Page MenuHomeFreeBSD

stand/powerpc/ofw: do not truncate device tree properties to 1024 bytes
ClosedPublic

Authored by pkubaj on Mon, Sep 28, 9:14 AM.
Tags
None
Referenced Files
F173916617: D60086.diff
Tue, Sep 29, 8:21 AM
F173857848: D60086.id187861.diff
Mon, Sep 28, 10:47 PM
F173846915: D60086.diff
Mon, Sep 28, 9:06 PM
Unknown Object (File)
Mon, Sep 28, 11:06 AM
Unknown Object (File)
Mon, Sep 28, 11:04 AM
Subscribers

Details

Summary

When the OpenFirmware loader flattens the firmware device tree into the FDT it hands to the kernel (usefdt=1, i.e. on every real-mode OF system such as pSeries LPARs and QEMU pseries guests), add_node_to_fdt() clamps every property value to 1024 bytes. Any larger property reaches the kernel truncated.

On QEMU pseries the PCI host bridge's "interrupt-map" is 3584 bytes (32 slots x 4 pins x 7 cells), so only the entries for slots 0-8 survive and the entry for slot 9 is cut in the middle. A PCI device in slot 9 or above therefore gets no INTx routing (irq 0), and with INVARIANTS the partial trailing entry trips the "ofw_bus_search_intrmap: truncated map" assertion in ofw_bus_search_intrmap() during PCI attach, panicking the kernel as soon as such a device is present. "ibm,drc-indexes", "ibm,drc-names" and "ibm,drc-power-domains" are cut the same way.

Drop the clamp. fdt_setprop() already reports a property that does not fit into the FDT buffer, so no separate limit is needed.

Fixes: 5ecf8e3852a9

Test Plan

FreeBSD/powerpc64 16.0-CURRENT (GENERIC64, INVARIANTS) QEMU pseries guest booted through SLOF, with a virtio-gpu-pci device in PCI slot 9.

Before: the kernel panics during PCI attach with "ofw_bus_search_intrmap: truncated map"; /dev/openfirm reports "interrupt-map", "ibm,drc-indexes", "ibm,drc-names" and "ibm,drc-power-domains" as exactly 1024 bytes each. On 15.1 guests (no INVARIANTS) the same device attaches with "irq 0".

After (patched loader installed as /boot/loader, boot1.elf in the PReP partition unchanged): the guest boots, the device gets irq 4609, and the kernel sees interrupt-map at 3584 bytes and the ibm,drc-* properties at 1028-1174 bytes. Devices in slots 1-8 keep the interrupts they had before.

Not tested on powerpc64le or on real pSeries hardware.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

should there be a larger length limit?

This revision is now accepted and ready to land.Mon, Sep 28, 9:21 PM

There are some OF properties (interrupt-map, ibm,drc-*), that grow with the number of slots and DRCs, so no.