Re: [PATCH v5 3/5] alpha: bound EV6 logout decoding by the processor area
From: Matt Turner
Date: Fri Oct 09 2026 - 21:38:56 EST
On Fri, Oct 9, 2026, Magnus Lindholm wrote:
> The ES40 correctable logout frame has only the common CPU registers before
> its system area at offset 0x58. The EV6 decoder treats those system words
> as extra CPU registers and reads beyond the 0x80-byte frame.
Is the short frame specific to the ES40? I would have guessed it comes
from the common EV6 PALcode, in which case Titan and Nautilus have had the
same problem. If you know either way, please say so here.
> + if (mchk_header->proc_offset != offsetof(struct el_common_EV6_mcheck,
> + I_STAT) ||
> + mchk_header->sys_offset < offsetof(struct el_common_EV6_mcheck,
> + EXC_ADDR) ||
> + mchk_header->sys_offset > mchk_header->size ||
> + ((mchk_header->sys_offset | mchk_header->size) & 7)) {
> + if (print)
> + printk("%s Invalid EV6 logout frame: size %x, CPU %x, system %x\n",
> + err_print_prefix, mchk_header->size,
> + mchk_header->proc_offset, mchk_header->sys_offset);
> + return MCHK_DISPOSITION_UNKNOWN_ERROR;
> + }
ev6_process_logout_frame() is also called for Titan and Nautilus, and
this has only been run on an ES40. If some other firmware builds its
frame a little differently, we now print this one line and throw the
contents away. Before the patch an unknown error at least got the frame
dumped.
Could the failure path dump the frame raw with mchk_dump_mem(), with the
length taken from size and capped at something sane? Then a frame we
reject is still there to look at.
The rest looks good to me.