Re: [PATCH] mailbox: bcm74110: Cap rx_svc_init_list growth to prevent PMC-induced OOM
From: Justin Chen
Date: Tue Sep 29 2026 - 13:53:05 EST
On 8/25/26 12:16 PM, Danesh Petigara wrote:
From: Florian Fainelli <florian.fainelli@xxxxxxxxxxxx>
bcm74110_rx_push_init_msg() allocates a GFP_ATOMIC struct for every
BCM_MSG_SVC_INIT word received from the PMC co-processor and appends it
to rx_svc_init_list with no cap on list length. The only consumers of
this list (bcm74110_rx_pop_init_msg_block / bcm74110_rx_flush_msg) are
called only during probe and at shutdown respectively; after probe
completes, PMC firmware can continuously inject BCM_MSG_SVC_INIT words,
exhausting GFP_ATOMIC reserves and causing a whole-device denial of
service.
Add BCM74110_INIT_MSG_MAX (16 entries) as the maximum list depth.
bcm74110_rx_push_init_msg() now checks the count under the existing
rx_svc_list_lock before allocating; if the cap is reached the message is
dropped and a rate-limited warning is emitted. The new rx_svc_init_count
field is decremented by bcm74110_rx_pop_init_msg() on successful dequeue
and reset to zero by bcm74110_rx_flush_msg() on shutdown.
Fixes: 52436007b862 ("mailbox: Add support for bcm74110")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Florian Fainelli <florian.fainelli@xxxxxxxxxxxx>
Assisted-by: Anthropic:claude-sonnet-4.6 cursor
Signed-off-by: Danesh Petigara <danesh.petigara@xxxxxxxxxxxx>
Signed-off-by: Justin Chen <justin.chen@xxxxxxxxxxxx>
Gentle ping on this patch.
Thanks,
Justin