. Of its other findings, the ignored submit error [1], the
iommu_group leak [2] and the unchecked allocation in rocket_job_open()
[3] are handled by patches already on the list. Until [1] lands, a job
that patch 3 rejects is dropped, but the ioctl still returns 0. The
__u32 regcmd cannot truncate an IOVA, as the rockchip IOMMU aperture is
32-bit.

Tested on RK3588 (ROCK 5B+): Teflon MobileNet v1 output and latency are
unchanged, the bad regcmd values are rejected, and an injected
drm_sched_init() failure fails probe cleanly.

Changes in v2:
- Add patches 1 and 2.
- Rebase onto drm-misc-next.

v1: https://lore.kernel.org/r/20260711062137.36044-1-sidong.yang@xxxxxxxxxx/

[1] https://lore.kernel.org/r/20260828064152.37822-4-Naixumogu@xxxxxxxxxxx/
[2] https://lore.kernel.org/r/20260610071045.3414828-2-zhaojinming@xxxxxxxxxxxxx/
[3] https://lore.kernel.org/r/20260818041505.1579320-1-triet.hoang.dev@xxxxxxxxx/

Sidong Yang (3):
accel/rocket: Don't tear down the scheduler when drm_sched_init()
fails
accel/rocket: Use an unsigned index to copy the job's tasks
accel/rocket: Validate task regcmd address and count on submission

drivers/accel/rocket/rocket_job.c | 28 +++++++++++++++++++++++++---
1 file changed, 25 insertions(+), 3 deletions(-)


base-commit: 70456f05d4b6396b22048c4b8cd3cb98ecf9f9e3
--
2.53.0