[PATCH v4 01/10] gpu: nova-core: gsp: cmdq: validate checksum earlier on receive
From: Alexandre Courbot
Date: Fri Oct 09 2026 - 08:07:27 EST
The checksum validation error message of `wait_for_msg` prints the
message's sequence number before validating the checksum.
But the checksum is part of the transport layer, and it not validating
indicates a corruption that could very well be in the RPC message
header, meaning the value of this field cannot be trusted.
Furthermore, the transport layer is not supposed to know the kind of
message it transports, and it accessing the RPC header is a layering
violation.
Thus, move the checksum validation before we start looking at the
message header, and drop that information from the error message.
Signed-off-by: Alexandre Courbot <acourbot@xxxxxxxxxx>
Reviewed-by: Eliot Courtney <ecourtney@xxxxxxxxxx>
---
drivers/gpu/nova-core/gsp/cmdq.rs | 24 +++++++++---------------
1 file changed, 9 insertions(+), 15 deletions(-)
diff --git a/drivers/gpu/nova-core/gsp/cmdq.rs b/drivers/gpu/nova-core/gsp/cmdq.rs
index 1b2f346a237f..b1d46d6d4d4a 100644
--- a/drivers/gpu/nova-core/gsp/cmdq.rs
+++ b/drivers/gpu/nova-core/gsp/cmdq.rs
@@ -792,6 +792,15 @@ fn wait_for_msg(&self, timeout: Delta) -> Result<GspMessage<'_>> {
// Extract the `GspMsgElement`.
let (header, slice_1) = GspMsgElement::from_bytes_prefix(slice_1).ok_or(EIO)?;
+ // Validate checksum after truncating the message to its exact length.
+ if Cmdq::calculate_checksum(
+ SBufferIter::new_reader([header.as_bytes(), slice_1, slice_2]).take(header.length()),
+ ) != 0
+ {
+ dev_err!(&self.dev, "GSP receive: bad checksum\n");
+ return Err(EIO);
+ }
+
dev_dbg!(
&self.dev,
"GSP RPC: receive: seq# {}, function={:?}, length=0x{:x}\n",
@@ -820,21 +829,6 @@ fn wait_for_msg(&self, timeout: Delta) -> Result<GspMessage<'_>> {
)
};
- // Validate checksum.
- if Cmdq::calculate_checksum(SBufferIter::new_reader([
- header.as_bytes(),
- slice_1,
- slice_2,
- ])) != 0
- {
- dev_err!(
- &self.dev,
- "GSP RPC: receive: Call {} - bad checksum\n",
- header.sequence()
- );
- return Err(EIO);
- }
-
Ok(GspMessage {
header,
contents: (slice_1, slice_2),
--
2.56.0